Should the breach register also document infringements of personal data protection law identified, for example, during an audit?
ANSWER
The breach register collects personal data breaches within the meaning of Article 4(12) GDPR, i.e. security breaches leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to personal data transmitted, stored or otherwise processed. This concept is not the same as an infringement of the GDPR — e.g. the controller's failure to fulfil information obligations or retaining data longer than necessary. In other words, the register records breaches of data protection, not infringements of GDPR provisions.


