# Notification Obligation — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/meldplicht
> Sources are cited per item. Verify against the official texts before relying on them.

Duty to report data breaches to authorities and affected individuals

## Overview

## Legal Framework

The notification obligation is governed primarily by [Article 33](/laws/gdpr/art-33) and [Article 34](/laws/gdpr/art-34) GDPR. Article 33 requires controllers to notify the competent supervisory authority of a personal data breach, while Article 34 requires communication to affected data subjects where the breach is likely to result in a high risk to their rights and freedoms.

The core timing requirement under Article 33(1) is strict:

> "In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority"
> — [GDPR Art. 33(1)](/laws/gdpr/art-33#par-1)

Where notification cannot be made within 72 hours, the controller must provide reasons for the delay. Article 33(2) separately obliges processors to notify controllers without undue delay after becoming aware of a breach. Article 33(3) specifies minimum content: the nature of the breach, categories and approximate numbers of data subjects and records affected, contact details, likely consequences, and mitigation measures.

Article 34 triggers a higher threshold — communication to data subjects is required only where the breach is likely to result in a high risk to rights and freedoms. Three exemptions apply: appropriate technical measures rendering data unintelligible (e.g., encryption), subsequent measures eliminating the high risk, or disproportionate effort justifying a public communication instead.

The EDPB has emphasized that recognition is the first step:

## Key Developments

Enforcement confirms that delayed or incomplete notification draws substantial penalties. The AEPD (Spain) imposed a €200,000 fine on an insurance broker following a ransomware attack, and VDAI (Lithuania) levied €450,000 against two medical companies after third-party system intrusions. These cases signal that supervisory authorities treat the 72-hour window and content requirements as hard compliance thresholds, not aspirational guidance.

The EDPB's Guidelines 01/2021 explicitly frame the dual notification regime:

Where information cannot be provided all at once, phased notification is expressly permitted:

> "Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay."
> — GDPR Art. 33(4)

## Status of the Debate

This topic is actively contested in court. The core legal text is settled, but its application — particularly what constitutes "without undue delay," when a controller is deemed to have "become aware" of a breach, and how the risk threshold under Article 33 differs from the high-risk threshold under Article 34 — remains in flux. Courts have diverged on whether the 72-hour clock starts at initial detection or at the point a controller reasonably concludes a breach has occurred. The boundary between Articles 33 and 34, specifically when individual notification is triggered versus only authority notification, is also being tested. What would resolve the open questions is a CJEU preliminary ruling clarifying the awareness trigger point and the proportionality assessment for the Article 34 exemptions.

## Practical Guidance

- **Establish an internal breach detection and escalation procedure** so that the 72-hour clock under [Article 33(1)](/laws/gdpr/art-33#par-1) starts ticking from the moment a controller's relevant personnel become aware, not from external notification.
- **Prepare notification templates in advance** covering all Article 33(3) content elements — breach nature, affected categories and numbers, DPO contact, consequences, and mitigation — to avoid incomplete filings.
- **Document the risk assessment process** distinguishing between "risk" (triggering Article 33) and "high risk" (triggering Article 34), with a written rationale for each determination.
- **Use phased notification where necessary** under Article 33(4), but ensure each phase is submitted without undue further delay and the initial filing is made within 72 hours.
- **Verify whether Article 34 exemptions apply** before deciding against individual notification — particularly encryption and subsequent mitigation measures — and retain evidence supporting that determination, as supervisory authorities can override it under [Article 34(4)](/laws/gdpr/art-34#par-3-pnt-a).

## Legislation (full text of key provisions)

### Communication of a personal data breach to the data subject

*Source: GDPR, gdpr-art-34-en, 2016-04-27 — https://overview.legal/posts/90649*

### Infringements entailing a personal data breach

*Source: NIS2, nis2-art-35-en, 2022-12-14 — https://overview.legal/posts/96467*

### Notification of a personal data breach to the supervisory authority

*Source: GDPR, gdpr-art-33-en, 2016-04-27 — https://overview.legal/posts/90633*

### Definitions

*Source: ePrivacy, eprivacy-art-2-en, 2002-07-12 — https://overview.legal/posts/132169*

DefinitionsSave as otherwise provided, the definitions in Directive 95/46/EC and in Directive 2002/21/EC of the European Parliament and of the Council of 7 March 2002 on a common regulatory framework for electronic communications networks and services (Framework Directive) ( 8 ) shall apply.The following definitions shall also apply:‘user’ means any natural person using a publicly available electronic communications service, for private or business purposes, without necessarily having subscribed to this service;‘traffic data’ means any data processed for the purpose of the conveyance of a communication on an electronic communications network or for the billing thereof; ▼M2 ‘location data’ means any data processed in an electronic communications network or by an electronic communications service, indicating the geographic position of the terminal equipment of a user of a publicly available electronic communications service; ▼B ‘communication’ means any information exchanged or conveyed between a finite number of parties by means of a publicly available electronic communications service. This does not include any information conveyed as part of a broadcasting service to the public over an electronic communications network except to the extent that the information can be related to the identifiable subscriber or user receiving the information; ▼M2 ————— ▼B ‘consent’ by a user or subscriber corresponds to the data subject's consent in Directive 95/46/EC;‘value added service’ means any service which requires the processing of traffic data or location data other than traffic data beyond what is necessary for the transmission of a communication or the billing thereof;‘electronic mail’ means any text, voice, sound or image message sent over a public communications network which can be stored in the network or in the recipient's terminal equipment until it is collected by the recipient; ▼M2 ‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed in connection with the provision of a publicly available electronic communications service in the Community.

