# Communication of a personal data breach to the data subject 34(3) — GDPR — provision context

> Focused context for a single provision (34(3)), curated from overview.legal on 2026-08-22. Canonical: https://overview.legal/laws/gdpr/art-34#par-3
> Verify against the official text (EUR-Lex / wetten.overheid.nl) before relying on it.

Part of **Communication of a personal data breach to the data subject** (GDPR, full article: https://overview.legal/laws/gdpr/art-34).

## Provision text

### 34(3)

The communication to the data subject referred to in paragraph 1 shall not be required if any of the following conditions are met:

a) the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption;
b) the controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects referred to in paragraph 1 is no longer likely to materialise;
c) it would involve disproportionate effort. In such a case, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.

## Topics on this provision

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons

## Cited by (exact-provision citations)

- **Guidelines 9/2022 on personal data breach notification under GDPR** (guidance) — https://overview.legal/posts/38058
- **Opinion 34/2025 on the draft decision of the Greek Supervisory Authority regarding C.E.C.L certification criteria** (guidance) — https://overview.legal/posts/51416
- **EDPB-EDPS Joint Opinion 02/2023 on the Proposal for a Regulation of the European Parliament and of the Council on the establishment of the digital euro** (guidance) — https://overview.legal/posts/125823
- **Opinion 34/2025 on the draft decision of the Greek Supervisory Authority regarding C.E.C.L certification criteria** §35 (guidance, EDPB) — https://overview.legal/posts/51416
- **Guidelines 9/2022 on personal data breach notification under GDPR** §97 (guidance, EDPB) — https://overview.legal/posts/38058
- **Guidelines 9/2022 on personal data breach notification under GDPR** §125 (guidance, EDPB) — https://overview.legal/posts/38058
- **Guidelines 9/2022 on personal data breach notification under GDPR** §99 (guidance, EDPB) — https://overview.legal/posts/38058

---
Generated by overview.legal · https://overview.legal/laws/gdpr/art-34#par-3 · 2026-08-22
