Data Protection Atlas

Personal data breach notification (GDPR family)

Tier 1 Archetype

How to detect, assess, record and (where required) notify a personal data breach under the EU/EEA GDPR. Two distinct thresholds govern the two distinct notification duties: notify the supervisory authority where the breach is likely to result in a RISK to the rights and freedoms of natural persons (Art 33); notify affected individuals only where the breach is likely to result in a HIGH risk to them (Art 34). Conflating the two is the single most common breach-response error.

Applies to

All EU/EEA states applying Regulation (EU) 2016/679 directly (the ~30-31 GDPR-family jurisdictions: the 27 EU Member States plus Iceland, Liechtenstein and Norway). National implementing acts adjust procedural detail (recipient authority, language, some public-sector carve-outs) but not the two-threshold architecture. See per-jurisdiction overrides for deltas.

Instruments: GDPR

Mechanics

Item Position
Regulator threshold Risk to rights and freedoms (Art 33)
Individual threshold High risk to rights and freedoms (Art 34)
Deadline to authority Without undue delay; where feasible within 72 hours of awareness
Processor deadline to controller Without undue delay (Art 33(2))
Register All breaches, notified or not (Art 33(5))

Steps

  1. Detect and record the breach

    A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data (Art 4(12)). It is not limited to confidentiality breaches: loss of availability (e.g. ransomware, accidental deletion with no backup) and integrity breaches count. Log every suspected breach in the internal register the moment it is identified, before you know whether it is notifiable.

    See GDPR

  2. Establish the point of awareness (start the clock)

    The 72-hour clock in Art 33(1) runs from when the controller becomes "aware" of the breach — i.e. has a reasonable degree of certainty that a security incident has occurred and compromised personal data, not from the moment of the incident itself. A short investigation to confirm is permitted, but awareness is not indefinitely deferrable. Document the moment of awareness and the reasoning.

    See GDPR

  3. Assess whether the regulator must be notified (the RISK test)

    Notify the competent supervisory authority UNLESS the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Art 33(1)). This is a low threshold: mere "risk" (not high risk) triggers the duty. Assess severity and likelihood by reference to the nature, sensitivity and volume of data, ease of identification of individuals, and potential consequences. If in genuine doubt, the defensible course is usually to notify.

    See GDPR

    Do not confuse the two thresholds. The regulator test is "risk"; the individual-notification test is "HIGH risk". A breach can require regulator notification but not individual notification. Treating them as one test is the most common and most penalised breach-response mistake.
  4. Notify the supervisory authority within 72 hours (Art 33 content)

    Where notification is required, make it without undue delay and, where feasible, not later than 72 hours after awareness. The notification must at least (a) describe the nature of the breach including, where possible, categories and approximate numbers of data subjects and records concerned; (b) give the name and contact details of the DPO or other contact point; (c) describe the likely consequences; and (d) describe the measures taken or proposed to address the breach and mitigate adverse effects (Art 33(3)). If notification is later than 72 hours it must be accompanied by reasons for the delay.

    See GDPR

  5. Assess whether individuals must be told (the HIGH RISK test)

    Communicate the breach to affected individuals without undue delay where it is likely to result in a HIGH risk to their rights and freedoms (Art 34(1)). The communication must be in clear and plain language and contain the Art 33(3)(b)-(d) information. No individual notification is required if (a) appropriate technical/organisational protections were applied to the affected data (e.g. strong encryption rendering it unintelligible); (b) subsequent measures ensure the high risk is no longer likely to materialise; or (c) it would involve disproportionate effort, in which case a public communication or equally effective measure suffices (Art 34(3)).

    See GDPR

  6. Phased and incomplete notification

    Where it is not possible to provide all information at once, information may be provided in phases without further undue delay (Art 33(4)). Making an initial notification within 72 hours with details to follow is expressly permitted and is preferable to missing the deadline while investigating.

    See GDPR

  7. Maintain the internal breach register (Art 33(5))

    The controller must document ALL personal data breaches — including those not notified — comprising the facts, effects and remedial action taken. This register must enable the supervisory authority to verify compliance. A breach you decided not to notify still has to be recorded, with the reasoning for the decision.

    See GDPR

    The register is the evidence base a regulator will ask for first. "We assessed it as low risk" is only defensible if the assessment is written down at the time.
  8. Processor-to-controller notification (Art 33(2))

    A processor must notify the controller without undue delay after becoming aware of a personal data breach. The processor has no direct duty to notify the supervisory authority or individuals; the controller carries those duties and its 72-hour clock effectively depends on prompt processor reporting. Build the notification trigger, timescale and content into the Art 28 processing contract.

    See GDPR

Sources

  • Primary Regulation (EU) 2016/679 (GDPR), Articles 4(12), 33 and 34 EUR-Lex / Publications Office of the EU
  • Regulator Guidelines 9/2022 on personal data breach notification under GDPR (v2.0) European Data Protection Board no verified URL yet

    Successor to WP29 Guidelines on Personal data breach notification (WP250 rev.01). URL to the specific EDPB guidelines page not confirmed exactly — URL unconfirmed.

  • Regulator Article 29 Working Party Guidelines on Personal data breach notification under Regulation 2016/679 (WP250rev.01) European Commission / EDPB archive no verified URL yet

    URL unconfirmed; endorsed by the EDPB.

Never independently verified.