Privacy & Data Protection

GDPR Data Breach Notification: The 72-Hour Rule

Standarity Editorial Team·GDPR and privacy management practitioners
··7 min read

GDPR data breach notification is the legal duty to report a personal data breach to the supervisory authority, and in high-risk cases to the affected individuals. Under Article 33, controllers must notify the authority without undue delay and, where feasible, within 72 hours of becoming aware.

What Counts As a Personal Data Breach

Article 4(12) defines a personal data breach as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. The definition is deliberately broad. It is not limited to hackers stealing data. A lost laptop, a misdirected email, ransomware that encrypts your records, or an employee accessing files without authorisation can all qualify.

This matters because the notification clock does not care how the breach happened. What triggers your obligations is the effect on the confidentiality, integrity, or availability of personal data. If a fire destroys the only copy of customer records, that is a breach of availability even though no attacker was involved.

The 72-Hour Clock: When It Starts

The most misunderstood part of the rule is when the countdown begins. It starts when your organisation becomes aware that a personal data breach has likely occurred, not when you have a complete forensic picture. Awareness means a reasonable degree of certainty that a security incident has compromised personal data, not the moment the investigation concludes.

You do not get to pause the clock while you gather every detail. If you have enough to reasonably conclude a breach happened, the 72 hours are running. This is why the phrase without undue delay sits alongside the 72-hour ceiling. The 72 hours is a maximum, not a target. If you can notify sooner, you should.

GDPR enforcement has now passed 7.1 billion euros in cumulative fines across more than 2,800 actions since 2018, with roughly 1.2 billion euros in new fines in 2025 alone (CMS GDPR Enforcement Tracker, January 2026). Late or absent breach notification is a recurring aggravating factor in these decisions.

If you cannot notify within 72 hours, Article 33(1) still lets you report late, but the notification must be accompanied by reasons for the delay. A phased notification is explicitly permitted: you can send what you know now and supplement it as your investigation develops.

What the Notification to the Authority Must Contain

Article 33(3) sets a minimum content standard. Even a first, incomplete notification should aim to cover these points, filling gaps as facts emerge.

  • The nature of the breach, including categories and approximate number of data subjects affected
  • The categories and approximate number of personal data records concerned
  • The name and contact details of the Data Protection Officer or other contact point
  • The likely consequences of the personal data breach
  • The measures taken or proposed to address the breach and mitigate its effects

Notice that the standard uses approximate numbers. Regulators do not expect precision on day one. They expect honesty about what you know, what you do not, and what you are doing about it. Building this reporting muscle is part of a wider programme, which we cover in our guide to implementing GDPR step by step.

Article 34: When You Must Tell the Individuals

Article 34 is a separate and higher bar. You notify the supervisory authority when a breach is likely to result in a risk to rights and freedoms. You notify the affected individuals only when the breach is likely to result in a high risk. That difference in wording is intentional. Risk triggers the regulator duty; high risk triggers the individual duty.

When you do notify individuals, the communication must be in clear and plain language and describe the nature of the breach, the DPO contact point, the likely consequences, and the measures taken. The goal is to let people protect themselves, for example by changing passwords or watching for fraud.

When Notification Is Not Required

Not every breach must be reported. Article 33 carves out breaches unlikely to result in a risk to the rights and freedoms of natural persons. Article 34 lists three situations where you do not need to notify individuals even after a high-risk breach.

  • The data was protected by measures such as strong encryption, rendering it unintelligible to anyone who accessed it
  • You took subsequent measures ensuring the high risk to individuals is no longer likely to materialise
  • Individual notification would involve disproportionate effort, in which case a public communication is used instead

The encryption exemption is a powerful incentive. If a stolen device holds only strongly encrypted data and the key was not compromised, the risk to individuals may be low enough that individual notification is not required. This is why a well-run Data Protection Impact Assessment, which we explain in our DPIA guide, pays off long before any breach occurs.

Preparing Before a Breach Happens

Seventy-two hours is not long once a breach lands on a Friday evening. Organisations that meet the deadline do so because they prepared. They maintain an internal breach register, a documented decision tree for the risk assessment, pre-drafted notification templates, and a named team that can convene fast. Every breach, whether reportable or not, must be documented internally under Article 33(5) so the authority can verify compliance.

The strongest programmes rehearse. A tabletop exercise that walks a simulated breach from detection to notification exposes gaps in ownership and communication while the stakes are still hypothetical. Pairing GDPR breach response with a structured incident management process gives you the operational backbone the regulation assumes you already have.

Frequently Asked Questions

When does the 72-hour GDPR breach notification clock start?

It starts when you become aware that a personal data breach has likely occurred, meaning you have a reasonable degree of certainty a security incident compromised personal data. It does not start only after the investigation is complete, and it is a maximum deadline rather than a target.

Do I have to report every data breach under GDPR?

No. Article 33 requires notification to the supervisory authority only where the breach is likely to result in a risk to the rights and freedoms of individuals. Breaches unlikely to create such a risk do not need to be reported to the authority, but you must still document them internally.

What is the difference between Article 33 and Article 34?

Article 33 covers notifying the supervisory authority and is triggered by a likely risk. Article 34 covers notifying the affected individuals and is triggered by a higher threshold, a likely high risk. You may need to do one, both, or neither depending on the severity of the breach.

What happens if I miss the 72-hour deadline?

You can still notify late, but Article 33 requires the notification to be accompanied by the reasons for the delay. Missing the deadline without justification is treated as an aggravating factor in enforcement and can increase the size of any fine.

Does encrypted data need to be reported if breached?

If the data was protected by strong encryption and the key was not compromised, the breach may be unlikely to result in a high risk to individuals. In that case Article 34 does not require you to notify the affected individuals, though notification to the authority may still be needed.

Who notifies the authority when a processor is breached?

The controller notifies the supervisory authority. A processor that suffers a breach must notify the controller without undue delay, and the controller then assesses the risk and handles any notification to the authority and to individuals.

Explore Courses on Udemy

Intermediate

The NIST Incident Management: A Step-by-Step Guide

Intermediate

The NIST Incident Management: A Step-by-Step Guide

Intermediate

Implement GDPR Step by Step with Templates

Intermediate

ISO/IEC 27701: Implement Privacy Management Step by Step