Data Protection

Personal data breach: when is notification mandatory and what happens in the first hour?

When the 72-hour clock starts, when you have to notify, and what the supervisory authority does once you have.

Author
Dr. Kilian Schmidt
Date
21.9.2026
Updated on
22.9.2026
Personal data breach: when is notification mandatory and what happens in the first hour?

This article is part of the series Ask a Compliance Expert.

Key takeaways

  • A personal data breach must be notified to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Art. 33(1) GDPR). Notification falls away only where the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
  • The clock runs from awareness, not from the incident. Under the European Data Protection Board's Guidelines 9/2022 (version 2.0, adopted 28 March 2023), awareness means a reasonable degree of certainty that a security incident has occurred that led to personal data being compromised. A short investigation period before that point is permitted.
  • Compliance with the deadline is weaker than the rule suggests. France's CNIL received 17,483 breach notifications between May 2018 and May 2023, of which roughly half met the 72 hours and 75 percent arrived within eleven days. The authority names waiting for complete information as the main reason for delay.
  • Every breach must be documented internally, including the ones you decide not to notify (Art. 33(5)). This is the most commonly skipped obligation in practice.
  • Breaches of Art. 33 and Art. 34 sit in the lower fine tier of Art. 83(4)(a): up to 10 million euros or 2 percent of total worldwide annual turnover. The 20 million tier does not apply here.

What counts as a personal data breach and what does not?

A personal data breach is any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data. That is the definition in Art. 4(12) GDPR. Whether it happened by accident or unlawfully makes no difference to the classification.

The definition covers three cases that look very different in practice. A confidentiality breach occurs when data is disclosed or someone gains access without authorization: the bulk email sent with visible recipients, the misapplied permission in the CRM, the data exfiltration that follows a phishing campaign. An integrity breach is the unauthorized alteration of data. An availability breach occurs when data is destroyed or access to it is lost, for example after ransomware encryption or a deletion with no working backup.

A common misunderstanding runs in both directions. Not every IT outage is a personal data breach: if a system holding no personal data goes down, that is an availability problem, not a case for Art. 33. In the other direction, teams routinely underrate the small cases. A termination confirmation sent to the wrong address is a personal data breach, even though nobody would call it an attack. The other obligations the Regulation attaches to the same data are brought together in our GDPR guide.

When does the 72-hour clock start?

At awareness, not at the incident. This is the most frequently misread point in the whole provision, and it decides whether a notification is on time.

Art. 33(1) requires notification "without undue delay and, where feasible, not later than 72 hours after having become aware of it." The European Data Protection Board fixes that moment in its Guidelines 9/2022 on personal data breach notification. In version 2.0 of 28 March 2023, which replace the earlier WP250 rev.01 guidelines of the Article 29 Working Party, a controller is regarded as aware once it has a reasonable degree of certainty that a security incident has occurred that has led to personal data being compromised. The guidelines are available in their current version.

Two things follow. First, you are allowed a short investigation period before the clock runs: a vague first report from an employee does not yet start the deadline. Second, that investigation has to begin immediately and reach a conclusion quickly; dragging out the check does not move the starting point, it breaches the obligation at that stage already.

Two practical points tend to get lost. The deadline is expressed in hours rather than working days, which makes Friday afternoon the hardest configuration in practice. And you do not have to know everything at the moment you notify: Art. 33(4) allows the information to be provided in phases without undue further delay. If you exceed the 72 hours anyway, the notification has to be accompanied by the reasons for the delay under Art. 33(1), second sentence.

Our Senior Privacy Expert puts the consequence plainly:

"In the case of a personal data breach, specific deadlines set out in the law start running from the moment of the incident, from its detection. Otherwise you risk not only damages claims from the data subjects, but also fines for breaching the GDPR."

Senior Privacy Expert at Kertos, translated from German

What happens in the first hour?

No form gets filled in during the first hour. The facts get established, far enough that a legal assessment becomes possible at all.

