Skip to main content
Back to knowledge base
Procedure

Data breach notification: procedure and deadlines

A data breach is a security incident leading to unauthorised access to, loss or destruction of personal data. The GDPR requires organisations to report breaches within strict deadlines. This article explains the procedure step by step.

28 March 20268 min read

What is a data breach?

The GDPR defines a personal data breach as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

Examples of data breaches:

  • A laptop containing customer data is stolen
  • An employee sends an email with personal data to the wrong recipient
  • A ransomware attack encrypts files containing personal data
  • A database with customer data is accessible via the internet without protection
  • A USB drive with employee data is lost

Step 1: Contain the damage

Once you discover a breach, the first step is to contain the damage. Block unauthorised access, change passwords, isolate affected systems and assemble an incident team.

Step 2: Assess the risk

Assess the risk to data subjects by considering:

  • Nature of the data: is it sensitive data (national ID, health, financial)?
  • Number of data subjects: how many people are affected?
  • Severity of the breach: is the data accessible to malicious actors?
  • Consequences: what harm could data subjects suffer (identity fraud, discrimination, financial loss)?

Step 3: Notify the supervisory authority (Art. 33)

You are required to notify the supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to data subjects' rights and freedoms.

The notification must include at minimum:

  • The nature of the breach, number of data subjects and categories of personal data
  • Name and contact details of the DPO (or other contact point)
  • The likely consequences of the breach
  • The measures taken to address the breach and mitigate its effects

If you do not have all information within 72 hours, you may submit a preliminary notification and supplement it later.

Step 4: Notify data subjects (Art. 34)

You must notify data subjects when the breach is likely to result in a high risk to their rights and freedoms. Notification is not required if:

  • The data was encrypted (and the key was not compromised)
  • You have taken measures that ensure the high risk can no longer materialise
  • It would require disproportionate effort (in that case: public communication)

Step 5: Register the incident

Art. 33(5) GDPR requires you to document all data breaches, including the facts, effects and measures taken. This applies even to breaches you did not report to the authority.

Common mistakes

  • Missing the 72-hour deadline — start assessing immediately upon discovery
  • Not maintaining an internal register — all breaches must be documented
  • Not informing data subjects — mandatory for high-risk breaches
  • Forgetting the processor must also report — your processor must notify you without undue delay

Practical tips

  • Establish a breach procedure and ensure all staff know what to do when an incident occurs
  • Practise the procedure annually with a tabletop exercise
  • Ensure DPAs contain a notification obligation for the processor
  • Use DPAkit to register breaches, document risk assessments and track the 72-hour deadline

Register data breaches with DPAkit

DPAkit includes a breach register where you can log incidents, assess them and track notification deadlines.

Start for free