Back to .md Directory

DSGVO/GDPR Compliance Guide

Defines a DSGVO/GDPR breach response procedure with notification timelines, documentation templates, and regulatory contacts for German federal states.

May 2, 2026
0 downloads
3 views
ai
View source

What this file does

Defines a DSGVO/GDPR breach response procedure with notification timelines, documentation templates, and regulatory contacts for German federal states.

When to use it

  • Deploying applications that process personal data of EU residents
  • Needing a structured data breach response plan with 72-hour notification deadlines
  • Operating in Germany and requiring regional data protection authority contacts
  • Creating internal documentation templates for breach reporting and subject notification

DSGVO/GDPR Compliance Guide

This document provides guidance on DSGVO (Datenschutz-Grundverordnung) / GDPR (General Data Protection Regulation) compliance for applications deployed on the PolyServer foundation. It outlines procedures to follow in case of data breaches or other incidents involving personal data, regardless of the specific application type.

Table of Contents

Data Protection Officer Information

[Complete this section with your organization's specific information]

Data Protection Officer (DPO):

  • Name: [DPO Name]
  • Email: [DPO Email]
  • Phone: [DPO Phone]

Alternate Contact:

  • Name: [Alternate Contact Name]
  • Email: [Alternate Contact Email]
  • Phone: [Alternate Contact Phone]

Personal Data in Applications

Applications deployed on PolyServer may contain or provide access to various types of personal data. Document the categories of personal data accessible through your applications:

Data CategoryDescriptionAccess LevelRetention Period
[Customer Data][Describe data][Who has access][How long kept]
[Employee Data][Describe data][Who has access][How long kept]
[Analytics Data][Describe data][Who has access][How long kept]
[User Data][Describe data][Who has access][How long kept]
[Session Data][Describe data][Who has access][How long kept]
[Application-Specific Data][Describe data][Who has access][How long kept]

Data Breach Response Procedure

Identification and Containment

  1. Immediate Response (first 24 hours):

    • The person who discovers or suspects a data breach must immediately notify the Security Team and DPO
    • Contact methods:
  2. Initial Containment (first 24-48 hours):

  3. Activate Response Team:

    • Security Officer
    • Data Protection Officer
    • IT Administrator
    • Legal Counsel
    • Communications Representative

Assessment and Documentation

  1. Breach Assessment (within 48-72 hours):

    • Determine what personal data was affected
    • Identify the number of data subjects affected
    • Assess potential consequences for affected individuals
    • Determine if the breach is ongoing or contained
    • Evaluate if encryption or other measures protected the data
  2. Documentation Requirements:

    • Timeline of the breach (detection, response, containment)
    • Nature of the breach (what happened)
    • Categories of data affected
    • Number of individuals affected
    • Likely consequences
    • Measures taken to address the breach
    • Use the structured documentation format in the templates section

Notification Requirements

To Supervisory Authority

  1. When to Notify:

    • Within 72 hours of becoming aware of a breach
    • Unless the breach is unlikely to result in a risk to individuals' rights and freedoms
  2. Authority to Notify:

  3. Information to Include:

    • Description of the breach
    • Name and contact details of DPO
    • Likely consequences
    • Measures taken or proposed
    • Categories and approximate number of data subjects concerned
    • Categories and approximate number of records concerned

To Affected Individuals

  1. When to Notify:

    • Without undue delay
    • When breach is likely to result in a high risk to rights and freedoms
  2. How to Notify:

    • Direct communication (email, letter, phone)
    • Public communication if direct contact is disproportionate
  3. Information to Include:

    • Clear, plain language description of the breach
    • Name and contact details of DPO
    • Likely consequences
    • Measures taken or proposed
    • Specific recommendations for individuals to protect themselves

Follow-up Actions

  1. Remediation:

    • Implement technical fixes to address vulnerabilities
    • Update security protocols if necessary
    • Consider implementing additional security measures
  2. Review and Lessons Learned:

