Skip to content
Topic Contested in court

Notification Obligation

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Duty to report data breaches to authorities and affected individuals

237 linked items 9 Laws21 Case Law60 Guidance107 Enforcement12 News

Overview

24 sources · Jul 23, 2026

Legal Framework

The notification obligation is governed primarily by Article 33 and Article 34 GDPR. Article 33 requires controllers to notify the competent supervisory authority of a personal data breach, while Article 34 requires communication to affected data subjects where the breach is likely to result in a high risk to their rights and freedoms.

The core timing requirement under Article 33(1) is strict:

"In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority"
— GDPR Art. 33(1)

Where notification cannot be made within 72 hours, the controller must provide reasons for the delay. Article 33(2) separately obliges processors to notify controllers without undue delay after becoming aware of a breach. Article 33(3) specifies minimum content: the nature of the breach, categories and approximate numbers of data subjects and records affected, contact details, likely consequences, and mitigation measures.

Article 34 triggers a higher threshold — communication to data subjects is required only where the breach is likely to result in a high risk to rights and freedoms. Three exemptions apply: appropriate technical measures rendering data unintelligible (e.g., encryption), subsequent measures eliminating the high risk, or disproportionate effort justifying a public communication instead.

The EDPB has emphasized that recognition is the first step:

Key Developments

Enforcement confirms that delayed or incomplete notification draws substantial penalties. The AEPD (Spain) imposed a €200,000 fine on an insurance broker following a ransomware attack, and VDAI (Lithuania) levied €450,000 against two medical companies after third-party system intrusions. These cases signal that supervisory authorities treat the 72-hour window and content requirements as hard compliance thresholds, not aspirational guidance.

The EDPB's Guidelines 01/2021 explicitly frame the dual notification regime:

Where information cannot be provided all at once, phased notification is expressly permitted:

"Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay."
— GDPR Art. 33(4)

Status of the Debate

This topic is actively contested in court. The core legal text is settled, but its application — particularly what constitutes "without undue delay," when a controller is deemed to have "become aware" of a breach, and how the risk threshold under Article 33 differs from the high-risk threshold under Article 34 — remains in flux. Courts have diverged on whether the 72-hour clock starts at initial detection or at the point a controller reasonably concludes a breach has occurred. The boundary between Articles 33 and 34, specifically when individual notification is triggered versus only authority notification, is also being tested. What would resolve the open questions is a CJEU preliminary ruling clarifying the awareness trigger point and the proportionality assessment for the Article 34 exemptions.

Practical Guidance

  • Establish an internal breach detection and escalation procedure so that the 72-hour clock under Article 33(1) starts ticking from the moment a controller's relevant personnel become aware, not from external notification.
  • Prepare notification templates in advance covering all Article 33(3) content elements — breach nature, affected categories and numbers, DPO contact, consequences, and mitigation — to avoid incomplete filings.
  • Document the risk assessment process distinguishing between "risk" (triggering Article 33) and "high risk" (triggering Article 34), with a written rationale for each determination.
  • Use phased notification where necessary under Article 33(4), but ensure each phase is submitted without undue further delay and the initial filing is made within 72 hours.
  • Verify whether Article 34 exemptions apply before deciding against individual notification — particularly encryption and subsequent mitigation measures — and retain evidence supporting that determination, as supervisory authorities can override it under Article 34(4).
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
art 33 Notification of a personal data breach to the supervisory authority Laws GDPR Apr 2016 obligation to notify breaches
why this is here
the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority

The article imposes a clear legal duty to notify a personal data breach, which is the essence of the 'meldplicht' (notification obligation) topic.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

art 34 Communication of a personal data breach to the data subject Laws GDPR Apr 2016 duty to inform data subjects of breaches
why this is here
the controller shall communicate the personal data breach to the data subject without undue delay

This article creates a specific notification obligation towards data subjects, distinct from the supervisory authority notification in Article 33.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 9/2022 personal data breach notification under GDPR Guidelines ·EDPB Guidance EDPB Apr 2023 obligation to notify supervisory authority and affected individuals
why this is here
the notification requirement has a number of benefits. When notifying the supervisory authority, controllers can obtain advice on whether the affected individuals need to be informed

The document is specifically about the notification obligation for data breaches.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 01/2021 Examples regarding Personal Data Breach Notification Guidelines ·EDPB Guidance EDPB Jan 2022 breach notification obligations
why this is here
notify the personal data breach to the supervisory authority, unless the data breach is unlikely to result in a risk to the rights and freedoms of natural persons

The document is a guideline on when and how to notify data breaches to authorities, which is the core of the notification obligation topic.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Guidance EDPB Jul 2021 Data breach notification as obligation
why this is here
data breach notification obligation

Breach notification is mentioned only as one of the obligations to distribute among joint controllers.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Norway's DPA fines medical device company for breach notification violation > Norway's data protection authority, the Datatilsynet, fined U.S.-based Argon Medical Devices 2.5 million kroner for failing to report a July 2021 data breach within the 72-hour… News IAPP Mar 2023 72-hour notification duty
why this is here
failing to report a July 2021 data breach within the 72-hour deadline required by the EU General Data Protection Regulation

The document is fundamentally about the breach notification obligation and its enforcement, making it a primary source for this topic.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Data Protection Officer or Chief Privacy Officer?The rise of the Data Protection Officer > Do we need an Chief Privacy Officer, a Data Protection Officer, or do we need both?In the following article, I will examine the benefits of both roles, but I will also look at… News White Label Consultancy Jan 2022 Breach notification example
why this is here
reducing the involvement of the DPO in the event of a personal data breach to merely informing the DPO of a decision after the incident will erode the function

The document mentions a data breach incident, but does not discuss the duty to notify authorities or individuals.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 60 Guidance · all 107 Enforcement · all 28 Literature