Skip to main content
GDPR-ADVANCED5 MIN READ

Write a Breach Risk Memo

Create a breach risk memo that supports Article 33 and Article 34 notification decisions.

A stolen laptop may expose an HR spreadsheet with salary bands, performance ratings, and manager comments for 320 employees. Breach memo = facts -> data sensitivity -> likelihood -> severity -> controls -> residual risk -> notification decision. The common shortcut is to focus on whether the company feels embarrassed or whether encryption exists, instead of assessing residual risk to employees. Facts Laptop stolen; HR spreadsheet exported; 320 employees affected; password may be stored on device. Separate known facts from assumptions. That makes updates easier. Severity Salary bands, ratings, and comments could create financial, reputational, and employment harm if misused.…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us