TL;DR for the DPO
The Art. 33 exemption applies where a breach is UNLIKELY to result in a risk. Citing the EDPB, the UODO recalls that this must be read narrowly: unlikely means the risk has no realistic possibility of materialising, not that it looks modest. When in doubt, notify - and write down why.
The facts
The municipality published a petition in its Public Information Bulletin without anonymising it. The document contained the names, surnames, home addresses and signature specimens of the 749 people who had signed it. The authority did not learn of it from a notification: it learned from a complaint by one of the people whose data had gone online.
The mayor explained that it had been an unintentional error and that the file had been replaced with the correct one. During the proceedings it emerged that the wrong file had remained accessible on the site for around ten days. He also asked for the failure-to-notify proceedings to be discontinued, arguing that proceedings on an individual complaint were already open on the same matter.
Why that defence fails
An individual complaint and own-motion proceedings look at different things: the first protects the rights of the complainant, the second checks whether the controller met its own obligations. The UODO says so expressly: the complaint was the occasion to notice irregularities of a different nature from those complained of, and justified opening separate proceedings. The fact that the data subject was protected does not cure the omission towards the authority.
The point that applies to everyone
The authority accepts that in this case there was NO high risk to rights and freedoms. And it fines anyway. High risk is the Art. 34 threshold, for communication to data subjects; notification to the authority under Art. 33 is due at a far lower threshold, and falls away only where a risk is unlikely. They are two separate assessments, and conflating them is the most common mistake in breach handling.
What weighed on the amount
- The controller is a local authority, a public body from which the highest knowledge of the law is expected.
- The file stayed online for around ten days, not for a few minutes.
- The controller did not change position even after being prompted by the authority and after proceedings were opened.
- By the date of the decision the notification had still not been made.
What to do now, in practice
1) In the breach register, for every event closed without notification, check that the reason is written down: not 'low risk', but the reasoning why the risk is unlikely. That reasoning is what gets examined. 2) If a client publishes documents on notice boards, bulletins or transparency sections, publication should be logged as a processing activity in the Art. 30 records, with a documented anonymisation step before going online. 3) A data subject complaint does not discharge obligations towards the authority: they run on separate tracks. 4) If you realise late that a notification was due, make it anyway and explain the delay: here the cost came from persisting, not from the original error.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free