Skip to main content
Praxikon

Guideline

Guidelines 01/2021 on Examples regarding Personal Data Breach Notification

Date
Status
final
Body
European Data Protection Board (EDPB)
Reference
Guidelines 01/2021 (version 2.0)

What it is about

These guidelines give eighteen practical examples of data breaches, such as ransomware, data exfiltration by attackers, internal human error, lost or stolen devices and misdirected mail. For each example they state whether you must notify the supervisory authority, whether you must inform data subjects and which measures are appropriate. The EDPB adopted version 2.0 after public consultation on 14 December 2021 and published it on 3 January 2022.

What this means in practice

You can compare your own breach with the examples to decide whether you must notify within 72 hours. You must record every breach internally, even when you do not notify. The examples show which precautions, such as encryption and backups, can avoid a notification.

The GDPR articles concerned

Source: EDPB guideline pagechecked on 15 September 2026

Summary and practical reading by Praxikon. Not legal advice; the source prevails.

Connections

What connects to this development

Case law

Guidelines

Enforcement and fines

Legislation in motion