Glossary | GDPR & Data Privacy

Data Breach Notification

What is Data Breach Notification?

Data breach notification is the obligation under Regulation (EU) 2016/679 (GDPR) to report a personal data breach to the relevant supervisory authority, and in certain cases to the affected individuals, within prescribed timeframes. A personal data breach is any security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

Why It Matters

A personal data breach can occur in any organisation — through a cyberattack, accidental disclosure, lost device, or internal error. How an organisation responds in the immediate aftermath is critical. The GDPR places strict obligations on controllers to notify breaches promptly, and failure to do so can significantly increase the severity of any regulatory response.

The 72-hour notification window is one of the most demanding timelines in the GDPR. Organisations that do not have clear internal processes for detecting, assessing, and escalating breaches are at serious risk of missing this deadline and compounding the original incident with a procedural breach.

For businesses of all sizes, having a documented and tested data breach response process is an essential part of GDPR compliance.

What is Data Breach Notification?

Key Requirements

When Must a Breach Be Notified?

Data breach notification obligations are triggered as follows:

  • Notification to the supervisory authority is required where a breach is likely to result in a risk to the rights and freedoms of individuals. This must be made without undue delay and within 72 hours of becoming aware of the breach.
  • Notification to affected individuals is required where the breach is likely to result in a high risk to their rights and freedoms. This must be made without undue delay.

This requirement applies under:

Where notification to the supervisory authority is not made within 72 hours, the controller must provide a reasoned justification for the delay alongside the notification.

Responsibilities Relating to Data Breach Notification

Data Controllers and Processors each carry distinct obligations, which commonly include:

  • Controllers – Notifying the supervisory authority within 72 hours, notifying affected individuals where a high risk exists, and documenting all breaches regardless of whether notification is required.
  • Processors – Notifying the Data Controller without undue delay upon becoming aware of a personal data breach, to enable the controller to meet their own notification obligations.
  • All organisations – Maintaining an internal breach register documenting the facts, effects, and remedial actions taken in relation to every breach.

What a Breach Notification Must Include

A notification to the supervisory authority must, where possible, include a description of the nature of the breach, including the categories and approximate number of individuals and personal data records affected, the name and contact details of the Data Protection Officer (DPO) or other relevant contact point, the likely consequences of the breach, and the measures taken or proposed to address and mitigate its effects.

Frequently Asked Questions

No. Notification is required only where the breach is likely to result in a risk to the rights and freedoms of individuals. However, all breaches — including those that do not meet the notification threshold — must be documented internally.

The GDPR allows for notification to be made in phases where all information is not yet available. An initial notification should be submitted within 72 hours with the information available at that time, followed by further details as they become known.

A processor must notify the controller without undue delay upon becoming aware of a breach. The controller then determines whether the breach meets the threshold for notification to the supervisory authority and affected individuals, and is responsible for making those notifications.

gdpr logo

Need GDPR Representative Services?

Euverify provides EU Representative services for organisations outside the European Union that are subject to the GDPR. Our team supports regulatory communication, documentation, and ongoing compliance management.