Legislation in motion
Proposal: breach notification only for high risk, within 96 hours, via a single entry point (Article 33 GDPR)
- Date
- Status
- proposal
- Body
- Europese Commissie
- Reference
- COM(2025) 837 final, 2025/0360 (COD), artikel 3, punt 8 (wijziging artikel 33 AVG), artikel 3, punt 14 (nieuw punt (hc) in artikel 70, lid 1 AVG) en artikel 6, punt 1 (nieuw artikel 23a NIS2); Raadsdocument ST 15698/25
What it is about
Notification to the supervisory authority would be required only for breaches likely to result in a high risk (currently: unless unlikely to result in a risk). The deadline moves from 72 to 96 hours. Notification would go through an EU single entry point run by ENISA under NIS2; until it exists, controllers notify the authority directly. The EDPB would propose a common template and a list of high-risk circumstances, adopted by the Commission by implementing act and reviewed at least every three years. The EDPB and EDPS (Joint Opinion 2/2026 of 10 February 2026) welcome the higher threshold, the longer deadline and the entry point, but want the EDPB itself to prepare and approve the template and list.
What this means in practice
If adopted, you would notify fewer breaches and have an extra day. You would need to justify why a breach is not high risk; the internal register duty of Article 33(5) remains. The duty to inform data subjects in high-risk cases (Article 34) is unchanged. Today the 72-hour deadline and the low threshold still apply: as of 15 September 2026 this is still a proposal, with no Council or Parliament position and no trilogue.
The GDPR articles concerned
Source: Raad van de EU, register (COM(2025) 837 final als ST 15698/25)checked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Part of the file
Themes where this returns
The counterpart in the other law
Case law
- Interim judge suspends DPA penalty order against Northwave: exhaust powers against the hosting provider first
2024-03-26 · final, Rechtbank Midden-Nederland, voorzieningenrechter (zittingsplaats Utrecht)
Guidelines
- EDPB Template for personal data breach notification
2026-06-10 · adopted, European Data Protection Board (EDPB)
- Guidelines 01/2021 on Examples regarding Personal Data Breach Notification
2021-12-14 · final, European Data Protection Board (EDPB)
- Guidelines 9/2022 on personal data breach notification under GDPR
2023-03-28 · final, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- EDPB and EDPS adopt Joint Opinion 2/2026 on the Digital Omnibus
2026-02-10 · final, European Data Protection Board en European Data Protection Supervisor
- European Economic and Social Committee adopts opinion on the Digital Omnibus
2026-03-18 · final, Europees Economisch en Sociaal Comité
- European Central Bank issues opinion on the Digital Omnibus
2026-03-10 · final, Europese Centrale Bank
Legislation in motion6 of 17
- Proposal: EU-wide DPIA lists, template and methodology (Articles 35, 57, 64 and 70 GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
2026-06-22 · under negotiation, Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper
- Commission publishes Digital Omnibus proposal COM(2025) 837
2025-11-19 · proposal, Europese Commissie
- Council: Irish Presidency continues with a revised compromise, Antici Group 11 September 2026
2026-09-11 · under negotiation, Raad van de Europese Unie, Iers voorzitterschap
- European Parliament: joint ITRE-LIBE draft report, amendments tabled, no committee vote yet
2026-06-22 · under negotiation, Europees Parlement, commissies ITRE en LIBE (gezamenlijke commissie)
- Committee of the Regions adopts opinion on the Digital Omnibus
2026-05-07 · final, Europees Comité van de Regio's