This article is part of the series Ask a Compliance Expert.
Key takeaways
- A personal data breach must be notified to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Art. 33(1) GDPR). Notification falls away only where the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
- The clock runs from awareness, not from the incident. Under the European Data Protection Board's Guidelines 9/2022 (version 2.0, adopted 28 March 2023), awareness means a reasonable degree of certainty that a security incident has occurred that led to personal data being compromised. A short investigation period before that point is permitted.
- Compliance with the deadline is weaker than the rule suggests. France's CNIL received 17,483 breach notifications between May 2018 and May 2023, of which roughly half met the 72 hours and 75 percent arrived within eleven days. The authority names waiting for complete information as the main reason for delay.
- Every breach must be documented internally, including the ones you decide not to notify (Art. 33(5)). This is the most commonly skipped obligation in practice.
- Breaches of Art. 33 and Art. 34 sit in the lower fine tier of Art. 83(4)(a): up to 10 million euros or 2 percent of total worldwide annual turnover. The 20 million tier does not apply here.
What counts as a personal data breach and what does not?
A personal data breach is any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data. That is the definition in Art. 4(12) GDPR. Whether it happened by accident or unlawfully makes no difference to the classification.
The definition covers three cases that look very different in practice. A confidentiality breach occurs when data is disclosed or someone gains access without authorization: the bulk email sent with visible recipients, the misapplied permission in the CRM, the data exfiltration that follows a phishing campaign. An integrity breach is the unauthorized alteration of data. An availability breach occurs when data is destroyed or access to it is lost, for example after ransomware encryption or a deletion with no working backup.
A common misunderstanding runs in both directions. Not every IT outage is a personal data breach: if a system holding no personal data goes down, that is an availability problem, not a case for Art. 33. In the other direction, teams routinely underrate the small cases. A termination confirmation sent to the wrong address is a personal data breach, even though nobody would call it an attack. The other obligations the Regulation attaches to the same data are brought together in our GDPR guide.
When does the 72-hour clock start?
At awareness, not at the incident. This is the most frequently misread point in the whole provision, and it decides whether a notification is on time.
Art. 33(1) requires notification "without undue delay and, where feasible, not later than 72 hours after having become aware of it." The European Data Protection Board fixes that moment in its Guidelines 9/2022 on personal data breach notification. In version 2.0 of 28 March 2023, which replace the earlier WP250 rev.01 guidelines of the Article 29 Working Party, a controller is regarded as aware once it has a reasonable degree of certainty that a security incident has occurred that has led to personal data being compromised. The guidelines are available in their current version.
Two things follow. First, you are allowed a short investigation period before the clock runs: a vague first report from an employee does not yet start the deadline. Second, that investigation has to begin immediately and reach a conclusion quickly; dragging out the check does not move the starting point, it breaches the obligation at that stage already.
Two practical points tend to get lost. The deadline is expressed in hours rather than working days, which makes Friday afternoon the hardest configuration in practice. And you do not have to know everything at the moment you notify: Art. 33(4) allows the information to be provided in phases without undue further delay. If you exceed the 72 hours anyway, the notification has to be accompanied by the reasons for the delay under Art. 33(1), second sentence.
Our Senior Privacy Expert puts the consequence plainly:
What happens in the first hour?
No form gets filled in during the first hour. The facts get established, far enough that a legal assessment becomes possible at all.
If you work with an external data protection officer, there is a limit worth knowing before the real thing happens:
This is not a formality, it is the reason some notifications end up close to the wire. The data protection officer can only make the legal assessment once the technical side has delivered. The joint work of the first hour looks accordingly:
"Which data is affected" is where most first assessments stall, and not through carelessness. If you do not know which personal data sits in which system, you cannot establish the scope of an incident in hours, you need days. That is exactly why data discovery is not a preparation exercise for the auditor but the precondition for the assessment fitting inside the deadline.
When is notification mandatory and when is it not?
You notify, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The exception is drawn narrowly: it applies where risk is absent, not where the harm is small and not where few people are affected.
Communication to the data subjects under Art. 34 has a higher threshold. It is required only where the breach is likely to result in a high risk, and then without undue delay and in clear and plain language. Art. 34(3) sets out three exceptions: the data was rendered unintelligible to unauthorized parties by appropriate measures such as encryption; subsequent measures mean the high risk is no longer likely to materialize; or individual communication would involve disproportionate effort, in which case a public communication takes its place. The supervisory authority can also require the communication under Art. 34(4).
What if the breach happens at a processor?
Then the processor notifies you without undue delay, and you notify the authority. The processor has no 72-hour deadline of its own toward the authority; its deadline toward you is "without undue delay," and yours starts with your awareness. In practice that means a vendor who takes three days to tell you has consumed your notification window before you knew anything had happened. What belongs in the contract on this point is covered in our article on what a data protection officer checks first in a data processing agreement.
Why notifying when in doubt is the safer call
Because the line between notifiable and not notifiable is rarely clean in practice, and because an unnecessary notification costs far less than an omitted one.
Deciding against notification is a decision you have to be able to justify. Art. 33(5) requires you to document every breach, including the facts relating to it, its effects, and the remedial action taken, and to do so expressly in a way that enables the supervisory authority to verify compliance with the article. That obligation applies whether or not you notified. A record containing only the notified cases does not satisfy it.
That turns "notify when in doubt" into more than a posture. Whoever decides against notification has to carry that decision in writing, months later, in front of an authority seeing the case for the first time.
What does the supervisory authority do when you notify?
