书面全程
邮件通知的数据泄露:书面全程
宣告数据泄露的那封邮件不是一种礼貌,它是一部条例里的一条。72 小时是朝着机构走的,告知欠你简明的语言和具体的内容,而投诉在你自己的国家提出。
法律状态核对于July 29, 2026
这份全程里带着答案。它在这里,是为了不玩也能读这个处境,为了能打印,也为了没有 JavaScript 时内容依然完整。
第 1 号材料 · 18:06,一封谨慎的邮件
在同一个应用里记录跑步 3 年:邮箱地址、路线、你出门的时间点。你住在比利时,这家服务设立在欧盟的另一个国家。
18:06 来了一封邮件。它有署名,它很平静,而它几乎什么都没说。
这封邮件:它究竟是什么?
答对 · 一份证据材料:我原样把它留下,连同它的日期,并且把它当作一部条例所要求的行为来读。
这封邮件不是一种礼貌,它是一项写明的义务 当一起泄露可能让你面临高风险时,公司无权选择要不要告诉你:告知是应当履行的,不得无故拖延。这封讯息之所以存在,是因为有一条条文要求它存在。而一部条例所要求的行为要留下来:它是接下来这一切的第一份材料。
“1. When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.”
非官方译文:如果泄露能伤到你,他们必须告诉你,针对你个人,直接地,而且不拖拖拉拉。这封邮件是一份法律文件,不是一份订阅通讯。
Article 34(1) · Regulation (EU) 2016/679, Article 34 (Communication of a personal data breach to the data subject), paragraph 1 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679误区 · 要是严重,他们不会只发一封邮件。我把它删了。
误区:“没有挂号信,就没有真问题” 欧盟官方页面说的恰好相反:当泄露带有严重风险时,公司必须直接告知你。一封低调的邮件不是一个微弱的信号,它就是规则所规定的渠道。把它删掉,等于扔掉一份刚刚自己打开的卷宗的第 1 号材料。
“the data controller (the person or body handling your personal data) must report it to the national data protection authority. The data controller must also inform you directly if there are serious risks related to your personal data or privacy due to the breach.”
非官方译文:这封讯息是一项针对你的法律义务。法律义务是要存卷的,不是扔进回收站的。
Section “Unauthorised access to your data” · Data protection: unauthorised access to your data (data breach) · https://europa.eu/youreurope/citizens/consumers/internet-telecoms/data-protection-online-privacy/index_en.htm误区 · 他们说的是“内部事件”,不是入侵:那不算真正的泄露。
误区:“泄露必定意味着黑客” 条例对个人数据泄露的定义远比一部劫案片宽:毁坏、丢失、篡改、未经授权的披露或者未经授权的访问,无论是意外的还是不法的。一台忘在列车上的笔记本电脑就符合这个定义。“事件”这个词并不能把任何人带出条文之外。
“‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;”
非官方译文:不需要戴帽衫的黑客。一次内部失误、一次丢失、一次多出来的访问:定义把这些全都覆盖,而随之而来的义务同样适用。
Article 4(12) · Regulation (EU) 2016/679, Article 4 (Definitions), point 12 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679第 2 号材料 · 所有人都记错的那个数字
那天晚上来了一条朋友的讯息:他收到了同一封邮件。
那 72 小时:它们究竟在计什么?
答对 · 是向机构发出的通知。我应当得到的是一次“不得无故拖延”的告知,上面没有附任何数字。
72 小时朝着机构,不得无故拖延朝着你 条例启动两个各自独立的计时。第一个带着数字,朝着监管机构走:通知不得无故拖延,并且在可行的情况下不迟于 72 小时,否则通知必须带上延迟的理由。第二个在风险很高时朝着你走:不得无故拖延,没有数字。知道哪个计时是哪一个,就意味着从第一封信起就瞄得准。
“1. In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.”
非官方译文:那 72 小时是他们与机构的约,不是与你的约。一旦风险很高,你应当得到一次不加拖延的告知,而机构可以核查他们的时间表。
Article 33(1) · Regulation (EU) 2016/679, Article 33 (Notification of a personal data breach to the supervisory authority), paragraph 1 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679误区 · 他们必须在 72 小时内提醒我:超过期限,自动赔偿。
误区:“72 小时内提醒我,否则中大奖” 第 33 条的 72 小时计的是向监管机构发出的通知,不是寄给你的那封邮件。而条文没有规定任何自动赔偿:向机构迟到的通知要的是理由,不是一张支票。把你的主张建立在错误的期限上,等于把世上最容易的答复递给公司:“那个期限与你无关”,而它会是对的。
“Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.”
非官方译文:即便他们对机构迟到了,写明的后果也是要提供一份理由,不是一笔从天上掉下来的钱。你真正的牌在别处:告知的内容,以及在你自己国家提出的投诉。
Article 33(1) · Regulation (EU) 2016/679, Article 33 (Notification of a personal data breach to the supervisory authority), paragraph 1 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679没有作用 · 我把这封邮件转发给我整个通讯录,主题:READ THIS。公众告知任务完成。
告知公众早已是一项义务,而它不是你的义务 条例为提醒每一个人需要付出不成比例的努力的情形作了安排:那时应由公司作出一次公开告知,其效果与直接讯息相当。你的通讯录不是官方渠道,而你的牙医并未受到影响。把力气省下来,留给唯一重要的那份清单:告知就你个人而言欠你什么。
“it would involve disproportionate effort. In such a case, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.”
