Re: Crucial point here, it doesn't become public knowledge. Hush, hush now.
It doesn't say you can only tell the Commissioner or the controller.
Although I'm sure someone will have fun with "intending to cause ... damage ... to a person", which doesn't specify that the person has to be the subject, it can be the person who failed to anonymise the data.