EU Privacy Law EU/EEA

GDPR Breach Notification: The 72-Hour Playbook for Controllers and Processors

GDPR Articles 33 and 34 explained: what counts as a breach, the 72-hour deadline, when individuals must be told, and how to document every incident.

Regulation

GDPR, Articles 33 and 34

Max Penalty

EUR 10 million or 2% of global annual turnover for notification failures

Enforcing Authority

National supervisory authorities, coordinated by the EDPB

Official Source

eur-lex.europa.eu

Executive Summary

  • Article 33 requires controllers to notify the supervisory authority within 72 hours of becoming aware of a personal data breach, unless it is unlikely to risk individuals' rights.
  • Article 34 separately requires telling affected individuals without undue delay when the breach is likely to create a high risk for them.
  • Processors have their own duty: notify the controller without undue delay after becoming aware (Article 33(2)).
  • Every breach must be documented internally under Article 33(5), even ones you decide not to report.
  • Late notification is independently fined: British Airways and Marriott both received eight-figure penalties in cases where breach response was central.

A personal data breach under GDPR is any security incident that compromises the confidentiality, integrity, or availability of personal data. Article 33 gives controllers 72 hours from awareness to notify the supervisory authority, and Article 34 adds a duty to warn affected individuals when the risk to them is high. The deadlines are short by design, which means the playbook has to exist before the incident.

RegulationGDPR, Articles 33 and 34
Deadline72 hours to the authority; individuals without undue delay
Max penaltyEUR 10M or 2% of global turnover (Art. 83(4))
Enforcing authorityNational supervisory authorities, coordinated by the EDPB
Official textEUR-Lex CELEX 32016R0679

The decision sequence

  1. Detect and contain. Security response comes first; the legal clock runs in parallel.
  2. Establish awareness. Once you have reasonable certainty personal data is affected, the 72 hours start. Log this moment; regulators ask for it.
  3. Assess risk to individuals. Consider data types, volume, encryption, and how easily people could be harmed. This assessment decides both notification duties.
  4. Notify the authority if there is any real risk. The Article 33(3) content list: nature of the breach, categories and approximate numbers of people and records, DPO contact, likely consequences, and measures taken. You may notify in phases as facts develop.
  5. Notify individuals if the risk is high. Plain language, what happened, what you are doing, and what they should do (Article 34(2)).
  6. Document everything. Article 33(5) requires an internal record of every breach, including the ones you judged non-reportable and why.

Processor breaches

Processors do not notify the authority; they notify their controller without undue delay under Article 33(2), and the controller’s 72 hours generally start on receiving that notice. Article 28 contracts should pin the processor to a specific internal deadline, commonly 24 or 48 hours, because a slow vendor consumes the controller’s entire window.

What enforcement looks like

The UK ICO’s GBP 20 million British Airways fine and GBP 18.4 million Marriott fine (both 2020, under GDPR before Brexit took full effect) turned heavily on security and incident handling. National authorities also fine pure notification failures, typically in the five- to six-figure range, where the breach itself was survivable but the silence was not. The pattern across cases is consistent: organizations that notified promptly and documented their reasoning fare dramatically better than those that sat on incidents.

Prepare before it happens

Keep a current data inventory so you can scope a breach in hours instead of days, maintain a contact list for your lead supervisory authority, and pre-draft both notification templates. Then rehearse. Our global breach notification comparison maps how the 72-hour rule lines up against other jurisdictions’ deadlines, and a free scan shows what personal data your public site exposes to third parties in the first place.

Frequently Asked Questions

What counts as a personal data breach under GDPR?

A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data (Article 4(12)). It covers ransomware, lost laptops, misdirected emails, and availability incidents, not just hacking.

When does the 72-hour clock start?

When the controller becomes aware, meaning it has a reasonable degree of certainty that a breach affecting personal data occurred. You can investigate briefly to establish that, but you cannot delay awareness by not looking.

Do I have to notify every breach?

No. Notification to the authority is required unless the breach is unlikely to result in a risk to individuals. But every breach, reported or not, must be documented internally with your risk reasoning (Article 33(5)).

What if I miss the 72-hour deadline?

Notify anyway and include the reasons for the delay, which Article 33(1) expressly permits. A late, well-explained notification is treated far better than none.

When must affected individuals be told?

When the breach is likely to result in a high risk to their rights and freedoms (Article 34), such as exposed passwords, financial data, or special category data. Encryption that renders data unintelligible can lift this duty.

Regulatory Crosswalk

UK GDPRNIS2US state breach lawsHIPAA Breach Notification Rule

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.