GDPR Data Breach Fines: The 72-Hour Rule That Costs Companies Millions

Under the GDPR, a personal-data breach starts a clock: Article 33 requires notification to the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Miss or mishandle that window and the notification failure becomes its own sanctionable violation — separate from whatever caused the breach. Where the breach creates a high risk for individuals, Article 34 additionally requires informing the affected persons themselves.

Enforcement in Germany is decentralized: each federal state runs its own data-protection authority, and they actively fine late, incomplete or omitted notifications. The GDPR reaches non-EU companies that offer goods or services to people in the EU or monitor their behavior, so an international business with German customers is in scope regardless of where its servers or headquarters sit — non-EU controllers typically need an EU representative precisely for this contact.

Companies rarely get to choose whether a breach becomes known. Processors are legally required to report breaches to their controllers, affected individuals complain to authorities, ransomware groups publish stolen data, and journalists call the regulator before they call you. The only controllable variable is preparation: an assessed, documented, on-time notification consistently ends better than a scramble on hour 70.

The sanctions you are facing

€20 millionor 4% of turnover

GDPR violations carry fines of up to €20 million or 4% of global annual turnover.

72 hrsnotification deadline

Notifiable data breaches must be reported to the supervisory authority without undue delay, where feasible within 72 hours.

Notificationof data subjects

Where there is a high risk, the affected individuals must additionally be informed without undue delay.

Matching tool

Report every data breach on time and securely.

GDPR 72h Leak Shield → Check now for free

Frequently asked questions

Do GDPR breach rules apply to companies without an EU office?

Yes, if the GDPR applies to the processing — which it does for non-EU companies offering goods or services to people in the EU or monitoring their behavior. Such companies must generally designate an EU representative, and a breach affecting EU individuals triggers the same Article 33 notification duties as for a local company.

Is a late notification really fined separately from the breach itself?

Yes. Article 33 is a standalone obligation: notifying late without a reasoned justification, notifying incompletely, or not notifying at all can each be sanctioned even if the underlying breach was handled well otherwise. European authorities, including the German state authorities, have issued fines specifically for notification failures.

Does every data breach have to be reported within 72 hours?

No. Notification is required unless the breach is unlikely to result in a risk to the rights and freedoms of individuals — a lost encrypted laptop with secure keys may fall out. But that risk assessment must be done fast and documented, because every breach, reported or not, must be recorded internally under Article 33(5).

Which authority do we notify in Germany?

The supervisory authority of the German federal state where your responsible establishment sits; Germany has separate authorities per state plus a federal authority for specific sectors. Cross-border cases run through the lead-authority mechanism at your EU main establishment. Identifying the right authority in advance is itself a preparation step — the deadline does not pause while you look it up.

More about GDPR 72h Leak Shield →