Data breach reported: The 72-hour roadmap
What really matters in the first hours after a GDPR data breach — step by step.
What is a notifiable data breach?
Not every security gap triggers a notification obligation. A personal data breach is notifiable under Art. 33 GDPR if it is likely to result in a risk to the rights and freedoms of natural persons. The risk assessment is decisive — and it must be done quickly but carefully.
The clock starts at first awareness
The 72-hour deadline starts as soon as your company becomes aware of the data breach — not once all details are known. In practice, this is one of the biggest hurdles: you know something has happened, but the exact scope is still unclear.
- Hours 0–4: immediate measures — contain the breach, activate the internal reporting chain
- Hours 4–24: initial risk assessment; early warning to the data protection authority if needed
- Hours 24–72: full notification with all mandatory details under Art. 33(3) GDPR
- From hour 72: final documentation; notification of data subjects where the risk is high
What goes into the notification to the supervisory authority?
Art. 33(3) GDPR prescribes what the notification must contain: the nature of the breach, the categories and approximate number of data subjects and records concerned, the contact details of the data protection officer, the likely consequences, and the measures taken and planned to address it.
When do I not have to notify?
If the risk to data subjects is low — for example, when an encrypted device with a strong password is lost — there is no obligation to notify the authority. But this decision must be documented: in the internal breach register under Art. 33(5) GDPR, including the reasoning for not notifying.
Informing the affected individuals
If there is a high risk to the data subjects — for example with health data, financial data, or login credentials — they must additionally be informed without undue delay and in clear, plain language. The information must go directly to the affected individuals, not just as a notice on your website.
Frequently asked questions
Do I have to report a breach if no personal data is affected?
No, the GDPR notification obligation under Art. 33 applies exclusively to personal data. For other data incidents, however, other reporting obligations may apply — for example under NIS2 (BSIG) to the BSI, or under the German Banking Act for financial institutions.
What happens if the 72-hour deadline is missed?
A late notification is possible but must be justified. The supervisory authority can treat the delay as a violation warranting a fine. With cooperative conduct, authorities often mitigate the sanction. The principle: better late than never.
Do we need a data protection officer for the notification?
No, the notification can be made without a DPO. However, companies required to appoint a DPO (e.g., for regular large-scale processing of sensitive data) should involve them. Their contact details must be included in the notification, where available.
How do we keep the internal breach register correctly?
The breach register under Art. 33(5) GDPR must document all breaches — including unreported ones, with reasoning. It contains: the date and nature of the breach, the data and individuals affected, the measures taken, and the risk assessment. Supervisory authorities may inspect it at any time.