Notification Period. The GDPR states that a report must be submitted 'immediately'. According to the Data Protection Authority, this means without undue delay and, if possible, no later than 72 hours after its discovery by the data subject. If a security incident occurs, AgroVision will notify the customer as soon as possible, but no later than 48 hours after its discovery of the security incident. The customer will have to make its own assessment as to whether the security incident qualifies as a 'data leak' and must be reported to the Data Protection Authority. AgroVision will keep the customer informed on progress and the measures taken. AgroVision records all security incidents and handles them according to a standard procedure (workflow).
Appears in 2 contracts
Sources: Data Processing Agreement, Data Processing Agreement