{"id":4100,"date":"2026-08-19T21:00:00","date_gmt":"2026-08-19T19:00:00","guid":{"rendered":"https:\/\/www.lablogic.pl\/?p=4100"},"modified":"2026-08-20T18:03:42","modified_gmt":"2026-08-20T16:03:42","slug":"what-should-a-personal-data-breach-register-contain","status":"publish","type":"post","link":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/","title":{"rendered":"What should a personal data breach register contain?"},"content":{"rendered":"\n<p class=\"ll-art-meta wp-block-paragraph\"><a href=\"https:\/\/www.lablogic.pl\/en\/michal-rutkowski\/\"><strong>Micha\u0142 Rutkowski<\/strong><\/a> &bull; for data protection officers and compliance teams &bull; published 19 August 2026 &bull; updated 19 August 2026 &bull; 7 min read<\/p>\n\n\n\n<div class=\"wp-block-columns ll-art-shell is-layout-flex wp-container-core-columns-is-layout-7387b849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column ll-art-rail is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-railinner is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-group ll-art-railcard is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\">On this page<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"#krotka-odpowiedz\">Short answer<\/a><\/li>\n\n\n\n<li><a href=\"#dlaczego\">Why the question arises at all<\/a><\/li>\n\n\n\n<li><a href=\"#co-ustalic\">What to establish before deciding<\/a><\/li>\n\n\n\n<li><a href=\"#bledy\">Common mistakes<\/a><\/li>\n\n\n\n<li><a href=\"#wnioski\">Conclusions and next steps<\/a><\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-group ll-art-railcard ll-art-railmeta is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\">Legal status<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>August 2026.<\/strong> The documentation obligation: Article 33(5) GDPR; the scope of an entry: the guidance of the President of the Personal Data Protection Office (UODO) of 20 February 2025, chapter 8; the basis of accountability: Article 5(2) GDPR.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Last substantive update: 19 August 2026.<\/p>\n<\/div>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column ll-art-main is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-answer is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 id=\"krotka-odpowiedz\" class=\"wp-block-heading\">Short answer<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The regulation does not speak of a register but of documentation: the controller documents any personal data breach, including the facts relating to it, its effects and the remedial action taken. The quality test is set by the second sentence of Article 33(5) GDPR &mdash; the documentation must enable the supervisory authority to verify compliance with that article as a whole. That also covers the finding that the decision not to notify a breach was correct. This is why the entries that call for the most content are those concerning breaches the controller did not notify.<\/p>\n<\/div>\n\n\n\n<h2 id=\"dlaczego\" class=\"wp-block-heading\">Why the question arises at all<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A breach register is often kept as a list of cases sent to the supervisory authority. What results is a document that duplicates knowledge the authority already has. It says nothing about the cases resolved internally &mdash; and those are the ones later subject to verification.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second source of confusion is terminological. Article 33(5) GDPR does not use the word &ldquo;register&rdquo; and imposes no form. The President of the Personal Data Protection Office (UODO) states expressly that an internal breach register may help in meeting the obligation. Keeping a separate record is not mandatory, however. What matters is that the information is clearly marked and available for inspection. The obligation is therefore an evidential result, not a table.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The third source is organisational and becomes visible only over time. An entry is usually created on the day the case is closed. It then contains a summary sufficient for the people who worked on it. A year later the same entry is read by someone else, most often for the purposes of proceedings. That is when it turns out that what is missing is not facts but reasons.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is also worth separating two documents that are confused because their names are similar. The record of processing activities under Article 30 GDPR describes what the organisation processes day to day and why. The breach documentation under Article 33(5) describes events and decisions. These are two different obligations with different evidential functions.<\/p>\n\n\n\n<h2 id=\"co-ustalic\" class=\"wp-block-heading\">What to establish before deciding<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What the regulation requires and what it does not<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The regulation requires three things.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Document <strong>any<\/strong> personal data breach.<\/li>\n\n\n\n<li>Cover the facts relating to the breach, its effects and the remedial action taken.<\/li>\n\n\n\n<li>Ensure that the documentation enables the supervisory authority to verify compliance with Article 33.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">It prescribes no form, no system and no template. Nor does it set a retention period. That latitude is sometimes read as leniency on the part of the regulation. The opposite is true &mdash; it is the controller who answers for whether the chosen form can carry the evidential function.