非官方译文:当针对个人的邮件不可能时,条文要求一份同样能告知到位的公开声明。传播告知是一项被组织起来的义务,不是一封连锁信。
Article 34(3) · Regulation (EU) 2016/679, Article 34 (Communication to the data subject), paragraph 3, points (a) and (c) · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679第 3 号材料 · 邮件没有说的东西
你重读那封邮件,这一次把条例的清单摆在旁边。你逐项勾掉已经有的东西。很快就完了。
- 泄露的性质
- “一起安全事件”,没有其他细节
- 联络点
- 缺失
- 可能的后果
- 缺失
- 已采取的措施
- “我们的系统已经加固”,没有细节
- 给出的建议
- “无需采取任何行动”
你回复什么,你要求什么?
答对 · 我回复,要求补齐缺失的部分:联络点、可能的后果、措施的细节。
告知有一张采购清单,而它是写下来的 你应当得到的告知必须至少包含三样东西,与向机构发出的通知相同:一个可以获得更多信息的联络点、泄露可能的后果,以及为应对它已采取或拟采取的措施。“无需采取任何行动”一样也代替不了。缺失的东西是拿来主张的,一件一件地主张。
“3. The notification referred to in paragraph 1 shall at least: […] (b) communicate the name and contact details of the data protection officer or other contact point where more information can be obtained; (c) describe the likely consequences of the personal data breach; (d) describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.”
非官方译文:一个回答你问题的联络方式、一份关于你面临什么风险的诚实说明,以及一份他们正在做什么的交代。这三行是欠你的,而第 34 条一字一句地把它们搬进了寄给你的那封邮件里。
Article 33(3) · Regulation (EU) 2016/679, Article 33 (Notification to the supervisory authority), paragraph 3, points (b) to (d) · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679误区 · 调查还在进行:他们不被允许告诉我更多,保密优先。
误区:“他们什么都不能说,这是保密的” 条例已经在谨慎和你的知情之间做过裁断:寄给你的告知要用简明易懂的语言描述泄露的性质,并且至少包含联络点、可能的后果和已采取的措施。这份清单是法律上的最低限度,不是危机之后的一份人情。一家用保密来把它掏空的公司,念的是自己的内部政策,不是条文。
“2. The communication to the data subject referred to in paragraph 1 of this Article shall describe in clear and plain language the nature of the personal data breach and contain at least the information and measures referred to in points (b), (c) and (d) of Article 33(3).”
非官方译文:告知的最低内容由条例本身设定。缺失的东西可以拿来主张,而公司不能拿自己的调查来对付你。
Article 34(2) · Regulation (EU) 2016/679, Article 34 (Communication to the data subject), paragraph 2 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679误区 · 这是技术话题,术语躲不掉:跟得上是我的事。
误区:“泄露只能用术语来解释” “用简明易懂的语言”:条例里的五个词,恰好安放在那里,在描述告知邮件的那一条里。清晰不是留给公司好意去做的一种文风努力,它是对讯息形式的法律要求。一份读不懂的文字不是一份合规的文字,而你可以要一个能读的版本。
“The communication to the data subject referred to in paragraph 1 of this Article shall describe in clear and plain language the nature of the personal data breach”
非官方译文:让人看得懂是他们的活,当工程师不是你的活。法律既要求讯息的内容,也同样要求讯息的清晰。
Article 34(2) · Regulation (EU) 2016/679, Article 34 (Communication to the data subject), paragraph 2 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679第 4 号材料 · 什么都没收到的那一位
一位同事用同一个应用。她一封邮件都没收到。四处找了找,你发现服务网站上发布了一份声明。
她很生气:“没有针对个人的邮件,这是违法的吧?”
就近期发现的安全事件,我们确认密码受到强加密的保护。
数据可能受到影响的用户已被逐一联系。其他任何人都无需采取任何行动。
她没有收到邮件:这就自动构成违规行为吗?
答对 · 不是自动的:条文规定了写明的出口,而我知道谁可以核查它们。
如果公司免掉了那封邮件,机构可以把它抓住 条例规定了不要求针对个人的邮件的情形:诸如加密这样的措施、事后消除风险的措施,或者在给每个人写信不成比例时作出的公开告知。但它同时点名了裁判:监管机构可以考量风险是否很高,并且要求作出告知,或者认可该例外。你的同事和公司,谁都不能单独说最后一句话。
“4. If the controller has not already communicated the personal data breach to the data subject, the supervisory authority, having considered the likelihood of the personal data breach resulting in a high risk, may require it to do so or may decide that any of the conditions referred to in paragraph 3 are met.”
