Less Known Cambridge Analytica Partner Receives a GDPR Hit
After GDPR coming into force, it was assumed the big players – multinational companies were the first to receive sanctions. […]
A GDPR data breach can turn into a compliance problem very quickly if nobody is clear on who is doing what. The first priority is to contain the incident and establish the facts. At the same time, the privacy team needs to assess the risk, document the decisions and work out whether the supervisory authority and affected individuals must be notified.
Under Article 33 of the GDPR, a controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to people’s rights and freedoms. The 72 hours is a maximum window, not a target.
This guide gives in-house DPOs, privacy managers and compliance teams a practical GDPR data breach checklist from first alert through post-incident follow-up.
A controller must notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to people’s rights and freedoms. The 72 hours is a maximum window, not a target.
When a possible personal data breach is reported, your response should run on two tracks at the same time: contain the incident and assess the GDPR consequences.
The hour-by-hour checklist below is a practical workflow, not a set of legal sub-deadlines. If you already have enough information to conclude that a breach is notifiable, do not wait for a later stage in the checklist to notify.
A personal data breach is more than a hacked database. Under the GDPR, it is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
In practice, breaches are often described as involving one or more of three effects:
A ransomware incident, misdirected email, stolen laptop, incorrectly configured cloud folder, lost paper file or accidental deletion can all be personal data breaches depending on the circumstances.
No. The threshold for notifying the supervisory authority is whether the breach is likely to result in a risk to the rights and freedoms of individuals. If a risk is unlikely, Article 33 does not require supervisory-authority notification. You still need to document the breach and the reasoning behind that decision.
Risk cannot be decided by data category alone. Sensitive or financial data will often increase the potential impact, but factors such as the number of people affected, identifiability, encryption, the recipient, the likelihood of misuse and the consequences for individuals all matter.
The clock starts when the controller becomes aware of the personal data breach. European Data Protection Board guidance describes awareness as the point at which the controller has a reasonable degree of certainty that a security incident has occurred and has led to personal data being compromised.
This matters because “we were still investigating” is not automatically a reason to postpone notification. Article 33 allows information to be provided in phases when it is not possible to provide everything at the same time.
If notification is made after 72 hours, the controller must give reasons for the delay.
A processor must notify the controller without undue delay after becoming aware of a personal data breach. The processor should not wait until it has completed a full investigation before telling the controller.
For controllers, this is one reason breach clauses in Data Processing Agreements matter. Contracts should make the escalation route, contact people and expected information clear enough that the controller can still meet its own Article 33 obligations.
The hour markers are a practical sequence. They are not separate legal deadlines. If a breach is clearly notifiable on day one, notify then.
The GDPR response does not end when a notification is filed.
Supplement incomplete notifications. If information was provided in phases, send further information without undue further delay as it becomes available.
Complete the Article 33(5) breach record. Record the final facts, effects, risk assessment, decisions, notifications and remedial actions.
Complete the root-cause analysis. Identify why the incident happened and what technical, organisational, contractual or process changes are needed. Root-cause analysis is a practical incident-management step rather than a separate Article 33 notification requirement.
Update connected compliance records. If the breach exposed an incomplete RoPA, missing vendor, weak DPA, outdated retention rule or risk-assessment gap, fix the underlying record rather than treating the breach as an isolated event.
Track remediation to completion. Assign owners and deadlines for corrective actions and retain evidence that they were completed.
You do not need every fact before a required notification is made. GDPR expressly allows information to be provided in phases when it cannot all be provided at the same time.
The rule is “without undue delay and, where feasible, not later than 72 hours.” If you know on day one that notification is required, waiting until hour 71 creates unnecessary risk.
Special-category, financial or credential data can significantly increase risk, but the assessment still needs to consider the actual circumstances, protections and likely consequences.
A “no notification” decision is still a decision that should be supported by a contemporaneous record. Article 33(5) applies to personal data breaches whether or not they are reported to the authority.
Processors need to notify controllers without undue delay. Controllers should obtain the information they need, but their own breach process should not stop while waiting for a vendor’s final root-cause report.
Tick each item as you complete it. Progress is tracked as you go, and saved in your browser so you can return to it during an incident.
This article provides general information and is not legal advice. Breach obligations depend on the facts, the data, the parties, the risk to individuals and the competent supervisory authority.
GDPR Register keeps the breach workflow and its evidence in one place, connected to your RoPA, vendors, DPAs and privacy assessments rather than scattered across email and spreadsheets.