In this module, we’ve learned what to do if things go wrong.
A lot of organisations wouldn’t report a breach if they were in Mike’s position. Not only is this unethical, it can backfire horribly.
Some of the biggest fines in GDPR history have been given to companies who’ve tried to cover up a data breach.

On the other hand, organisations which do their best to comply with the GDPR don’t have much to worry about.
The ICO isn’t a bogeyman, and reporting a data breach doesn’t mean you’ll be punished.