### Recital 86 — data breach notification to data subjects

*Source: GDPR, gdpr-rec-86-en, 2016-04-27 — https://overview.legal/posts/91687*

The controller should communicate to the data subject a personal data breach, without undue delay, where that personal data breach is likely to result in a high risk to the rights and freedoms of the natural person in order to allow him or her to take the necessary precautions. The communication should describe the nature of the personal data breach as well as recommendations for the natural person concerned to mitigate potential adverse effects. Such communications to data subjects should be made as soon as reasonably feasible and in close cooperation with the supervisory authority, respecting guidance provided by it or by other relevant authorities such as law-enforcement authorities. For example, the need to mitigate an immediate risk of damage would call for prompt communication with data subjects whereas the need to implement appropriate measures against continuing or similar personal data breaches may justify more time for communication.

### Recital 88 — personal data breach notification rules

*Source: GDPR, gdpr-rec-88-en, 2016-04-27 — https://overview.legal/posts/91691*

In setting detailed rules concerning the format and procedures applicable to the notification of personal data breaches, due consideration should be given to the circumstances of that breach, including whether or not personal data had been protected by appropriate technical protection measures, effectively limiting the likelihood of identity fraud or other forms of misuse. Moreover, such rules and procedures should take into account the legitimate interests of law-enforcement authorities where early disclosure could unnecessarily hamper the investigation of the circumstances of a personal data breach.

### Recital 87 — personal data breach notification requirements

*Source: GDPR, gdpr-rec-87-en, 2016-04-27 — https://overview.legal/posts/91689*

It should be ascertained whether all appropriate technological protection and organisational measures have been implemented to establish immediately whether a personal data breach has taken place and to inform promptly the supervisory authority and the data subject. The fact that the notification was made without undue delay should be established taking into account in particular the nature and gravity of the personal data breach and its consequences and adverse effects for the data subject. Such notification may result in an intervention of the supervisory authority in accordance with its tasks and powers laid down in this Regulation.

### Recital 85 — personal data breach notification requirements

*Source: GDPR, gdpr-rec-85-en, 2016-04-27 — https://overview.legal/posts/91685*

A personal data breach may, if not addressed in an appropriate and timely manner, result in physical, material or non-material damage to natural persons such as loss of control over their personal data or limitation of their rights, discrimination, identity theft or fraud, financial loss, unauthorised reversal of pseudonymisation, damage to reputation, loss of confidentiality of personal data protected by professional secrecy or any other significant economic or social disadvantage to the natural person concerned. Therefore, as soon as the controller becomes aware that a personal data breach has occurred, the controller should notify the personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the controller is able to demonstrate, in accordance with the accountability principle, that the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where such notification cannot be achieved within 72 hours, the reasons for the delay should accompany the notification and information may be provided in phases without undue further delay.

### Recital 73 — lawful restrictions on data subject rights

*Source: GDPR, gdpr-rec-73-en, 2016-04-27 — https://overview.legal/posts/91661*

Restrictions concerning specific principles and the rights of information, access to and rectification or erasure of personal data, the right to data portability, the right to object, decisions based on profiling, as well as the communication of a personal data breach to a data subject and certain related obligations of the controllers may be imposed by Union or Member State law, as far as necessary and proportionate in a democratic society to safeguard public security, including the protection of human life especially in response to natural or manmade disasters, the prevention, investigation and prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security, or of breaches of ethics for regulated professions, other important objectives of general public interest of the Union or of a Member State, in particular an important economic or financial interest of the Union or of a Member State, the keeping of public registers kept for reasons of general public interest, further processing of archived personal data to provide specific information related to the political behaviour under former totalitarian state regimes or the protection of the data subject or the rights and freedoms of others, including social protection, public health and humanitarian purposes. Those restrictions should be in accordance with the requirements set out in the Charter and in the European Convention for the Protection of Human Rights and Fundamental Freedoms.

## Case law

### Judgment of the Court (First Chamber) of 26 September 2024.#TR v Land Hessen.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 57(1)(a) and (f) – Tasks of the supervisory authority – Article 58(2) – Corrective powers – Administrative fine – Discretion of the supervisory authority – Limits.#Case C-768/21.

