Article 93 — Communication of a personal data breach to the data subject

Forordning (EU) 2018/1725 — databeskyttelse for EU-institusjoner

I rettsaktenEU 2018/1725
CELEX32018R1725
Lest2026-08-14

Offisiell tekst

Lest hos EUs publikasjonskontor for dette CELEX-nummeret. Ordlyden står slik den er publisert, ingenting er skrevet om eller sammenfattet.

Teksten vises på engelsk. Norsk er ikke et offisielt EU-språk, så den offisielle ordlyden finnes ikke på norsk.

1. Where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.

2. The communication to the data subject referred to in paragraph 1 of this Article shall describe in clear and plain language the nature of the personal data breach and shall contain at least the information and the recommendations provided for in points (b), (c) and (d) of Article 92(2).

3. The communication to the data subject referred to in paragraph 1 shall not be required if any of the following conditions are met:

(a) the controller has implemented appropriate technological and organisational protection measures, and those measures were applied to the operational personal data affected by the personal data breach, in particular those that render the operational personal data unintelligible to any person who is not authorised to access it, such as encryption;

(b) the controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects referred to in paragraph 1 is no longer likely to materialise;

(c) it would involve a disproportionate effort. In such a case, there shall instead be a public communication or a similar measure whereby the data subjects are informed in an equally effective manner.

Artikkelen fortsetter i den offisielle teksten.

Åpne artikkelen på EUR-Lex

Teksten er sitert fra den offisielle kilden og er ikke juridisk rådgivning. En nasjonal domstol leser språkversjonen som binder i sin jurisdiksjon.

Tilbake til rettsakten · EU-rettsakter, lest helt ned til nasjonal lov

ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.

Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.