Notifying the authority and closing

Notifying the authority and closing

How to generate the notification to the authority, communicate to data subjects and close the incident.

When to notify the authority

Notification to the authority is mandatory within 72 hours if the breach may pose a risk to the rights and freedoms of natural persons. Privacta automatically assesses the obligation based on the data entered in the incident record.

Risk level Authority notification Communication to data subjects
Low No No
Medium Yes (within 72h) No
High Yes (within 72h) Yes (without undue delay)

Generating the draft notification

  1. From the incident record, click Generate authority notification
  2. Privacta pre-fills the official form with the information already entered in the record
  3. Review and complete the missing sections
  4. Have the notification approved by the DPO before sending

The draft generated by Privacta follows the format recommended by the Italian data protection authority. Always verify the information is accurate before official submission.

Communicating to data subjects

If the breach poses a high risk, you must communicate it directly to the people involved. Privacta assists you in drafting the communication, which must include:

  • Nature of the breach and data involved
  • Contact details of the DPO or privacy contact
  • Possible consequences of the incident
  • Measures taken and advice for data subjects

Closing the incident

After completing all the required actions:

  1. Verify that all corrective measures have been implemented
  2. Document the lessons learned in the incident record
  3. Click Close incident — the closure is recorded in the audit trail with date and user

Closed incidents remain in the internal register and are accessible for future audits or authority inspections.

📄 Add an example of a generated authority notification and the DPO approval flow