9. Data breach notifications
- In the event of a personal data breach, Decentriq shall cooperate with and assist Controller for the latter to comply with its obligations pertaining to personal data breaches under applicable data protection laws, where applicable, taking into account the nature of processing and the information available to Decentriq.
- Data breach concerning the Data by Controller:
In the event of a personal data breach concerning the Data processed by Controller, Decentriq shall assist Controller:
- in notifying the personal data breach to the competent supervisory authority/ies, without undue delay after Controller has become aware of it, where relevant, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons;
- in obtaining the following information which shall be stated in the Controller’s notification, and must at least include:
- the nature of the personal data including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- the likely consequences of the personal data breach;
- the measures taken or proposed to be taken by Controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay.
- in complying with the obligation to communicate without undue delay the personal data breach to the affected data subjects, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons.
- Data breach concerning Data processed by Decentriq:
In the event of a personal data breach concerning data processed by Decentriq, the latter shall notify Controller without undue delay after having become aware of the breach. Such notification shall contain, at least:
- a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects and data records concerned);
- the details of a contact point where more information concerning the personal data breach can be obtained;
- its likely consequences and the measures taken or proposed to be taken to address the breach, including to mitigate its possible adverse effects.
Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay.
The parties shall set out in the Annex all other elements to be provided by Decentriq, if any, when assisting Controller in the compliance with Controller’s data breach notification obligations under applicable data protection laws.
- Controller acknowledges that (i) any personal data breach related to the Data is unlikely to result in a in a high risk or any risk at all to the rights and freedoms of the affected data subjects, since the Data is encrypted on hardware-level and can only be processed through the Service by authorized end users and (ii) Decentriq cannot provide any assistance that would require it to access or have accessed any unencrypted Data (e.g. to verify the types of data subjects, type of data or volumes of data affected by a data breach).