Skip to content
Legiscope
Menu
Data Privacy

GDPR Data Breach Response: The 72-Hour Playbook

A step-by-step playbook for GDPR data breach notification within 72 hours, covering risk assessment, authority reporting, and subject communication.

A GDPR data breach notification process must distinguish detection, awareness, risk assessment and communication. Article 33 requires authority notification without undue delay and, where feasible, within 72 hours of awareness, unless the breach is unlikely to result in a risk to people. Article 34 separately governs high-risk communication to affected individuals.

This playbook translates the legal requirements into an operational incident response process for DPOs, CISOs, and incident response teams who need to move from detection to notification without delay.

What Triggers the 72-Hour Clock?

The obligation to file a gdpr data breach notification begins the moment the controller becomes “aware” of a personal data breach. Awareness, as defined by the EDPB Guidelines on personal data breach notification, does not require a completed forensic investigation: it requires a reasonable degree of certainty that a security incident has compromised personal data.

An alert, customer complaint or processor notice is a signal to investigate promptly. Awareness occurs once the controller has a reasonable degree of certainty that a security incident has compromised personal data. Do not treat every unverified alert as confirmed awareness, or postpone awareness until senior management receives a briefing. Preserve the facts and timestamps supporting the conclusion.

The deadline runs continuously, including weekends and public holidays. If your team confirms a breach at 14:00 on a Friday, the notification must reach the supervisory authority by 14:00 on Monday. If full information is not available within 72 hours, Article 33(4) permits phased notification: submit what you have now, then supplement without undue further delay.

Step-by-Step Incident Response Process

An effective breach response requires pre-established roles, templates, and escalation paths. The following process covers detection through notification and post-incident review.

Step 1: Detect, contain, and classify

The first priority is stopping the breach from expanding – isolate affected systems, revoke compromised credentials, and preserve forensic evidence. Document every containment action with timestamps.

Simultaneously, classify the incident against the three EDPB breach categories: confidentiality breach (unauthorised disclosure or access), integrity breach (unauthorised alteration), or availability breach (loss of access or destruction of data). Determine the categories of data affected, the approximate number of data subjects, and whether encryption or pseudonymisation was in place.

Step 2: Assess risk to data subjects

This is the pivotal decision point. The GDPR imposes two distinct thresholds:

  1. Notification to the supervisory authority (Article 33): required unless the breach is “unlikely to result in a risk” to individuals.
  2. Communication to data subjects (Article 34): required when the breach is “likely to result in a high risk” to individuals.

Assess likely consequences for the affected people, including the sensitivity and context of the data, identifiability, recipient, ease of misuse, duration of unavailability, vulnerability and effectiveness of safeguards. Special-category data increases concern but does not make every event automatically high risk. A prior DPIA can identify relevant harms, but the incident-specific evidence controls the decision.

Step 3: Notify the authority, communicate with data subjects, and document

Under Article 33(3), the supervisory authority notification must include:

Required element Detail
Nature of the breach Categories and approximate number of data subjects and records
DPO contact Name and contact details of the DPO or designated contact
Likely consequences Description of anticipated impact on data subjects
Remedial measures Actions taken or proposed to address the breach and mitigate effects

Most supervisory authorities provide online notification portals. Controllers with Swiss operations should note that the revised FADP follows different rules – see our FADP vs GDPR breach notification comparison. Prepare templates in advance and integrate them into your GDPR compliance checklist so incident responders are not drafting from scratch under pressure. If the notification is filed after 72 hours, Article 33(1) requires the controller to provide reasons for the delay.

When the breach meets the Article 34 high-risk threshold, communicate with affected individuals in clear, plain language describing the breach, its likely consequences, and recommended protective actions. Article 34(3) provides three exceptions: (a) encryption rendered the data unintelligible, (b) subsequent measures eliminated the high risk, or © direct communication would require disproportionate effort, in which case a public communication is required.

For organisations managing complex data processing agreements, the contractual notification chain between controllers and processors must also be activated.

Finally, Article 33(5) requires an internal breach register documenting every breach, its effects, and remedial actions – regardless of whether notification was required. Keep it linked to the relevant ROPA entry, while retaining the breach log as a distinct record with access appropriate to incident evidence.

What Happens When Organisations Get It Wrong?

Enforcement data makes the cost of failure concrete. Supervisory authorities have issued substantial fines specifically for breach notification failures, distinct from fines for the underlying security deficiency.

Meta Platforms — EUR 91 million (2024). The Irish Data Protection Commission fined Meta after discovering that Facebook user passwords had been stored in plaintext. The fine addressed multiple violations, including failure to notify within the required timeframe and inadequate documentation under Article 33(5).

Booking.com — EUR 475,000 (2021). The Dutch Autoriteit Persoonsgegevens fined Booking.com for notifying a breach 22 days late. The breach involved unauthorised access to data of over 4,000 customers, including credit card details. The authority emphasised that internal investigation delays do not suspend the clock.

