Skip to content
Legiscope
Menu
Data Privacy

GDPR Data Breach Notification: The 72-Hour Rule

Learn how GDPR data breach notification works, the 72-hour reporting rule, what to include, and how to avoid regulatory penalties.

A GDPR personal data breach must be notified to the competent supervisory authority without undue delay and, where feasible, within 72 hours after the controller becomes aware of it, unless it is unlikely to result in a risk to individuals’ rights and freedoms. The starting point is awareness, not automatically the time when the incident occurred.

This guide explains the GDPR data breach notification framework in practical terms, covering who must notify, what the notification must contain, when the 72-hour deadline starts, and how to build an internal process that keeps your organisation compliant.

What Counts as a Personal Data Breach?

Before examining the notification process, it is essential to understand what qualifies as a personal data breach. Article 4(12) GDPR defines a personal data breach as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed.

Breach categories defined by the EDPB

The EDPB Guidelines on personal data breach notification classify breaches into three categories:

  • Confidentiality breach – unauthorised or accidental disclosure of, or access to, personal data. Example: a database exposed to the public internet, or an email sent to the wrong recipient.
  • Integrity breach – unauthorised or accidental alteration of personal data. Example: a ransomware attack that modifies patient records before encryption.
  • Availability breach – accidental or unauthorised loss of access to, or destruction of, personal data. Example: a server failure that permanently destroys customer records without backup.

A single incident can combine confidentiality, integrity and availability consequences. Assess the actual personal data and people affected, including temporary loss of access where it can harm individuals.

The 72-Hour Notification Obligation

The cornerstone of GDPR data breach notification is set out in Article 33 GDPR. The controller must notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of the breach.

Starting point for the deadline

The clock begins when the controller becomes “aware” of the breach. The EDPB guidance clarifies that awareness occurs when the controller has a reasonable degree of certainty that a security incident has compromised personal data. This does not require full forensic analysis. If a processor detects a breach, it must notify the controller without undue delay under Article 33(2). The controller’s period begins when it first becomes aware, which may be through that notice or earlier evidence. A later processor notification does not restart the period.

Controllers must have appropriate arrangements to detect and investigate incidents promptly. A failure to detect a breach can raise separate security and accountability issues; it does not justify replacing the awareness assessment with an automatic incident-date deadline. The EDPB’s final breach guidelines explain the circumstances-based assessment.

Required content of the notification

The notification to the supervisory authority must contain at minimum:

  • The nature of the breach, including the categories and approximate number of data subjects and personal data records affected
  • The name and contact details of the Data Protection Officer or other contact point (see the DPO definition and missions for more detail)
  • A description of the likely consequences of the breach
  • A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects

If all information is not available at the time of initial notification, the GDPR allows it to be provided in phases without undue further delay.

When Must You Also Notify Data Subjects?

Article 34 GDPR imposes a separate obligation to notify the affected individuals directly when a breach is likely to result in a high risk to their rights and freedoms. The threshold for notifying data subjects is higher than for notifying the supervisory authority.

Assess the nature of the data, the people affected, likelihood and severity of harm, identification possibilities and effective protective measures. Health, financial or identity data can increase the risk, but the category alone does not establish an automatic Article 34 communication duty. Check the actual incident and the exceptions below.

Article 34(3) provides three exceptions where communication to data subjects is not required: (a) the data was rendered unintelligible through encryption or similar measures, (b) subsequent measures have ensured that the high risk is no longer likely to materialise, or © the communication would involve disproportionate effort, in which case a public communication must be made instead.

Building an Internal Breach Response Process

Having a documented breach response procedure is not merely best practice – it is an implicit requirement of the accountability principle and the broader obligation of privacy by design. Organisations that lack a structured response process are far more likely to miss the 72-hour deadline.

