GDPR data breach notification is the legal duty to report a personal data breach to the supervisory authority, and in high-risk cases to the affected individuals. Under Article 33, controllers must notify the authority without undue delay and, where feasible, within 72 hours of becoming aware.
What Counts As a Personal Data Breach
Article 4(12) defines a personal data breach as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. The definition is deliberately broad. It is not limited to hackers stealing data. A lost laptop, a misdirected email, ransomware that encrypts your records, or an employee accessing files without authorisation can all qualify.
This matters because the notification clock does not care how the breach happened. What triggers your obligations is the effect on the confidentiality, integrity, or availability of personal data. If a fire destroys the only copy of customer records, that is a breach of availability even though no attacker was involved.
The 72-Hour Clock: When It Starts
The most misunderstood part of the rule is when the countdown begins. It starts when your organisation becomes aware that a personal data breach has likely occurred, not when you have a complete forensic picture. Awareness means a reasonable degree of certainty that a security incident has compromised personal data, not the moment the investigation concludes.
You do not get to pause the clock while you gather every detail. If you have enough to reasonably conclude a breach happened, the 72 hours are running. This is why the phrase without undue delay sits alongside the 72-hour ceiling. The 72 hours is a maximum, not a target. If you can notify sooner, you should.
GDPR enforcement has now passed 7.1 billion euros in cumulative fines across more than 2,800 actions since 2018, with roughly 1.2 billion euros in new fines in 2025 alone (CMS GDPR Enforcement Tracker, January 2026). Late or absent breach notification is a recurring aggravating factor in these decisions.
If you cannot notify within 72 hours, Article 33(1) still lets you report late, but the notification must be accompanied by reasons for the delay. A phased notification is explicitly permitted: you can send what you know now and supplement it as your investigation develops.
What the Notification to the Authority Must Contain
Article 33(3) sets a minimum content standard. Even a first, incomplete notification should aim to cover these points, filling gaps as facts emerge.
- The nature of the breach, including categories and approximate number of data subjects affected
- The categories and approximate number of personal data records concerned
- The name and contact details of the Data Protection Officer or other contact point
- The likely consequences of the personal data breach
- The measures taken or proposed to address the breach and mitigate its effects
Notice that the standard uses approximate numbers. Regulators do not expect precision on day one. They expect honesty about what you know, what you do not, and what you are doing about it. Building this reporting muscle is part of a wider programme, which we cover in our guide to implementing GDPR step by step.
Article 34: When You Must Tell the Individuals
Article 34 is a separate and higher bar. You notify the supervisory authority when a breach is likely to result in a risk to rights and freedoms. You notify the affected individuals only when the breach is likely to result in a high risk. That difference in wording is intentional. Risk triggers the regulator duty; high risk triggers the individual duty.
When you do notify individuals, the communication must be in clear and plain language and describe the nature of the breach, the DPO contact point, the likely consequences, and the measures taken. The goal is to let people protect themselves, for example by changing passwords or watching for fraud.
When Notification Is Not Required
Not every breach must be reported. Article 33 carves out breaches unlikely to result in a risk to the rights and freedoms of natural persons. Article 34 lists three situations where you do not need to notify individuals even after a high-risk breach.
- The data was protected by measures such as strong encryption, rendering it unintelligible to anyone who accessed it
- You took subsequent measures ensuring the high risk to individuals is no longer likely to materialise
- Individual notification would involve disproportionate effort, in which case a public communication is used instead
The encryption exemption is a powerful incentive. If a stolen device holds only strongly encrypted data and the key was not compromised, the risk to individuals may be low enough that individual notification is not required. This is why a well-run Data Protection Impact Assessment, which we explain in our DPIA guide, pays off long before any breach occurs.
Preparing Before a Breach Happens
Seventy-two hours is not long once a breach lands on a Friday evening. Organisations that meet the deadline do so because they prepared. They maintain an internal breach register, a documented decision tree for the risk assessment, pre-drafted notification templates, and a named team that can convene fast. Every breach, whether reportable or not, must be documented internally under Article 33(5) so the authority can verify compliance.
The strongest programmes rehearse. A tabletop exercise that walks a simulated breach from detection to notification exposes gaps in ownership and communication while the stakes are still hypothetical. Pairing GDPR breach response with a structured incident management process gives you the operational backbone the regulation assumes you already have.