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second sentence settles the matter. Verification covers <strong>the whole article<\/strong>, so it reaches paragraph 1 and the ground for not notifying as well. That ground rests on a finding that the breach is unlikely to result in a risk to the rights and freedoms of natural persons. It is precisely that conclusion which is reviewed. An entry without its reasoning gives the authority no material to verify and the controller no basis on which to defend itself.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Which events belong in the documentation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The scope is wider than the practice of most organisations suggests. It falls into three circles.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The first circle is breaches identified and notified to the authority. The second is breaches identified and not notified &mdash; the documentation obligation covers them in the same way, because the regulation speaks of any breach. The third circle goes beyond the letter of Article 33(5). The President of UODO recommends documenting also those security incidents which the controller has classified as events that are not personal data breaches. The recommendation covers the reasons for that decision in particular.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That recommendation rests on the accountability principle in Article 5(2) GDPR, not on a separate obligation. It carries practical weight nonetheless. Without it, the organisation cannot show that it considered an event the authority knows about from another source.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What a single entry has to contain<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The table below combines the elements listed in the regulation with the scope indicated in the guidance of the President of UODO. The third column shows what a given element is for. That is what settles how detailed the record needs to be.<\/p>\n\n\n\n<figure class=\"wp-block-table ll-art-table\"><table><thead><tr><th>Element of the entry<\/th><th>Where the requirement comes from<\/th><th>What it is for<\/th><\/tr><\/thead><tbody><tr><td>The facts: date and time of occurrence, of becoming aware and of closure; how it was detected; cause and course<\/td><td>Article 33(5) GDPR, UODO guidance<\/td><td>Establishing the moment of becoming aware, from which the notification deadline runs<\/td><\/tr><tr><td>Type and scope of the data, number and categories of data subjects<\/td><td>Article 33(3)(a), UODO guidance<\/td><td>The basis for assessing the severity of the potential impact<\/td><\/tr><tr><td>The effects and the possible effects for data subjects<\/td><td>Article 33(5) GDPR<\/td><td>Telling an effect that materialised from one that is merely possible<\/td><\/tr><tr><td><strong>The reasoning behind the risk assessment<\/strong><\/td><td>UODO guidance, the accountability principle<\/td><td>The element the authority verifies first<\/td><\/tr><tr><td>Remedial and preventive action<\/td><td>Article 33(5) GDPR<\/td><td>Showing the response and its effect on the risk of recurrence<\/td><\/tr><tr><td>Details of the notification <strong>or the reasons for the decision not to notify<\/strong><\/td><td>Article 33(1), UODO guidance<\/td><td>Verifying the ground for not notifying<\/td><\/tr><tr><td>Details of the communication to data subjects <strong>or the reasons for the decision not to communicate<\/strong><\/td><td>Article 34(3), UODO guidance<\/td><td>Showing which of the three exceptions applied<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The two rows in bold are what separates useful documentation from a list of events. The rest describes what happened. These two describe why the organisation acted as it did.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The reasoning behind a risk assessment is worth recording as reasoning, not as a result. The entry &ldquo;risk low&rdquo; says nothing about what the controller took into account. What can be checked is a record setting out the categories of data, the safeguards applied and the likelihood of harm that follows from them. It works even where the authority assesses the case differently.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The template below shows the shape of such a record. It does not describe an actual case; it is a skeleton to be filled in with the organisation&rsquo;s own data.<\/p>\n\n\n\n<div class=\"wp-block-group ll-art-note is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\">The breach covered the first name, surname and e-mail address of [number] data subjects. The data reached a single known external recipient as a result of an addressing error. The recipient confirmed deletion of the message; the confirmation has been retained in the case file. No identifiers enabling impersonation and no special categories of personal data were involved. The likelihood of further dissemination was assessed as low &mdash; there is one recipient, that recipient is known and deletion has been confirmed. The severity of the potential impact is limited by the scope of the data, which is contact data.<\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">That record can be checked. It sets out the scope of the data, the circumstance that limits the risk and the conclusion which follows from them. The formula &ldquo;low risk, case closed&rdquo; contains none of those three elements.