GDPR Data Breach Response Checklist: Meeting the 72-Hour Notification Deadline

When personal data is breached, the GDPR gives you 72 hours from awareness to notify the supervisory authority, unless the breach is unlikely to pose a risk to individuals. Within that window you must contain the incident, establish facts, assess risk, and produce a notification covering the nature of the breach, categories and approximate numbers affected, likely consequences and countermeasures. High-risk breaches additionally require informing the affected individuals without undue delay.

No organization assembles this capability during an incident — least of all an international one that first has to work out which German or EU authority is competent. The checklist below is the preparation and response sequence: the top items you do now, in calm conditions; the rest is the drill you execute when the clock is running.

Your checklist

  1. 1Define and socialize 'breach': train staff that lost devices, misdirected emails and compromised accounts are potential personal-data breaches that must be escalated immediately — the 72 hours run from awareness.
  2. 2Identify your supervisory authority in advance: determine the competent German state authority or your EU lead authority, and bookmark its notification portal before you ever need it.
  3. 3Stand up the response team: name the incident lead, DPO, IT forensics, legal and communications roles, with deputies and out-of-hours contacts.
  4. 4Contain and preserve: on detection, stop the leak, secure systems and preserve logs and evidence — containment and investigation run in parallel with notification prep, not before it.
  5. 5Assess the risk methodically: evaluate data categories, number of affected persons, likelihood and severity of harm; document the assessment even when you conclude no notification is needed.
  6. 6Notify within 72 hours: submit the Article 33 notification with the required content; if facts are incomplete, notify in phases rather than waiting — lateness needs a documented justification.
  7. 7Inform data subjects on high risk: where the breach likely creates high risk for individuals, notify them without undue delay in clear, plain language with concrete protective advice.
  8. 8Manage processors and contracts: ensure processor agreements oblige vendors to report breaches to you without undue delay, so their incident does not silently consume your deadline.
  9. 9Keep the breach register and debrief: record every breach with facts, effects and remedies under Article 33(5), and feed lessons back into security measures and the playbook.

Matching tool

Report every data breach on time and securely.

GDPR 72h Leak Shield → Check now for free

Frequently asked questions

When does the 72-hour clock actually start?

On awareness — when the controller has a reasonable degree of certainty that a security incident compromising personal data has occurred, not when the investigation is finished. A short verification phase is accepted, but treating a week of internal analysis as 'not yet aware' is exactly the pattern authorities sanction.

What if we don't have all the facts within 72 hours?

The GDPR expressly allows notification in phases: submit the initial notification on time with what you know, flag it as preliminary, and supplement it as the investigation progresses. An on-time partial notification is legally far stronger than a complete one delivered late.

A vendor processing our data was breached — whose deadline is it?

Yours. The processor must report to you without undue delay, but the Article 33 notification duty toward the authority sits with you as controller, and your 72 hours run from your awareness. This is why processor contracts need hard breach-notification clauses and tested escalation paths.

More about GDPR 72h Leak Shield →