A personal data breach under GDPR is any security incident that compromises the confidentiality, integrity, or availability of personal data. Article 33 gives controllers 72 hours from awareness to notify the supervisory authority, and Article 34 adds a duty to warn affected individuals when the risk to them is high. The deadlines are short by design, which means the playbook has to exist before the incident.
| Regulation | GDPR, Articles 33 and 34 |
|---|---|
| Deadline | 72 hours to the authority; individuals without undue delay |
| Max penalty | EUR 10M or 2% of global turnover (Art. 83(4)) |
| Enforcing authority | National supervisory authorities, coordinated by the EDPB |
| Official text | EUR-Lex CELEX 32016R0679 |
The decision sequence
- Detect and contain. Security response comes first; the legal clock runs in parallel.
- Establish awareness. Once you have reasonable certainty personal data is affected, the 72 hours start. Log this moment; regulators ask for it.
- Assess risk to individuals. Consider data types, volume, encryption, and how easily people could be harmed. This assessment decides both notification duties.
- Notify the authority if there is any real risk. The Article 33(3) content list: nature of the breach, categories and approximate numbers of people and records, DPO contact, likely consequences, and measures taken. You may notify in phases as facts develop.
- Notify individuals if the risk is high. Plain language, what happened, what you are doing, and what they should do (Article 34(2)).
- Document everything. Article 33(5) requires an internal record of every breach, including the ones you judged non-reportable and why.
Processor breaches
Processors do not notify the authority; they notify their controller without undue delay under Article 33(2), and the controller’s 72 hours generally start on receiving that notice. Article 28 contracts should pin the processor to a specific internal deadline, commonly 24 or 48 hours, because a slow vendor consumes the controller’s entire window.
What enforcement looks like
The UK ICO’s GBP 20 million British Airways fine and GBP 18.4 million Marriott fine (both 2020, under GDPR before Brexit took full effect) turned heavily on security and incident handling. National authorities also fine pure notification failures, typically in the five- to six-figure range, where the breach itself was survivable but the silence was not. The pattern across cases is consistent: organizations that notified promptly and documented their reasoning fare dramatically better than those that sat on incidents.
Prepare before it happens
Keep a current data inventory so you can scope a breach in hours instead of days, maintain a contact list for your lead supervisory authority, and pre-draft both notification templates. Then rehearse. Our global breach notification comparison maps how the 72-hour rule lines up against other jurisdictions’ deadlines, and a free scan shows what personal data your public site exposes to third parties in the first place.