Article 33: Notification of a personal data breach to the supervisory authority
Praxikon tracks Article 33 (Notification of a personal data breach to the supervisory authority) under the GDPR, alongside the EU AI Act, citing the source for every statement.
What does Article 33 govern?
Article 33 sets out what a controller must do in the case of a personal data breach, in plain terms a data leak: data have for example been stolen, sent to the wrong person by mistake or become inaccessible. The controller notifies such a breach to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of people (paragraph 1). A processor that discovers a breach notifies the controller without undue delay (paragraph 2). The notification has a fixed content (paragraph 3), may be completed in phases (paragraph 4), and every breach must be documented internally, even when no notification is needed (paragraph 5). Recital 85 explains why: a breach that is not addressed quickly can lead to identity fraud, financial loss, damage to reputation or loss of control over one's own data; if the breach is likely to result in a high risk, you must also inform the data subject directly under Article 34.
Key term: Breach notification duty: a personal data breach must, where feasible, be notified to the supervisory authority within 72 hours of becoming aware of it, unless a risk to data subjects is unlikely (paragraph 1)
Directly affects:controllerprocessordata protection officersupervisory authority
Praxikon’s reading of the text and the recitals; the official text below prevails.
Official text
Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.
What does this mean for you?
Controller
Set up a procedure that lets you recognise a breach quickly, assess the risk to data subjects and, where a risk is not unlikely, notify the supervisory authority without undue delay and where feasible within 72 hours of becoming aware (paragraph 1). Make sure the notification contains the elements of paragraph 3 and complete it in phases if not everything is known yet (paragraph 4). Document every breach with the facts, its effects and the remedial action taken, even when you do not notify (paragraph 5).
Processor
Notify the controller without undue delay as soon as you discover a breach (paragraph 2). You do not notify the supervisory authority yourself; the controller does that (paragraph 1). Article 28(3)(f) also requires you to assist the controller with this notification duty.
Data Protection Officer
Your name and contact details go into the notification as the contact point where the supervisory authority can obtain more information (paragraph 3(b)). Make sure you are reachable and know the content of the notification.
Compliance checklist
Related recitals
A personal data breach may, if not addressed in an appropriate and timely manner, result in physical, material or non-material damage to natural persons such as loss of control over their personal dat...
(86)The controller should communicate to the data subject a personal data breach, without undue delay, where that personal data breach is likely to result in a high risk to the rights and freedoms of the ...
(87)It should be ascertained whether all appropriate technological protection and organisational measures have been implemented to establish immediately whether a personal data breach has taken place and ...
(88)In setting detailed rules concerning the format and procedures applicable to the notification of personal data breaches, due consideration should be given to the circumstances of that breach, includin...
(89)Directive 95/46/EC provided for a general obligation to notify the processing of personal data to the supervisory authorities. While that obligation produces administrative and financial burdens, it d...
Cross-references
Frequently asked questions
Connections
What connects to Article 33 GDPR
Themes where this returns
The counterpart in the other law
Case law
- Interim judge suspends DPA penalty order against Northwave: exhaust powers against the hosting provider first
2024-03-26 · final, Rechtbank Midden-Nederland, voorzieningenrechter (zittingsplaats Utrecht)
Guidelines
- EDPB Template for personal data breach notification
2026-06-10 · adopted, European Data Protection Board (EDPB)
- Guidelines 01/2021 on Examples regarding Personal Data Breach Notification
2021-12-14 · final, European Data Protection Board (EDPB)
- Guidelines 9/2022 on personal data breach notification under GDPR
2023-03-28 · final, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- EDPB and EDPS adopt Joint Opinion 2/2026 on the Digital Omnibus
2026-02-10 · final, European Data Protection Board en European Data Protection Supervisor
Legislation in motion
- Proposal: breach notification only for high risk, within 96 hours, via a single entry point (Article 33 GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
2026-06-22 · under negotiation, Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper
- Commission publishes Digital Omnibus proposal COM(2025) 837
2025-11-19 · proposal, Europese Commissie