Notification Trigger
Definition
The threshold condition that activates a legal notification obligation. Under GDPR the trigger is any personal data breach that poses a risk to individuals; below-risk breaches must be documented internally but not reported. Under many US state laws, the trigger is unauthorised access to defined categories of personal information without a risk qualification.
- GDPR trigger
- Any personal data breach posing risk to individuals
- GDPR below-risk case
- Must be logged internally, not reported externally
- Typical US state trigger
- Unauthorised access to defined categories of personal information
- Key difference
- US triggers often apply without a separate risk assessment step
Common questions
Why does the difference in triggers matter for a multinational breach response?+
An organisation with data subjects in the EU and multiple US states may need to run a GDPR risk assessment for one population while simultaneously applying a stricter, access-based test for another, so the same incident can require notification in one jurisdiction and only internal logging in another.
Who decides whether a breach crosses the GDPR risk threshold?+
The data controller makes the initial risk assessment, but that judgment can later be reviewed by the relevant supervisory authority, which is why organisations document the reasoning behind a decision not to notify.
Related terms
- Covered Entity / Business Associate
- Terms used in the US HIPAA framework. Covered entities are healthcare providers, health plans, and healthcare clearinghouses. Business Associates are contractors that...
- Data Fiduciary
- The term used in India's Digital Personal Data Protection Act 2023 for an entity that determines the purpose and means of processing...
- Personal Data Breach
- Under GDPR, a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal...
- Safe Harbour (Encryption)
- A provision in many breach notification frameworks that exempts organisations from individual notification obligations if the breached data was encrypted and the...
- Supervisory Authority
- The national data protection regulator responsible for enforcing GDPR in a given EU member state, such as the UK Information Commissioner's Office...