Articles

How to Handle a GDPR Data Breach: A 72-Hour Response Checklist

GDPR data breach 72-hour response timeline and notification checklist

A GDPR data breach can turn into a compliance problem very quickly if nobody is clear on who is doing what. The first priority is to contain the incident and establish the facts. At the same time, the privacy team needs to assess the risk, document the decisions and work out whether the supervisory authority and affected individuals must be notified.

Under Article 33 of the GDPR, a controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to people’s rights and freedoms. The 72 hours is a maximum window, not a target.

This guide gives in-house DPOs, privacy managers and compliance teams a practical GDPR data breach checklist from first alert through post-incident follow-up.

Article 33 GDPR

The 72-hour rule, in one line

Notify without undue delay, and where feasible within 72 hours

A controller must notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to people’s rights and freedoms. The 72 hours is a maximum window, not a target.

A 2026 note on pending reform. The European Commission’s Digital Omnibus proposal (published November 2025) would raise the reporting threshold to high risk and extend the deadline from 72 to 96 hours. This GDPR track has not been adopted and is not expected before late 2026 at the earliest, so the 72-hour rule and the current risk threshold remain binding today.

Quick Answer: What Should You Do After a GDPR Data Breach?

When a possible personal data breach is reported, your response should run on two tracks at the same time: contain the incident and assess the GDPR consequences.

  • Confirm whether personal data is affected.
  • Contain the incident and preserve evidence.
  • Record when the organisation became aware of the breach.
  • Identify the data, people, systems, processing activities and vendors involved.
  • Assess the likely risk to individuals.
  • If notification is required, notify the competent supervisory authority without undue delay and, where feasible, within 72 hours.
  • If the breach is likely to result in a high risk to individuals, communicate it to them without undue delay unless an Article 34 exemption applies.
  • Document the breach, decisions and remedial actions even if no notification is made.

The hour-by-hour checklist below is a practical workflow, not a set of legal sub-deadlines. If you already have enough information to conclude that a breach is notifiable, do not wait for a later stage in the checklist to notify.

What Counts as a GDPR Personal Data Breach?

A personal data breach is more than a hacked database. Under the GDPR, it is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

In practice, breaches are often described as involving one or more of three effects:

  • Confidentiality: personal data is disclosed to or accessed by someone who should not have it.
  • Integrity: personal data is altered without authorisation or by accident.
  • Availability: personal data is destroyed, lost or becomes unavailable when it should be accessible.

A ransomware incident, misdirected email, stolen laptop, incorrectly configured cloud folder, lost paper file or accidental deletion can all be personal data breaches depending on the circumstances.

Does every GDPR data breach have to be reported?

No. The threshold for notifying the supervisory authority is whether the breach is likely to result in a risk to the rights and freedoms of individuals. If a risk is unlikely, Article 33 does not require supervisory-authority notification. You still need to document the breach and the reasoning behind that decision.

Risk cannot be decided by data category alone. Sensitive or financial data will often increase the potential impact, but factors such as the number of people affected, identifiability, encryption, the recipient, the likelihood of misuse and the consequences for individuals all matter.

When Does the GDPR 72-Hour Clock Start?

The clock starts when the controller becomes aware of the personal data breach. European Data Protection Board guidance describes awareness as the point at which the controller has a reasonable degree of certainty that a security incident has occurred and has led to personal data being compromised.

This matters because “we were still investigating” is not automatically a reason to postpone notification. Article 33 allows information to be provided in phases when it is not possible to provide everything at the same time.

If notification is made after 72 hours, the controller must give reasons for the delay.

What if a processor discovers the breach?

A processor must notify the controller without undue delay after becoming aware of a personal data breach. The processor should not wait until it has completed a full investigation before telling the controller.

For controllers, this is one reason breach clauses in Data Processing Agreements matter. Contracts should make the escalation route, contact people and expected information clear enough that the controller can still meet its own Article 33 obligations.

A workflow, not legal sub-deadlines

The 72-hour response, phase by phase

The hour markers are a practical sequence. They are not separate legal deadlines. If a breach is clearly notifiable on day one, notify then.

1
Hours 0 to 4

Contain, escalate and open the record

  1. Confirm that personal data may be involved
  2. Contain the incident and preserve logs and evidence
  3. Escalate to the privacy lead and assign a named incident owner
  4. Open a GDPR breach record immediately, per Article 33(5)
  5. Identify processors and other third parties involved
2
Hours 4 to 24

Establish the facts and assess risk

  1. Identify the data and people affected
  2. Assess the likely consequences for individuals
  3. Link the incident to your RoPA and systems
  4. Review relevant Data Processing Agreements
  5. Make and document the Article 33 decision
3
Hours 24 to 48

Submit or supplement the authority notification

  1. Prepare the Article 33 notification
  2. Notify the competent supervisory authority
  3. Record exactly what was submitted, with timestamp and reference
4
Hours 24 to 72

Assess whether individuals must be informed

  1. Assess whether the breach is likely to result in a high risk
  2. Prepare clear communication to affected people if required
  3. Check the Article 34 exemptions and document any reliance
5
By 72 hours

Make sure the record matches reality

  1. Confirm the Article 33 decision is documented and any notification made
  2. Follow up open facts and complete the Article 34 assessment
  3. If a required notification cannot be made in time, notify as soon as possible with reasons for the delay

After 72 Hours: Complete the Investigation and Prevent a Repeat

The GDPR response does not end when a notification is filed.

