{"id":9229,"date":"2026-08-05T09:18:28","date_gmt":"2026-08-05T07:18:28","guid":{"rendered":"https:\/\/atb.law\/?post_type=blog-post&#038;p=9229"},"modified":"2026-08-05T12:34:48","modified_gmt":"2026-08-05T10:34:48","slug":"gdpr-nis2-2026-data-breach-notification-obligations","status":"publish","type":"blog-post","link":"https:\/\/atb.law\/en\/blog-post\/dsgvo-nisg-2026-data-breach-meldepflichten\/","title":{"rendered":"Data Breach: The Devil Never Sleeps"},"content":{"rendered":"<h2 id=\"page-when-in-the-eu\">When in the EU...<\/h2>\n<p>Article 4 (12) of the GDPR defines a \u201epersonal data breach\u201c (aka \u201edata breach\u201c) as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.<\/p>\n<p>Uploading data to a third-party cloud account certainly falls under this.<\/p>\n<h2 id=\"page-in-72-stunden-zur-datenschutzbehorde\">To the data protection authority within 72 hours<\/h2>\n<p>As soon as the controller becomes aware of the breach, they must notify the supervisory authority\u2014in Austria, the DSB\u2014without undue delay and, where feasible, not later than 72 hours after having become aware of it. Exceptions apply to cases where the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons, which is almost never the case with customer data. The 72 hours do not constitute a strict deadline. Anyone who reports later must, of course, justify the delay.<\/p>\n<p>Two points are regularly overlooked in practice.<\/p>\n<ol>\n<li>Phased notification: Article 33(4) GDPR allows subsequent notifications. Not all details of the incident have to be provided all at once\u2014waiting for further information cannot justify an excuse for missing a deadline. A common mistake is reporting late and completely rather than on time and provisionally. Added to this is a point that hurts operationally: the 72-hour deadline does not recognize weekends; it runs continuously by the calendar. An incident confirmed on Friday afternoon must be reported by Monday afternoon. Many attackers time things accordingly, and not entirely by coincidence.<\/li>\n<li>Data Processing Agreement (DPA): As a rule, the service provider reports to the controller rather than the supervisory authority, and the controller's deadline begins upon receipt of the notification. What \u201eundue delay\u201c means in Art 33 para 2 GDPR should be specified in the DPA. The EDPB recommends a specific number of hours and a designated contact point. Take a look at your contracts!<\/li>\n<\/ol>\n<h2 id=\"page-information-der-betroffenen\">Information of those affected<\/h2>\n<p>If there is a likely high risk to the rights and freedoms of natural persons, for example because account, ID, or health data has been leaked, those affected must be informed without undue delay and in clear, plain language. This is the moment of maximum reputational risk and precisely the moment when most companies hesitate for too long. Blank Rome took five weeks; in Austria, that would require some explaining.<\/p>\n<p>Article 34 paragraph 3 GDPR provides for exceptions, and one of them is the best argument for any encryption project that is currently stuck in the budget. If the affected data was effectively encrypted and the key has not been compromised, the notification of the data subjects is waived. The notification to the supervisory authority remains unaffected by this.<\/p>\n<h2 id=\"page-drama-baby-drama\">Drama, Baby, Drama!<\/h2>\n<p>The range of fines for violations of Articles 33 and 34 of the GDPR extends up to EUR 10 million or 2 % of global annual revenue (Article 83(4) of the GDPR). That is still the \u201emoderate\u201c threat. Anyone who, in the same incident, has also violated Articles 5 or 6 of the GDPR\u2014for example, because the leaked data should not have been processed (anymore)\u2014will face the upper limit of EUR 20 million or 4 % of global annual revenue.