Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. Personal Data Breaches: Notification Procedure (Art. 33 & 34)
Courses Guides Blog Resources News
Français English Nederlands
Fiche 47/54 Part 5 — Operational Obligations & Sanctions Advanced Reviewed 2026-08-23

Personal Data Breaches: Notification Procedure (Art. 33 & 34)

A data breach requires rapid response: notification to the competent supervisory authority within 72 hours from becoming aware of it (Art. 33), and direct communication to affected individuals without

Open in interactive reader
⚖️ 72-Hour Statutory Deadline 📋 EDPB Guidelines 9/2022 on Data Breaches

Data Breaches: Notification Procedure (Art. 33 & 34)

⚡ In 30 seconds

Under Article 4(12), a personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. The controller must notify the competent supervisory authority within 72 hours of becoming aware (Art. 33), and communicate with affected individuals if the breach results in a high risk (Art. 34).

Breach Severity Tier Regulatory Duty Timeline & Action
Low Risk / No Risk Internal documentation only (Art. 33.5). Record in internal breach register: root cause, effects, and corrective measures implemented.
Risk to Rights (Standard) Notify Supervisory Authority (Art. 33). Submit formal notification via DPA portal within 72 hours; progressive updates allowed.
High Risk to Rights Notify DPA + Notify Data Subjects (Art. 34). Communicate directly to affected individuals without undue delay in clear and plain language.
⚡ Key Takeaways
  • Exemption from notifying individuals: data was rendered unintelligible (e.g. robustly encrypted with keys intact).
  • Phased notifications: information may be provided in phases without undue further delay if unavailable initially.
  • Article 33(5) mandate: all security incidents must be documented internally, regardless of severity.
⚠️ Common Pitfall

Waiting for forensic vendor reports to conclude before starting the 72-hour notification clock, causing serious fines for late reporting.

🛠️ In Practice

Establish an incident response playbook with automated escalation workflows reaching the DPO within 2 hours of detection.

⚖️ Official Sources: Art. 33 & 34 GDPR · Recitals 85–88 · EDPB Guidelines 9/2022 on Personal Data Breach Notification ✓ Legal review: 23 August 2026

✓ Key takeaways

  • Strict 72-hour notification deadline to the DPA starting from the moment the controller becomes 'aware'.
  • Communication to affected individuals is mandatory where the breach presents a likely high risk.
  • Processors must notify the controller without undue delay immediately upon discovering a breach (Art. 33.2).

⚠ Common pitfall: Hiding security incidents internally or delaying reporting because full forensic analysis is not yet completed (phased notifications are expressly authorized).

→ Actionable practice: Maintain an internal data breach register recording facts, effects, and remedial actions for all incidents, even non-notifiable ones.

← Security of Processing: Organizational Measures (Art. 32) Codes of Conduct & Certifications (Art. 40-43) →