Auditen
Home / Frameworks / GDPR / Personal data breach notification
GDPR · Art. 33

Personal data breach notification

Article 33 requires organizations to notify the relevant supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it. Notification is mandatory unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. All breaches, including those not reported to authorities, must be internally documented.

What it means

In practice, this requirement ensures that regulators can oversee the mitigation of risks following a security incident. It mandates that organizations move from "detection" to "assessment" and "notification" rapidly. The clock starts at the moment the organization becomes "aware" that a breach has occurred.

The scope covers any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. This includes external cyberattacks as well as internal errors, such as sending sensitive data to the wrong email recipient.

Organizations must apply a risk-based approach. If an assessment determines that the breach poses no significant risk to individuals (e.g., the data was strongly encrypted and the key remains secure), notification is not required. However, the reasoning for this decision must be recorded internally.

How to meet it

Evidence an auditor asks for

  • The written Data Breach Response Policy and Procedure manual.
  • The internal Personal Data Breach Log/Register showing all recorded incidents, their timestamps, and outcomes.
  • Copies of notifications sent to supervisory authorities, including metadata proving they were submitted within 72 hours of awareness.
  • Documented risk assessments for breaches that were *not* reported, providing the legal or technical justification for non-notification.

Common pitfalls

  • Waiting until a full forensic investigation is complete before notifying the authority; notifications can be provided in phases if all information is not available immediately.
  • Failing to document "near misses" or low-risk breaches, leaving the organization unable to prove it has a functioning detection and assessment process.
  • Misinterpreting "awareness," such as assuming the clock