{"id":4100,"date":"2026-08-13T09:45:00","date_gmt":"2026-08-13T07:45:00","guid":{"rendered":"https:\/\/www.lablogic.pl\/?p=4100"},"modified":"2026-10-03T00:36:50","modified_gmt":"2026-10-02T22:36:50","slug":"what-should-a-personal-data-breach-register-contain","status":"publish","type":"post","link":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/","title":{"rendered":"What should a personal data breach register contain?"},"content":{"rendered":"\n<p class=\"ll-art-meta wp-block-paragraph\"><a href=\"https:\/\/www.lablogic.pl\/en\/michal-rutkowski\/\"><strong>Micha\u0142 Rutkowski<\/strong><\/a> \u2022 for data protection officers and compliance teams \u2022 published August 13, 2026 \u2022 updated August 19, 2026 \u2022 7 min read<\/p>\n\n\n\n<div class=\"wp-block-columns ll-art-shell is-layout-flex wp-container-core-columns-is-layout-7387b849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column ll-art-rail is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-railinner is-layout-constrained wp-block-group-is-layout-constrained\">\n\n\n\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column ll-art-main is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-answer is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 id=\"krotka-odpowiedz\" class=\"wp-block-heading\">Short answer<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The regulation does not speak of a register but of documentation. The controller documents any personal data breach, including the facts relating to it, its effects and the remedial action taken. The quality test is set by the second sentence of Article 33(5) GDPR \u2014 the documentation must enable the supervisory authority to verify compliance with that article as a whole. That also covers the finding that the decision not to notify a breach was correct. This is why the entries that call for the most content are those concerning breaches the controller did not notify.<\/p>\n<\/div>\n\n\n\n<h2 id=\"dlaczego\" class=\"wp-block-heading\">Why the question arises at all<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A breach register is often kept as a list of cases sent to the supervisory authority. What results is a document that duplicates knowledge the authority already has. It says nothing about the cases resolved internally \u2014 and those are the ones later subject to verification.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second source of confusion is terminological. Article 33(5) GDPR does not use the word \u201cregister\u201d and imposes no form. The President of the Personal Data Protection Office (UODO) states expressly that an internal breach register may help in meeting the obligation. Keeping a separate record is not mandatory, however. What matters is that the information is clearly marked and available for inspection. The obligation is therefore an evidential result, not a table.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The third source is organisational and becomes visible only over time. An entry is usually created on the day the case is closed. It then contains a summary sufficient for the people who worked on it. A year later the same entry is read by someone else, most often for the purposes of proceedings. That is when it turns out that what is missing is not facts but reasons.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is also worth separating two documents that are confused because their names are similar. The record of processing activities under Article 30 GDPR describes what the organisation processes day to day and why. The breach documentation under Article 33(5) describes events and decisions. These are two different obligations with different evidential functions.<\/p>\n\n\n\n<h2 id=\"co-ustalic\" class=\"wp-block-heading\">What to establish before deciding<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What the regulation requires and what it does not<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The regulation requires three things.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Document <strong>any<\/strong> personal data breach.<\/li>\n\n\n\n<li>Cover the facts relating to the breach, its effects and the remedial action taken.<\/li>\n\n\n\n<li>Ensure that the documentation enables the supervisory authority to verify compliance with Article 33.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">It prescribes no form, no system and no template. Nor does it set a retention period. That latitude is sometimes read as leniency on the part of the regulation. The opposite is true \u2014 it is the controller who answers for whether the chosen form can carry the evidential function.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second sentence settles the matter. Verification covers <strong>the whole article<\/strong>, so it reaches paragraph 1 and the ground for not notifying as well. That ground rests on a finding that the breach is unlikely to result in a risk to the rights and freedoms of natural persons. It is precisely that conclusion which is reviewed.<\/p>\n\n\n\n<div class=\"wp-block-group ll-art-zdanie is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<p class=\"wp-block-paragraph\">Remember<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An entry without the reasoning behind the decision gives the authority no material to verify and the controller no basis on which to defend itself.<\/p>\n\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Which events belong in the documentation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The scope is wider than the practice of most organisations suggests. It falls into three circles.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The first circle is breaches identified and notified to the authority. The second is breaches identified and not notified \u2014 the documentation obligation covers them in the same way, because the regulation speaks of any breach. The third circle goes beyond the letter of Article 33(5). The President of UODO recommends documenting also those security incidents which the controller has classified as events that are not personal data breaches. The recommendation covers the reasons for that decision in particular.