If you work with an external data protection officer, there is a limit worth knowing before the real thing happens:

"At Kertos we act as external data protection officers, and every client needs to be clear about that. We are external service providers. It means we have no visibility into the systems in question and that, already at the fact-finding stage, we depend on the client and its IT, whether that is in-house or outsourced. Certain information has to be supplied to us from the technical side so that we can then assess the case legally."

Senior Privacy Expert at Kertos, translated from German

This is not a formality, it is the reason some notifications end up close to the wire. The data protection officer can only make the legal assessment once the technical side has delivered. The joint work of the first hour looks accordingly:

"We sit down with the client and look at it: who, when, how, where? What actually happened, and what can already be established technically at this point, reliably and demonstrably? Which data is affected? And then to make the legal assessment, because that is what determines whether the supervisory authority has to be contacted and, where there is a high risk to the data subject, whether the data subject has to be informed as well."

Senior Privacy Expert at Kertos, translated from German

"Which data is affected" is where most first assessments stall, and not through carelessness. If you do not know which personal data sits in which system, you cannot establish the scope of an incident in hours, you need days. That is exactly why data discovery is not a preparation exercise for the auditor but the precondition for the assessment fitting inside the deadline.

When is notification mandatory and when is it not?

You notify, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The exception is drawn narrowly: it applies where risk is absent, not where the harm is small and not where few people are affected.

Communication to the data subjects under Art. 34 has a higher threshold. It is required only where the breach is likely to result in a high risk, and then without undue delay and in clear and plain language. Art. 34(3) sets out three exceptions: the data was rendered unintelligible to unauthorized parties by appropriate measures such as encryption; subsequent measures mean the high risk is no longer likely to materialize; or individual communication would involve disproportionate effort, in which case a public communication takes its place. The supervisory authority can also require the communication under Art. 34(4).

Who notifies Whom Deadline Legal basis
Controller competent supervisory authority without undue delay, where feasible within 72 hours of awareness Art. 33(1)
Controller, where the 72 hours are exceeded the same authority, with reasons for the delay as soon as possible thereafter Art. 33(1), second sentence
Processor controller without undue delay, with no 72-hour clock of its own Art. 33(2)
Controller, only where the risk is high data subjects without undue delay Art. 34(1)
Controller its own internal record every breach, including those not notified Art. 33(5)

What if the breach happens at a processor?

Then the processor notifies you without undue delay, and you notify the authority. The processor has no 72-hour deadline of its own toward the authority; its deadline toward you is "without undue delay," and yours starts with your awareness. In practice that means a vendor who takes three days to tell you has consumed your notification window before you knew anything had happened. What belongs in the contract on this point is covered in our article on what a data protection officer checks first in a data processing agreement.

Why notifying when in doubt is the safer call

Because the line between notifiable and not notifiable is rarely clean in practice, and because an unnecessary notification costs far less than an omitted one.

"Often the boundaries here are not black or white, as is so often the case in law. There are fluid boundaries between: is this notifiable or not? And here I take the advisory approach in dubio pro Meldung, meaning when in doubt, you notify. Because at least that rules out that you are in breach of the GDPR yourself."

Senior Privacy Expert at Kertos, translated from German

Deciding against notification is a decision you have to be able to justify. Art. 33(5) requires you to document every breach, including the facts relating to it, its effects, and the remedial action taken, and to do so expressly in a way that enables the supervisory authority to verify compliance with the article. That obligation applies whether or not you notified. A record containing only the notified cases does not satisfy it.

That turns "notify when in doubt" into more than a posture. Whoever decides against notification has to carry that decision in writing, months later, in front of an authority seeing the case for the first time.

What does the supervisory authority do when you notify?

It examines the facts, asks questions, and forms a view. What it does not normally do is treat the notification as an invitation to open a wide-ranging investigation. The opposite assumption is nonetheless widespread:

"This is a situation companies often find themselves in, wrongly, when they are not advised: they think the supervisory authority will now take an interest in them, and that if they report that customer data has leaked, the authority will investigate further and come knocking. I can give a warning about that: supervisory authorities are not there to annoy anyone, they are sparring partners and they support you. The notification obligation is therefore also a way not only of meeting your obligation but of getting support from the authorities and planning the next steps together, especially with larger incidents."

Senior Privacy Expert at Kertos, translated from German

The clearest public figures on this come from France. Between May 2018 and May 2023 the CNIL received 17,483 breach notifications. Roughly half met the 72 hours and 75 percent arrived within eleven days, and the authority names the wish to have a complete file before notifying as the main reason for delay. That is precisely what Art. 33(4) removes the need for: phased notification exists so that you do not have to wait for the forensic report to open the case. The CNIL describes its own role in a breach as accompanying the organization, aimed at helping limit the consequences of the incident.

None of which means notifying puts you in the clear. A German example makes the distinction sharper. In November 2018 the supervisory authority of Baden-Württemberg issued a 20,000 euro fine against a chat operator after an attack exposed data belonging to around 330,000 users. The basis was Art. 32, inadequate security, not the notification. The company had reported the incident itself and informed the affected users, and the authority described its transparency and willingness to cooperate as exemplary, adding that its aim was not the highest possible fines but better data protection and data security for the users concerned. The fine hit the security gap, not the openness.

How do GDPR and NIS2 breach reporting differ?

In trigger, recipient, and how the clocks run. Both regimes have a 72-hour mark, which invites people to treat them as one rule; they are two separate obligations, and a single ransomware attack at an in-scope company can trigger both.

GDPR NIS2
Trigger breach of the security of personal data significant incident, with or without personal data
Recipient the competent data protection supervisory authority the national competent authority or CSIRT designated by the member state
Deadlines one notification, without undue delay and where feasible within 72 hours of awareness staged: early warning within 24 hours, incident notification within 72 hours, final report no later than one month after the notification
Legal basis Art. 33 GDPR Art. 23 of the NIS2 Directive

One caveat that matters for any company operating across several countries: the NIS2 column describes the Directive, and the national picture is not uniform. Germany transposed it into the BSIG; France had not yet passed its transposition law at the time of writing, so only the GDPR obligation applies there. Which authority you report to, and whether NIS2 applies to you at all, depends on the member state. The NIS2 Directive guide covers the scoping and the staged procedure in detail.

An organization under both regimes does not need two incident response processes, but it does need two decision points inside one process and two named owners.

How do you prepare before it happens?

By walking the process through once while nothing is on fire, rather than inventing it on the day.

"It would have been good to have dealt with it beforehand, at least in theory, to know how you handle it. Otherwise you are left standing there the first time it happens and you do not know how to deal with it."

Senior Privacy Expert at Kertos, translated from German

Four decisions are enough to start and each one can be made in an afternoon. First: who takes the report internally, and through which channel do support, sales, and engineering reach that person on a Saturday? Second: who on the technical side produces the finding, and in what form? Third: who makes the final call on notification, and who covers for that person during vacation? Fourth: where does the Art. 33(5) record live, and who enters the cases that were not notified?

Testing whether those decisions hold takes an hour. Tell the team about a fictional incident on a Friday at 5pm, say a misconfigured storage bucket holding job applications, and ask each role what it does in the next sixty minutes. Wherever the answer is a question rather than an action, a decision is missing. That is the exercise that makes the difference between thirty hours and seventy on the day.

These decisions are not only a data protection matter. Incident response is a requirement that recurs across several frameworks, so a process defined once can be evidenced against more than one of them. How requirements from ISO 27001, the GDPR, and SOC 2 map onto a shared control set is covered in our article on one control set for three frameworks.

The payoff is concrete. A breach record kept under Art. 33(5) also feeds the ISO 27001 management review and the evidence of an incident management process, without being written twice.

One last point of orientation: a personal data breach is not the only case where a deadline runs from a moment that is hard to pin down. The same mechanic applies to a data subject access request under Art. 15, where the month runs from receipt and not from the point at which the responsible team hears about it. Both obligations fail at the same place in practice, which is that nobody is named to recognize them.

How does Kertos help during a personal data breach?

Kertos takes on the mandate as external data protection officer and assigns a named contact from the team of certified experts. During a breach that means joint fact-finding with your technical team, the legal assessment under Art. 33 and Art. 34, drafting the notification, and communication with the supervisory authority.