It examines the facts, asks questions, and forms a view. What it does not normally do is treat the notification as an invitation to open a wide-ranging investigation. The opposite assumption is nonetheless widespread:
The clearest public figures on this come from France. Between May 2018 and May 2023 the CNIL received 17,483 breach notifications. Roughly half met the 72 hours and 75 percent arrived within eleven days, and the authority names the wish to have a complete file before notifying as the main reason for delay. That is precisely what Art. 33(4) removes the need for: phased notification exists so that you do not have to wait for the forensic report to open the case. The CNIL describes its own role in a breach as accompanying the organization, aimed at helping limit the consequences of the incident.
None of which means notifying puts you in the clear. A German example makes the distinction sharper. In November 2018 the supervisory authority of Baden-Württemberg issued a 20,000 euro fine against a chat operator after an attack exposed data belonging to around 330,000 users. The basis was Art. 32, inadequate security, not the notification. The company had reported the incident itself and informed the affected users, and the authority described its transparency and willingness to cooperate as exemplary, adding that its aim was not the highest possible fines but better data protection and data security for the users concerned. The fine hit the security gap, not the openness.
How do GDPR and NIS2 breach reporting differ?
In trigger, recipient, and how the clocks run. Both regimes have a 72-hour mark, which invites people to treat them as one rule; they are two separate obligations, and a single ransomware attack at an in-scope company can trigger both.
One caveat that matters for any company operating across several countries: the NIS2 column describes the Directive, and the national picture is not uniform. Germany transposed it into the BSIG; France had not yet passed its transposition law at the time of writing, so only the GDPR obligation applies there. Which authority you report to, and whether NIS2 applies to you at all, depends on the member state. The NIS2 Directive guide covers the scoping and the staged procedure in detail.
An organization under both regimes does not need two incident response processes, but it does need two decision points inside one process and two named owners.
How do you prepare before it happens?
By walking the process through once while nothing is on fire, rather than inventing it on the day.
Four decisions are enough to start and each one can be made in an afternoon. First: who takes the report internally, and through which channel do support, sales, and engineering reach that person on a Saturday? Second: who on the technical side produces the finding, and in what form? Third: who makes the final call on notification, and who covers for that person during vacation? Fourth: where does the Art. 33(5) record live, and who enters the cases that were not notified?
Testing whether those decisions hold takes an hour. Tell the team about a fictional incident on a Friday at 5pm, say a misconfigured storage bucket holding job applications, and ask each role what it does in the next sixty minutes. Wherever the answer is a question rather than an action, a decision is missing. That is the exercise that makes the difference between thirty hours and seventy on the day.
These decisions are not only a data protection matter. Incident response is a requirement that recurs across several frameworks, so a process defined once can be evidenced against more than one of them. How requirements from ISO 27001, the GDPR, and SOC 2 map onto a shared control set is covered in our article on one control set for three frameworks.
The payoff is concrete. A breach record kept under Art. 33(5) also feeds the ISO 27001 management review and the evidence of an incident management process, without being written twice.
One last point of orientation: a personal data breach is not the only case where a deadline runs from a moment that is hard to pin down. The same mechanic applies to a data subject access request under Art. 15, where the month runs from receipt and not from the point at which the responsible team hears about it. Both obligations fail at the same place in practice, which is that nobody is named to recognize them.
How does Kertos help during a personal data breach?
Kertos takes on the mandate as external data protection officer and assigns a named contact from the team of certified experts. During a breach that means joint fact-finding with your technical team, the legal assessment under Art. 33 and Art. 34, drafting the notification, and communication with the supervisory authority.
What customers name about this setup is less the response time than the fact that there is a known person at the other end:
On the platform, the documentation sits in the same place as the data it refers to. The Art. 33(5) record is linked to the record of processing activities and the vendor landscape, so that "which data is affected" does not start from a blank page. Handling data subject requests runs in the same system, which matters in practice when access and erasure requests follow a larger incident.
That is the part customers name as the one that used to take time:
The assessment itself stays expert work. Whether an incident is notifiable is not decided by automation but by a person who knows the facts and can defend the decision to the authority. To see what that looks like for your own processes, book a demo.
Frequently asked questions
When do you have to report a data breach under GDPR?
As soon as you become aware of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons. Notification goes to the competent supervisory authority without undue delay and, where feasible, within 72 hours (Art. 33(1) GDPR). It falls away only where a risk is unlikely.
When do the 72 hours start?
From the point at which you as controller become aware of the breach, not from the incident itself. Under the European Data Protection Board's Guidelines 9/2022, awareness requires a reasonable degree of certainty that personal data has been compromised. A short investigation period beforehand is permitted, but it has to begin immediately.
What happens if you miss the 72-hour deadline?
The notification is still due. You make it as soon as possible and attach the reasons for the delay under Art. 33(1), second sentence. A late or omitted notification falls under Art. 83(4)(a) GDPR, with a ceiling of 10 million euros or 2 percent of total worldwide annual turnover, whichever is higher. For scale: the CNIL reports that roughly half of the notifications it receives meet the deadline.
Do you have to tell the affected individuals?
Only where the breach is likely to result in a high risk to their rights and freedoms (Art. 34(1) GDPR). The communication is then made without undue delay and in clear and plain language. Art. 34(3) allows three exceptions, among them effectively encrypted data and subsequent measures that remove the high risk.
Do you have to document breaches you do not report?
Yes. Art. 33(5) GDPR requires documentation of every breach, including the facts, its effects, and the remedial action taken, in a form that enables the supervisory authority to verify compliance with the article. The cases where you decided not to notify are precisely the ones that need a traceable justification in the record.