<\/p>\n<p>The understandable focus on fines often overshadows what other regulatory sanctions threaten and what other consequences a data breach can have. The far-reaching corrective powers of the data protection authority under Article 58 of the GDPR are frequently underestimated in risk analyses. The Austrian DPA can do much more than \u201ejust\u201c impose penalties: it can order controllers to adapt processing operations or, as its sharpest weapon, pronounce a temporary or permanent restriction of processing up to a complete ban on data processing (Article 58(2)(f) GDPR). For any company whose operational business relies on customer data, such a regulatory prohibition is tantamount to an operational cardiac arrest.<\/p>\n<p>These official interventions are often flanked by massive reputational damage (especially if the incident is not handled professionally). The moment you have to explain to customers or business partners that their sensitive data has fallen into the wrong hands\u2014possibly for avoidable reasons\u2014represents a fundamental breach of trust. Such a damaged image in the market cannot be restored by an IT backup and often leads to permanent customer loss, the economic damage of which can in the long run even exceed the actual fine.<\/p>\n<h2 id=\"page-schadenersatz-und-kollektive-rechtsdurchsetzung\">Damages and collective legal enforcement<\/h2>\n<p>This is where US law firms come in, and this is probably where the difference to the EU is greatest. Pursuant to Article 82 of the GDPR, any person who has suffered material or non-material damage as a result of an infringement has the right to compensation. Over time, the case law of the CJEU has somewhat shaped this provision, revealing a nuanced picture that cannot be pinned down in headlines. In principle, there is no de minimis or materiality threshold (CJEU C-300\/21). Negative feelings such as worry or annoyance as a result of a loss of control can also constitute compensable non-material damage (CJEU C-655\/23, Quirin Privatbank). Even the well-founded fear of future misuse is sufficient (CJEU C-340\/21), whereas a purely hypothetical risk is not (CJEU C-687\/21).<\/p>\n<p>A mere violation is not sufficient for a claim for damages. The Austrian Supreme Court (OGH) has summarized the rule for Austria (6 Ob 113\/24x): There must be a violation, a damage that has actually occurred, and causality between them, whereby the damage must be specifically demonstrated and unsubstantiated claims will fail. Article 82 GDPR serves a purely compensatory function; there is no US-style punitive damages. Furthermore, the degree of fault of the controller does not affect the amount of the claims. This puts the individual sum an affected party can receive into perspective, but it does not make a data breach risk-free from a damage law perspective. In the DACH region, mostly low three-digit to mid four-digit amounts are awarded, but multiplied by tens of thousands of affected parties (in the initial case: 57,554), this results in a figure that one must first be able to explain internally without suffering damage. Also to be factored into the risk assessment in this context is the burden of proof. In legal proceedings, it is the controller who must prove that the security measures were appropriate (Art. 5(2), Art. 24, Art. 32 GDPR, ECJ C-340\/21).<\/p>\n<p>Since July 18, 2024, a dedicated instrument has existed EU-wide, and thus also in Austria, for pooling such claims for damages: the representative action for redress (Sections 623 et seq. of the Code of Civil Procedure in conjunction with the Qualified Entities Act). A Qualified Entity\u2014alongside the Chamber of Labour (AK) and the Consumer Information Association (VKI), this also includes organizations like noyb\u2014can assert the pooled claims of at least 50 consumers before the Vienna Commercial Court; participation is by opt-in, and third-party funding is permissible. Austria is thus still a far cry from U.S.-style conditions. However, the infrastructure for class actions is in place and will certainly become more effective over time, thereby becoming a more relevant threat in the event of a data breach.<\/p>\n<h2 id=\"page-bald-kommt-ein-weiteres-fristenregime-dazu\">Soon another deadline regime will be added<\/h2>\n<p>Whoever believes that a GDPR notification is a sustainable solution has clearly turned a deaf ear to the topic of cybersecurity over the past few months. With the NISG 2026 (Federal Law Gazette I 94\/2025), Austria is implementing the NIS 2 Directive, which has been widely discussed for years, roughly two years after the implementation deadline has passed.