9.6.2—9.6.2
>Control Description
+ Data protection incidents (e.g. unauthorized access to personal data) are processed in a timely manner.
+ The requirements from 1.6 of the information security questionnaire also take into account data protection incidents or, alternatively, there is an emergency plan for dealing with data protection incidents.
+ In addition, procedures are established and documented to ensure the following aspects:
- immediate notification to the respective responsible person, as far as his order is affected
- Documentation of the incident handling activities
- Training of employees on the defined measures/processes
- Support of the respective controller in the processing of data protection incidents
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.