*Source: Court of Justice of the European Union, C-768/21, 2024-09-26 — https://overview.legal/posts/132245 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0768*

In Case C-768/21, the Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning TR's challenge of the Hessischer Beauftragte für Datenschutz und Informationsfreiheit (HBDI) for declining to exercise corrective powers against Sparkasse X following a personal data breach complaint. The Court clarified the limits of supervisory authorities' discretion under GDPR Articles 57(1) and 58(2), holding that while authorities retain discretion in selecting corrective measures, they are legally obliged to exercise those powers when an infringement is established, and complainants have a right to an effective remedy under Article 77 even where no enforcement action was taken. No fine was imposed in this proceeding, as the ruling addressed the supervisory authority's enforcement obligations rather than penalizing a controller.

### Privacy International v Secretary of State

*Source: CJEU, C-623/17, 2020-10-06 — https://overview.legal/posts/51481 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0623*

General and indiscriminate transmission of traffic data to security agencies incompatible with EU law.

### Data Protection Commissioner v Facebook Ireland and Maximillian Schrems

*Source: CJEU, C-311/18, 2020-07-16 — https://overview.legal/posts/51470 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=51470*

Invalidated Privacy Shield adequacy decision and upheld validity of Standard Contractual Clauses with additional safeguards required.

### Judgment of the Court (First Chamber) of 10 December 2020.#Land Nordrhein-Westfalen v D.-H. T. as liquidator of J & S Service UG.#Request for a preliminary ruling from the Bundesverwaltungsgericht.#Reference for a preliminary ruling – Personal data – Regulation (EU) 2016/679 – Article 23 – Restrictions to the data subject’s rights – Significant financial interest – Enforcement of civil law claims – National legislation referring to the provisions of EU law – Tax data concerning a legal person –

*Source: Court of Justice of the European Union, C-620/19, 2020-12-10 — https://overview.legal/posts/132326 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62019CJ0620*

In Case C-620/19, the Court of Justice of the European Union (First Chamber) addressed a preliminary ruling from the German Bundesverwaltungsgericht concerning whether Article 23(1)(e) and (j) of the GDPR permits national legislation restricting data subjects' rights to access tax data for the enforcement of civil law claims. The dispute arose between Land Nordrhein-Westfalen and D.-H. T., acting as insolvency administrator of J & S Service UG, regarding a request for the company's tax data. The Court found that because the GDPR does not apply to the processing of personal data concerning legal persons, it lacked jurisdiction to interpret Article 23 in this context, as the tax data at issue related to a legal entity rather than a natural person.

### SG Nürnberg - S 5 SF 65/24 DS

*Source: Social Court Nuremberg, 2026-06-10 — https://overview.legal/posts/122874 — original: https://gdprhub.eu/index.php?title=SG_Nürnberg_-_S_5_SF_65/24_DS*

Facts — The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus programme. The bonus programme was managed via an app. To handle the information technology operations of this programme, the controller hired the processor (an IT service provider), establishing a data processing agreement under Article 28 GDPR alongside specific information security guidelines. To provide these services, the processor utilised "MOVEit Transfer," a market-leading file transfer software developed by Progress Software Corp. On 31 May 2023, the software developer publicly announced a critical, previously unknown "zero-day" vulnerability in the software (later assigned CVE-2023-34362). At that exact moment, no security patch was available. On the very same day, 31 May 2023, the processor – alongside thousands of other companies worldwide – became the victim of a global cyberattack carried out by the hacker group "Clop." The hackers exploited this zero-day vulnerability to install a "web-shell" backdoor (typically named human2.aspx), bypassing authentication to exfiltrate database records. The compromised data included the data subject's first and last name, health insurance number, bonus points balance, and a bank account number (IBAN) belonging to her mother. No medical, health, or social security data was exfiltrated. On 1 June 2023, the developer released a security patch, which the processor installed immediately. On 2 June 2023, the German Federal Office for Information Security (BSI) issued a formal IT security warning (No. 2023-240133-1100, Version 1.1). The BSI classified the IT threat level as "3 / Orange" (business-critical), confirming active exploitation with data exfiltration. The BSI recommended immediately blocking all HTTP and HTTPS traffic to MOVEit environments, checking for specific Indicators of Compromise (IoCs) in the web server directories, and applying the newly released patch before reconnecting systems to the network. On 16 June 2023, the processor informed the controller about the incident. On 17 June 2023, the controller issued a public press release confirming that its external service provider for the bonus programme had been targeted on 31 May 2023. The release stated that the security vulnerability had been closed, that there was never any connection to the controller's internal IT systems, and that relevant supervisory authorities had been notified. The controller subsequently notified the data subject's parents. On 27 March 2024, the data subject, via legal counsel, sent a formal warning letter to the controller demanding an injunction, a declaration of liability for all potential future damages, and non-material damages of at least €3,000. Following the controller's refusal, the data subject filed a lawsuit with the Nuremberg Social Court (Sozialgericht Nürnberg), later expanding the claim to the processor as a joint defendant. Holding — The Court dismissed the lawsuit as partly inadmissible and otherwise unfounded, establishing the following legal principles: First, the Court held that a successful third-party cyberattack does not establish an irrebuttable presumption that a controller or processor failed to implement appropriate security measures under Article 32(1) GDPR and Article 5(1)(f) GDPR. To escape liability under Article 82(3) GDPR, an operator must prove they implemented robust baseline security controls (such as multi-factor authentication, encryption, and lockout policies) and applied a security patch immediately upon its release by the vendor, even if this occurred before formal alerts were issued by national IT security authorities. Second, the Court held that a claim for non-material damages under Article 82(1) GDPR based on the fear or distress of future data misuse cannot be established if the data subject is a minor who has no subjective knowledge or cognitive awareness of the data breach. Furthermore, if the compromised financial data (such as an IBAN) does not belong to the data subject personally, there is no direct risk of financial harm to them, rendering the alleged fear of financial damage unfounded. Third, the Court held that an injunction claim is inadmissible due to a lack of specificity if it merely demands that a controller stop making personal data accessible to third parties without implementing "state-of-the-art" security measures, without specifying the concrete technical or organisational measures the controller is required to take. Fourth, the Court held that a declaratory claim for potential future material damages is inadmissible under national procedural law (§ 55(1) SGG) if there is no realistic probability of future financial harm, particularly because the compromised bank account belonged to a third party (the mother) and the software vulnerability was immediately patched.

