Skip to content
Topic Contested in court

Data Breaches

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Security incidents involving unauthorized access to personal data

632 linked items 13 Laws32 Case Law91 Guidance402 Enforcement57 News

Overview

21 sources · Jul 15, 2026

Legal Framework

The GDPR governs personal data breaches primarily through Articles 33 and 34. Article 33 requires controllers to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it. A later notification is permissible but must be justified with reasons for the delay. Information may be provided in phases where not all details are immediately available, as confirmed by Recital 86. Article 34 imposes a corresponding obligation to communicate the breach to affected data subjects when the breach is likely to result in a high risk to their rights and freedoms. Article 4 provides the foundational definitions, including the scope of "personal data," which determines what constitutes a breach in the first place. The 72-hour clock starts when the controller gains awareness — meaning when the controller has a reasonable degree of certainty that a security incident has occurred affecting personal data, not merely when an anomaly is first flagged.

Key Developments

The Zeehondenmail case illustrates that breaches extend well beyond external cyberattacks. An employer was held accountable because its internal work processes allowed a colleague to access another employee's mailbox without authorization — the court found the employer's process design itself was at fault. This establishes that organizational failures in access management constitute reportable breaches. The GGD data leak litigation (WAMCA proceedings) demonstrates the severe civil liability exposure: claimants sought joint and several liability for all damages suffered, alongside court-ordered remediation of security deficiencies within a fixed timeframe. The RIVM vaccination data case confirms that even deletion requests involving special category data (Article 9) require stringent identity verification, and that mishandling such processes can itself constitute a breach. On the enforcement side, UODO fined the Mayor of Myślenice €1,790 under Article 33(1) for notification failures, and a Polish housing association €2,350 for insufficient breach notification compliance — signaling that even modest fines carry reputational and operational consequences, particularly in the public sector.

Practical Guidance

  • Establish internal breach detection and escalation procedures that feed into the 72-hour notification clock. The controller's awareness — not the IT team's initial detection — triggers the deadline. Ensure incident response protocols distinguish between preliminary investigation and confirmed awareness.

  • Document every decision point, including the rationale for any delayed notification beyond 72 hours. Recital 86 permits phased reporting, but each phase must be substantiated. Maintain an internal breach register as required by Article 33(5).

  • Conduct risk assessments for each breach to determine whether Article 34 communication to data subjects is triggered. The threshold is "high risk to rights and freedoms" — breaches involving special category data, financial data, or large-scale exposure will typically meet this standard.

  • Audit access controls and internal processes proactively. The Zeehondenmail ruling confirms that preventable internal access failures are attributable to the controller. Shared mailbox configurations, delegated access, and insufficient segregation of duties all create breach exposure.

  • Prepare breach notification templates in advance covering both Article 33 (authority) and Article 34 (data subject) requirements, including the mandatory content elements: nature of the breach, categories and approximate numbers of affected individuals and records, likely consequences, and mitigation measures taken or proposed.

Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
art 33 Notification of a personal data breach to the supervisory authority Laws GDPR Apr 2016 breach notification to authorities
why this is here
the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority

The provision directly mandates notification of personal data breaches to the supervisory authority, which is the central subject of the 'datalekken' topic.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

art 34 Communication of a personal data breach to the data subject Laws GDPR Apr 2016 high-risk breach notification to data subject
why this is here
When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject

The provision directly governs when and how data subjects must be informed of a breach, a central element of breach management.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 9/2022 personal data breach notification under GDPR Guidelines ·EDPB Guidance EDPB Apr 2023 definition and types of personal data breaches
why this is here
The GDPR defines a “personal data breach” in Article 4(12) as: “ a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed .”

The document is centrally about defining, classifying, and notifying data breaches.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 01/2021 Examples regarding Personal Data Breach Notification Guidelines ·EDPB Guidance EDPB Jan 2022 breach notification and risk assessment
why this is here
the GDPR requires the controller to: document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken

The document is entirely about personal data breach notification, risk assessment, and obligations under Articles 33 and 34 GDPR.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Guidance EDPB Jul 2021 Data breaches in processor selection context
why this is here
technical expertise with regard to security measures and data breaches

Data breaches are referenced only as a factor in evaluating processor expertise, not as a notification obligation.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 09/2020 relevant and reasoned objection under Regulation 2016/679 Guidelines ·EDPB Guidance EDPB Mar 2021 Example of data breach scenario
why this is here
the controller published the name, last name and telephone numbers of all its 100.000 clients on its website

A data breach is used only as an example to illustrate an objection to a proposed reprimand, not to discuss breach notification rules.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 91 Guidance · all 402 Enforcement · all 35 Literature · all 57 News