非官方译文:公司的沉默不是故事的结尾。一个机构可以核查它的推理,并迫使它写下那封它从未发出的邮件。
Article 34(4) · Regulation (EU) 2016/679, Article 34 (Communication to the data subject), paragraph 4 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679误区 · 没有针对个人的邮件就等于违规行为,没别的。她要求立即赔偿。
误区:“我没收到邮件,所以必定是违规行为” 条文明明白白地写出了不要求针对个人的告知的情形:对受影响的数据采取诸如加密这样的保护措施,或者在给每一个人写信需要付出不成比例的努力时作出一次同样有效的公开告知。对着一个写明的例外发火,会让你在下一回合失掉说法。正确的问题不是“为什么不是我?”,而是“这个例外站得住吗?”,而这个问题有一位裁判。
“3. The communication to the data subject referred to in paragraph 1 shall not be required if any of the following conditions are met: (a) the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption;”
非官方译文:妥当加密的数据可以免掉针对个人的邮件。这个例外存在,它很精确,而且可以被核查:写信之前先知道这一点更好。
Article 34(3) · Regulation (EU) 2016/679, Article 34 (Communication to the data subject), paragraph 3, points (a) and (c) · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679误区 · 如果他们写了已经加密,就此结案:没人能去核查。
误区:“他们的公开声明算作证据” 一份声明是一次宣称,不是一次核实。而本国数据保护机构其实已经被告知了:泄露一发生,就应当向它发出通知。它了解这份卷宗,它可以把声明拿去对照事实,而且如果风险很高,它可以要求作出针对个人的告知。因为公司自称没有过错就放弃,等于把被告当成了法院的书记官。
“the data controller (the person or body handling your personal data) must report it to the national data protection authority.”
非官方译文:你所在国家的机构因为义务而已经在局内。公司对公众说的话,必须能够向一个有权核查的对象证明。
Section “Unauthorised access to your data” · Data protection: unauthorised access to your data (data breach) · https://europa.eu/youreurope/citizens/consumers/internet-telecoms/data-protection-online-privacy/index_en.htm第 5 号材料 · 3 周之后
钓鱼邮件现在落进那个你只为这个应用用过的邮箱。它们知道你的名字。泄露和你的收件箱之间的那条线自己画了出来。
你希望有人来审查这份卷宗。问题是谁,以及在哪里。
你把这份卷宗带到哪里?
答对 · 我向我自己国家的数据保护机构提出投诉。
投诉在你居住的地方提出,不在服务设立的地方 这一条给你三个可供选择的地点,第一个是你的惯常居所;另外两个是你的工作地和被指称的违规行为发生地。公司的总部不在这份清单上。而你所提请的那个机构此后应当把消息给你:你投诉的进展和结果,包括司法救济的可能性。
“1. Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes this Regulation.”
非官方译文:你在自己的国家、用自己的语言、向自己的机构投诉。卷宗的地理由你选。
Article 77(1) and (2) · Regulation (EU) 2016/679, Article 77 (Right to lodge a complaint with a supervisory authority) · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679误区 · 没有经过证明、可以量化的损失,投诉就不会被受理。我要等到真的损失了钱再说。
误区:“要投诉,先得有一张发票” 门槛条件不是一项损失,而是一个有理由的看法:你认为你的权利没有得到尊重,于是你可以直接向本国机构投诉,机构会调查并在 3 个月内答复。等着被偷了再去报告那扇敞开的门,把顺序弄反了:投诉之所以存在,恰恰是为了让卷宗在事情变得更糟之前得到审查。
“If you think your data protection rights have not been respected, you can make a complaint directly to your national data protection authority which will investigate your complaint and give you a response within 3 months.”
非官方译文:“如果你认为”就够了。走进机构那扇门之前,没有什么损失需要证明。
Section “Making a complaint” · Data protection: making a complaint · https://europa.eu/youreurope/citizens/consumers/internet-telecoms/data-protection-online-privacy/index_en.htm误区 · 这样的卷宗,没有律师或者集体诉讼是走不动的。我不参与了。
误区:“只有一支律师大军才能对付数据泄露” 向机构提出投诉不是一场诉讼:它是一道你自己就能启动的行政程序,而条文使机构有义务把进展和结果持续告知你,包括其后司法救济的可能性。法院始终是一个选项,绝不是一个前置条件。你手上这份卷宗,连那封含糊的邮件一起,已经够开始了。
“2. The supervisory authority with which the complaint has been lodged shall inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Article 78.”
非官方译文:投诉一旦提出,机构就开始工作,并且向你回报。你没有支出任何费用,没有律师,没有审判。
Article 77(1) and (2) · Regulation (EU) 2016/679, Article 77 (Right to lodge a complaint with a supervisory authority) · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679裁定 · 一封三句话的邮件值多少
一封 18:06 到达的谨慎邮件、一份 30 秒就把它掏空的核对清单、一份有待核实的声明,以及一个从你自己国家提请的机构。
卷宗 EU 2016/679
这份卷宗里的材料
每份材料都有自己的页面。处境在这里玩;你留下的、你寄出的、你回头再读的,都住在隔壁。