The GDPR's Rules on Data Breaches: Analysing Their Rationales and Effects

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Borgesius, Frederik Zuiderveen, Asghari, Hadi, Bangma, Noël, Hoepman, Jaap-Henk
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909342710628352
author Borgesius, Frederik Zuiderveen
Asghari, Hadi
Bangma, Noël
Hoepman, Jaap-Henk
author_facet Borgesius, Frederik Zuiderveen
Asghari, Hadi
Bangma, Noël
Hoepman, Jaap-Henk
contents The General Data Protection Regulation (GDPR) requires an organisation that suffers a data breach to notify the competent Data Protection Authority. The organisation must also inform the relevant individuals, when a data breach threatens their rights and freedoms. This paper focuses on the following question: given the goals of the GDPR's data breach notification obligation, and we assess the obligation in the light of those goals. We refer to insights from information security and economics, and present them in a reader-friendly way for lawyers. Our main conclusion is that the GDPR's data breach rules are likely to contribute to the goals. For instance, the data breach notification obligation can nudge organisations towards better security; such an obligation enables regulators to perform their duties; and such an obligation improves transparency and accountability. However, the paper also warns that we should not have unrealistic expectations of the possibilities for people to protect their interests after a data breach notice. Likewise, we should not have high expectations of people switching to other service providers after receiving a data breach notification. Lastly, the paper calls for Data Protection Authorities to publish more information about reported data breaches. Such information can help to analyse security threats.
format Preprint
id arxiv_https___arxiv_org_abs_2410_06086
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle The GDPR's Rules on Data Breaches: Analysing Their Rationales and Effects
Borgesius, Frederik Zuiderveen
Asghari, Hadi
Bangma, Noël
Hoepman, Jaap-Henk
Cryptography and Security
Computers and Society
The General Data Protection Regulation (GDPR) requires an organisation that suffers a data breach to notify the competent Data Protection Authority. The organisation must also inform the relevant individuals, when a data breach threatens their rights and freedoms. This paper focuses on the following question: given the goals of the GDPR's data breach notification obligation, and we assess the obligation in the light of those goals. We refer to insights from information security and economics, and present them in a reader-friendly way for lawyers. Our main conclusion is that the GDPR's data breach rules are likely to contribute to the goals. For instance, the data breach notification obligation can nudge organisations towards better security; such an obligation enables regulators to perform their duties; and such an obligation improves transparency and accountability. However, the paper also warns that we should not have unrealistic expectations of the possibilities for people to protect their interests after a data breach notice. Likewise, we should not have high expectations of people switching to other service providers after receiving a data breach notification. Lastly, the paper calls for Data Protection Authorities to publish more information about reported data breaches. Such information can help to analyse security threats.
title The GDPR's Rules on Data Breaches: Analysing Their Rationales and Effects
topic Cryptography and Security
Computers and Society
url https://arxiv.org/abs/2410.06086