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That recommendation rests on the accountability principle in Article 5(2) GDPR, not on a separate obligation. It carries practical weight nonetheless. Without it, the organisation cannot show that it considered an event the authority knows about from another source.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What a single entry has to contain<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The table below combines the elements listed in the regulation with the scope indicated in the guidance of the President of UODO. The third column shows what a given element is for. That is what settles how detailed the record needs to be.<\/p>\n\n\n\n<figure class=\"wp-block-table ll-art-table\"><table><thead><tr><th>Element of the entry<\/th><th>Where the requirement comes from<\/th><th>What it is for<\/th><\/tr><\/thead><tbody><tr><td>The facts \u2014 date and time of occurrence, of becoming aware and of closure; how it was detected; cause and course<\/td><td>Article 33(5) GDPR, UODO guidance<\/td><td>Establishing the moment of becoming aware, from which the notification deadline runs<\/td><\/tr><tr><td>Type and scope of the data, number and categories of data subjects<\/td><td>Article 33(3)(a), UODO guidance<\/td><td>The basis for assessing the severity of the potential impact<\/td><\/tr><tr><td>The effects and the possible effects for data subjects<\/td><td>Article 33(5) GDPR<\/td><td>Telling an effect that materialised from one that is merely possible<\/td><\/tr><tr><td><strong>The reasoning behind the risk assessment<\/strong><\/td><td>UODO guidance, the accountability principle<\/td><td>The element the authority verifies first<\/td><\/tr><tr><td>Remedial and preventive action<\/td><td>Article 33(5) GDPR<\/td><td>Showing the response and its effect on the risk of recurrence<\/td><\/tr><tr><td>Details of the notification <strong>or the reasons for the decision not to notify<\/strong><\/td><td>Article 33(1), UODO guidance<\/td><td>Verifying the ground for not notifying<\/td><\/tr><tr><td>Details of the communication to data subjects <strong>or the reasons for the decision not to communicate<\/strong><\/td><td>Article 34(3), UODO guidance<\/td><td>Showing which of the three exceptions applied<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The two rows in bold are what separates useful documentation from a list of events. The rest describes what happened. These two describe why the organisation acted as it did.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The reasoning behind a risk assessment is worth recording as reasoning, not as a result. The entry \u201crisk low\u201d says nothing about what the controller took into account. What can be checked is a record setting out the categories of data, the safeguards applied and the likelihood of harm that follows from them. It works even where the authority assesses the case differently.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The template below shows the shape of such a record. It does not describe an actual case; it is a skeleton to be filled in with the organisation\u2019s own data.<\/p>\n\n\n\n<div class=\"wp-block-group ll-art-note is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\">The breach covered the first name, surname and e-mail address of [number] data subjects. The data reached a single known external recipient as a result of an addressing error. The recipient confirmed deletion of the message; the confirmation has been retained in the case file. No identifiers enabling impersonation and no special categories of personal data were involved. The likelihood of further dissemination was assessed as low \u2014 there is one recipient, that recipient is known and deletion has been confirmed. The severity of the potential impact is limited by the scope of the data, which is contact data.<\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">That record can be checked. It sets out the scope of the data, the circumstance that limits the risk and the conclusion which follows from them. The formula \u201clow risk, case closed\u201d contains none of those three elements.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How the documentation changes over time<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">An entry is not closed once and for all. Information about a breach arrives in stages, and each new piece may change the risk assessment and the soundness of the earlier decision. The documentation is meant to mirror that and to keep a trace of the change, not only the final state.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This has a direct procedural consequence. A breach assessed at first as not requiring notification may require it once the full scope of the data is established. The moment the decision was taken can then be explained only by documentation showing when the controller learned of the new circumstance.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How long to keep it and what not to put in it<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The GDPR gives no period after which information about breaches may be erased. The President of UODO therefore recommends keeping it for as long as possible. A second, less obvious recommendation follows from the first. An internal register <strong>is neither required nor recommended to contain personal data<\/strong> \u2014 neither of the people affected by the breach nor of those involved in handling the case.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is the position broken most often in practice. Registers kept in spreadsheets usually contain the names of the people affected and of the authors of the entries. The result is a set of data kept indefinitely, for which a separate legal basis and retention period have to be established. The answer is to separate the layers. The register works with a case identifier and aggregated data, while material containing personal data sits in the case file with its own retention period.