Supplement incomplete notifications. If information was provided in phases, send further information without undue further delay as it becomes available.

Complete the Article 33(5) breach record. Record the final facts, effects, risk assessment, decisions, notifications and remedial actions.

Complete the root-cause analysis. Identify why the incident happened and what technical, organisational, contractual or process changes are needed. Root-cause analysis is a practical incident-management step rather than a separate Article 33 notification requirement.

Update connected compliance records. If the breach exposed an incomplete RoPA, missing vendor, weak DPA, outdated retention rule or risk-assessment gap, fix the underlying record rather than treating the breach as an isolated event.

Track remediation to completion. Assign owners and deadlines for corrective actions and retain evidence that they were completed.

Common GDPR Data Breach Mistakes

Waiting for the investigation to be finished before notifying

You do not need every fact before a required notification is made. GDPR expressly allows information to be provided in phases when it cannot all be provided at the same time.

Treating 72 hours as the target

The rule is “without undue delay and, where feasible, not later than 72 hours.” If you know on day one that notification is required, waiting until hour 71 creates unnecessary risk.

Assuming sensitive data automatically determines the answer

Special-category, financial or credential data can significantly increase risk, but the assessment still needs to consider the actual circumstances, protections and likely consequences.

Failing to document non-notifiable breaches

A “no notification” decision is still a decision that should be supported by a contemporaneous record. Article 33(5) applies to personal data breaches whether or not they are reported to the authority.

Letting a processor’s investigation control your timeline

Processors need to notify controllers without undue delay. Controllers should obtain the information they need, but their own breach process should not stop while waiting for a vendor’s final root-cause report.

Work through it

72-hour breach response checklist

Tick each item as you complete it. Progress is tracked as you go, and saved in your browser so you can return to it during an incident.

Breach response checklist

0 of 21 complete
Questions we hear

Frequently asked questions

What is the GDPR 72-hour data breach rule?+
Under Article 33, a controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.
When does the 72-hour period start?+
It starts when the controller becomes aware of the breach. EDPB guidance describes awareness as having a reasonable degree of certainty that a security incident has occurred and compromised personal data.
Do all GDPR data breaches have to be reported?+
No. Supervisory-authority notification is not required where the breach is unlikely to result in a risk to individuals' rights and freedoms. The controller must still document the breach under Article 33(5).
What information must a breach notification contain?+
As far as possible, it must describe the nature of the breach, the categories and approximate numbers of affected data subjects and records, the DPO or contact point, the likely consequences, and the measures taken or proposed to address the breach and mitigate adverse effects.
Can a breach notification be updated later?+
Yes. Where information cannot be provided at the same time, Article 33 allows it to be provided in phases without undue further delay.
When must affected individuals be told about a breach?+
Under Article 34, affected individuals must be informed without undue delay where the breach is likely to result in a high risk to their rights and freedoms, unless one of the Article 34 exemptions applies.
What happens if the 72-hour deadline is missed?+
If notification is required but not made within 72 hours, the notification must include reasons for the delay. The organisation should still notify as soon as possible rather than treating a missed deadline as a reason not to report.
Does a processor have its own 72-hour deadline?+
Article 33(2) does not give processors a separate 72-hour window. A processor must notify the controller without undue delay after becoming aware of a personal data breach.
Do I need a record if I decide not to report the breach?+
Yes. Article 33(5) requires controllers to document personal data breaches, including the facts, effects and remedial action taken. The record should also support the risk assessment and the decision not to notify.
Primary sources

Official sources

  1. European Parliament and Council, Regulation (EU) 2016/679 (GDPR), Articles 33 and 34
  2. European Data Protection Board, Guidelines 9/2022 on personal data breach notification under GDPR
  3. European Data Protection Board, Personal data breaches, what to do

This article provides general information and is not legal advice. Breach obligations depend on the facts, the data, the parties, the risk to individuals and the competent supervisory authority.

Do not design the process while the clock is running

GDPR Register keeps the breach workflow and its evidence in one place, connected to your RoPA, vendors, DPAs and privacy assessments rather than scattered across email and spreadsheets.

See breach management
Tags:
case study
data privacy framework
gdpr
gutenberg
interesting
international transfers
scc
schrems ii
EU AI Act compliance checklist and application timeline for DPOs
PREVIOUS
EU AI Act Compliance Checklist for DPOs in 2026