The Guidelines aim to assist data controllers in identifying breaches, assessing risks, and implementing appropriate measures, based on the collective experiences of EEA supervisory authorities since the GDPR's implementation. The guidelines cover breach categorization (confidentiality, integrity, availability), risk assessment, notification requirements, and appropriate breach mitigation measures. Additionally, the document provides fictitious case studies based on real experiences to guide controllers in assessing and handling various types of data breaches.
Author: European Data Protection Board
Status: Adopted / Published
Adoption date: 2021-12-14
Last updated: 02 Sept 2025
Category: Guidance
Subcategory: Official guidance