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Where personal data does end up in the record after all, the minimisation principle applies to it on ordinary terms.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Who keeps the documentation where processing is entrusted<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The obligation under Article 33(5) GDPR is addressed to the controller. The processor notifies the controller of a breach without undue delay and assists the controller in meeting the obligations under Articles 32 to 36, which includes documentation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The practical conclusion concerns the contract, not the regulation. The controller documents the facts of an event that took place in someone else\u2019s infrastructure. It therefore needs a contractual route to data on the time of detection, the scope and the course of events. A processing agreement providing for notification alone, with no scope for the information to be passed on, leaves the controller with an entry it cannot justify.<\/p>\n\n\n\n<h2 id=\"bledy\" class=\"wp-block-heading\">Common mistakes<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n<li><strong>A register covering notified breaches only.<\/strong> The obligation covers any breach. Entries on cases that were not notified are the ones actually subject to verification.<\/li>\n\n\n\n<li><strong>A risk assessment recorded as a result.<\/strong> \u201cLow risk\u201d is not a justification. What can be verified is the line of reasoning, not its conclusion.<\/li>\n\n\n\n<li><strong>Confusing breach documentation with the record of processing activities.<\/strong> These are two separate obligations with different subject matter \u2014 Article 30 describes processing, Article 33(5) describes events and decisions.<\/li>\n\n\n\n<li><strong>Keeping personal data in the register indefinitely.<\/strong> The recommendation to keep things for a long time concerns information about breaches, not data about people. Those two layers have to be separated when the record is designed.<\/li>\n\n\n\n<li><strong>No trace of events classified as non-breaches.<\/strong> A decision that an event is not a personal data breach calls for a record together with its reason.<\/li>\n\n\n\n<li><strong>An entry closed on the day of the event.<\/strong> The documentation is meant to be updated, because new information may change the risk assessment and force a notification after a deadline first treated as not running.<\/li>\n<\/ul>\n\n\n\n<h2 id=\"wnioski\" class=\"wp-block-heading\">Conclusions and next steps<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Breach documentation is evidence of a decision-making process, not a record of events. That single premise settles what it contains. An entry has to reconstruct what the organisation knew at a given moment and what conclusion it drew from that. Cases notified to the authority take the least work in this arrangement, because their justification already sits in the notification.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An order of work that proves itself where a register already exists.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Check whether the record holds entries on breaches that were not notified; their absence means the register does not perform the function under Article 33(5).<\/li>\n\n\n\n<li>Review the entries for the reasoning behind the risk assessment and complete those that give the result alone.<\/li>\n\n\n\n<li>Separate the register layer from the case file and remove from the register any personal data that is not needed there.<\/li>\n\n\n\n<li>Establish where information about breaches at processors comes from and whether the contracts secure it.<\/li>\n\n\n\n<li>Introduce a rule of updating the entry as information arrives, keeping a trace of the changes.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Documentation in good order also yields material available from no other source, namely the recurrence of mistakes of the same type. That is the right starting point for designing <a href=\"https:\/\/www.lablogic.pl\/en\/training\/\">training matched to roles and processes<\/a>. It points to the processes in which events actually arise.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Related materials<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/\">Does every data breach need to be reported?<\/a><\/strong> \u2014 the notification threshold and the risk assessment whose outcome the register preserves.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/what-to-do-after-detecting-an-incident\/\">What to do after detecting an incident?<\/a><\/strong> \u2014 the sequence of actions that produces the entry.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/cybersecurity-incident-vs-personal-data-breach\/\">Cybersecurity incident vs personal data breach: what is the difference?<\/a><\/strong> \u2014 classifying the event before the entry is made.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/how-to-notify-data-subjects-of-a-breach\/\">How do you notify data subjects of a breach and what must the communication contain?<\/a><\/strong> \u2014 what to record about the communication to data subjects or about the reasons for not sending it.