### SO Warszawa - III C 904/23

*Source: Regional Court in Warsaw, 2026-02-16 — https://overview.legal/posts/53100 — original: https://gdprhub.eu/index.php?title=SO_Warszawa_-_III_C_904/23*

Facts — The Financial Ombudsman’s office (the controller) sent a letter containing the name, the address, and the case reference number of a customer (the data subject) to 28,366 public institutions and entities registered on an official government platform in February 2021. The data subject demanded compensation for the unauthorised disclosure of his personal data from the controller in November 2021. The controller refused to accept liability for the incident. The supervisory authority issued the controller a reprimand in September 2022 for disclosure of personal data in violation of Article 6(1) GDPR. The data subject brought a lawsuit for damages under Article 82 GDPR before the Regional Court in Warsaw in August 2023. The data subject stated that they had experienced severe stress and lost the sense of security and control over their data as a result of the unauthorised disclosure of the letter. The controller argued it was not at fault for the incident as it was caused by a temporary IT system failure that the controller could not have foreseen. Holding — The Regional Court in Warsaw held that the controller was undoubtedly liable for the unauthorised disclosure of the data subject’s personal data pursuant to Article 82 GDPR: the controller was an administrator for the government platform and had not taken adequate measures to secure the data. Second, the court held that the data subject had suffered non-material damage in connection with the aforementioned incident. It took into account that the data had been disclosed to numerous entities. In addition, the deterioration of the data subject’s mental state was confirmed by a witness. The court awarded the data subject PLN 40,000 in damages. It considered the data subject’s claim of PLN 50,000 to be excessive in light of established case law.

### Judgment of the Court (Third Chamber) of 20 June 2024.#JU and SO v Scalable Capital GmbH.#Request for a preliminary ruling from the Amtsgericht München.#References for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 82 – Right to compensation for damage caused by data processing that infringes that regulation – Concept of ‘non-material damage’ – Compensation of a punitive nature or purely in respect of damag

*Source: Court of Justice of the European Union, C-182/22, 2024-06-20 — https://overview.legal/posts/132254 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0182*

In Joined Cases C-182/22 and C-189/22, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Amtsgericht München concerning the interpretation of Article 82 GDPR in proceedings brought by data subjects JU and SO against Scalable Capital GmbH following the theft of their personal data from the company's trading application. The core issue was whether Article 82 GDPR permits compensation for non-material damage that is minimal or symbolic, and whether such compensation can serve a punitive function. The Court held that Article 82 GDPR does not preclude the awarding of minimal compensation for non-material damage, such as distress following a personal data breach, provided the damage is genuine and actually arose from the infringement, but clarified that compensation under the GDPR must be purely reparative and cannot have a punitive character.

