Data breach notification

Data protection glossary · 1 minute read

The obligation to notify personal data breaches requires controllers to report a data breach to the supervisory authority within 72 hours of becoming aware of it.

The 72-hour deadline

The deadline starts when the controller becomes aware of the breach, not when it has been fully investigated. Anyone who submits the notification late without giving reasons risks a separate fine in addition to the incident itself.

Notification is only unnecessary if the breach is unlikely to result in a risk to the rights and freedoms of the data subjects. If not all the information is available yet, it can be provided in phases.

Content of the notification

  • nature of the breach, categories and approximate number of data subjects and records
  • name and contact details of the data protection officer
  • likely consequences
  • measures taken or proposed

Communication to data subjects

Where there is likely to be a high risk, the data subjects must also be informed without undue delay. This may not be necessary if, for example, the data was effectively encrypted. Processors must notify the controller of breaches without undue delay.

Art. 33 GDPR
Notification to the supervisory authority within 72 hours.
Art. 34 GDPR
Communication to the data subjects.
Art. 83(4)(a) GDPR
Range of fines for infringements of the notification obligation.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.