Fiche 47/54
Part 5 — Operational Obligations & Sanctions
Advanced
Reviewed 2026-08-23
Personal Data Breaches: Notification Procedure (Art. 33 & 34)
Data Breaches: Notification Procedure (Art. 33 & 34)
⚡ In 30 seconds
Under Article 4(12), a personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. The controller must notify the competent supervisory authority within 72 hours of becoming aware (Art. 33), and communicate with affected individuals if the breach results in a high risk (Art. 34).
| Breach Severity Tier | Regulatory Duty | Timeline & Action |
|---|---|---|
| Low Risk / No Risk | Internal documentation only (Art. 33.5). | Record in internal breach register: root cause, effects, and corrective measures implemented. |
| Risk to Rights (Standard) | Notify Supervisory Authority (Art. 33). | Submit formal notification via DPA portal within 72 hours; progressive updates allowed. |
| High Risk to Rights | Notify DPA + Notify Data Subjects (Art. 34). | Communicate directly to affected individuals without undue delay in clear and plain language. |