<\/p>\n<p>Starting October 1, 2026, mandatory risk management and reporting obligations will apply to approximately 4,000 essential and important entities across 18 sectors, with even tighter timelines than those of the GDPR:<\/p>\n<ul>\n<li>Early warning within 24 hours,<\/li>\n<li>Notification within 72 hours,<\/li>\n<li>Final report within one month (\u00a7 34 NISG 2026).<\/li>\n<\/ul>\n<p>The notification addressee is the newly created Federal Office for Cybersecurity (Cybersecurity Authority). When applying the NISG 2026, it is important not to get the following data wrong:<\/p>\n<ul>\n<li>Effective October 1, 2026, the substantive obligations\u2014namely risk management, governance (discussed below), and reporting obligations\u2014will apply without any further grace period.<\/li>\n<li>By December 31, 2026, registration with the cybersecurity authority will be added (\u00a7 29), an administrative step that says nothing about the status of implementation.<\/li>\n<li>By September 30, 2027, a structured self-declaration on the implemented risk management measures must then be submitted (\u00a7 33). This final deadline is not an implementation deadline, but a reporting deadline. Anyone who only begins working in the summer of 2027 informs the authority in writing that they have been working illegally for eleven months.<\/li>\n<\/ul>\n<p>For managing directors and board members, the regulations under the heading \u201eGovernance\u201c in Section 31 of the NISG 2026 (Article 20 of the NIS-2 Directive) represent a significant innovation. Management bodies must approve risk management measures, monitor their implementation, and complete training themselves. Cybersecurity is therefore definitively no longer an IT department issue, but rather a duty of care for executive management.<\/p>\n<p>Practically speaking, two notification logics exist side by side, and they are not congruent. The GDPR ties into personal data, whereas the NISG 2026 ties into significant cybersecurity incidents. A case like Blank Rome would clearly be a data breach under the GDPR, but likely not a reportable incident under the NISG 2026. Conversely, a system outage at a company within the scope of application can be reportable solely under the NISG 2026 even without any data exfiltration. Anyone who pours both into a single process must query two thresholds and generate two different reports.<\/p>\n<p>Therefore, in an emergency, reports must be made twice. And those not directly covered are frequently held to the same standards contractually through the supply chain obligations of their NIS-2-bound clients.<\/p>\n<h2 id=\"page-fazit\">Conclusion<\/h2>\n<p>An excellent reputation protects neither against attackers nor against subsequent lawsuits. The GDPR does not demand error-free IT; it requires appropriate technical and organizational measures and functioning crisis management. One should not rely on the argument that a single employee simply failed. Fines directly affect the legal entity, even without a specific natural person being named. Within the scope of the GDPR, there is no room for Section 11 of the Austrian Data Protection Act (DSG) (warning instead of penalties) and Section 33a of the Austrian Administrative Offences Act (VStG) because EU law takes precedence (Federal Administrative Court [BVwG], Mar 24, 2026, W298 2323263-1). Anyone hoping for national mitigation mechanisms is therefore hoping in vain.<\/p>\n<p>Anyone who can demonstrate measures, training, and a documented reporting process is in a significantly better position after an incident than someone who merely claims to have had bad luck. The difference costs a few days of work beforehand and often an order of magnitude more afterward.<\/p>\n<h2 id=\"page-haufige-bzw-relevante-fragen-faqs\">Frequently Asked Questions (FAQs)<\/h2>\n<div class=\"schema-faq-section\">\n<h4 id=\"page-ab-wann-laufen-die-72-stunden\"><em><strong>From when do the 72 hours start?