Skip to main content
Praxikon

Direct answer · GDPR

When must a personal data breach be notified to the supervisory authority and to data subjects?

Short answer

A personal data breach is notified to the supervisory authority without undue delay and, where feasible, within 72 hours, unless it is unlikely to result in a risk to the rights and freedoms of natural persons (Article 33(1)). Every breach is documented internally (Article 33(5)). Data subjects are only informed if the breach is likely to result in a high risk to them (Article 34(1)).

Direct answer · GDPR

Notifying a personal data breach

Notify the supervisory authority, in the Netherlands the Autoriteit Persoonsgegevens: without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Article 33(1)). Every breach is documented internally, also when it does not have to be notified (Article 33(5)). The data subjects themselves are only informed if the breach is likely to result in a high risk to them (Article 34(1)). Even then that obligation lapses if, for example, the data were encrypted, if the high risk has been removed by subsequent measures, or if informing each person individually would involve disproportionate effort; in that last case a public communication follows (Article 34(3)).

For you to establish

  • Which data were breached, of how many people, and were they encrypted?

Articles

Guidelines and decisions

Read the article Check your own case General interpretation, not legal advice. The official source remains authoritative.

Check your own situation

Describe your system or project in the free case check and get a reasoned first assessment of, among other things, the DPIA obligation, Article 22 GDPR and the AI Act, with the source for every conclusion.

Go to the free case check
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist