Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Articles 33-34 (Data breaches)
Resources
🇫🇷 FR 🇬🇧 EN 🇳🇱 NL
EU Legal Reference⚖️ GDPR Regulatory Text⚖️ Binding Legal Force

Articles 33 & 34 GDPR : Personal Data Breach Notification Procedure

Official EU Regulation (EU) 2016/679 legal analysis · Controlled official sources

⚡ In 30 seconds:

Article 33 GDPR requires controllers to notify any personal data breach to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.

Supervisory Authority Notification within 72 Hours (Art. 33 GDPR)

Article 33(1) GDPR provides that in the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the competent supervisory authority.

Notification is strictly exempted only where the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.

  • Describe the nature of the personal data breach including, where possible, the categories and approximate number of data subjects and personal data records concerned;
  • Communicate the name and contact details of the Data Protection Officer (DPO) or other contact point;
  • Describe the likely consequences of the personal data breach;
  • Describe the measures taken or proposed to be taken by the controller to address the breach, including measures to mitigate its possible adverse effects.

Where, and in so far as, it is not possible to provide the information at the same time, Article 33(4) permits the information to be provided in phases without undue further delay.

Communication to Data Subjects in Case of High Risk (Art. 34 GDPR)

When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay in clear and plain language (Art. 34.1).

Communication to the data subject is not required if appropriate technological and organisational protection measures were applied (notably encryption rendering the data unintelligible to unauthorised persons), if subsequent measures ensure that the high risk is no longer likely to materialise, or if individual communication would involve disproportionate effort (in which case public communication or a similar effective measure is mandatory).

Verified Official Sources

⚖️ Binding Source
Regulation (EU) 2016/679 (GDPR) · CELEX: 32016R0679 · 2016-04-27

General Data Protection Regulation — EU Reference Legal Framework

Consult official source →
🇪🇺 Adopted EDPB Guidelines
Guidelines 9/2022 on personal data breach notification under GDPR

Notification des violations de données (Art. 33-34), délai de 72h, communication aux personnes

Consult official source →

Associated Operational Micro-Tools

🚨
Art. 33 & 34 GDPR
Breach Assistant (72h Notification)

Assess security incidents, calculate the 72-hour statutory deadline, and determine supervisory notification duties.

Launch interactive tool →

See Also in the Legal Framework

Article 28 GDPR Official Text

Article 28 GDPR: Data Processing Agreement & Mandatory Clauses

Comprehensive guide to Article 28 GDPR: mandatory clauses of the Data Processing Agreement (DPA), controller and process...

View document
Article 35 GDPR Official Text

Article 35 GDPR : Criteria and Methodology of the DPIA

Legal framework of the Data Protection Impact Assessment (Art. 35 GDPR): mandatory cases, WP248 high-risk criteria, asse...

View document
Article 32 GDPR Official Text

Article 32 GDPR : Security of Processing Through Risk-Appropriate Measures

Article 32 GDPR: pseudonymisation and encryption, confidentiality, integrity, availability and resilience, prompt restor...

View document
← Explore this topic in the interactive RGPD.click knowledge base
Reviewed date: 2026-08-23 Last modified: 2026-08-23

Independent legal reference documentation on Regulation (EU) 2016/679 (GDPR).

Home · Resources Index · Privacy Policy · Legal Notice