# Communication of a personal data breach to the data subject — GDPR — context bundle

> Focused context for a single provision, curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/laws/gdpr/art-34
> Every item cites its source. Verify against the official text (EUR-Lex / wetten.overheid.nl) before relying on it.

## Provision

### Communication of a personal data breach to the data subject — Communication of a personal data breach to the data subject

*GDPR, gdpr-art-34-en — https://overview.legal/laws/gdpr/art-34*

1. When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.

2. The communication to the data subject referred to in paragraph 1 of this Article shall describe in clear and plain language the nature of the personal data breach and contain at least the information and measures referred to in points (b), (c) and (d) of Article 33(3).

3. The communication to the data subject referred to in paragraph 1 shall not be required if any of the following conditions are met:
   a) the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption;
   b) the controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects referred to in paragraph 1 is no longer likely to materialise;
   c) it would involve disproportionate effort. In such a case, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.

4. If the controller has not already communicated the personal data breach to the data subject, the supervisory authority, having considered the likelihood of the personal data breach resulting in a high risk, may require it to do so or may decide that any of the conditions referred to in paragraph 3 are met.

## Enforcement

62 decision(s) on record cite Article 34, totalling approximately €83,454,966 in fines (median €28,850).

Top fines:
- **Intesa Sanpaolo S.p.A.: Insufficient technical and organisational measures to ensure information security** (Italy, €31,800,000) — https://overview.legal/posts/53613
- **FREE: Insufficient technical and organisational measures to ensure information security** (FRANCE, €15,000,000) — https://overview.legal/posts/51505
- **ONVOLDRAAGLIJK: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen.** (FRANCE, €15,000,000) — https://overview.legal/posts/51849
- **ENDESA ENERGÍA, S.A.U.: Non-compliance with general data processing principles** (SPAIN, €6,100,000) — https://overview.legal/posts/48335
- **Fastweb S.p.A.: Non-compliance with general data processing principles** (ITALY, €4,500,000) — https://overview.legal/posts/46735

## Guidance

### Guidelines on processing of personal data through blockchain technologies

*EDPB — https://overview.legal/posts/125668*

Guidelines 02/2025 on processing of personal data through blockchain technologies Version 2.0 Adopted on 07 July 2026 1 | Adopted Version history Version Date Adoption information version 1.1 08 April 2025 adoption of the guidelines before public consultation version 2.0 07 July 2026 adoption of the guidelines after public consultation 3 | Adopted 4 | Adopted The European Data Protection Board Having regard to Article 70 (1)(e) of the Regulation 2016/679/EU of the European Parliament and of the…

### Template for Cross-Regulatory Cooperation Agreements

*EDPB — https://overview.legal/posts/125669*

1 | Adopted Template for Cross-Regulatory Cooperation Agreements Adopted by the EDPB on July 7 th 2026 2 | Adopted Explanatory note Cross-regulatory cooperation between data protection supervisory authorities (DPAs) and other national and EU competent authorities has become increasingly important as legal and practical challenges emerge at the intersection of different regulatory fields. Cooperation agreements can be an important basis to organise and strengthen cooperation and dialogue between…

### Opinion 21/2026 on the draft decision of the Irish Supervisory Authority regarding the Controller Binding Corporate Rules of the Flutter Group

*EDPB — https://overview.legal/posts/125670*

Opinion 21/2026 on the draft decision of the Irish Supervisory Authority regarding the Controller Binding Corporate Rules of the Flutter Group Adopted on 07 July 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 20/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the Fluor Group

*EDPB — https://overview.legal/posts/125671*

Opinion 20/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the Fluor Group Adopted on 07 July 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 19/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Rubrik Group

*EDPB — https://overview.legal/posts/125672*

Opinion 19/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Rubrik Group Adopted on 08 June 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

## Related topics

- **Data Breaches** — https://overview.legal/topics/datalekken
  ## Legal Framework
- **Notification Obligation** — https://overview.legal/topics/meldplicht
  ## Legal Framework
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  ## Legal Framework

---
Generated by overview.legal · https://overview.legal/laws/gdpr/art-34 · 2026-08-22
