Should violations of personal data protection regulations, such as the absence of information clauses discovered during an audit, be entered in the breach register, or do we only enter personal data breaches in the register?
ANSWER
Non-conformities with personal data protection regulations, such as the absence of information clauses, are included in the audit report and not in the breach register. The breach register should contain exclusively breaches as defined in Article 2(12), i.e. "personal data breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed.