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Sources<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-sources\">\n<li>Regulation (EU) 2016\/679 of the European Parliament and of the Council (GDPR), Article 5(2), Article 24(1), Article 28(3)(f), Article 30, Article 33 and Article 34, consolidated text \u2014 EUR-Lex: <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:02016R0679-20160504\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a><\/li>\n\n\n\n<li>President of the Personal Data Protection Office (UODO), \u201cObligations of controllers relating to personal data breaches\u201d, version of February 20, 2025, chapter 8 \u2014 <a href=\"https:\/\/uodo.gov.pl\/pl\/598\/3563\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a> (in Polish)<\/li>\n\n\n\n<li>European Data Protection Board, Guidelines 01\/2021 on examples regarding personal data breach notification, version 2.0 adopted on December 14, 2021 \u2014 <a href=\"https:\/\/www.edpb.europa.eu\/our-work-tools\/our-documents\/guidelines\/guidelines-012021-examples-regarding-personal-data-breach_en\" target=\"_blank\" rel=\"noreferrer noopener\">edpb.europa.eu<\/a><\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-group ll-art-cta is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading ll-nietoc\">Check whether your register will defend your decisions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The worth of a register shows only when a decision taken a year ago has to be explained. Putting the assessment of incidents and breaches in order covers a review of the existing entries and settles the scope the organisation is actually able to demonstrate.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/www.lablogic.pl\/en\/incident-response\/\">Support with incidents and breaches<\/a><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Article 33(5) GDPR requires documentation, not a register in a prescribed form. The documentation has to let the supervisory authority verify compliance with the whole article, which is why the entries that call for the most content are those on breaches the controller did not notify.<\/p>\n","protected":false},"author":2,"featured_media":5563,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ll_stan_prawny":"August 2026","footnotes":""},"categories":[71],"tags":[],"class_list":["post-4100","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-incidents"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"What a personal data breach register must contain under Article 33(5) GDPR, which events it covers and why unnotified breaches call for the most detail.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Micha\u0142 Rutkowski\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Breach register: what Article 33(5) requires\" \/>\n\t\t<meta property=\"og:description\" content=\"The entries that need the most detail are the breaches you did not report.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t\t<meta property=\"article:section\" content=\"Incidents and Breaches\" \/>\n\t\t<meta property=\"article:tag\" content=\"gdpr\" \/>\n\t\t<meta property=\"article:tag\" content=\"breaches\" \/>\n\t\t<meta property=\"article:tag\" content=\"register\" \/>\n\t\t<meta property=\"article:tag\" content=\"compliance\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-08-13T07:45:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-10-02T22:36:50+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Breach register: what Article 33(5) requires\" \/>\n\t\t<meta name=\"twitter:description\" content=\"The entries that need the most detail are the breaches you did not report.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#article\",\"name\":\"Personal data breach register \\u2014 what an entry must contain\",\"headline\":\"What should a personal data breach register contain?\",\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg\",\"width\":1200,\"height\":630,\"caption\":\"What should a breach register contain? \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"datePublished\":\"2026-08-13T09:45:00+02:00\",\"dateModified\":\"2026-10-03T00:36:50+02:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#webpage\"},\"articleSection\":\"Incidents and Breaches\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"position\":1,\"name\":\"LabLogic\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/#listItem\",\"name\":\"Incidents and Breaches\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/#listItem\",\"position\":2,\"name\":\"Incidents and Breaches\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#listItem\",\"name\":\"What should a personal data breach register contain?\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"name\":\"LabLogic\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#listItem\",\"position\":3,\"name\":\"What should a personal data breach register contain?\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/#listItem\",\"name\":\"Incidents and Breaches\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\",\"name\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"email\":\"m.rutkowski@lablogic.pl\",\"telephone\":\"+48586231777\",\"foundingDate\":\"2004\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/cropped-lablogic-site-icon-512.png\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#organizationLogo\",\"width\":512,\"height\":512},\"image\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"additionalType\":\"https:\\\/\\\/schema.org\\\/ProfessionalService\",\"legalName\":\"LabLogic Consulting Micha\\u0142 Rutkowski\",\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"ul. Wolno\\u015bci 15\",\"postalCode\":\"81-327\",\"addressLocality\":\"Gdynia\",\"addressRegion\":\"pomorskie\",\"addressCountry\":\"PL\"},\"vatID\":\"PL9580972114\",\"taxID\":\"9580972114\",\"areaServed\":{\"@type\":\"Country\",\"name\":\"Poland\"},\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"founder\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"hasOfferCatalog\":{\"@type\":\"OfferCatalog\",\"name\":\"Services\",\"itemListElement\":[{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"External Data Protection Officer (DPO)\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/external-dpo\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"NIS2 and KSC implementation support\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-ksc\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"Incident and data breach response\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/incident-response\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"GDPR and NIS2 training\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/training\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"AI Act: roles, obligations and preparation\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/ai-act\\\/\"}}]}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/michal-rutkowski\\\/\",\"name\":\"Micha\\u0142 Rutkowski\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski-portret\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/michal-rutkowski-iod-dpo-rodo-nis2-lablogic.webp\",\"width\":864,\"height\":1080,\"caption\":\"Micha\\u0142 Rutkowski\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"jobTitle\":\"Data Protection Officer (DPO), NIS2\\\/KSC and cybersecurity advisor\",\"description\":\"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.