Notified Body Reporting and Notification Obligations
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.The content addresses specific reporting and notification obligations of notified bodies to authorities and other stakeholders, which is a distinct operational requirement deserving separate coverage.
Overview
19 sources · Jul 23, 2026Legal Framework
Article 19 GDPR establishes a downstream notification obligation: when a controller rectifies, erases, or restricts processing of personal data under Articles 16, 17(1), or 18, it must communicate that change to every recipient to whom the data were previously disclosed. This obligation is subject to a proportionality carve-out — the controller need not comply where notification proves impossible or involves disproportionate effort — but must, upon request, inform the data subject of those recipients. Article 51 GDPR complements this by requiring each Member State to designate one or more independent supervisory authorities responsible for monitoring GDPR application. The doctrinal commentary confirms that the Netherlands has designated the Autoriteit Persoonsgegevens as its sole supervisory authority, declining the GDPR's option to establish additional sector-specific authorities.
Beyond GDPR, NIS2 Recital 116 introduces representative and reporting obligations for non-EU service providers offering services within the Union — including cloud computing, data centre, managed service, and DNS providers — creating an overlapping notification regime for entities that may also process personal data. Recital 28 clarifies that the Digital Operational Resilience Act (DORA) governs ICT-related incident reporting for financial entities, displacing NIS2 provisions in that sector.
Key Developments
Enforcement practice demonstrates that supervisory authorities treat breach notification failures as standalone violations warranting independent fines. The Polish DPA (UODO) imposed a €9,450 fine on a Gynecological Center that suffered a data breach but failed to report it to the DPO — establishing that the notification obligation runs to the supervisory authority regardless of whether the underlying breach itself is contested. In a separate action, UODO fined a Housing Association €2,350 for insufficient fulfilment of data breach notification duties, indicating that partial or deficient notification — not merely total omission — triggers liability.
The EDPB's Guidelines 04/2022 on administrative fine calculation provide the methodology supervisory authorities apply when assessing these violations, ensuring harmonised treatment across Member States. The EDPB also issued version 2.0 of its Guidelines 9/2022 on personal data breach notification, refining the practical standards for what constitutes a notifiable breach.
Dutch case law reinforces that institutional obligations cannot be deflected through procedural limitations. The Council of State's 2006 ruling (ECLI:NL:RVS:2006:AY0333) confirmed that municipal authorities bear full responsibility for properly establishing identity under the GBA, and the Gerechtshof Den Haag's 2026 decision demonstrated that operational failures — including late filing of annual accounts — can constitute serious professional misconduct, signalling that systemic administrative failures carry consequences beyond their immediate context.
Practical Guidance
- Map all recipients before notification becomes necessary. Article 19 requires communication to each recipient of disclosed data. Controllers who cannot identify recipients ex ante will struggle to meet the proportionality threshold and should maintain disclosure logs as a matter of course.
- Establish a dual-track breach notification procedure. Notifications must reach both the supervisory authority (Article 33) and, where applicable, affected data subjects (Article 34). The Polish enforcement actions confirm that failure on either track constitutes an independent violation.
- Assess NIS2 overlap for cross-regime entities. Cloud providers, managed service providers, and data centre operators offering services in the Union must evaluate whether NIS2 incident reporting obligations run parallel to GDPR breach notification — and designate an EU representative where not established in the Union.
- Document the proportionality analysis for Article 19. When deciding that downstream notification involves disproportionate effort, record the reasoning contemporaneously. The burden of justifying non-notification rests with the controller.
- Verify sector-specific displacement. Financial entities should confirm whether DORA's ICT incident reporting regime has fully displaced NIS2 obligations for their operations, as Recital 28 contemplates, to avoid duplicate reporting or gaps.