GDPR Breach Reporting Rules Explained
When a data breach occurs, GDPR mandates a strict 72-hour deadline for notifying regulators and a high-risk threshold for informing affected individuals.
By Priya Nair · Published · 11 min read

Under the EU's General Data Protection Regulation (GDPR), organizations must report certain types of personal data breaches to the relevant supervisory authority within 72 hours of becoming aware of them. If the breach is likely to result in a high risk to the rights and freedoms of individuals, they must also inform those affected people without undue delay.
What Constitutes a "Personal Data Breach" Under GDPR?
Before diving into reporting timelines, it's crucial to understand what GDPR considers a "personal data breach." It’s broader than just a malicious hack. Article 4(12) defines it as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
This definition covers three distinct types of incidents:
- Confidentiality Breach: Unauthorized or accidental disclosure of, or access to, personal data. This is the classic hack or data leak scenario, like when a database of customer information is stolen and published. It also includes an employee accidentally emailing a sensitive spreadsheet to the wrong recipient.
- Integrity Breach: Unauthorized or accidental alteration of personal data. For example, a threat actor gaining access to a medical database and changing patient blood types, or a software bug corrupting customer contact details.
- Availability Breach: Accidental or unauthorized loss of access to, or destruction of, personal data. A ransomware attack that encrypts critical files, making them inaccessible, is a perfect example. So is the accidental deletion of a production database without a viable backup.
Many incidents, like ransomware attacks, are breaches of all three types simultaneously: data is accessed (confidentiality), encrypted (integrity), and made inaccessible (availability). Understanding how data breaches happen: the common entry points is the first step for any organization looking to prevent them.
The 72-Hour Countdown: Reporting to a Supervisory Authority
The most famous—and feared—element of GDPR's breach rules is the 72-hour notification deadline. As soon as a data controller becomes aware of a personal data breach, a clock starts ticking. Within 72 hours, they must notify their competent data protection authority, also known as a Supervisory Authority (SA).
"Awareness" doesn't mean having a complete, forensic-level report of the incident. The European Data Protection Board (EDPB) clarifies that awareness is achieved when the controller has a reasonable degree of certainty that a security incident has occurred and has compromised personal data. At this point, the 72-hour obligation begins, even if the full extent of the breach is not yet known.
This is a strict deadline that includes weekends and holidays. If the notification is made after 72 hours, the controller must provide a reasoned justification for the delay.
Organizations don't need to report every single incident. The obligation is triggered if the breach is likely to result in a risk to the rights and freedoms of natural persons. This is a relatively low threshold. An accidental email to the wrong person containing a single customer's name and order number might meet this bar. The only exceptions are for breaches that are *unlikely* to result in any risk—for example, if the lost data was robustly encrypted and the key was not compromised.
If all details aren't available within the 72-hour window, organizations can provide information in phases. An initial notification can be followed by more detailed reports as the investigation progresses.
When Must Individuals Be Notified?
While reporting to a Supervisory Authority is common, notifying the individuals affected by the breach is subject to a higher threshold. According to Article 34, controllers must communicate the breach to the data subjects without undue delay only when it is likely to result in a high risk to their rights and freedoms.
This "high risk" assessment is a critical judgment call. Factors to consider include:
- Type of data: Breaches involving sensitive data (e.g., health information, political opinions, biometric data), financial details (credit cards, bank accounts), or credentials (passwords, secret questions) are almost always considered high risk.
- Volume of data: The more data compromised about an individual, the higher the potential risk.
- Nature of the breach: A ransomware attack on a hospital carries a higher risk than an internal mix-up of mailing addresses for a low-value marketing campaign.
- Consequences for individuals: The potential for identity theft, financial loss, fraud, reputational damage, or physical harm are all key considerations. If a breach exposes information that could lead to discrimination or social disadvantage, the risk is high.
There is no requirement to notify individuals if effective technical and organizational protection measures were in place (e.g., the data was encrypted) or if subsequent measures have been taken to ensure the high risk is no longer likely to materialize. If you receive a notification, it's important to understand what to do after your data is exposed in a breach to protect yourself.
