Common use of Notification of personal data breach Clause in Contracts

Notification of personal data breach. In the event of a personal data breach, the processor shall cooperate with and assist the controller for the controller to comply with its obligations under Articles 33 and 34 of Regulation (EU) 2016/679, where applicable, taking into account the nature of processing and the information available to the processor. 9.1 Data breach concerning data processed by the controller a) in notifying the personal data breach to the competent supervisory authority/ies, without undue delay after the controller has become aware of it, where relevant (unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons); b) in obtaining the following information which, pursuant to Article 33(3) of Regulation (EU) 2016/679, shall be stated in the controller’s notification, and must at least include: 1) the nature of the personal data including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned; 2) the likely consequences of the personal data breach; 3) the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects. Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay. c) in complying, pursuant to Article 34 of Regulation (EU) 2016/679, with the obligation to communicate without undue delay the personal data breach to the data subject, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons. 9.2 Data breach concerning data processed by the processor a) a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects and data records concerned); b) the details of a contact point where more information concerning the personal data breach can be obtained; c) its likely consequences and the measures taken or proposed to be taken to address the breach, including to mitigate its possible adverse effects. Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay. The Parties shall set out in Annex III all other elements to be provided by the processor when assisting the controller in the compliance with the controller’s obligations under Articles 33 and 34 of Regulation (EU) 2016/679.

Appears in 2 contracts

Sources: Data Processing Agreement, Data Processing Agreement

Notification of personal data breach. In the event of a personal data breach, the processor shall cooperate with and assist the controller for the controller to comply with its obligations under Articles 33 and 34 of Regulation (EU) 2016/679, where applicable, taking into account the nature of processing and the information available to the processor. 9.1 Data breach concerning data processed by the controller In the event of a personal data breach concerning data processed by the controller, the processor shall assist the controller: a) in notifying the personal data breach to the competent supervisory authority/ies, without undue delay after the controller has become aware of it, where relevant (unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons); b) in obtaining the following information which, pursuant to Article 33(3) of Regulation (EU) 2016/679, shall be stated in the controller’s notification, and must at least include: 1) . the nature of the personal data including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned; 2) . the likely consequences of the personal data breach; 3) . the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects. . c) Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay.; cd) in complying, pursuant to Article 34 of Regulation (EU) 2016/679, with the obligation to communicate without undue delay the personal data breach to the data subject, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons. 9.2 Data breach concerning data processed by the processor In the event of a personal data breach concerning data processed by the processor, the processor shall notify the controller without undue delay after the processor having become aware of the breach. Such notification shall contain, at least: a) a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects and data records concerned); b) the details of a contact point where more information concerning the personal data breach can be obtained; c) its likely consequences and the measures taken or proposed to be taken to address the breach, including to mitigate its possible adverse effects. Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay. The Parties shall set out in Annex III all other elements to be provided by the processor when assisting the controller in the compliance with the controller’s obligations under Articles 33 and 34 of Regulation (EU) 2016/679.

Appears in 2 contracts

Sources: Data Processing Agreement, Data Processing Agreement

Notification of personal data breach. In the event of a personal data breach, the processor shall cooperate with and assist the controller for the controller to comply with its obligations under Articles 33 and 34 of Regulation (EU) 2016/6792016/679 or [for GH being an EC/EU only] under Articles 34 and 35 of Regulation (EU) 2018/1725, where applicable, taking into account the nature of processing and the information available to the processor. 9.1 . Data breach concerning data processed by the controller In the event of a personal data breach concerning data processed by the controller a) , the processor shall assist the controller: in notifying the personal data breach to the competent supervisory authority/ies, without undue delay after the controller has become aware of it, where relevant relevant/ (unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons); b) . in obtaining the following information which, pursuant to Article 33(3) of Regulation (EU) 2016/6792016/679/ [for GH being an EC/EU only] Article 34(3) of Regulation (EU) 2018/1725, shall be stated in the controller’s notification, and must at least include: 1) : the nature of the personal data including where possible, the categories and approximate number of data subjects concerned concerned, and the categories and approximate number of personal data records concerned; 2) . the likely consequences of the personal data breach; 3) . the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects. Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay. c) . in complying, pursuant to Article 34 of Regulation (EU) 2016/6792016/679 / [for GH being an EC/EU only] Article 35 of Regulation (EU) 2018/1725, with the obligation to communicate without undue delay the personal data breach to the data subject, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons. 9.2 . Data breach concerning data processed by the processor In the event of a personal data breach concerning data processed by the processor a) , the processor shall notify the controller without undue delay after the processor having become aware of the breach. Such notification shall contain, at least: a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects and data records concerned); b) . the details of a contact point where more information concerning the personal data breach can be obtained; c) . its likely consequences and the measures taken or proposed to be taken to address the breach, including to mitigate its possible adverse effects. Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay. The Parties shall set out in Annex III all other elements to be provided by the processor when assisting the controller in the compliance with the controller’s obligations under Articles 33 and 34 of Regulation (EU) 2016/6792016/679 / [for GH being an EC/EU only] Articles 34 and 35 of Regulation (EU) 2018/1725.

Appears in 1 contract

Sources: Cost Action Grant Agreement

Notification of personal data breach. In the event of a personal data breach, the processor shall cooperate with and assist the controller for the controller to comply with its obligations under Articles 33 and 34 of Regulation (EU) 2016/6792016/679 or under Articles 34 and 35 of Regulation (EU) 2018/1725, where applicable, taking into account the nature of processing and the information available to the processor. 9.1 Data breach concerning data processed by the controller (a) in notifying the personal data breach to the competent supervisory authority/ies, without undue delay after the controller has become aware of it, where relevant (unless relevant/(unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons); (b) in obtaining the following information which, pursuant to Article 33(3) of Regulation (EU) 2016/679, shall be stated in the controller’s notification, and must at least include: (1) the nature of the personal data including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned; (2) the likely consequences of the personal data breach; (3) the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects. Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay. (c) in complying, pursuant to Article 34 of Regulation (EU) 2016/679, with the obligation to communicate without undue delay the personal data breach to the data subject, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons. 9.2 Data breach concerning data processed by the processor (a) a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects and data records concerned); (b) the details of a contact point where more information concerning the personal data breach can be obtained; (c) its likely consequences and the measures taken or proposed to be taken to address the breach, including to mitigate its possible adverse effects. Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay. The Parties shall set out in Annex III all other elements to be provided by the processor when assisting the controller in the compliance with the controller’s obligations under Articles 33 and 34 of Regulation (EU) 2016/679.

Appears in 1 contract

Sources: Data Processing Agreement