Skip to main content
Praxikon

Article 33: Notification of a personal data breach to the supervisory authority

Praxikon tracks Article 33 (Notification of a personal data breach to the supervisory authority) under the GDPR, alongside the EU AI Act, citing the source for every statement.

Chapter IVIn force since 25-05-2018

What does Article 33 govern?

Article 33 sets out what a controller must do in the case of a personal data breach, in plain terms a data leak: data have for example been stolen, sent to the wrong person by mistake or become inaccessible. The controller notifies such a breach to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of people (paragraph 1). A processor that discovers a breach notifies the controller without undue delay (paragraph 2). The notification has a fixed content (paragraph 3), may be completed in phases (paragraph 4), and every breach must be documented internally, even when no notification is needed (paragraph 5). Recital 85 explains why: a breach that is not addressed quickly can lead to identity fraud, financial loss, damage to reputation or loss of control over one's own data; if the breach is likely to result in a high risk, you must also inform the data subject directly under Article 34.

Key term: Breach notification duty: a personal data breach must, where feasible, be notified to the supervisory authority within 72 hours of becoming aware of it, unless a risk to data subjects is unlikely (paragraph 1)

Directly affects:controllerprocessordata protection officersupervisory authority

Praxikon’s reading of the text and the recitals; the official text below prevails.

Official text

/
In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
The notification referred to in paragraph 1 shall at least: (a) describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned; (b) communicate the name and contact details of the data protection officer or other contact point where more information can be obtained; (c) describe the likely consequences of the personal data breach; (d) describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.

Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.

What does this mean for you?

Controller

Set up a procedure that lets you recognise a breach quickly, assess the risk to data subjects and, where a risk is not unlikely, notify the supervisory authority without undue delay and where feasible within 72 hours of becoming aware (paragraph 1). Make sure the notification contains the elements of paragraph 3 and complete it in phases if not everything is known yet (paragraph 4). Document every breach with the facts, its effects and the remedial action taken, even when you do not notify (paragraph 5).

Processor

Notify the controller without undue delay as soon as you discover a breach (paragraph 2). You do not notify the supervisory authority yourself; the controller does that (paragraph 1). Article 28(3)(f) also requires you to assist the controller with this notification duty.

Data Protection Officer

Your name and contact details go into the notification as the contact point where the supervisory authority can obtain more information (paragraph 3(b)). Make sure you are reachable and know the content of the notification.

Compliance checklist

Related recitals

Cross-references

Frequently asked questions

Connections

What connects to Article 33 GDPR

Themes where this returns

The counterpart in the other law

Case law

Guidelines

Legislation in motion