Under the GDPR, a laptop with full-disk encryption is stolen and its key is held elsewhere; must anyone be notified?
answer
- still a breach, maybe not notifiable
- risk versus high risk
- unintelligible to unauthorised persons
- key, backup and power state
- Art. 34(3) exceptions
basics
~20 sUnder the GDPR the theft is still a breach and is recorded. With effective encryption, an uncompromised key and another copy of the data, it is usually unlikely to cause risk, so neither the authority nor individuals are notified.
solid answer
~40 sThe theft is a personal data breach under Art. 4(12) and goes into the Art. 33(5) record whatever the outcome. Whether anyone is notified depends on risk. EDPB Guidelines 9/2022 say a lost device with **state-of-the-art encryption**, a key that was **not compromised**, and data that is **not the only copy** is unlikely to result in a risk. So there is no Art. 33 notice to the authority and no Art. 34 communication to individuals. Art. 34 sets a higher bar anyway: individuals are told only when a breach is *likely to result in a high risk*, and **Art. 34(3)(a)** removes even that duty where the data was unintelligible, for example encrypted. The conclusion is re-examined if the key or the encryption is later found weak.
go deeper
Recall the two thresholds: a risk means notifying the authority, a high risk means also telling individuals. Encryption lowers risk but does not stop the event being a breach.
Walk through the EDPB conditions: effective encryption, an uncompromised key, another copy of the data. Then list the three Art. 34(3) exceptions and which audience each one affects.
Probe where encryption fails in practice, such as stand-by, default keys or a co-located key, and show that deciding not to notify requires documented evidence and later reassessment.
Weigh how device-encryption policy and key custody decide, in advance, which losses become paperwork and which become notifications to regulators and customers.
## Two thresholds, two audiences The GDPR sets different thresholds for its two notification duties: | Duty | Article | Trigger | Deadline | |---|---|---|---| | Notify the **supervisory authority** | Art. 33(1) | always, *unless* the breach is unlikely to result in a risk | without undue delay, where feasible within 72 hours of awareness | | Communicate to **data subjects** | Art. 34(1) | only when the breach is likely to result in a **high risk** | without undue delay | | Document the breach | Art. 33(5) | every breach | no deadline in the text; the record must let the authority verify compliance | The EDPB calls the Art. 34 threshold "higher" on purpose: it spares people notification fatigue. So a breach can be notified to the authority without being communicated to individuals. The order can also invert: the guidelines say that in exceptional cases urgent communication to individuals may come before the authority is notified. ## Applying it to the stolen laptop **Step 1: is it a breach?** Yes. A device holding personal data was lost to an unauthorised person. The encryption changes the risk, not the classification. **Step 2: is it likely to result in a risk?** EDPB Guidelines 9/2022 give this exact case as one that does **not** need notifying: *a securely encrypted mobile device is lost, the encryption key remains in the controller's secure possession, and the device is not the sole copy of the personal data*. Each condition closes a different door: - **effective encryption** means the thief cannot read the data, so there is no confidentiality risk; - **the key held elsewhere and uncompromised** keeps it that way; - **another copy of the data** means the controller has not lost access to it, so there is no availability risk. Without that copy the theft could still be a notifiable availability breach. **Step 3: high risk and Art. 34(3).** Even where there is some risk, **Art. 34(3)** lists three conditions that remove the duty to tell individuals: 1. **(a)** appropriate protection measures were applied to the affected data, *"in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption"*; 2. **(b)** subsequent measures ensure the high risk *"is no longer likely to materialise"*; 3. **(c)** individual contact would involve **disproportionate effort**, in which case a public communication or similar, equally effective measure is required instead. Note what Art. 34(3) does *not* do: it is an exemption from telling **individuals**. Whether the **authority** is notified depends only on the Art. 33(1) risk test. ## Where the encryption argument breaks The guidelines warn that encryption only helps if it actually protected the data at the moment of loss: - a device can be encrypted when **switched off but not in stand-by**, so a laptop stolen while asleep may be readable; - some products ship with **default keys** that each customer must change; - a **key stored with the device**, for example in a file on the same disk, gives no protection; - an algorithm that was adequate may become **outdated**. A controller that skips notification when the data was not in fact securely encrypted fails to comply with Art. 33. And if the key is later found compromised, or a flaw appears in the encryption software, the risk must be **reassessed** and notification may become due. ## What the record should show Under **Art. 33(5)** the controller records the facts, effects and remedial action. For a decision *not* to notify, the EDPB recommends also recording the reasoning, and if an Art. 34(3) condition is relied on, the evidence for it. That means the encryption status at the time of theft, where the key lived, and that the data exists elsewhere. ## What individuals are told when Art. 34 applies If the high-risk threshold is met and no exception applies, **Art. 34(2)** requires the communication to describe the breach *"in clear and plain language"* and include at least the items in Art. 33(3)(b), (c) and (d): a contact point, the likely consequences, and the measures taken or proposed. Under **Art. 34(4)** the supervisory authority may require the controller to communicate, or may decide that an Art. 34(3) condition is met.
- Under the GDPR, what if the stolen laptop was asleep rather than powered off?EDPB Guidelines 9/2022 warn that a device may be encrypted when switched off but not in stand-by. If the data was readable, the encryption argument fails. The controller then assesses risk and high risk as it would for unencrypted data, and notification under Art. 33 and possibly Art. 34 may follow.
- Under GDPR Art. 34, when may a public announcement replace individual messages?Art. 34(3)(c) applies where contacting individuals directly would involve disproportionate effort, for example when the contact details were lost. There must instead be a public communication or similar measure that informs data subjects in an equally effective manner. The EDPB says a press release or corporate blog alone is not effective.
saying these in an interview costs you the question
- Encryption means a stolen laptop isn't a personal data breach at all.
- Art. 34(3)'s exemptions also excuse notifying the supervisory authority.
- Once the authority is notified, individuals must always be told too.
- Individuals only need telling if the supervisory authority orders it.
- Any encryption counts, even with the key stored on the same device.