Article 34: Communication of a personal data breach to the data subject
Praxikon tracks Article 34 (Communication of a personal data breach to the data subject) under the GDPR, alongside the EU AI Act, citing the source for every statement.
What does Article 34 govern?
Article 34 sets out when you must inform the people concerned directly about a personal data breach. You must do so without undue delay when the breach is likely to result in a high risk to their rights and freedoms (paragraph 1), a higher threshold than the notification to the supervisory authority under Article 33, where an ordinary risk is enough. The communication must describe in clear and plain language what happened and contain at least the contact point, the likely consequences and the measures taken from Article 33(3)(b), (c) and (d) (paragraph 2). Recital 86 explains why: data subjects must be able to take precautions themselves. There are three exceptions, such as encryption of the affected data (paragraph 3), and the supervisory authority may still require you to communicate or may decide that an exception applies (paragraph 4).
Key term: High risk: the threshold above which you must inform the data subject directly; for an ordinary risk the notification to the supervisory authority under Article 33 is sufficient (paragraph 1)
Directly affects:controllerdata subjectsupervisory authority
Praxikon’s reading of the text and the recitals; the official text below prevails.
Official text
Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.
What does this mean for you?
Controller
For every breach, assess whether a high risk to the data subjects is likely and, if so, inform them without undue delay, in clear and plain language, with the elements of Article 33(3)(b), (c) and (d) (paragraphs 1 and 2). Check whether one of the three exceptions in paragraph 3 applies and record that reasoning; where the effort would be disproportionate, use a public communication that reaches data subjects in an equally effective manner. Bear in mind that the supervisory authority can still require you to communicate (paragraph 4).
Processor
The article is addressed to the controller. Your role is limited to the assistance Article 28(3)(f) requires of you, such as quickly providing the facts the controller needs for the communication.
Data Protection Officer
Your contact details appear in the communication to data subjects, because paragraph 2 refers to Article 33(3)(b). Expect data subjects to put questions to you after the communication.
Data Subject
You hear it from the organisation itself when a data breach is likely to result in a high risk to you, in plain language and with the measures that have been taken (paragraphs 1 and 2, recital 86). If you hear nothing, that may mean the risk was low or that an exception in paragraph 3 applied; the supervisory authority can still require the organisation to communicate (paragraph 4).
Compliance checklist
Related recitals
A personal data breach may, if not addressed in an appropriate and timely manner, result in physical, material or non-material damage to natural persons such as loss of control over their personal dat...
(86)The controller should communicate to the data subject a personal data breach, without undue delay, where that personal data breach is likely to result in a high risk to the rights and freedoms of the ...
(87)It should be ascertained whether all appropriate technological protection and organisational measures have been implemented to establish immediately whether a personal data breach has taken place and ...
(88)In setting detailed rules concerning the format and procedures applicable to the notification of personal data breaches, due consideration should be given to the circumstances of that breach, includin...
(89)Directive 95/46/EC provided for a general obligation to notify the processing of personal data to the supervisory authorities. While that obligation produces administrative and financial burdens, it d...
Cross-references
Frequently asked questions
Connections
What connects to Article 34 GDPR
Themes where this returns
The counterpart in the other law
Guidelines
- EDPB Template for personal data breach notification
2026-06-10 · adopted, European Data Protection Board (EDPB)
- Guidelines 01/2021 on Examples regarding Personal Data Breach Notification
2021-12-14 · final, European Data Protection Board (EDPB)
- Guidelines 9/2022 on personal data breach notification under GDPR
2023-03-28 · final, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
Legislation in motion
- Proposal: breach notification only for high risk, within 96 hours, via a single entry point (Article 33 GDPR)
2025-11-19 · proposal, Europese Commissie