<\/strong><\/em><\/h4>\n<p>From the time the controller becomes aware. Awareness exists as soon as it is established with reasonable certainty that a security incident has led to a personal data breach. A short verification phase is permissible, but it must not become a delaying tactic. If a processor becomes aware, it must inform the controller without undue delay. According to EDPB Guidelines 9\/2022, the controller's time limit then begins with the notification by the processor.<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<div class=\"schema-faq-section\">\n<h4 id=\"page-muss-jede-datenpanne-gemeldet-werden\"><em><strong>Must every data breach be reported?<\/strong><\/em><\/h4>\n<p>No. The notification is not required if the breach is unlikely to result in a risk to the rights and freedoms of natural persons, for example in the case of a document sent to the wrong internal department without sensitive content. The incident must still be documented, including the justification for why it was not reported (Art. 33(5) GDPR).<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<div class=\"schema-faq-section\">\n<h4 id=\"page-wann-mussen-wir-zusatzlich-die-betroffenen-informieren\"><em><strong>When do we additionally have to inform the data subjects?<\/strong><\/em><\/h4>\n<p>If there is a likely high risk, in particular regarding identity, account, health, or access data. The information must be provided without undue delay and in clear and plain language. It may be omitted under certain risk-mitigating circumstances (Art. 34(3) GDPR).<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<div class=\"schema-faq-section\">\n<h4 id=\"page-ist-unser-unternehmen-vom-nisg-2026-erfasst\"><em><strong>Is our company covered by the NISG 2026?<\/strong><\/em><\/h4>\n<p>Sector and size are decisive. Covered are entities from 18 sectors that generally have at least 50 employees or more than 10 million euros in annual turnover or balance sheet total; a few activities are covered regardless of company size. The classification must be carried out independently; there is no official notification. Even those not directly covered should check whether NIS-2-obligated customers pass on the requirements via supply chain clauses.<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<div class=\"schema-faq-section\">\n<h4 id=\"page-mit-welchen-schadenersatzforderungen-ist-in-osterreich-im-falle-eines-data-breach-auf-grundlage-bisheriger-erfahrungen-realistisch-zu-rechnen\"><em><strong>What claims for damages can realistically be expected in Austria in the event of a data breach (based on previous experience)?<\/strong><\/em><\/h4>\n<p>In individual cases mostly in the low three-figure to mid four-figure range, depending on the data category, intensity, and duration of the infringement. The claim requires concretely demonstrated damage; the mere violation is not sufficient (OGH 6 Ob 113\/24x). The actual risk lies in the multiplication across a large number of affected parties and in the burden of proof, since the controller must prove the appropriateness of the security measures.<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<h3 id=\"page-sind-sie-auf-den-ernstfall-vorbereitet-oder-stecken-sie-schon-mittendrin\">Are you prepared for the worst-case scenario, or are you already right in the middle of it?<\/h3>\n<p><em>ATB.LAW assists you with GDPR compliance, reviews your contracts with IT service providers, and stands by your side in an emergency, from reporting to the data protection authority to defending against claims for damages. Contact us before trouble knocks at your door. Contact <a href=\"https:\/\/atb.law\/en\/stefan-knotzer\/\">Stefan Knotzer<\/a> and <a href=\"https:\/\/atb.law\/en\/roman-taudes\/\">Roman Taudes<\/a> at any time under <a href=\"mailto:office@atb.law\">office@atb.law<\/a> or by phone at <a href=\"tel:+4313912345\">01 39 12345<\/a> for a non-binding initial consultation.