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How the documentation changes over time<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">An entry is not closed once and for all. Information about a breach arrives in stages, and each new piece may change the risk assessment and the soundness of the earlier decision. The documentation is meant to mirror that and to keep a trace of the change, not only the final state.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This has a direct procedural consequence. A breach assessed at first as not requiring notification may require it once the full scope of the data is established. The moment the decision was taken can then be explained only by documentation showing when the controller learned of the new circumstance.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How long to keep it and what not to put in it<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The GDPR gives no period after which information about breaches may be erased. The President of UODO therefore recommends keeping it for as long as possible. A second, less obvious recommendation follows from the first. An internal register <strong>is neither required nor recommended to contain personal data<\/strong> &mdash; neither of the people affected by the breach nor of those involved in handling the case.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is the position broken most often in practice. Registers kept in spreadsheets usually contain the names of the people affected and of the authors of the entries. The result is a set of data kept indefinitely, for which a separate legal basis and retention period have to be established. The answer is to separate the layers: the register works with a case identifier and aggregated data, while material containing personal data sits in the case file with its own retention period.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Where personal data does end up in the record after all, the minimisation principle applies to it on ordinary terms.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Who keeps the documentation where processing is entrusted<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The obligation under Article 33(5) GDPR is addressed to the controller. The processor notifies the controller of a breach without undue delay and assists the controller in meeting the obligations under Articles 32 to 36, which includes documentation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The practical conclusion concerns the contract, not the regulation. The controller documents the facts of an event that took place in someone else&rsquo;s infrastructure. It therefore needs a contractual route to data on the time of detection, the scope and the course of events. A processing agreement providing for notification alone, with no scope for the information to be passed on, leaves the controller with an entry it cannot justify.<\/p>\n\n\n\n<h2 id=\"bledy\" class=\"wp-block-heading\">Common mistakes<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n<li><strong>A register covering notified breaches only.<\/strong> The obligation covers any breach. Entries on cases that were not notified are the ones actually subject to verification.<\/li>\n\n\n\n<li><strong>A risk assessment recorded as a result.<\/strong> &ldquo;Low risk&rdquo; is not a justification. What can be verified is the line of reasoning, not its conclusion.<\/li>\n\n\n\n<li><strong>Confusing breach documentation with the record of processing activities.<\/strong> These are two separate obligations with different subject matter &mdash; Article 30 describes processing, Article 33(5) describes events and decisions.<\/li>\n\n\n\n<li><strong>Keeping personal data in the register indefinitely.<\/strong> The recommendation to keep things for a long time concerns information about breaches, not data about people. Those two layers have to be separated when the record is designed.<\/li>\n\n\n\n<li><strong>No trace of events classified as non-breaches.<\/strong> A decision that an event is not a personal data breach calls for a record together with its reason.<\/li>\n\n\n\n<li><strong>An entry closed on the day of the event.<\/strong> The documentation is meant to be updated, because new information may change the risk assessment and force a notification after a deadline first treated as not running.<\/li>\n<\/ul>\n\n\n\n<h2 id=\"wnioski\" class=\"wp-block-heading\">Conclusions and next steps<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Breach documentation is evidence of a decision-making process, not a record of events. That single premise settles what it contains: an entry has to reconstruct what the organisation knew at a given moment and what conclusion it drew from that. Cases notified to the authority take the least work in this arrangement, because their justification already sits in the notification.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An order of work that proves itself where a register already exists.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Check whether the record holds entries on breaches that were not notified; their absence means the register does not perform the function under Article 33(5).<\/li>\n\n\n\n<li>Review the entries for the reasoning behind the risk assessment and complete those that give the result alone.<\/li>\n\n\n\n<li>Separate the register layer from the case file and remove from the register any personal data that is not needed there.<\/li>\n\n\n\n<li>Establish where information about breaches at processors comes from and whether the contracts secure it.<\/li>\n\n\n\n<li>Introduce a rule of updating the entry as information arrives, keeping a trace of the changes.