Our own servers in Europe · GDPR · Support in your language

Module 6 of 6 · GDPR · Block 6

Security breaches and data processors

The final block covers two critical obligations: notifying security breaches on time and controlling those who process data on the company's behalf.

Content reviewed on

Breach notification

A 72-hour deadline to notify a security breach to the supervisory authority when it poses a risk to data subjects.

Breach register

Documenting every breach detected, even if not notified, with its analysis and the measures taken.

Data processing agreements

A formal agreement with every supplier that processes personal data on the organization's behalf, with the guarantees the GDPR requires.

What an auditor usually asks for

  • Breach detection and notification procedure
  • Security breach register documented
  • Data processing agreements with all relevant suppliers
  • Breach response drill carried out

How to cover this block in Kimobox

  1. 1Log every security breach detected with its timeline and analysis in Kimobox.
  2. 2Track the 72-hour notification deadline from the dashboard.
  3. 3Manage data processing agreements from the supplier portal.

The breach notification deadline stays under control from minute one, with nothing depending on a manual alert.

See Kimobox's supplier management

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. Regulation (EU) 2016/679, General Data Protection Regulation EUR-Lex · Applicable since 25 May 2018
  2. Organic Law 3/2018 on Data Protection and guarantee of digital rights BOE-A-2018-16673 · 6 December 2018
  3. Spanish Data Protection Agency AEPD · Supervisory authority