What Information Must Be in a Breach Notification?
GDPR is prescriptive about the content of a breach notification. Whether reporting to the SA or to individuals, clarity and transparency are key. The goal is to provide enough information for the authorities to assess the situation and for individuals to take protective measures.
Notification to the Supervisory Authority (Article 33)
A notification to the SA must, at a minimum, include:
- Nature of the Breach: Describe the incident, including the approximate number of data subjects affected and the categories and approximate number of personal data records concerned.
- Contact Information: The name and contact details of the Data Protection Officer (DPO) or other contact point where more information can be obtained.
- Likely Consequences: A description of the likely consequences of the personal data breach.
- Measures Taken: A description of the measures taken or proposed to be taken by the controller to address the breach, including, where appropriate, measures to mitigate its possible adverse effects.
Communication to Data Subjects (Article 34)
When the high-risk threshold is met, the communication to individuals must be in clear and plain language and should contain:
- The nature of the personal data breach.
- The name and contact details of the DPO or other contact point.
- A description of the likely consequences.
- A description of the measures taken or proposed by the controller, including mitigation measures.
- Specific advice on what individuals can do to protect themselves, such as changing passwords or monitoring their bank accounts.
Consequences of Non-Compliance: Fines and Penalties
Failure to comply with GDPR's breach reporting obligations can lead to severe financial penalties. Regulators have the power to issue fines of up to €10 million, or 2% of the company’s total worldwide annual turnover of the preceding financial year, whichever is higher, just for reporting failures.
If the breach itself also resulted from a violation of core GDPR principles (like data protection by design), the fines can reach the upper tier: up to €20 million or 4% of global turnover. Data protection authorities across Europe have demonstrated their willingness to use these powers. Fines for various GDPR violations, like the one Spain levied against Amadeus for passenger profiling, underscore the financial risks of non-compliance. These penalties are designed not only to punish but also to serve as a powerful deterrent, forcing organizations to take their data protection duties seriously.
Beyond fines, non-compliance can lead to reputational damage, loss of customer trust, and civil litigation from affected individuals who may be entitled to compensation. The individual's ability to seek redress is one of the cornerstones of the regulation, reinforcing why understanding your GDPR rights and how to use them is so important for European residents.
Documenting Everything: The Internal Breach Register
One often-overlooked requirement is found in Article 33(5). It states that all data controllers must document every personal data breach, regardless of whether it required notification to the SA or individuals. This internal register must include the facts relating to the breach, its effects, and the remedial action taken.
This log serves as evidence of compliance. During an audit or investigation, a Supervisory Authority will almost certainly ask to see this register. It allows them to verify that the controller has a process in place for handling incidents and has made reasoned decisions about which breaches to report. A well-maintained register demonstrates accountability and good governance. Failure to maintain one is a breach of GDPR in its own right.
Building Your Breach Response Plan
Compliance with GDPR's breach notification rules isn't something you can figure out after an incident happens. The 72-hour window is too short for improvisation. Proactive preparation is essential.
Here are practical steps every organization handling EU residents' data should take:
- Create and Rehearse an Incident Response Plan: This plan should clearly define roles, responsibilities, and the step-by-step process for responding to a potential breach. It must include the procedure for assessing risk and making the decision to notify.
- Identify Your Lead Supervisory Authority: If your organization operates in multiple EU countries, determine your lead SA based on where your main establishment is located. Know who you need to contact and how.
- Train Your Staff: The 72-hour clock starts when the *organization* is aware, not just the security team. Every employee should be trained to recognize a potential data breach and know how to report it internally immediately.
- Appoint a Data Protection Officer (DPO): If required by Article 37, appoint a DPO. If not required, designate a person or team responsible for privacy compliance and managing breach response.
- Keep a Documentation Toolkit: Have templates ready for the internal breach register entry, the notification to the SA, and the communication to data subjects. This saves critical time during a crisis.
By embedding these rules and processes into the fabric of your security operations, you can move from a state of reactive panic to one of prepared, efficient, and compliant response.