Read the individual findings before attributing a total fine to notification alone. The Meta total covered several infringements; a case involving security and notification does not establish a €91 million notification-only penalty.

These cases illustrate a consistent pattern: supervisory authorities treat the notification obligation as a standalone compliance requirement. A failure in the gdpr data breach notification process generates independent liability even where the underlying breach was not egregious.

Document a Decision Not to Notify

Suppose a laptop containing customer records is stolen. “Encrypted” is an input to the assessment, not the conclusion. Confirm full-disk encryption was active, keys or credentials were not exposed with the device, the device was locked, and a usable backup exists. Assess whether lost availability still creates risk, including missed appointments or inability to deliver a service.

Record the affected data and people, the facts verified, the uncertainty, the likely consequences, the safeguards and why risk is unlikely if that is the conclusion. Keep the owner and assessment time. If the device was unlocked or logs later show account access, reopen the decision and assess the reporting consequences promptly.

For a misdirected email, a trusted recipient’s confirmation of deletion may reduce risk, but consider what was disclosed, whether it could have been copied and whether the recipient is subject to relevant duties. A generic “recipient deleted it” checkbox is insufficient for a file containing medical or identity documents.

Whether notifying or not, keep the record required by Article 33(5), with the rationale for the separate Article 34 decision. The EDPB breach-notification guidelines support this evidence-based approach. A decision not to report is an accountable decision, not an absence of paperwork.

Preparing Before a Breach Occurs

Prepare the reporting route, contacts and templates before an incident. Test that a backup submitter can access the authority portal and that the incident team can preserve proof of submission if the main contact is unavailable.

Effective preparation includes:

  • Pre-drafted notification templates aligned with Article 33(3) requirements and tailored to your supervisory authority’s portal
  • Defined escalation paths specifying who evaluates awareness, who authorises notification, and who communicates with data subjects
  • Processor contracts that implement the statutory “without undue delay” duty with clear escalation contacts, information and prompt contractual service levels – see our data processing agreement guide
  • Tabletop exercises simulating breach scenarios at least annually, involving legal, IT, communications, and senior management
  • A current data inventory so the incident response team can rapidly determine what data was affected and how many individuals are involved

Integrating breach response into your broader GDPR requirements programme ensures notification is not treated as an afterthought bolted onto security operations.

Processor Notification Obligations

Under Article 33(2), processors notify the controller without undue delay after becoming aware of a personal data breach; they do not first apply the controller’s risk threshold to decide whether to tell it. A processor may submit an authority report on the controller’s behalf if authorised, but responsibility remains with the controller. Agree an initial alert and subsequent updates rather than waiting for a complete investigation. An agreed maximum number of hours must not legitimise avoidable delay.

FAQ

What qualifies as a personal data breach under GDPR?

Any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. This covers confidentiality breaches, integrity breaches, and availability breaches. A ransomware attack, a misdirected email, or a database left exposed on the internet all qualify.

Can the 72-hour deadline be extended?

The GDPR does not provide a formal extension. Article 33(4) allows information to be provided in phases, and supervisory authorities accept phased notifications for complex incidents, but they expect the initial notification within 72 hours even if incomplete. Late notifications must include reasons for the delay.

When is notifying data subjects required?

Communication to data subjects under Article 34 is required only when the breach is likely to result in a high risk to their rights and freedoms. Breaches involving health data, financial information, or identity documents typically meet this threshold. Breaches where data was encrypted with uncompromised keys generally do not.

What is the penalty for failing to notify a breach on time?

Article 83(4)(a) provides the €10 million/2% tier for Article 33/34 infringements, whichever is higher for an undertaking. A total fine in a multi-infringement case may include separate security or principle findings, so do not treat the whole total as a notification-only benchmark.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
02Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

International transfers require the appropriate Chapter V route. Adequacy decisions, including the EU–US Data Privacy Framework for covered recipients, fall under Article 45. Standard Contractual…

April 30, 2026
03Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — a useful reminder to examine whether the organisation supports the DPO’s actual tasks and…

July 7, 2026
04Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026
05Data Privacy

Canada-EU Data Transfers: Adequacy Scope and SCCs

Canada is one of the few countries the European Commission has recognised as offering adequate protection, and it is the country where that recognition is most often over-read. The decision is…

July 30, 2026
06Data Privacy

Cassie (Syrenis) Alternatives & Comparison 2026

Cassie (Syrenis) is positioned by its maker around consent and preference management, with publicly advertised ROPA and data-subject rights capabilities as well. If you are looking for an…

July 9, 2026
07Data Privacy

Consent Management Platforms Compared (2026)

Choosing the right consent management platform is one of the most consequential technical decisions an organisation makes for privacy compliance. A poorly configured CMP exposes you to enforcement…

March 28, 2026
08Data Privacy

Cookie Audit: How to Map Your Website's Cookies

A cookie audit is the foundational step for any website's GDPR and ePrivacy compliance. Without a complete, documented inventory of every cookie and tracking technology deployed on your site, your…

March 28, 2026