Personal data breach notification
Article 33 requires organizations to notify the relevant supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it. Notification is mandatory unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. All breaches, including those not reported to authorities, must be internally documented.
What it means
In practice, this requirement ensures that regulators can oversee the mitigation of risks following a security incident. It mandates that organizations move from "detection" to "assessment" and "notification" rapidly. The clock starts at the moment the organization becomes "aware" that a breach has occurred.
The scope covers any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. This includes external cyberattacks as well as internal errors, such as sending sensitive data to the wrong email recipient.
Organizations must apply a risk-based approach. If an assessment determines that the breach poses no significant risk to individuals (e.g., the data was strongly encrypted and the key remains secure), notification is not required. However, the reasoning for this decision must be recorded internally.
How to meet it
- Establish a formal Data Breach Response Plan that defines "awareness," assigns roles for escalation, and sets clear timelines for reporting.
- Implement a risk assessment framework to objectively determine whether a breach meets the threshold for regulatory notification based on the likelihood and severity of the risk to individuals.
- Create a standardized notification template that includes required details: nature of the breach, categories and approximate number of data subjects/records, DPO contact details, likely consequences, and mitigation measures taken.
- Set up an internal reporting channel (e.g., a dedicated email or ticket system) so employees can report suspected incidents to the compliance team immediately.
- Maintain a centralized Breach Register to log every security incident, including those that were deemed too low-risk to report to the authority.
Evidence an auditor asks for
- The written Data Breach Response Policy and Procedure manual.
- The internal Personal Data Breach Log/Register showing all recorded incidents, their timestamps, and outcomes.
- Copies of notifications sent to supervisory authorities, including metadata proving they were submitted within 72 hours of awareness.
- Documented risk assessments for breaches that were *not* reported, providing the legal or technical justification for non-notification.
Common pitfalls
- Waiting until a full forensic investigation is complete before notifying the authority; notifications can be provided in phases if all information is not available immediately.
- Failing to document "near misses" or low-risk breaches, leaving the organization unable to prove it has a functioning detection and assessment process.
- Misinterpreting "awareness," such as assuming the clock