Salta al contenuto principale

Practical guide

How to keep a data breach register in your firm

The GDPR requires the controller to document any personal data breach, regardless of whether it is later notified to the supervisory authority. For a condominium management firm this means keeping an internal breach register, a tool too often overlooked until it is needed. The register is not the notification to the authority: it is the archive gathering every incident, its assessment and the measures taken. This guide explains what to record for each event, how to assess severity, when notification becomes mandatory and how to organise it all with a checklist.

What to record for each breach

  1. Date and time of the event and of the moment it was discovered.
  2. A description of what happened and how it was detected.
  3. Categories and approximate number of data subjects and records involved.
  4. Likely consequences for the data subjects.
  5. Measures taken to contain and remedy the breach.
  6. The risk assessment and the decision whether to notify the authority and the data subjects.
  7. The reasoning behind the decision, even when not notifying.

Why the register must always be kept

Article 33(5) of the GDPR requires the controller to document any personal data breach, including the circumstances, the consequences and the measures taken. This documentation enables the supervisory authority to verify compliance. In practice this means the register must be kept even for incidents that do not require notification, and even an empty register shows that the firm has organised event management.

A breach is not just the dramatic cyberattack. In a condominium the most common cases are mundane and frequent: a statement sent by mistake to the wrong owner, an arrears list ending up in the wrong hands, a lost device, a compromised password. All these events are breaches of the confidentiality or availability of data and must be recorded.

How to assess the severity of an event

To decide how to react you must assess the risk to the rights and freedoms of data subjects. What matters is the nature of the data involved, the number of people affected, how easily they can be identified and the possible consequences, such as financial harm, discrimination or reputational damage. An email address disclosed by mistake carries a different weight than a list of debt situations or health data.

The assessment must be made and documented for every event, even when it concludes that the risk is low. Recording the reasoning is essential: it shows that the decision not to notify, when that is the choice, is reasoned and not the result of carelessness.

  • Nature of the data: ordinary, financial, special categories such as health data.
  • Number and identifiability of the data subjects involved.
  • Possible concrete consequences for the people affected.
  • Reversibility of the breach and measures already in place.
  • Likelihood that the data is actually used in a harmful way.

When notification is triggered

If the breach entails a risk to the rights and freedoms of data subjects, the controller must notify the supervisory authority without undue delay and, where feasible, within seventy-two hours of becoming aware of it. If the risk is high, the data subject must also be informed, in clear language, except for the exceptions provided by the rule.

In the condominium context, the administrator who manages the processing on behalf of the controller must promptly activate the communication chain. The register serves precisely to save time: if every event is already documented with times, assessment and measures, the decision whether to notify comes faster and is more solid.

Organising the register and linking it to incident response

The register must be kept in an orderly format with reliable dates, so that each line can be reconstructed later. It helps to pair it with an internal incident response procedure that sets out who to contact, how to contain the event and who decides on notification: register and procedure together make the reaction fast and consistent.

Software that centralises documents, communications and operation tracking helps both to reduce breaches and to document them when they happen, because it lets you trace who did what and when. AmministraPro's features are described on the /funzioni page and the plans on the /prezzi page.

Frequently asked questions

Must the breach register be kept even if there have never been incidents?

Yes. The duty under Article 33 of the GDPR concerns documenting every breach, but setting up the register is part of organising compliance. An existing empty register shows that the firm is ready to handle an incident, while the total absence of a tool is itself a sign of disorganisation.

Must every breach be notified to the authority?

No. Notification is mandatory only when the breach entails a risk to the rights and freedoms of data subjects. If the risk is unlikely, notification is not due, but the event must still be recorded together with the assessment that led to not notifying.

Within what time must notification be made?

When due, notification to the supervisory authority must be made without undue delay and, where feasible, within seventy-two hours of the controller becoming aware of the breach. If notification occurs beyond this deadline, it must be accompanied by the reasons for the delay.

Is sending to the wrong recipient a breach to be recorded?

Yes. Sending a document with personal data to the wrong owner is a confidentiality breach and must be recorded in the register with a risk assessment. Often the risk is limited and does not require notification, but recording and assessment remain due in any case.

Try AmministraPro

Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.