<\/em><\/p>","protected":false},"template":"","categories":[29],"class_list":["post-9229","blog-post","type-blog-post","status-publish","has-post-thumbnail","hentry","category-datenschutz-und-ki"],"acf":[],"post-kategorie":"29","_post-kategorie":"field_66d947537140a","post-kurzbeschreibung":"Was \u00f6sterreichische Unternehmen aus dem Vorfall einer US-Gro\u00dfkanzlei lernen k\u00f6nnen","_post-kurzbeschreibung":"field_66d949fe1efe2","post-beitragsbild":"9230","_post-beitragsbild":"field_66d94a4a1efe3","post-author_post-author-name":"Stefan Knotzer","_post-author_post-author-name":"field_66d94a801efe5","post-author_post-author-foto":"8759","_post-author_post-author-foto":"field_66d94aa11efe6","post-author":"","_post-author":"field_66d94ee2827ca","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data Breach, DSGVO, NISG 2026 &amp; Co: Was im Ernstfall z\u00e4hlt<\/title>\n<meta name=\"description\" content=\"Ein Data Breach kann jedem passieren. Erfahren Sie, was DSGVO &amp; Co bei Cyber-Vorf\u00e4llen vorsehen und was im Ernstfall zu beachten ist.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/atb.law\/en\/blog-post\/gdpr-nis2-2026-data-breach-notification-obligations\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data Breach, DSGVO, NISG 2026 &amp; Co: Was im Ernstfall z\u00e4hlt\" \/>\n<meta property=\"og:description\" content=\"Ein Data Breach kann jedem passieren. Erfahren Sie, was DSGVO &amp; Co bei Cyber-Vorf\u00e4llen vorsehen und was im Ernstfall zu beachten ist.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/atb.law\/en\/blog-post\/gdpr-nis2-2026-data-breach-notification-obligations\/\" \/>\n<meta property=\"og:site_name\" content=\"ATB.LAW\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-05T10:34:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/atb.law\/wp-content\/uploads\/2026\/08\/Bild_001-1024x559.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"559\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/dsgvo-nisg-2026-data-breach-meldepflichten\\\/\",\"url\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/dsgvo-nisg-2026-data-breach-meldepflichten\\\/\",\"name\":\"Data Breach, DSGVO, NISG 2026 & Co: Was im Ernstfall z\u00e4hlt\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/atb.law\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/dsgvo-nisg-2026-data-breach-meldepflichten\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/dsgvo-nisg-2026-data-breach-meldepflichten\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Bild_001-scaled.png\",\"datePublished\":\"2026-08-05T07:18:28+00:00\",\"dateModified\":\"2026-08-05T10:34:48+00:00\",\"description\":\"Ein Data Breach kann jedem passieren. Erfahren Sie, was DSGVO & Co bei Cyber-Vorf\u00e4llen vorsehen und was im Ernstfall zu beachten ist.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/dsgvo-nisg-2026-data-breach-meldepflichten\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/atb.law\\\/blog-post\\\/dsgvo-nisg-2026-data-breach-meldepflichten\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/dsgvo-nisg-2026-data-breach-meldepflichten\\\/#primaryimage\",\"url\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Bild_001-scaled.png\",\"contentUrl\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Bild_001-scaled.png\",\"width\":2560,\"height\":1396,\"caption\":\"Laptop verliert Daten\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/dsgvo-nisg-2026-data-breach-meldepflichten\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/atb.law\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data Breach: Der Teufel schl\u00e4ft nicht\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/atb.law\\\/#website\",\"url\":\"https:\\\/\\\/atb.law\\\/\",\"name\":\"atb Rechtsanw\u00e4lte\",\"description\":\"Rechtsanwaltskanzlei in Wien\",\"publisher\":{\"@id\":\"https:\\\/\\\/atb.law\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/atb.law\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/atb.law\\\/#organization\",\"name\":\"atb Rechtsanw\u00e4lte\",\"url\":\"https:\\\/\\\/atb.law\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/atb.law\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/ATB_Rechtsanwaelte_site-logo-beige.png\",\"contentUrl\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/ATB_Rechtsanwaelte_site-logo-beige.png\",\"width\":1572,\"height\":1110,\"caption\":\"atb Rechtsanw\u00e4lte\"},\"image\":{\"@id\":\"https:\\\/\\\/atb.law\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data Breach, GDPR, NISG 2026 &amp; Co: What Counts in an Emergency","description":"A data breach can happen to anyone. Learn what GDPR and other regulations require in the event of cyber incidents and what to watch out for in an emergency.