\",\"email\":\"m.rutkowski@lablogic.pl\",\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"worksFor\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#webpage\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/\",\"name\":\"Personal data breach register \\u2014 what an entry must contain\",\"description\":\"What a personal data breach register must contain under Article 33(5) GDPR, which events it covers and why unnotified breaches call for the most detail.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#mainImage\",\"width\":1200,\"height\":630,\"caption\":\"What should a breach register contain? \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/what-should-a-personal-data-breach-register-contain\\\/#mainImage\"},\"datePublished\":\"2026-08-13T09:45:00+02:00\",\"dateModified\":\"2026-10-03T00:36:50+02:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"name\":\"Micha\\u0142 Rutkowski - LabLogic\",\"alternateName\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Personal data breach register \u2014 what an entry must contain","description":"What a personal data breach register must contain under Article 33(5) GDPR, which events it covers and why unnotified breaches call for the most detail.","canonical_url":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#article","name":"Personal data breach register \u2014 what an entry must contain","headline":"What should a personal data breach register contain?","author":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"publisher":{"@id":"https:\/\/www.lablogic.pl\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg","width":1200,"height":630,"caption":"What should a breach register contain? \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"datePublished":"2026-08-13T09:45:00+02:00","dateModified":"2026-10-03T00:36:50+02:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#webpage"},"isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#webpage"},"articleSection":"Incidents and Breaches"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","position":1,"name":"LabLogic","item":"https:\/\/www.lablogic.pl\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/#listItem","name":"Incidents and Breaches"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/#listItem","position":2,"name":"Incidents and Breaches","item":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#listItem","name":"What should a personal data breach register contain?"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","name":"LabLogic"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#listItem","position":3,"name":"What should a personal data breach register contain?","previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/#listItem","name":"Incidents and Breaches"}}]},{"@type":"Organization","@id":"https:\/\/www.lablogic.pl\/#organization","name":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","url":"https:\/\/www.lablogic.pl\/en\/","email":"m.rutkowski@lablogic.pl","telephone":"+48586231777","foundingDate":"2004","logo":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/cropped-lablogic-site-icon-512.png","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#organizationLogo","width":512,"height":512},"image":{"@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#organizationLogo"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"additionalType":"https:\/\/schema.org\/ProfessionalService","legalName":"LabLogic Consulting Micha\u0142 Rutkowski","address":{"@type":"PostalAddress","streetAddress":"ul. Wolno\u015bci 15","postalCode":"81-327","addressLocality":"Gdynia","addressRegion":"pomorskie","addressCountry":"PL"},"vatID":"PL9580972114","taxID":"9580972114","areaServed":{"@type":"Country","name":"Poland"},"knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"founder":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"hasOfferCatalog":{"@type":"OfferCatalog","name":"Services","itemListElement":[{"@type":"Offer","itemOffered":{"@type":"Service","name":"External Data Protection Officer (DPO)","url":"https:\/\/www.lablogic.pl\/en\/external-dpo\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"NIS2 and KSC implementation support","url":"https:\/\/www.lablogic.pl\/en\/nis2-ksc\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"Incident and data breach response","url":"https:\/\/www.lablogic.pl\/en\/incident-response\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"GDPR and NIS2 training","url":"https:\/\/www.lablogic.pl\/en\/training\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"AI Act: roles, obligations and preparation","url":"https:\/\/www.lablogic.pl\/en\/ai-act\/"}}]}},{"@type":"Person","@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski","url":"https:\/\/www.lablogic.pl\/michal-rutkowski\/","name":"Micha\u0142 Rutkowski","image":{"@type":"ImageObject","@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski-portret","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/michal-rutkowski-iod-dpo-rodo-nis2-lablogic.webp","width":864,"height":1080,"caption":"Micha\u0142 Rutkowski"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"jobTitle":"Data Protection Officer (DPO), NIS2\/KSC and cybersecurity advisor","description":"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.","email":"m.rutkowski@lablogic.pl","knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"worksFor":{"@id":"https:\/\/www.lablogic.pl\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#webpage","url":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/","name":"Personal data breach register \u2014 what an entry must contain","description":"What a personal data breach register must contain under Article 33(5) GDPR, which events it covers and why unnotified breaches call for the most detail.