    • Conduct post-incident review within 2 weeks
    • Document lessons learned
    • Update security procedures based on findings
    • Schedule follow-up assessment after 1 month
  3. Documentation Retention:

    • All breach-related documentation must be retained for at least 5 years

Regulatory Contacts

Germany

Federal Authority:

Regional Authorities by Federal State:

Baden-Württemberg:

Bayern (Bavaria):

Berlin:

Brandenburg:

Bremen:

Hamburg:

Hessen:

Mecklenburg-Vorpommern:

Niedersachsen (Lower Saxony):

Nordrhein-Westfalen (North Rhine-Westphalia):

  • Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
  • Phone: +49 211 38424-0
  • Email: poststelle@ldi.nrw.de
  • Website: https://www.ldi.nrw.de
  • Address: Kavalleriestraße 2-4, 40213 Düsseldorf

Rheinland-Pfalz (Rhineland-Palatinate):

Saarland:

Sachsen (Saxony):

Sachsen-Anhalt:

Schleswig-Holstein:

Thüringen (Thuringia):

Other EU Member States

For operations in other EU member states, consult the European Data Protection Board's list of supervisory authorities:

Documentation Templates

Internal Data Breach Report

INTERNAL DATA BREACH REPORT
===========================

INCIDENT DETAILS
---------------
Date and time of discovery: [YYYY-MM-DD HH:MM]
Date and time of breach (if known): [YYYY-MM-DD HH:MM]
Discovered by: [Name/Role]
Breach reference number: [ORG-YEAR-NUMBER]

BREACH DETAILS
-------------
Description of breach:
[Detailed description]

Systems affected:
[List affected systems]

Personal data affected:
[Types of personal data]

Categories of data subjects:
[Types of individuals affected]

Approximate number of data subjects affected:
[Number or range]

Approximate number of records affected:
[Number or range]

IMPACT ASSESSMENT
---------------
Potential consequences for data subjects:
[Description of potential harm]

Risk level:
[ ] Low - unlikely to result in risk to individuals
[ ] Medium - may result in risk to individuals
[ ] High - likely to result in high risk to individuals

Reasoning for risk assessment:
[Explanation of risk classification]

RESPONSE ACTIONS
--------------
Containment measures taken:
[Actions taken to limit the breach]

Evidence preserved:
[List of evidence collected]

Technical remediation:
[Technical steps taken to fix the issue]

NOTIFICATION DECISIONS
--------------------
Supervisory authority notification:
[ ] Required (medium/high risk) - Deadline: [Date/time - 72h after discovery]
[ ] Not required (low risk) - Justification: [Reasoning]

Data subject notification:
[ ] Required (high risk) - Deadline: [Date/time - without undue delay]
[ ] Not required (low/medium risk) - Justification: [Reasoning]

APPROVALS
--------
Report completed by: [Name, Role]
Date: [YYYY-MM-DD]

DPO review: [Name, Comments]
Date: [YYYY-MM-DD]

Legal review: [Name, Comments]
Date: [YYYY-MM-DD]

Data Subject Notification

SUBJECT: IMPORTANT: Data Security Incident Notification

Dear [Data Subject],

We are writing to inform you about a data security incident that occurred on [date] 
which may have affected your personal data.

What happened:
[Clear description of the breach in plain language]

What information was involved:
[Types of personal data affected]

What this means for you:
[Potential consequences]

What we are doing:
[Actions taken to address the breach and protect data]

What you can do:
[Specific advice on how individuals can protect themselves]

Further information and contact details:
If you have any questions or concerns, please contact our Data Protection Officer:
- Name: [DPO Name]
- Email: [DPO Email]
- Phone: [DPO Phone]

We sincerely apologize for this incident and any concern it may cause you.

