Skip to main content
Praxikon

Legislation in motion

Proposal: breach notification only for high risk, within 96 hours, via a single entry point (Article 33 GDPR)

Date
Status
proposal
Body
Europese Commissie
Reference
COM(2025) 837 final, 2025/0360 (COD), artikel 3, punt 8 (wijziging artikel 33 AVG), artikel 3, punt 14 (nieuw punt (hc) in artikel 70, lid 1 AVG) en artikel 6, punt 1 (nieuw artikel 23a NIS2); Raadsdocument ST 15698/25

What it is about

Notification to the supervisory authority would be required only for breaches likely to result in a high risk (currently: unless unlikely to result in a risk). The deadline moves from 72 to 96 hours. Notification would go through an EU single entry point run by ENISA under NIS2; until it exists, controllers notify the authority directly. The EDPB would propose a common template and a list of high-risk circumstances, adopted by the Commission by implementing act and reviewed at least every three years. The EDPB and EDPS (Joint Opinion 2/2026 of 10 February 2026) welcome the higher threshold, the longer deadline and the entry point, but want the EDPB itself to prepare and approve the template and list.

What this means in practice

If adopted, you would notify fewer breaches and have an extra day. You would need to justify why a breach is not high risk; the internal register duty of Article 33(5) remains. The duty to inform data subjects in high-risk cases (Article 34) is unchanged. Today the 72-hour deadline and the low threshold still apply: as of 15 September 2026 this is still a proposal, with no Council or Parliament position and no trilogue.

The GDPR articles concerned

Source: Raad van de EU, register (COM(2025) 837 final als ST 15698/25)checked on 15 September 2026

Summary and practical reading by Praxikon. Not legal advice; the source prevails.

Connections

What connects to this development

Case law

Guidelines

Legislation in motion6 of 17