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/atb.law\/en\/blog-post\/gdpr-nis2-2026-data-breach-notification-obligations\/","og_locale":"en_US","og_type":"article","og_title":"Data Breach, DSGVO, NISG 2026 & Co: Was im Ernstfall z\u00e4hlt","og_description":"Ein Data Breach kann jedem passieren. Erfahren Sie, was DSGVO & Co bei Cyber-Vorf\u00e4llen vorsehen und was im Ernstfall zu beachten ist.","og_url":"https:\/\/atb.law\/en\/blog-post\/gdpr-nis2-2026-data-breach-notification-obligations\/","og_site_name":"ATB.LAW","article_modified_time":"2026-08-05T10:34:48+00:00","og_image":[{"width":1024,"height":559,"url":"https:\/\/atb.law\/wp-content\/uploads\/2026\/08\/Bild_001-1024x559.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/atb.law\/blog-post\/dsgvo-nisg-2026-data-breach-meldepflichten\/","url":"https:\/\/atb.law\/blog-post\/dsgvo-nisg-2026-data-breach-meldepflichten\/","name":"Data Breach, GDPR, NISG 2026 &amp; Co: What Counts in an Emergency","isPartOf":{"@id":"https:\/\/atb.law\/#website"},"primaryImageOfPage":{"@id":"https:\/\/atb.law\/blog-post\/dsgvo-nisg-2026-data-breach-meldepflichten\/#primaryimage"},"image":{"@id":"https:\/\/atb.law\/blog-post\/dsgvo-nisg-2026-data-breach-meldepflichten\/#primaryimage"},"thumbnailUrl":"https:\/\/atb.law\/wp-content\/uploads\/2026\/08\/Bild_001-scaled.png","datePublished":"2026-08-05T07:18:28+00:00","dateModified":"2026-08-05T10:34:48+00:00","description":"A data breach can happen to anyone. Learn what GDPR and other regulations require in the event of cyber incidents and what to watch out for in an emergency.","breadcrumb":{"@id":"https:\/\/atb.law\/blog-post\/dsgvo-nisg-2026-data-breach-meldepflichten\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/atb.law\/blog-post\/dsgvo-nisg-2026-data-breach-meldepflichten\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/atb.law\/blog-post\/dsgvo-nisg-2026-data-breach-meldepflichten\/#primaryimage","url":"https:\/\/atb.law\/wp-content\/uploads\/2026\/08\/Bild_001-scaled.png","contentUrl":"https:\/\/atb.law\/wp-content\/uploads\/2026\/08\/Bild_001-scaled.png","width":2560,"height":1396,"caption":"Laptop verliert Daten"},{"@type":"BreadcrumbList","@id":"https:\/\/atb.law\/blog-post\/dsgvo-nisg-2026-data-breach-meldepflichten\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/atb.law\/"},{"@type":"ListItem","position":2,"name":"Data Breach: Der Teufel schl\u00e4ft nicht"}]},{"@type":"WebSite","@id":"https:\/\/atb.law\/#website","url":"https:\/\/atb.law\/","name":"atb Attorneys at Law","description":"Law firm in Vienna","publisher":{"@id":"https:\/\/atb.law\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/atb.law\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/atb.law\/#organization","name":"atb Attorneys at Law","url":"https:\/\/atb.law\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/atb.law\/#\/schema\/logo\/image\/","url":"https:\/\/atb.law\/wp-content\/uploads\/2024\/05\/ATB_Rechtsanwaelte_site-logo-beige.png","contentUrl":"https:\/\/atb.law\/wp-content\/uploads\/2024\/05\/ATB_Rechtsanwaelte_site-logo-beige.png","width":1572,"height":1110,"caption":"atb Rechtsanw\u00e4lte"},"image":{"@id":"https:\/\/atb.law\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/blog-post\/9229","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/blog-post"}],"about":[{"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/types\/blog-post"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/media\/9230"}],"wp:attachment":[{"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/media?parent=9229"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/categories?post=9229"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}