Notification Obligation
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Duty to report data breaches to authorities and affected individuals
Overview
24 sources · Jul 23, 2026Legal Framework
The notification obligation is governed primarily by Article 33 and Article 34 GDPR. Article 33 requires controllers to notify the competent supervisory authority of a personal data breach, while Article 34 requires communication to affected data subjects where the breach is likely to result in a high risk to their rights and freedoms.
The core timing requirement under Article 33(1) is strict:
"In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority"
— GDPR Art. 33(1)
Where notification cannot be made within 72 hours, the controller must provide reasons for the delay. Article 33(2) separately obliges processors to notify controllers without undue delay after becoming aware of a breach. Article 33(3) specifies minimum content: the nature of the breach, categories and approximate numbers of data subjects and records affected, contact details, likely consequences, and mitigation measures.
Article 34 triggers a higher threshold — communication to data subjects is required only where the breach is likely to result in a high risk to rights and freedoms. Three exemptions apply: appropriate technical measures rendering data unintelligible (e.g., encryption), subsequent measures eliminating the high risk, or disproportionate effort justifying a public communication instead.
The EDPB has emphasized that recognition is the first step:
Key Developments
Enforcement confirms that delayed or incomplete notification draws substantial penalties. The AEPD (Spain) imposed a €200,000 fine on an insurance broker following a ransomware attack, and VDAI (Lithuania) levied €450,000 against two medical companies after third-party system intrusions. These cases signal that supervisory authorities treat the 72-hour window and content requirements as hard compliance thresholds, not aspirational guidance.
The EDPB's Guidelines 01/2021 explicitly frame the dual notification regime:
Where information cannot be provided all at once, phased notification is expressly permitted:
"Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay."
— GDPR Art. 33(4)
Status of the Debate
This topic is actively contested in court. The core legal text is settled, but its application — particularly what constitutes "without undue delay," when a controller is deemed to have "become aware" of a breach, and how the risk threshold under Article 33 differs from the high-risk threshold under Article 34 — remains in flux. Courts have diverged on whether the 72-hour clock starts at initial detection or at the point a controller reasonably concludes a breach has occurred. The boundary between Articles 33 and 34, specifically when individual notification is triggered versus only authority notification, is also being tested. What would resolve the open questions is a CJEU preliminary ruling clarifying the awareness trigger point and the proportionality assessment for the Article 34 exemptions.
Practical Guidance
- Establish an internal breach detection and escalation procedure so that the 72-hour clock under Article 33(1) starts ticking from the moment a controller's relevant personnel become aware, not from external notification.
- Prepare notification templates in advance covering all Article 33(3) content elements — breach nature, affected categories and numbers, DPO contact, consequences, and mitigation — to avoid incomplete filings.
- Document the risk assessment process distinguishing between "risk" (triggering Article 33) and "high risk" (triggering Article 34), with a written rationale for each determination.
- Use phased notification where necessary under Article 33(4), but ensure each phase is submitted without undue further delay and the initial filing is made within 72 hours.
- Verify whether Article 34 exemptions apply before deciding against individual notification — particularly encryption and subsequent mitigation measures — and retain evidence supporting that determination, as supervisory authorities can override it under Article 34(4).