Back to Blog
gdpr9 min read·June 15, 2026

GDPR Breach Notification: The 72-Hour Rule Explained

DSL

Dr. Sophie Laurent

Head of Data Protection

/What Is a Personal Data Breach?

Under Article 4(12), a personal data breach is any security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. This covers confidentiality breaches (data exposed), integrity breaches (data altered), and availability breaches (data lost or inaccessible).

The 72-hour clock starts the moment you become "aware" of the breach — not when the incident began. Delaying awareness through poor monitoring does not stop the clock and is itself an Article 32 failure.

/Article 33: Notifying the Supervisory Authority

Article 33 requires controllers to notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach. If notification takes longer, you must explain the delay. Processors must notify controllers "without undue delay" after becoming aware.

  • The nature of the breach and, where possible, the categories and approximate number of data subjects and records concerned
  • The name and contact details of the Data Protection Officer or other contact point
  • The likely consequences of the breach
  • The measures taken or proposed to address the breach and mitigate its adverse effects

/Article 34: Communicating to Data Subjects

When a breach is likely to result in a high risk to the rights and freedoms of individuals, you must also communicate the breach to affected data subjects without undue delay. The communication must be clear, plain language and describe the nature of the breach and the steps they can take.

You are exempt from this communication duty if: the data was rendered unintelligible (e.g., strong encryption), you took subsequent measures ensuring the high risk is no longer likely, or communication would involve disproportionate effort (in which case a public communication is required).

Failure to notify a breach can result in fines up to €10 million or 2% of annual global turnover under Article 83(4).

/Building a 72-Hour Response Workflow

Meeting the deadline requires a pre-built, rehearsed incident response plan. The biggest enemy of the 72-hour rule is decision latency — time spent deciding whether something is "really" a breach while the clock runs.

text
0h   Detection (monitoring alert / report)
0-4h Triage & confirm breach (is personal data involved?)
4-12h Scope assessment (records, categories, risk)
12-24h Draft notification + legal review
24-48h Authority notification submitted
48-72h Affected-data-subject communication if high risk
72h+  Post-incident review & documentation

/Documentation Requirements

Regardless of whether a breach is notifiable, Article 33(5) requires you to document every personal data breach — including the facts, effects, and remedial action. This internal breach register is the evidence regulators request during an audit. Our incident response tooling maintains this register automatically and pre-fills notification templates. Contact us to review your breach response readiness.

GDPRArticle 33Article 34Breach NotificationIncident Response
GDPR Breach Notification: The 72-Hour Rule Explained | SecureAudit Pro Blog | SecureAudit Pro