Yours sincerely,
[Name]
[Position]
[Organization]

Authority Notification

DATA BREACH NOTIFICATION TO SUPERVISORY AUTHORITY
================================================

1. CONTROLLER DETAILS
--------------------
Organization name: [Organization name]
Address: [Full address]
Registration number: [If applicable]

2. CONTACT DETAILS
----------------
Primary contact: [Name, Position]
Phone: [Direct phone number]
Email: [Direct email]

Data Protection Officer:
Name: [DPO name]
Phone: [DPO phone]
Email: [DPO email]

3. BREACH DETAILS
---------------
Date and time of breach (if known): [YYYY-MM-DD HH:MM]
Date and time of discovery: [YYYY-MM-DD HH:MM]
Ongoing breach: [Yes/No]
If yes, current status: [Description of current situation]

Description of the breach:
[Detailed description including the type of breach (confidentiality, integrity, availability)]

Cause of the breach (if known):
[Description of how the breach occurred]

Systems and data involved:
[Description of affected systems, applications, or records]

4. DATA AND SUBJECTS AFFECTED
---------------------------
Categories of personal data affected:
[List all types of personal data]

Special categories of data affected:
[List any sensitive data as defined by GDPR Article 9]

Categories of data subjects:
[Types of individuals affected]

Approximate number of data subjects:
[Number or best estimate]

Approximate number of data records:
[Number or best estimate]

5. POTENTIAL CONSEQUENCES
----------------------
Likely consequences for data subjects:
[Description of potential harm to individuals]

Severity assessment:
[Low/Medium/High with justification]

6. MEASURES TAKEN
---------------
Containment measures already implemented:
[Actions taken to contain the breach]

Measures to address adverse effects:
[Actions taken to mitigate harm to individuals]

Technical and organizational measures in place before the breach:
[Security measures that were in place]

7. COMMUNICATION
--------------
Data subject notification:
[ ] Already notified on [date]
[ ] Will be notified by [date]
[ ] Not notifying - Justification: [Reasoning]

Content of notification to data subjects:
[Summary or attach copy]

Communication channel(s) used/to be used:
[Email/Letter/Phone/Public notice/etc.]

8. CROSS-BORDER ASPECTS
---------------------
Does the breach affect data subjects in other EU member states?
[ ] Yes - Member states affected: [List countries]
[ ] No

Has notification been made to other supervisory authorities?
[ ] Yes - Authorities notified: [List authorities]
[ ] No

9. ADDITIONAL INFORMATION
----------------------
[Any other relevant information]

10. ATTACHMENTS
-------------
[ ] Internal breach report
[ ] Technical investigation report
[ ] Data subject notification template
[ ] Other: [Specify]

Report completed by: [Name, Position]
Date: [YYYY-MM-DD]

DSGVO/GDPR Tools and Resources

Official Resources

Risk Assessment Tools

Recommended Actions for Compliance

  1. Regular Data Mapping

    • Document all personal data in Application
    • Review data access permissions quarterly
    • Validate data retention periods
  2. User Training

    • Conduct regular DSGVO awareness training
    • Ensure all Application users understand data protection principles
    • Practice breach response procedures annually
  3. Technical Measures

    • Maintain all security measures outlined in README.md
    • Implement data minimization in Application queries
    • Consider pseudonymization for analytics data
    • Ensure strong encryption for all personal data
  4. Documentation

    • Maintain records of processing activities
    • Document data sharing agreements
    • Keep audit logs of data access
    • Regularly update privacy policies and notices

What's inside

6 sections: DPO info table, personal data categories table, 4-step breach procedure, 16 German authority contacts, 3 documentation templates, compliance resources

Change this for your project

  • Replace [DPO Name], [DPO Email], [DPO Phone] with your organization's data protection officer details
  • Replace [security@your-organization.com] and [Emergency security phone number] with your security team contact info
  • Replace [ORG-YEAR-NUMBER] in the internal report template with your breach numbering scheme
  • Replace [Organization name] and [Full address] in the authority notification template with your legal entity details

Where it goes

Keep it in your repository where the agent or team that needs it will read it.

Worth borrowing

  • Checklist-style templates for internal breach reports, subject notifications, and authority notifications that can be reused verbatim
  • 72-hour notification clock with explicit risk-level decision tree for when to notify authorities versus subjects

Related Documents