Skip to content
Call, 0511 – 47 55 58 11

Data breach: what to do in the first 72 hours

The notification deadline under Art. 33 GDPR is 72 hours from the controller becoming aware. It runs over weekends, and it does not start only once the incident has been investigated.

to notify, counted from becoming aware
72 h
mandatory items in the notification under Art. 33(3) GDPR
4
exceptions to the documentation duty under Art. 33(5) GDPR
0
of annual turnover or 10 million euros as the range of fines
2 %

The first steps

  1. Step 1: Record when you became aware

    Date, time and who knew. The deadline runs from here, and this is what the authority asks about first.

  2. Step 2: Stop the breach continuing

    Block access, isolate systems, close open routes. Preserve evidence while doing so, because whoever tidies up first often cannot show anything afterwards.

  3. Step 3: Assess and document the risk

    Is there a risk to the rights and freedoms of those affected? The assessment has to be documented in every case.

  4. Step 4: Notify

    Where there is a risk, the competent supervisory authority. Where details are missing, Art. 33(4) GDPR allows notification in phases.

  5. Step 5: Inform those affected

    Where a high risk is likely, additionally under Art. 34 GDPR, in clear and plain language.

Where the line runs

Notify the authority

  • Where a risk to the rights and freedoms of natural persons is likely
  • Within 72 hours of becoming aware, later only with reasons for the delay
  • Also where the facts have not yet been fully established

Additionally the individuals

  • Only where a high risk is likely, which is the higher threshold
  • Without undue delay and in clear, plain language
  • Exceptions for instance where data was effectively encrypted or the risk has since been removed

No notification

  • Where a risk is unlikely
  • The assessment itself is still never dispensed with
  • And it has to be documented, particularly where it comes out against notifying

That documentation matters more in practice than it sounds. Where an authority asks years later why an incident was not reported, it decides on the basis of what was recorded at the time. Without documentation, what stands in the room is not a defensible assessment but the allegation that none was made.

What the notification must contain

How we support you

We assess the risk with you, draft the notification, conduct the correspondence with the supervisory authority and prepare the communication to the individuals affected. Alongside that we deal with claims against the service providers involved and with what has to be reported to your insurer and when.

Is the clock already running?

Get in touch before the 72 hours are up. We are available at short notice.

Get in touch now

Frequently asked questions

We do not yet know whether any data actually left the building. Do we still have to notify?

The deadline starts when you become aware of the breach, not when the investigation is complete. Art. 33(4) GDPR expressly allows notification in phases where not all information is available at once. The right course is therefore usually to notify on time with what is known and supplement afterwards, rather than to wait.

The 72 hours have already passed. Should we still notify?

Yes. A late notification is better than none. Under the second sentence of Art. 33(1) GDPR it has to be accompanied by reasons for the delay. The authority will assess the delay, and it assesses the omission more harshly.

Do we also have to inform the individuals affected?

Only where there is likely to be a high risk to their rights and freedoms, Art. 34(1) GDPR. That is a different and higher threshold than the one for notifying the authority. Art. 34(3) GDPR sets out exceptions, for instance where the data was effectively encrypted or where subsequent measures have removed the high risk.

Related