Have you had a personal data breach in the past three years that involved reporting to a governmental agency, notice to individuals (including voluntary notice), or notice to another organization or institution?
Explanation
Example Responses
Example Response 1
No, our organization has not experienced any personal data breaches in the past three years that required reporting to governmental agencies, notification to individuals, or notification to other organizations We maintain a comprehensive security incident response program that includes monitoring, detection, and containment procedures While we have experienced minor security events, none have risen to the level of a reportable personal data breach.
Example Response 2
Yes, in November 2021, we experienced a data breach affecting approximately 2,500 customer records containing names, email addresses, and encrypted passwords (no financial information was compromised) We reported this incident to the relevant data protection authorities in compliance with GDPR requirements and notified all affected individuals within 72 hours of discovery Following the incident, we conducted a thorough investigation with the assistance of a third-party forensics firm, implemented additional security controls including enhanced access management and encryption protocols, and conducted company-wide security awareness training We have since passed two independent security audits and have had no further incidents.
Example Response 3
We have not had any breaches requiring governmental reporting in the past three years However, we did experience a minor security incident in February 2022 where an employee's email account was compromised Our investigation determined that while the account contained some customer contact information, there was no evidence that the data was accessed or exfiltrated by the unauthorized party After consulting with our legal counsel and following our incident response procedures, we determined that this incident did not meet the threshold requirements for mandatory reporting under applicable regulations As a precautionary measure, we reset all potentially affected passwords and implemented multi-factor authentication across all employee accounts.
Context
- Tab
- Privacy
- Category
- General Privacy

