Breach notification
A 72-hour deadline to notify a security breach to the supervisory authority when it poses a risk to data subjects.
Breach register
Documenting every breach detected, even if not notified, with its analysis and the measures taken.
Data processing agreements
A formal agreement with every supplier that processes personal data on the organization's behalf, with the guarantees the GDPR requires.
What an auditor usually asks for
- Breach detection and notification procedure
- Security breach register documented
- Data processing agreements with all relevant suppliers
- Breach response drill carried out
How to cover this block in Kimobox
- 1Log every security breach detected with its timeline and analysis in Kimobox.
- 2Track the 72-hour notification deadline from the dashboard.
- 3Manage data processing agreements from the supplier portal.
The breach notification deadline stays under control from minute one, with nothing depending on a manual alert.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- Regulation (EU) 2016/679, General Data Protection Regulation EUR-Lex · Applicable since 25 May 2018
- Organic Law 3/2018 on Data Protection and guarantee of digital rights BOE-A-2018-16673 · 6 December 2018
- Spanish Data Protection Agency AEPD · Supervisory authority