Essential elements of a breach response plan

An effective breach response plan should include the following components:

  1. Detection and escalation procedures. Define how staff report suspected incidents, who receives the initial report, and how the incident is triaged.
  2. Assessment protocol. Establish criteria for determining whether an incident constitutes a personal data breach, the categories of data involved, and the risk level. This assessment feeds directly into both the regulatory notification and the decision on whether to notify data subjects.
  3. Notification templates. Prepare pre-drafted notification templates for both regulatory and individual notifications. Having templates ready saves critical hours during a live incident.
  4. Roles and responsibilities. Assign clear ownership to specific individuals or teams, including the DPO, IT security, legal counsel, and communications.
  5. Post-incident review. After every breach, conduct a lessons-learned review and update your security measures accordingly. This continuous improvement loop demonstrates compliance with GDPR requirements.

A Data Protection Impact Assessment carried out during the design phase of high-risk processing activities can also help identify breach scenarios in advance, enabling more targeted response planning.

Penalties for Notification Failures

Failure to comply with GDPR data breach notification obligations can result in significant administrative fines. Under Article 83(4)(a), infringements of the notification obligation attract fines of up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher.

Enforcement track record

The DPC’s 2022 annual report records a EUR 17 million Meta decision under Articles 5(2) and 24(1), concerning the ability to demonstrate security measures in the context of twelve notified breaches. That is an accountability finding, not an example of a fine for missing the Article 33 deadline. Distinguish the actual infringements in any enforcement example.

Breach preparedness is a component of how to comply with GDPR. Beyond fines, delayed notification can increase the overall harm to data subjects, leading to further reputational and legal consequences.

How Does Breach Notification Connect to Other GDPR Obligations?

Breach notification does not exist in isolation. It connects directly to several other GDPR obligations that organisations must maintain continuously.

Your GDPR compliance checklist should treat breach preparedness as a standing item. The retention periods you apply under the storage limitation principle and your ability to respond to right of access requests all influence how effectively you can investigate and report a breach. An organisation that has implemented the right to erasure correctly will have cleaner data inventories, making breach assessment faster and more accurate.

FAQ

Is the 72-hour notification deadline absolute?

No. Article 33(1) states notification must occur “where feasible” within 72 hours. If you exceed the deadline, you must provide a reasoned justification for the delay alongside your notification. However, supervisory authorities expect the justification to be genuine and well-documented. Routine administrative delays will not be accepted as valid reasons.

Do processors notify the supervisory authority directly?

Processors must notify the controller without undue delay after becoming aware of a personal data breach, as required by Article 33(2). The controller holds the notification obligation; a processor can assist or notify on its behalf if duly authorised, without transferring that responsibility. The data processing agreement between controller and processor should specify the exact notification procedures and contact points to avoid delays.

Does every breach require regulatory notification?

No. The controller must notify unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If the breach poses no such risk – for example, an encrypted device is lost but the encryption is robust and the key has not been compromised – you must still document the breach internally but are not required to notify the authority. The internal record must include the facts of the breach, its effects, and the remedial action taken.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
02Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

International transfers require the appropriate Chapter V route. Adequacy decisions, including the EU–US Data Privacy Framework for covered recipients, fall under Article 45. Standard Contractual…

April 30, 2026
03Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — a useful reminder to examine whether the organisation supports the DPO’s actual tasks and…

July 7, 2026
04Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026
05Data Privacy

Canada-EU Data Transfers: Adequacy Scope and SCCs

Canada is one of the few countries the European Commission has recognised as offering adequate protection, and it is the country where that recognition is most often over-read. The decision is…

July 30, 2026
06Data Privacy

Cassie (Syrenis) Alternatives & Comparison 2026

For a regulated-industry DPO, that distinction is the whole decision. Consent is one lawful basis under Art. 6(1)(a) GDPR; a compliance program is everything around it.

July 9, 2026
07Data Privacy

Consent Management Platforms Compared (2026)

Choosing the right consent management platform is one of the most consequential technical decisions an organisation makes for privacy compliance. A poorly configured CMP exposes you to enforcement…

March 28, 2026
08Data Privacy

Cookie Audit: How to Map Your Website's Cookies

A cookie audit is the foundational step for any website's GDPR and ePrivacy compliance. Without a complete, documented inventory of every cookie and tracking technology deployed on your site, your…

March 28, 2026