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/#website"},"breadcrumb":{"@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#breadcrumblist"},"author":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"creator":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg","@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#mainImage","width":1200,"height":630,"caption":"What should a breach register contain? \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"primaryImageOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/#mainImage"},"datePublished":"2026-08-13T09:45:00+02:00","dateModified":"2026-10-03T00:36:50+02:00"},{"@type":"WebSite","@id":"https:\/\/www.lablogic.pl\/en\/#website","url":"https:\/\/www.lablogic.pl\/en\/","name":"Micha\u0142 Rutkowski - LabLogic","alternateName":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.lablogic.pl\/#organization"}}]},"og:locale":"en_US","og:site_name":"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice","og:type":"article","og:title":"Breach register: what Article 33(5) requires","og:description":"The entries that need the most detail are the breaches you did not report.","og:url":"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/","og:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg","og:image:secure_url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg","og:image:width":1200,"og:image:height":630,"article:section":"Incidents and Breaches","article:tag":["gdpr","breaches","register","compliance"],"article:published_time":"2026-08-13T07:45:00+00:00","article:modified_time":"2026-10-02T22:36:50+00:00","twitter:card":"summary_large_image","twitter:title":"Breach register: what Article 33(5) requires","twitter:description":"The entries that need the most detail are the breaches you did not report.","twitter:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg"},"aioseo_meta_data":{"post_id":"4100","title":"Personal data breach register \u2014 what an entry must contain","description":"What a personal data breach register must contain under Article 33(5) GDPR, which events it covers and why unnotified breaches call for the most detail.","keywords":null,"keyphrases":{"focus":{"keyphrase":"personal data breach register"},"additional":[{"keyphrase":"documenting personal data breaches"},{"keyphrase":"Article 33(5) GDPR"},{"keyphrase":"breach record GDPR"},{"keyphrase":"what a breach register entry contains"}]},"primary_term":null,"canonical_url":null,"og_title":"Breach register: what Article 33(5) requires","og_description":"The entries that need the most detail are the breaches you did not report.","og_object_type":"article","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"Incidents and Breaches","og_article_tags":[{"label":"GDPR","value":"GDPR"},{"label":"breaches","value":"breaches"},{"label":"register","value":"register"},{"label":"compliance","value":"compliance"}],"twitter_use_og":true,"twitter_card":"summary_large_image","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":0,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-08-19 20:57:42","updated":"2026-10-02 22:36:53","seo_analyzer_scan_date":null,"focus_keyword":"personal data breach register","additional_keywords":[{"word":"documenting personal data breaches","score":0},{"word":"Article 33(5) GDPR","score":0},{"word":"breach record GDPR","score":0},{"word":"what a breach register entry contains","score":0}],"truseo_locale":null},"spectra_blocks_featured_image_url":{"thumbnail":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-personal-data-breach-register-contain-en-1-150x150.jpg","width":150,"height":150},"medium":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-personal-data-breach-register-contain-en-1-300x158.jpg","width":300,"height":158},"medium_large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-personal-data-breach-register-contain-en-1-768x403.jpg","width":768,"height":403},"large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-personal-data-breach-register-contain-en-1-1024x538.jpg","width":1024,"height":538},"full":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-what-should-a-personal-data-breach-register-contain-en-1.jpg","width":1200,"height":630}},"spectra_blocks_author_info":{"display_name":"Micha\u0142 Rutkowski","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","author_link":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/","description":"Micha\u0142 Rutkowski \u2014 praktyk ochrony danych i cyberbezpiecze\u0144stwa, w\u0142a\u015bciciel LabLogic. Od 2004 roku pracuje na styku technologii, ochrony danych i zarz\u0105dzania ryzykiem. Pe\u0142ni funkcj\u0119 zewn\u0119trznego IOD\/DPO, prowadzi audyty RODO, kwalifikacj\u0119 i wdro\u017cenia NIS2 oraz ustawy o KSC, wspiera organizacje przy incydentach i naruszeniach ochrony danych, szkoli zarz\u0105dy, kadr\u0119 kierownicz\u0105 oraz zespo\u0142y IT i compliance. Pracuje ze \u015brednimi i du\u017cymi organizacjami, w tym z sektora finansowego i bran\u017c regulowanych."},"_links":{"self":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/4100","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/comments?post=4100"}],"version-history":[{"count":5,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/4100\/revisions"}],"predecessor-version":[{"id":5762,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/4100\/revisions\/5762"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media\/5563"}],"wp:attachment":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media?parent=4100"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/categories?post=4100"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/tags?post=4100"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}