### Judgment of the Court (Third Chamber) of 25 January 2024.#BL v MediaMarktSaturn Hagen-Iserlohn GmbH.#Request for a preliminary ruling from the Amtsgericht Hagen.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Interpretation of Articles 5, 24, 32 and 82 – Assessment of the validity of Article 82 – Inadmissibility of the request for an assessment of validity – Right to compensation for damage caused by

*Source: Court of Justice of the European Union, C-687/21, 2024-01-25 — https://overview.legal/posts/132272 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0687*

In Case C-687/21, the Court of Justice of the European Union interpreted Articles 5, 24, 32, and 82 of the GDPR in response to a preliminary ruling request from the Amtsgericht Hagen in proceedings between data subject BL and MediaMarktSaturn Hagen-Iserlohn GmbH concerning alleged non-material damage from personal data transmitted to an unauthorized third party due to employee error. The Court held that a controller's infringement of GDPR security obligations through employee error can give rise to a right to compensation under Article 82, that the severity of the infringement may be relevant to assessing both the appropriateness of protective measures and the existence of damage, and that the concept of non-material damage should be interpreted broadly without requiring a minimum threshold of severity. No fine was imposed, as the ruling addresses interpretation of GDPR provisions rather than administrative penalties.

### VB v Natsionalna agentsia za prihodite

*Source: CJEU, C-340/21, 2023-12-14 — https://overview.legal/posts/51485 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0340*

Data breach alone does not establish inadequate security measures. Burden on controller to prove adequacy.

### Judgment of the Court (Eighth Chamber) of 4 October 2024.#A v Patērētāju tiesību aizsardzības centrs.#Request for a preliminary ruling from the Augstākā tiesa (Senāts).#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 82(1) – Right to compensation and liability – Unlawful processing of data – Infringement of the right to protection of personal data – Concept of ‘damage’ – Compensation for non-material damage in the form of apologies – Whether

*Source: Court of Justice of the European Union, C-507/23, 2024-10-04 — https://overview.legal/posts/132162 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0507*

The Court of Justice of the European Union issued a preliminary ruling on a reference from the Latvian Supreme Court in Case C-507/23, involving an individual ("A") and the Patērētāju tiesību aizsardzības centrs (Consumer Rights Protection Centre, Latvia) regarding compensation for non-material damage allegedly suffered from unlawful processing of personal data under Article 82(1) GDPR. The Court addressed whether apologies can constitute compensation for non-material damage and whether the controller's attitude and motivation may be considered in assessing the form and level of compensation. No fine was imposed, as the ruling clarifies interpretive questions of EU law for the referring national court.

### Judgment of the Court (Third Chamber) of 11 April 2024.#GP v juris GmbH.#Request for a preliminary ruling from the Landgericht Saarbrücken.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 82 – Right to compensation for damage caused by data processing that infringes that regulation – Concept of ‘non-material damage’ – Impact of the seriousness of the damage suffered – Liability of the controlle

*Source: Court of Justice of the European Union, C-741/21, 2024-04-11 — https://overview.legal/posts/132262 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0741*

In Case C-741/21, the Court of Justice of the European Union (Third Chamber) addressed a preliminary reference from the Landgericht Saarbrücken in proceedings between data subject GP and juris GmbH concerning GP's claim for compensation under Article 82 GDPR after the company processed his personal data for marketing purposes despite his objections. The Court held that "non-material damage" under Article 82(1) GDPR must be interpreted broadly and is not subject to a seriousness threshold, that a controller may be exempt from liability under Article 82(3) if it proves it was not in any way responsible for the infringement (including where a person acting under its authority under Article 29 was at fault), and that the criteria for administrative fines under Article 83 GDPR do not apply to the assessment of compensation amounts.

### UI v Österreichische Post AG

*Source: CJEU, C-300/21, 2023-05-04 — https://overview.legal/posts/51483 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0300*

Right to compensation under GDPR Article 82 requires proof of actual damage.

## Guidance

### Guidelines 9/2022 on personal data breach notification under GDPR

*Source: EDPB, edpb-guidelines-on-personal-data-breach-notification-under-gdpr, 2023-04-04 — https://overview.legal/posts/38058 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-92022-on-personal-data-breach-notification-under-gdpr_en*

The EDPB adopted Guidelines 9/2022 (Version 2.0, 28 March 2023) to update and replace the prior WP250 guidance on personal data breach notification under Articles 33 and 34 of the GDPR. The guidelines address the definition and types of personal data breaches, controller and processor notification obligations, the concept of a controller becoming "aware" of a breach, cross-border and non-EU establishment breach scenarios, and the conditions under which notification to supervisory authorities and data subjects is or is not required.

### Guidelines 01/2021

*Source: EDPB, edpb-guidelines-on-examples-regarding-personal-data-breach-notification, 2022-01-03 — https://overview.legal/posts/38047 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012021-on-examples-regarding-personal-data-breach-notification_en*

The European Data Protection Board (EDPB) adopted Guidelines 01/2021 on December 14, 2021, providing practical examples and analysis regarding personal data breach notification obligations under Articles 33 and 34 of the GDPR. The guidelines present hypothetical scenarios covering ransomware attacks and data exfiltration incidents, illustrating how controllers should assess risk to determine whether notification to supervisory authorities and communication to data subjects are required. The document serves as interpretive guidance for controllers evaluating breach severity, appropriate mitigation measures, and notification decisions, and does not impose any fines or sanctions.

