We act fast when your data is exposed. An email sent to the wrong recipient, ransomware or a stolen laptop can be a personal data breach. If it is likely to result in a risk to people, the GDPR requires notifying the AEPD without undue delay and, at the latest, within 72 hours of becoming aware of it. We help you decide whether to notify, do it properly and prevent it from happening again.
Has this happened to you?
If you recognise any of these situations, you may be facing a security breach:
- You sent an email containing personal data to the wrong recipient or with all addresses visible.
- Ransomware has encrypted your computers or servers.
- Someone on your team fell for a phishing email and handed over their credentials.
- A laptop, mobile phone or USB stick containing data has been lost or stolen.
- A supplier tells you it has suffered an attack.
- A former employee has taken customer data.