What customers name about this setup is less the response time than the fact that there is a known person at the other end:

"For us, Kertos is not just a compliance tool, but a real sparring partner: the privacy expert works through complex issues with us instead of just handing over templates. So we have a dedicated, personally reachable point of contact who understands our business model and are not dealing with an anonymous support queue."

Alexander S., Co-Founder, Small-Business (50 or fewer emp.), G2

On the platform, the documentation sits in the same place as the data it refers to. The Art. 33(5) record is linked to the record of processing activities and the vendor landscape, so that "which data is affected" does not start from a blank page. Handling data subject requests runs in the same system, which matters in practice when access and erasure requests follow a larger incident.

That is the part customers name as the one that used to take time:

"Previously, managing data subject access requests (DSARs) and data inventories was a time-consuming and often confusing manual task. Kertos has automated these workflows, saving us countless hours and significantly reducing the risk of human error."

Lukas P., Founders Associate & Product Owner, Small-Business (50 or fewer emp.), G2

The assessment itself stays expert work. Whether an incident is notifiable is not decided by automation but by a person who knows the facts and can defend the decision to the authority. To see what that looks like for your own processes, book a demo.

Frequently asked questions

When do you have to report a data breach under GDPR?

As soon as you become aware of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons. Notification goes to the competent supervisory authority without undue delay and, where feasible, within 72 hours (Art. 33(1) GDPR). It falls away only where a risk is unlikely.

When do the 72 hours start?

From the point at which you as controller become aware of the breach, not from the incident itself. Under the European Data Protection Board's Guidelines 9/2022, awareness requires a reasonable degree of certainty that personal data has been compromised. A short investigation period beforehand is permitted, but it has to begin immediately.

What happens if you miss the 72-hour deadline?

The notification is still due. You make it as soon as possible and attach the reasons for the delay under Art. 33(1), second sentence. A late or omitted notification falls under Art. 83(4)(a) GDPR, with a ceiling of 10 million euros or 2 percent of total worldwide annual turnover, whichever is higher. For scale: the CNIL reports that roughly half of the notifications it receives meet the deadline.

Do you have to tell the affected individuals?

Only where the breach is likely to result in a high risk to their rights and freedoms (Art. 34(1) GDPR). The communication is then made without undue delay and in clear and plain language. Art. 34(3) allows three exceptions, among them effectively encrypted data and subsequent measures that remove the high risk.

Do you have to document breaches you do not report?

Yes. Art. 33(5) GDPR requires documentation of every breach, including the facts, its effects, and the remedial action taken, in a form that enables the supervisory authority to verify compliance with the article. The cases where you decided not to notify are precisely the ones that need a traceable justification in the record.

The Founder's Guide about NIS2: Prepare your company Now before

Protect your startup: Discover how NIS2 can impact your business and what you need to consider now. Read the free white paper now!

Herwig Gangl
Co-Founder

"Implementing data protection and compliance in a structured way with Kertos"

From the very start, we felt that we were working with a partner who takes a realistic view of the effort and the process involved. The result, for us, is now a central platform that lets us manage our compliance topics in a structured way, across teams.

Ready, your compliance to put on autopilot?
Dr. Kilian Schmidt

Dr. Kilian Schmidt

CEO & Co-Founder at Kertos

Kilian had a strong focus on legal processes from an early age and began his career at Home24 as a Senior Legal Counsel and Data Protection Officer for the Home24 group. After a stint at Freshfields Bruckhaus Deringer, he moved to TIER Mobility, where he expanded the company's legal and public policy departments from one to 65 cities and from 50 to 800 employees. Driven by the lack of technology in the legal field and confirmed by his consulting work at Gorillas Technologies, he decided to found Kertos to develop the next generation of compliance – made in Europe.

About Kertos

Kertos is the modern backbone of the data protection and compliance activities of scaling companies. We enable our customers to implement integrated data protection and information security processes in accordance with GDPR, ISO 27001, TISAX®, SOC2 and many other standards quickly and cheaply through automation.

Ready to simplify GDPR compliance?

CTA Image

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check