### Guidelines on Personal data breach notification under Regulation 2016/679, WP250 rev.01

*Source: EDPB, guidelines-on-personal-data-breach-notification-under-regulation-2016679-wp250-en, 2018-05-25 — https://overview.legal/posts/126319 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-on-personal-data-breach-notification-under-regulation-2016679-wp250_en*

Уведомления относно нарушение на сигурността на личните данни Насока 25 May 2018 Уведомления относно нарушение на сигурността на личните данни Related documents Всички

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### Opinion 14/2019 on the draft Standard Contractual Clauses submitted by the DK SA (Article 28(8) GDPR)

*Source: EDPB, opinion-142019-on-the-draft-standard-contractual-clauses-en, 2019-07-12 — https://overview.legal/posts/126212 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-142019-on-the-draft-standard-contractual-clauses_en*

Adopted 1 Opinion 14/2019 on the draft Standard Contractual Clauses sub mitted by the DK SA (Article 28( 8 ) GDPR) Adopted on 9 July 2019 Adopted 2 1 CONTENTS 2 Summary of the Facts ................................ ................................ ................................ .................... 4 3 Assessment ................................ ................................ ................................ ................................ .... 5 3.1 General reasoning of the Board…

### EDPB Work Programme 2023-2024

*Source: EDPB, edpb-work-programme-2023-2024-en, 2023-02-22 — https://overview.legal/posts/125868 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-work-programme-2023-2024_en*

EDPB Work Programme 2023/2024 Adopted on 14 February 2023 The European Data Protection Board The European Data Protection Board (EDPB) is an independent European body established by the General Data Protection Regulation (GDPR). The EDPB has the following main tasks: To issue opinions, guidelines, recommendations and best practices to promote a common understanding of the GDPR and the Law Enforcement Directive (LED); To advise the European Commission on any issue related to the protection of…

### EDPB Annual Report 2021

*Source: EDPB, edpb-annual-report-2021-en, 2022-05-12 — https://overview.legal/posts/125941 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2021_en*

Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which provides an overview of key EDPB activities in 2021, is also available. Further details about the EDPB can be found on our website at edpb.europa.eu. 3 EDPB Annual Report 2021 3 GLOSSARY 7 FOREWORD 10 2021 - HIGHLIGHTS 13 3.1. STRATEGY 2021-2023 AND WORK PROGRAMME 2021-2022 13 3.2. EDPB OPINIONS ON DRAFT UK ADEQUACY…

### Contribution of the EDPB to the evaluation of the GDPR under Article 97

*Source: EDPB, contribution-of-the-edpb-to-the-evaluation-of-the-gdpr-en, 2020-02-18 — https://overview.legal/posts/126182 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/contribution-of-the-edpb-to-the-evaluation-of-the-gdpr_en*

1 Adopted Contribution of the EDPB to the e valuation of the GDPR under Article 97 Adopted on 18 February 2020 2 Adopted Table of content s General EDPB policy messages ................................ ................................ .......................... 3 Questionnaire on Evaluation of the GDPR under Article 97 ................................ ................. 5 Reply of the European Data Protection Board ................................ ................................ .... 5 I.…

## Enforcement decisions

### Mayor of the City and Municipality of Myślenice: Insufficient fulfilment of data breach notification obligations

*Source: Polish National Personal Data Protection Office (UODO), 2026-04-30 — https://overview.legal/posts/83463 — original: https://www.enforcementtracker.com/ETid-3198*

The Polish DPA (UODO) fined the Mayor of the City and Municipality of Myślenice €1,790 for insufficient fulfilment of personal data breach notification obligations under Article 33(1) GDPR. The authority found that the public sector entity failed to properly comply with the requirement to notify the supervisory authority of a personal data breach within the prescribed 72-hour timeframe.

### UODO (Poland) - DKN.5131.7.2022

*Source: UODO (Poland), 2026-04-13 — https://overview.legal/posts/53109 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.7.2022*

Facts — An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone application between July 2020 and March 2021 to send pictures of customer contracts containing the personal data of individuals residing at addresses visited during door-to-door sales (the data subjects). The controller had not authorised this practice, and former employees of the sub-processor could still access the personal data through the app. The controller identified the use of the app as a data breach and notified the supervisory authority about it in April 2021. The DPA initiated administrative proceedings in March 2022. Holding — First, the DPA held that the controller had violated the principles of integrity and confidentiality enshrined in Article 5(1)(f) and the principle of accountability laid down in Article 5(2) GDPR. It had also violated Articles 24(1), 25(1), 28(1), 32(1) and 32(2) GDPR, which specify these principles. The DPA issued the controller a reprimand. The DPA found the controller had failed to implement appropriate technical and organisational measures itself and also failed to properly verify whether the (sub-)processors had provided sufficient guarantees that they had implemented such measures. The data protection agreements required in Article 28(1) GDPR were very general in nature, and none of the parties in the chain of contracts had conducted a risk analysis to select appropriate security measures. In addition, the controller had not continuously monitored the processing activities. Second, the DPA held that the two processor and the sub-processor had violated Articles 32(1) and 32(2) GDPR read in conjunction with Article 28(4) GDPR. They had all failed to implement appropriate technical and organisational measures to ensure the security of personal data processing. The sub-processor was largely held responsible for the data breach – it had started using the app to process customers’ personal data without authorisation from the controller or the processors. Furthermore, the DPA pointed out the sub-processor should have verified whether the application would allow access to the personal data through it even after the termination of the employment relationship. The DPA reprimanded the processors and fined the sub-processor €2,415.

### Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra: Insufficient fulfilment of data breach notification obligations

*Source: Polish National Personal Data Protection Office (UODO), 2021-06-30 — https://overview.legal/posts/46884 — original: https://www.enforcementtracker.com/ETid-769*

The Polish DPA (UODO) has imposed a fine of EUR 3,000 on the Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra Foundation for the promotion of mediation and legal education. The controller had not immediately informed the DPA and the data subjects about a personal data breach. Several folders containing personal data had been stolen from the controller in early 2020. These included the names, addresses and telephone numbers, and in 3 to 4 cases also the PESEL numbers (Polish identificatio

### Enea S.A.: Insufficient fulfilment of data breach notification obligations

*Source: Polish National Personal Data Protection Office (UODO), 2021-01-11 — https://overview.legal/posts/46699 — original: https://www.enforcementtracker.com/ETid-584*

The Polish DPA (UODO) fined Enea S.A. EUR 30,000 for the controller's failure to report a personal data breach, in violation of Art. 33 (1) GDPR. The DPA received information about a personal data breach from a person who had become an unauthorized recipient of personal data. The breach consisted of sending an email with an unencrypted, non-password protected attachment that contained personal data of several hundred individuals. The sender of the email was an employee of the sanctioned controll

### Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A.: Insufficient fulfilment of data breach notification obligations

*Source: Polish National Personal Data Protection Office (UODO), 2020-12-28 — https://overview.legal/posts/46616 — original: https://www.enforcementtracker.com/ETid-501*

The Polish DPA (UODO) fined Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. EUR 18,930 for a breach of Art. 33 (1) GDPR and Art. 34 (1) GDPR. In May 2020, the DPA received a notification from a third party about a personal data breach involving an insurance agent acting as a processing agent for Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. who sent an insurance policy to an unauthorized addressee by email. The document contained personal data concerning, among others, surnames, first name

### PVV Overijssel: Insufficient fulfilment of data breach notification obligations

*Source: Autoriteit Persoonsgegevens, 2020-06-16 — https://overview.legal/posts/46787 — original: https://www.enforcementtracker.com/ETid-672*

The Dutch DPA (AP) fined the Overijssel local branch of the PVV party EUR 7,500 for failing to notify the AP of a personal data breach, in violation of Art. 33 GDPR. An email regarding the convening of a meeting had been sent via an open distribution list due to a human error. Since the total of 101 recipients were addressed as 'Friends of the PVV' in the email, the political beliefs of the data subjects were thus disclosed to all addressees.

### Housing Associaction: Insufficient fulfilment of data breach notification obligations

*Source: Polish National Personal Data Protection Office (UODO), 2026-04-07 — https://overview.legal/posts/53565 — original: https://www.enforcementtracker.com/ETid-3114*

Polish National Personal Data Protection Office (UODO) fined Housing Associaction €2,350 on 2026-04-07 for: Insufficient fulfilment of data breach notification obligations.

### Court Bailiff: Insufficient fulfilment of data breach notification obligations

*Source: Polish National Personal Data Protection Office (UODO), 2025-10-23 — https://overview.legal/posts/49055 — original: https://www.enforcementtracker.com/ETid-2940*

The Polish DPA has imposed a fine of EUR 5,000 on a court bailiff. The controller forwarded a letter containing personal data to the wrong person, failing to inform either the affected data subjects or the DPA.

## Recent developments

### ANSPDCP (Romania) - ANSPDCP (Romania) - Fine against Poliserv JG (PJG) SRL

*Source: GDPRhub, 2026-08-21 — https://overview.legal/posts/291402 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_ANSPDCP_(Romania)_-_Fine_against_Poliserv_JG_(PJG)_SRL*

The Romanian DPA imposed a fine of RON 15,728 (€ 3,000) on a car dealer for failing to implement appropriate technical and organisational measures in order to guarantee the security of its processing, in breach of Article 32 GDPR. English Summary. Facts. A personal data breach occurred because of a cyberattack made possible through a phishing method that stole the credentials of a controller account with administrator privileges. Thus, the personal data of individual customers (at least their fi

### DPC (Ireland) - IN-19-9-4

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291263 — original: https://gdprhub.eu/index.php?title=DPC_(Ireland)_-_IN-19-9-4*

