可打印的卡片
数据泄露:值得留存的材料
七个反应,按它们用得上的顺序排列,从告知邮件到投诉。每一条都带着支撑它的条文。
卷宗 EU 2016/679
本页是为打印做的:打印时周围整个界面都会消失。
法律状态核对于July 29, 2026
- 01
留住告知邮件,连同它的日期
告知一起高风险的泄露是一项法律义务:那条讯息是一份证据材料。截图、时间戳、全文,在任何其他步骤之前先做。
Article 34(1) · Regulation (EU) 2016/679, Article 34 (Communication of a personal data breach to the data subject), paragraph 1 · eur-lex.europa.eu - 02
不要让“事件”这个词让你安心
官方定义涵盖毁坏、丢失、篡改、未经授权的披露或访问,无论是意外的还是不法的。公司选用的词汇不改变法律上的类别。
Article 4(12) · Regulation (EU) 2016/679, Article 4 (Definitions), point 12 · eur-lex.europa.eu - 03
核对应当给出的三样东西,并主张缺失的部分
一个可以获得更多信息的联络点、可能的后果、已采取或拟采取的措施:告知必须至少包含这三个要素,并且用简明易懂的语言。
Article 34(2) · Regulation (EU) 2016/679, Article 34 (Communication to the data subject), paragraph 2 · eur-lex.europa.eu - 04
认清两个计时
在可行的情况下不迟于 72 小时向监管机构发出通知,否则通知要带上延迟的理由。朝着你的那一边没有数字:一旦风险很高,就不得无故拖延。绝不要把主张建立在错误的计时上。
Article 33(1) · Regulation (EU) 2016/679, Article 33 (Notification of a personal data breach to the supervisory authority), paragraph 1 · eur-lex.europa.eu - 05
去问那个联络点,它就是为此而设的
条文要求告知数据保护官的姓名和联系方式,或者另一个可以获得更多信息的联络点。哪些数据、哪些后果、哪些措施:就在那里问。
Article 33(3) · Regulation (EU) 2016/679, Article 33 (Notification to the supervisory authority), paragraph 3, points (b) to (d) · eur-lex.europa.eu - 06
没有收到邮件?先核对例外,再生气
对受影响的数据采取的加密、事后消除风险的措施,或者在给每一个人写信不成比例时作出的公开告知:这些出口存在,而且是写下来的。监管机构可以核查它们,并要求作出告知。
Article 34(3) · Regulation (EU) 2016/679, Article 34 (Communication to the data subject), paragraph 3, points (a) and (c) · eur-lex.europa.eu - 07
在你自己的国家提出投诉
惯常居所、工作地或者违规行为发生地:机构由你选。为了提请它,没有什么可量化的损失需要证明,而它应当把进展和结果给你。
Article 77(1) and (2) · Regulation (EU) 2016/679, Article 77 (Right to lodge a complaint with a supervisory authority) · eur-lex.europa.eu
关于欧洲共同底线的一般信息,不是针对你个案的法律咨询。独立的教育网站,与欧盟机构无关。本卷宗里的救济链接只指向官方机构。
来源核对于 July 29, 2026。 · https://depleindroit.odersa.org/zh/fiches/la-fuite-de-donnees · 内容采用 CC BY 4.0 许可。
法律欠你什么
每一项权利,连同它的金额或期限、支撑它的官方文本节录,以及它的网址。
泄露不只是一次入侵
个人数据泄露涵盖毁坏、丢失、篡改、未经授权的披露或者未经授权的访问,无论是意外的还是不法的。一次内部失误或者一台丢失的笔记本电脑,与一次攻击同样符合这个定义。
官方文本,原文语言 · Article 4(12)
Official Journal of the European Union · EUR-Lex · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679“‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;”
风险高时直接得到告知
当泄露可能对你的权利和自由造成高风险时,数据控制者要针对你个人把它告知你,不得无故拖延。那封告知邮件是一项义务,不是一次商业上的表示。
官方文本,原文语言 · Article 34(1)
Official Journal of the European Union · EUR-Lex · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679“1. When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.”
最低内容,用简明易懂的语言
告知要描述泄露的性质,并且至少包含一个可以获得更多信息的联络点、可能的后果,以及已采取或拟采取的措施。缺失的东西可以拿来主张。
官方文本,原文语言 · Article 34(2)
Official Journal of the European Union · EUR-Lex · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679“2. The communication to the data subject referred to in paragraph 1 of this Article shall describe in clear and plain language the nature of the personal data breach and contain at least the information and measures referred to in points (b), (c) and (d) of Article 33(3).”
72 小时:计时朝着机构走
72 小时
向监管机构发出的通知应当给出,不得无故拖延,并且在可行的情况下不迟于知悉之后 72 小时;超过这个时间,它必须带上延迟的理由。给你的那份告知没有数字:一旦风险很高,它就应当给出,不得无故拖延。
官方文本,原文语言 · Article 33(1)
Official Journal of the European Union · EUR-Lex · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679“1. In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.”
机构可以命令他们提醒你
如果公司没有给你写信,监管机构可以考量该泄露是否带有高风险,然后要求作出针对个人的告知,或者认定某个写明的例外适用。最后一句话不属于那份公开声明。
官方文本,原文语言 · Article 34(4)
Official Journal of the European Union · EUR-Lex · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679“4. If the controller has not already communicated the personal data breach to the data subject, the supervisory authority, having considered the likelihood of the personal data breach resulting in a high risk, may require it to do so or may decide that any of the conditions referred to in paragraph 3 are met.”
一项在你居住的地方提出的投诉
向监管机构提出,尤其是向你惯常居所、工作地或者违规行为发生地所在成员国的监管机构提出。该机构此后会把进展和结果告知你,包括司法救济的可能性。
官方文本,原文语言 · Article 77(1) and (2)
Official Journal of the European Union · EUR-Lex · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679“1. Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes this Regulation. 2. The supervisory authority with which the complaint has been lodged shall inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Article 78.”
本站是教育性的、独立的:本站不是欧盟的官方网站,本裁定也不是针对你个案的法律咨询。所引录的期限和表述均取自官方条文或官方页面,其链接列在每一项权利之下。
卷宗 EU 2016/679
这份卷宗里的材料
每份材料都有自己的页面。处境在这里玩;你留下的、你寄出的、你回头再读的,都住在隔壁。