1 It should be ascertained whether all appropriate technological protection and organisational measures have been implemented to establish immediately whether a personal data breach has taken place and to inform promptly the supervisory authority and the data subject. 2 The fact that the notification was made without undue delay should be established taking into account in particular the nature and gravity of the personal data breach and its consequences and adverse effects for the data subject. 3 Such notification may result in an intervention of the supervisory authority in accordance with its tasks and powers laid down in this Regulation.
This recital of the General Data Protection Regulation clarifies article 33 GDPR (Notification of a personal data breach to the supervisory authority) and article 34 GDPR (Communication of a personal data breach to the data subject).*