The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR.The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR. English Summary. English Summary On 8 October 2019, the DPA initiated an own-volition inquiry to determine whether the

### EDPB meets with EU Commissioner McGrath and adopts common data breach notification template

*Source: European Data Protection Board, 2026-06-10 — https://overview.legal/posts/53059 — original: https://www.edpb.europa.eu/news/edpb-meets-with-eu-commissioner-mcgrath-and-adopts-common-data-breach-notification-template_en*

Brussels, 10 June – During its latest plenary, the EDPB met with Michael McGrath, Commissioner for Democracy, Justice, the Rule of Law and Consumer Protection. In addition, the Board has adopted a common data breach notification template.The Board held a meeting with Commissioner McGrath, engaging in a fruitful discussion about common priorities and ongoing work on areas of mutual interest.The Digital Omnibus was among the key topics that shaped the discussion. The Board reiterated that, while s

### Norway's DPA fines medical device company for breach notification violation

*Source: IAPP, 2023-03-22 — https://overview.legal/posts/6231 — original: https://iapp.org/news/a/norwegian-dpa-fines-medical-device-company-for-breach-notification-violation#entry-4175*

> 
																						Norway's data protection authority, the Datatilsynet, fined U.S.-based Argon Medical Devices 2.5 million kroner for failing to report a July 2021 data breach within the 72-hour deadline required by the EU General Data Protection Regulation. "This case is an important reminder that data controllers — including those established outside the (European Economic Area) — must have suitable measures in place to be able to immediately determine whether a breach of personal data

### The Italian SA fined Poste Vita for data breach

*Source: European Data Protection Board, 2026-06-04 — https://overview.legal/posts/53061 — original: https://www.edpb.europa.eu/news/the-italian-sa-fined-poste-vita-for-data-breach_en*

Background informationDate of final decision: 10 July 2025National caseController: Poste Vita s.p.a.Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 33 (Notification of a personal data breach to the supervisory authority)Decision: Administrative fineKey words: Administrative fine, Clients, Data security, Insurance, Personal data breachSummary of the DecisionOrigin of the case The investigation was initiated following a complaint from an insurance compan

## Literature

### European Union ∙ EDPB Adopts updated Guidelines on Personal Data Breach Notification under GDPR: The End of the One-Stop-Shop Reporting Mechanism for Non-EU Establishments

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132622 — original: https://doi.org/10.21552/edpl/2022/4/11*

### IMPACT OF GDPR ON UKRAINIAN PERSONAL DATA PROTECTION LEGISLATION

*Source: Pravo ta nauki, 2018-12-30 — https://overview.legal/posts/132472 — original: https://doi.org/10.66556/2522-4549.1519.koshovyi-b*

The article examines the impact of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation – GDPR), which entered into force on 25 May 2018, on Ukrainian personal data protection legislation. The main novelties of GDPR are analyzed, including the principle of accountability, the right to erasure (right to be

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit?

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132504 — original: https://doi.org/10.21552/edpl/2022/4/8*

### GDPR: A new challenge for personal data protection

*Source: Bankarstvo, 2017-01-01 — https://overview.legal/posts/132473 — original: https://doi.org/10.5937/bankarstvo1704166m*

stručni članak Erne Mraznica Raiffeisen banka ad Beograd erne.mraznica@raiffeisenbank.rs GDPR - NOVI IZAZOV ZAŠTITE PODATAKA O LIČNOSTI Rezime Dana 4. maja 2016. godine objavljena je Opšta Uredba o zaštiti podataka o ličnosti u Sl. glasniku EU, koja će se primenjivati od 25. maja 2018. godine. Cilj propisa je harmonizacija zaštite podataka o ličnosti na nivou EU, veći stepen kontrole za lica čiji se podaci obrađuju i unapređeno upravljanje savremenim rizicima iz ove oblasti. Banke, po prirodi svog poslovanja, spadaju među najveće rukovaoce podataka o ličnosti i u postupku usklađivanja sa obavezama utvrđenih Uredbom biće u prilici da izvrše punu analizu svog postojećeg regulatornog i infrastrukturnog okvira zaštite podataka o ličnosti. Istovremeno, pruža im se prilika da isprave eventualne nedostatke u postojećim procesima, odnosno da značajno povećaju svest organizacije o standardima zaštite podataka o ličnosti, posebno imajući u vidu zaprećene stroge sankcije za slučaj neusklađenosti. Ključne reči : GDPR, podatak o ličnosti, osnovni principi, prava lica, rukovalac, obrada podataka, transfer podataka, sankcije, usklađivanje JEL : F52, G14 doi: 10.5937/bankarstvo1704166M 166 Bankars

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Data Breaches** — https://overview.legal/topics/datalekken
  Security incidents involving unauthorized access to personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data

---
Generated by overview.legal · https://overview.legal/topics/meldplicht · 2026-08-22
