Almost nobody at an SME knows what they have to do the morning they discover someone got into their email, that a laptop with the customer list was left in a taxi, or that the invoicing system woke up encrypted. They call whoever looks after IT, try to recover what they can and hope nothing comes of it. Meanwhile a clock is running that few have heard about.
The GDPR gives 72 hours from the moment the company becomes aware of the breach to notify the data protection authority (in Spain, the AEPD), unless the breach is unlikely to pose a risk to people. If the risk is high, the people affected must be told as well, without delay. And whether it is notified or not, everything has to be written down. The fines we read about in the press rarely punish the attack itself. They punish not being prepared, and informing late or badly.
The basics fit in four rules that do not require knowing IT.
- A breach does not need a hacker. An email sent to the wrong recipient, a lost laptop or a ransomware that only encrypts the data without stealing it are breaches too. What counts is that personal data was lost, altered or seen by someone who should not have seen it.
- The clock starts when you know. Not when a technical report confirms it weeks later. From that moment there are 72 hours to notify the authority, and you can notify with what you know and complete it later. Being late means explaining why.
- Tell the people affected, without delay and in their language. If the risk to them is high, they must be told what happened, what could happen to them, what they can do and who to ask. In plain language, not lawyers' language.
- Everything gets written down, even if nobody is notified. The internal breach register is mandatory. What happened, what effect it had, what was done and, if it was not notified, why not. That sheet is the first thing the regulator will ask for.
The question is not technical. If your customers' data is stolen tomorrow morning, who calls whom, and by when?
Three signs show this needs attention. Nobody could say who gets called first. The contract with the supplier that holds the data does not say within how many hours they must warn you if it happens to them. And the last email sent to the wrong person was settled with a "sorry" and never written down anywhere.
To bring it down to practice we have prepared a downloadable two-page guide. The first page sums up the essentials. What a breach is and is not, the four rules and the terms worth knowing. The second is the tool, a printable checklist of the first 72 hours in four stages, from hour zero to closure, which once filled in and filed also serves as the internal record of the incident.
That the conversation with the regulator afterwards has a price is something we saw in the AEPD fine to Flexicar. The regulator did not fine the company for suffering the attack. It fined them for not being prepared for it.
