The European Data Protection Board published updated guidelines on personal data breach notification under the EU General Data Protection Regulation. The guidelines, adopted 28 March following public consultation, clarify notification requirements for personal data breaches at non-EU establishments. The guidelines state each supervisory authority for member states where affected data subjects reside need to be notified of a breach.