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Documentation in good order also yields material available from no other source: the recurrence of mistakes of the same type. That is the right starting point for designing <a href=\"https:\/\/www.lablogic.pl\/en\/training-and-workshops-based-on-real-world-experience\/\">training matched to roles and processes<\/a>. It points to the processes in which events actually arise.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Related materials<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/\">Does every data breach need to be reported?<\/a><\/strong> &mdash; the notification threshold and the risk assessment whose outcome the register preserves.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/what-to-do-after-detecting-an-incident\/\">What to do after detecting an incident?<\/a><\/strong> &mdash; the sequence of actions that produces the entry.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/\">Cybersecurity incident vs personal data breach: what is the difference?<\/a><\/strong> &mdash; classifying the event before the entry is made.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Sources<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-sources\">\n<li>Regulation (EU) 2016\/679 of the European Parliament and of the Council (GDPR), Article 5(2), Article 24(1), Article 28(3)(f), Article 30, Article 33 and Article 34, consolidated text &mdash; EUR-Lex: <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:02016R0679-20160504\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a> (accessed 19 August 2026)<\/li>\n\n\n\n<li>President of the Personal Data Protection Office (UODO), &ldquo;Obligations of controllers relating to personal data breaches&rdquo;, version of 20 February 2025, chapter 8 &mdash; <a href=\"https:\/\/uodo.gov.pl\/pl\/598\/3563\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a> (in Polish, accessed 19 August 2026)<\/li>\n\n\n\n<li>European Data Protection Board, Guidelines 01\/2021 on examples regarding personal data breach notification, version 2.0 adopted on 14 December 2021 &mdash; <a href=\"https:\/\/www.edpb.europa.eu\/our-work-tools\/our-documents\/guidelines\/guidelines-012021-examples-regarding-personal-data-breach_en\" target=\"_blank\" rel=\"noreferrer noopener\">edpb.europa.eu<\/a> (accessed 19 August 2026)<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-group ll-art-author is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading\">Author<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Micha\u0142 Rutkowski<\/strong> &mdash; LabLogic. Combines legal, organisational and technological perspectives in work with the boards of medium and large organisations: support for and performance of the DPO role, NIS2 and KSC readiness, incident response, audits and training. Contact: M.Rutkowski@LabLogic.pl<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group ll-art-cta is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading\">Check whether your register will defend your decisions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The worth of a register shows only when a decision taken a year ago has to be explained. Putting the assessment of incidents and breaches in order covers a review of the existing entries and settles the scope the organisation is actually able to demonstrate.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/www.lablogic.pl\/en\/incidents-and-breaches-structured-response-and-sound-decisions\/\">Support with incidents and breaches<\/a><\/div>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group ll-art-disclaimer is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\">This material is general and educational. It is not individual legal advice or a recommendation for any specific organisation. The scope of obligations should be assessed in the light of that organisation&rsquo;s circumstances.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Legal status: August 2026.<\/strong><\/p>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Article 33(5) GDPR requires documentation, not a register in a prescribed form. The documentation has to let the supervisory authority verify compliance with the whole article, which is why the entries that call for the most content are those on breaches the controller did not notify.<\/p>\n","protected":false},"author":2,"featured_media":4286,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[71],"tags":[],"class_list":["post-4100","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-incidents"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"What a personal data breach register must contain under Article 33(5) GDPR, which events it covers and why unnotified breaches call for the most detail.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Micha\u0142 Rutkowski\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"LabLogic - Micha\u0142 Rutkowski | DPO, RODO, NIS2 i Cybersecurity w praktyce\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Breach register: scope of an entry and risk reasoning\" \/>\n\t\t<meta property=\"og:description\" content=\"What has to be in an entry and why unnotified breaches matter most.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t\t<meta property=\"article:section\" content=\"Incidents and Breaches\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-08-19T19:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-08-20T16:03:42+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Breach register: scope of an entry and risk reasoning\" \/>\n\t\t<meta name=\"twitter:description\" content=\"What has to be in an entry and why unnotified breaches matter most.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#article\",\"name\":\"Personal data breach register: what an entry must contain\",\"headline\":\"What should a personal data breach register contain?