Dr. Sophie Laurent
Head of Data Protection
Under Article 4(12), a personal data breach is any security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. This covers confidentiality breaches (data exposed), integrity breaches (data altered), and availability breaches (data lost or inaccessible).
⚠The 72-hour clock starts the moment you become "aware" of the breach — not when the incident began. Delaying awareness through poor monitoring does not stop the clock and is itself an Article 32 failure.
Article 33 requires controllers to notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach. If notification takes longer, you must explain the delay. Processors must notify controllers "without undue delay" after becoming aware.
When a breach is likely to result in a high risk to the rights and freedoms of individuals, you must also communicate the breach to affected data subjects without undue delay. The communication must be clear, plain language and describe the nature of the breach and the steps they can take.
You are exempt from this communication duty if: the data was rendered unintelligible (e.g., strong encryption), you took subsequent measures ensuring the high risk is no longer likely, or communication would involve disproportionate effort (in which case a public communication is required).
“Failure to notify a breach can result in fines up to €10 million or 2% of annual global turnover under Article 83(4).”
Meeting the deadline requires a pre-built, rehearsed incident response plan. The biggest enemy of the 72-hour rule is decision latency — time spent deciding whether something is "really" a breach while the clock runs.
0h Detection (monitoring alert / report)
0-4h Triage & confirm breach (is personal data involved?)
4-12h Scope assessment (records, categories, risk)
12-24h Draft notification + legal review
24-48h Authority notification submitted
48-72h Affected-data-subject communication if high risk
72h+ Post-incident review & documentationRegardless of whether a breach is notifiable, Article 33(5) requires you to document every personal data breach — including the facts, effects, and remedial action. This internal breach register is the evidence regulators request during an audit. Our incident response tooling maintains this register automatically and pre-fills notification templates. Contact us to review your breach response readiness.
Article 32 requires appropriate technical and organizational measures to ensure data security. We break down exactly wha...
Cumulative EU regulatory fines have surpassed €6.8 billion. We analyze enforcement trends, fine structures, and what thi...