Skip to content
iGaming Cyprus

iGaming data breach response: assess, record and notify

A personal-data breach can involve loss, alteration, unauthorised disclosure or access, not only a hacker stealing a database. Assess the facts promptly, preserve evidence and determine the applicable notification duties. Do not wait for a complete technical investigation before considering legal deadlines.

iGaming Cyprus · Last updated:

When does a security incident become a data breach?

The EDPB describes a personal-data breach broadly, including accidental events. A misdirected verification document or loss of access to personal data can therefore require assessment alongside more obvious intrusions.

Give staff a simple internal reporting route. The first report should identify what happened, when it was noticed, which systems or records may be involved and who is responding. Avoid requiring the reporter to decide the final legal classification before escalating.

How should the first response be organised?

Contain the incident while preserving the evidence needed to understand it. Assign technical, privacy and operational owners so urgent actions do not proceed in disconnected workstreams.

  • Record the awareness timeline and facts currently known.
  • Limit further exposure using appropriate containment steps.
  • Identify affected data categories and individuals where possible.
  • Assess potential consequences and existing safeguards.
  • Determine regulator, individual and contractual notification duties separately.
  • Record decisions and update the assessment as evidence changes.

What does the 72-hour rule mean?

Under the GDPR notification framework, a controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of awareness unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. Communication to individuals has a separate high-risk test and relevant exceptions.

The EDPB’s guidance addresses incomplete information and phased notification. The practical lesson is to make and document the assessment promptly rather than assume the deadline begins only when every technical detail is known.

Which gaming-specific dependencies need attention?

An incident may affect identity documents, player balances, account access or customer communications. Coordinate the privacy response with payment, security and customer-support teams while limiting unnecessary access to sensitive information.

Gaming-regulator reporting and supplier-contract notifications may be separate from data-protection notifications. Use a recipient-and-deadline matrix so one completed notification is not mistaken for completion of every obligation.

What should the post-incident review produce?

Document the cause, affected scope, decisions, corrective action and evidence of remediation. Review whether access controls, logging, supplier escalation or staff training failed.

Rehearse a scenario such as a verification file sent to the wrong recipient. Check how quickly it reaches the right people and whether the team can assess the data and risks. A small tabletop exercise can expose missing contact details and decision authority before a larger event.

Frequently asked questions

No. Assess the applicable risk test and exceptions; keep the decision documented.

Do not assume so. Notification timing depends on the applicable awareness and risk rules, not simply the completion of a forensic report.

Sources and scope

  1. EDPB — personal-data breaches
  2. EDPB — Guidelines 9/2022

This guide was prepared with AI assistance using the linked sources. It provides general information and practical preparation suggestions, not a legal opinion for a particular business. No personal professional review is claimed.

Get the right structure for your case

Book a free, no-obligation consultation. We’ll confirm the right Cyprus company + licence setup and a fixed fee for your business.

Book my free consultation30 minutes · no obligation · talk to a qualified Cyprus advocate.
Not ready to talk? Get the 2026 licence comparison by email

Receive links to the licensing and cost guides, with the requirements to check before choosing a structure.

One requested guide email. No mailing-list subscription. Privacy

Book my free consultation