\",\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/user_lablogic\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg\",\"width\":1200,\"height\":630,\"caption\":\"What should a breach register contain? \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"datePublished\":\"2026-08-19T21:00:00+02:00\",\"dateModified\":\"2026-08-20T18:03:42+02:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#webpage\"},\"articleSection\":\"Incidents and Breaches, Optional\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"position\":1,\"name\":\"LabLogic\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/#listItem\",\"name\":\"Incidents and Breaches\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/#listItem\",\"position\":2,\"name\":\"Incidents and Breaches\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#listItem\",\"name\":\"What should a personal data breach register contain?\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"name\":\"LabLogic\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#listItem\",\"position\":3,\"name\":\"What should a personal data breach register contain?\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/#listItem\",\"name\":\"Incidents and Breaches\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\",\"name\":\"Micha\\u0142 Rutkowski - LabLogic\",\"description\":\"DPO, RODO, NIS2 i Cybersecurity w praktyce\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"telephone\":\"+48586231777\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2020\\\/03\\\/LABLOGIC_LOGO2.png\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/user_lablogic\\\/#author\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/user_lablogic\\\/\",\"name\":\"Micha\\u0142 Rutkowski\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Micha\\u0142 Rutkowski\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#webpage\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/\",\"name\":\"Personal data breach register: what an entry must contain\",\"description\":\"What a personal data breach register must contain under Article 33(5) GDPR, which events it covers and why unnotified breaches call for the most detail.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/user_lablogic\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/user_lablogic\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#mainImage\",\"width\":1200,\"height\":630,\"caption\":\"What should a breach register contain? \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#mainImage\"},\"datePublished\":\"2026-08-19T21:00:00+02:00\",\"dateModified\":\"2026-08-20T18:03:42+02:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"name\":\"Micha\\u0142 Rutkowski - LabLogic\",\"alternateName\":\"LabLogic\",\"description\":\"DPO, RODO, NIS2 i Cybersecurity w praktyce\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Personal data breach register: what an entry must contain","description":"What a personal data breach register must contain under Article 33(5) GDPR, which events it covers and why unnotified breaches call for the most detail.","canonical_url":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#article","name":"Personal data breach register: what an entry must contain","headline":"What should a personal data breach register contain?","author":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/user_lablogic\/#author"},"publisher":{"@id":"https:\/\/www.lablogic.pl\/en\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg","width":1200,"height":630,"caption":"What should a breach register contain? \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"datePublished":"2026-08-19T21:00:00+02:00","dateModified":"2026-08-20T18:03:42+02:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#webpage"},"isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#webpage"},"articleSection":"Incidents and Breaches, Optional"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","position":1,"name":"LabLogic","item":"https:\/\/www.lablogic.pl\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/#listItem","name":"Incidents and Breaches"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/#listItem","position":2,"name":"Incidents and Breaches","item":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#listItem","name":"What should a personal data breach register contain?"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","name":"LabLogic"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#listItem","position":3,"name":"What should a personal data breach register contain?","previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/#listItem","name":"Incidents and Breaches"}}]},{"@type":"Organization","@id":"https:\/\/www.lablogic.pl\/en\/#organization","name":"Micha\u0142 Rutkowski - LabLogic","description":"DPO, RODO, NIS2 i Cybersecurity w praktyce","url":"https:\/\/www.lablogic.pl\/en\/","telephone":"+48586231777","logo":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2020\/03\/LABLOGIC_LOGO2.png","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#organizationLogo"},"image":{"@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/www.lablogic.pl\/en\/author\/user_lablogic\/#author","url":"https:\/\/www.lablogic.pl\/en\/author\/user_lablogic\/","name":"Micha\u0142 Rutkowski","image":{"@type":"ImageObject","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","width":96,"height":96,"caption":"Micha\u0142 Rutkowski"}},{"@type":"WebPage","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#webpage","url":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/","name":"Personal data breach register: what an entry must contain","description":"What a personal data breach register must contain under Article 33(5) GDPR, which events it covers and why unnotified breaches call for the most detail.