Final guidelines on breach notification under GDPR
I’ve been engaged with data breach notification for many years and from many perspectives. I wrote what was probably the first ever breach notification letter in 2002, before California’s landmark law had taken effect.
The breach that inspired the law took place in a state server and exposed the personal information, including Social Security numbers, of more than a quarter-million state government employees. It was discovered in the spring of 2002, while the legislation requiring notification would not be in effect until July 2003.
Source: Once more, into the breach: Final guidelines on notification under GDPR