The obligation to notify personal data breaches requires controllers to report a data breach to the supervisory authority within 72 hours of becoming aware of it.
The 72-hour deadline
The deadline starts when the controller becomes aware of the breach, not when it has been fully investigated. Anyone who submits the notification late without giving reasons risks a separate fine in addition to the incident itself.
Notification is only unnecessary if the breach is unlikely to result in a risk to the rights and freedoms of the data subjects. If not all the information is available yet, it can be provided in phases.
Content of the notification
- nature of the breach, categories and approximate number of data subjects and records
- name and contact details of the data protection officer
- likely consequences
- measures taken or proposed
Communication to data subjects
Where there is likely to be a high risk, the data subjects must also be informed without undue delay. This may not be necessary if, for example, the data was effectively encrypted. Processors must notify the controller of breaches without undue delay.
Legal provisions
- Art. 33 GDPR
- Notification to the supervisory authority within 72 hours.
- Art. 34 GDPR
- Communication to the data subjects.
- Art. 83(4)(a) GDPR
- Range of fines for infringements of the notification obligation.