Luxembourg DPA Publishes Data Breach Reporting Form
On February 12, 2018, the Luxembourg data protection authority ( Commission nationale pour la protection des donées , “CNPD”) published on its website (in English and French ) a form to be used for the purpose of compliance with data breach notification requirements applicable under the EU General Data Protection Regulation (the “GDPR”).
Pursuant to the GDPR, data controllers must notify the competent supervisory authority of a data breach within 72 hours of becoming aware of it, if the breach is likely to result in a risk to the rights and freedoms of individuals. Though breach notification is currently not required under the EU Data Protection Directive 95/46/EC, the CNPD has already published the form to assist companies with breach reporting prior to the GDPR coming into force.