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/#website"},"breadcrumb":{"@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#breadcrumblist"},"author":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/user_lablogic\/#author"},"creator":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/user_lablogic\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#mainImage","width":1200,"height":630,"caption":"What should a breach register contain? \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"primaryImageOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#mainImage"},"datePublished":"2026-08-19T21:00:00+02:00","dateModified":"2026-08-20T18:03:42+02:00"},{"@type":"WebSite","@id":"https:\/\/www.lablogic.pl\/en\/#website","url":"https:\/\/www.lablogic.pl\/en\/","name":"Micha\u0142 Rutkowski - LabLogic","alternateName":"LabLogic","description":"DPO, RODO, NIS2 i Cybersecurity w praktyce","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.lablogic.pl\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"LabLogic - Micha\u0142 Rutkowski | DPO, RODO, NIS2 i Cybersecurity w praktyce","og:type":"article","og:title":"Breach register: scope of an entry and risk reasoning","og:description":"What has to be in an entry and why unnotified breaches matter most.","og:url":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/","og:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg","og:image:secure_url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg","og:image:width":1200,"og:image:height":630,"article:section":"Incidents and Breaches","article:published_time":"2026-08-19T19:00:00+00:00","article:modified_time":"2026-08-20T16:03:42+00:00","twitter:card":"summary_large_image","twitter:title":"Breach register: scope of an entry and risk reasoning","twitter:description":"What has to be in an entry and why unnotified breaches matter most.","twitter:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg"},"aioseo_meta_data":{"post_id":"4100","title":"Personal data breach register: what an entry must contain","description":"What a personal data breach register must contain under Article 33(5) GDPR, which events it covers and why unnotified breaches call for the most detail.","keywords":null,"keyphrases":{"focus":{"keyphrase":"personal data breach register"},"additional":[{"keyphrase":"documenting personal data breaches"},{"keyphrase":"Article 33(5) GDPR"},{"keyphrase":"breach record GDPR"},{"keyphrase":"what a breach register entry contains"}]},"primary_term":null,"canonical_url":null,"og_title":"Breach register: scope of an entry and risk reasoning","og_description":"What has to be in an entry and why unnotified breaches matter most.","og_object_type":"article","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"Incidents and Breaches","og_article_tags":null,"twitter_use_og":true,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-08-19 20:57:42","updated":"2026-08-20 16:03:52","seo_analyzer_scan_date":null,"focus_keyword":"personal data breach register","additional_keywords":[{"word":"documenting personal data breaches","score":0},{"word":"Article 33(5) GDPR","score":0},{"word":"breach record GDPR","score":0},{"word":"what a breach register entry contains","score":0}],"truseo_locale":null},"spectra_blocks_featured_image_url":{"thumbnail":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/ll-og-what-should-a-personal-data-breach-register-contain-en-1-150x150.jpg","width":150,"height":150},"medium":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/ll-og-what-should-a-personal-data-breach-register-contain-en-1-300x158.jpg","width":300,"height":158},"medium_large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/ll-og-what-should-a-personal-data-breach-register-contain-en-1-768x403.jpg","width":768,"height":403},"large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/ll-og-what-should-a-personal-data-breach-register-contain-en-1-1024x538.jpg","width":1024,"height":538},"full":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg","width":1200,"height":630}},"spectra_blocks_author_info":{"display_name":"Micha\u0142 Rutkowski","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","author_link":"https:\/\/www.lablogic.pl\/en\/author\/user_lablogic\/","description":"Micha\u0142 Rutkowski \u2014 praktyk ochrony danych i cyberbezpiecze\u0144stwa, w\u0142a\u015bciciel LabLogic. Od 2004 roku pracuje na styku technologii, ochrony danych i zarz\u0105dzania ryzykiem. Pe\u0142ni funkcj\u0119 zewn\u0119trznego IOD\/DPO, prowadzi audyty RODO, kwalifikacj\u0119 i wdro\u017cenia NIS2 oraz ustawy o KSC, wspiera organizacje przy incydentach i naruszeniach ochrony danych, szkoli zarz\u0105dy, kadr\u0119 kierownicz\u0105 oraz zespo\u0142y IT i compliance. Pracuje ze \u015brednimi i du\u017cymi organizacjami, w tym z sektora finansowego i bran\u017c regulowanych."},"_links":{"self":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/4100","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/comments?post=4100"}],"version-history":[{"count":3,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/4100\/revisions"}],"predecessor-version":[{"id":4182,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/4100\/revisions\/4182"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media\/4286"}],"wp:attachment":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media?parent=4100"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/categories?post=4100"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/tags?post=4100"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}