{"answer_id":"praxikon:eu:gdpr:answer:datalek","canonical_page":"https://www.praxikon.com/en/antwoord/avg/datalek","query":"When must a personal data breach be notified to the supervisory authority and to data subjects?","lang":"en","view":"full","mode":"gdpr","regime":"gdpr","topic":"datalek","question":"When must a personal data breach be notified to the supervisory authority and to data subjects?","label":"Notifying a personal data breach","answer":"Notify the supervisory authority, in the Netherlands the Autoriteit Persoonsgegevens: without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Article 33(1)). Every breach is documented internally, also when it does not have to be notified (Article 33(5)). The data subjects themselves are only informed if the breach is likely to result in a high risk to them (Article 34(1)). Even then that obligation lapses if, for example, the data were encrypted, if the high risk has been removed by subsequent measures, or if informing each person individually would involve disproportionate effort; in that last case a public communication follows (Article 34(3)).","applied_to_question":null,"matched_terms":[],"articles":[{"article":33,"source_locator":"Art. 33(1) GDPR","point":"Notification within 72 hours, unless no risk is likely.","source_title":"GDPR (Regulation (EU) 2016/679)","source_url":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","human_page":"https://www.praxikon.com/en/avg/artikel/33"},{"article":33,"source_locator":"Art. 33(5) GDPR","point":"Document every breach internally.","source_title":"GDPR (Regulation (EU) 2016/679)","source_url":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","human_page":"https://www.praxikon.com/en/avg/artikel/33"},{"article":34,"source_locator":"Art. 34(1) GDPR","point":"Inform data subjects where a high risk is likely.","source_title":"GDPR (Regulation (EU) 2016/679)","source_url":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","human_page":"https://www.praxikon.com/en/avg/artikel/34"},{"article":34,"source_locator":"Art. 34(3)(a) to (c) GDPR","point":"Exceptions: encryption, subsequent measures, disproportionate effort.","source_title":"GDPR (Regulation (EU) 2016/679)","source_url":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","human_page":"https://www.praxikon.com/en/avg/artikel/34"}],"case_law":[],"guidance":[{"id":"edpb-gl-9-2022","kind":"guidance","title":"Guidelines 9/2022 on personal data breach notification under GDPR","issuer":"EDPB","reference":"v2.0","ecli":null,"date":"2023-03-28","status":"final","point":"Guidelines on personal data breach notification.","source_url":"https://www.edpb.europa.eu/documents/guideline/guidelines-92022-on-personal-data-breach-notification-under-gdpr_en","human_page":null},{"id":"edpb-gl-01-2021","kind":"guidance","title":"Guidelines 01/2021 on Examples regarding Personal Data Breach Notification","issuer":"EDPB","reference":"v2.0","ecli":null,"date":"2021-12-14","status":"final","point":"Examples of personal data breaches and how to handle them.","source_url":"https://www.edpb.europa.eu/documents/guideline/guidelines-012021-on-examples-regarding-personal-data-breach-notification_en","human_page":null}],"enforcement":[],"open_questions":["Which data were breached, of how many people, and were they encrypted?"],"human_page":"https://www.praxikon.com/en/avg/artikel/33","dataset":{"id":"praxikon-gdpr","source":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","known_at":"2026-09-15"},"casus_check":"https://www.praxikon.com/en/casus-check","disclaimer":"General interpretation, not legal advice. The official source remains authoritative.","methodology":"https://www.praxikon.com/en/methodologie"}