Guideline
Guidelines 01/2021 on Examples regarding Personal Data Breach Notification
- Date
- Status
- final
- Body
- European Data Protection Board (EDPB)
- Reference
- Guidelines 01/2021 (version 2.0)
What it is about
These guidelines give eighteen practical examples of data breaches, such as ransomware, data exfiltration by attackers, internal human error, lost or stolen devices and misdirected mail. For each example they state whether you must notify the supervisory authority, whether you must inform data subjects and which measures are appropriate. The EDPB adopted version 2.0 after public consultation on 14 December 2021 and published it on 3 January 2022.
What this means in practice
You can compare your own breach with the examples to decide whether you must notify within 72 hours. You must record every breach internally, even when you do not notify. The examples show which precautions, such as encryption and backups, can avoid a notification.
The GDPR articles concerned
Source: EDPB guideline pagechecked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Themes where this returns
The counterpart in the other law
Case law
- Gelderland District Court: bankruptcy trustee is controller, DPA fine for unsecured hard drive cut to 58,125 euros
2025-08-07 · status not established, Rechtbank Gelderland
- Interim judge suspends DPA penalty order against Northwave: exhaust powers against the hosting provider first
2024-03-26 · final, Rechtbank Midden-Nederland, voorzieningenrechter (zittingsplaats Utrecht)
- Russmedia: an online marketplace operator is controller for personal data in adverts and must check before publication
2025-12-02 · final, Hof van Justitie van de EU (Grote kamer), X tegen Russmedia Digital SRL en Inform Media Press SRL
Guidelines
- EDPB Template for personal data breach notification
2026-06-10 · adopted, European Data Protection Board (EDPB)
- Guidelines 9/2022 on personal data breach notification under GDPR
2023-03-28 · final, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default
2020-10-20 · final, European Data Protection Board (EDPB)
- Guidelines 01/2025 on Pseudonymisation
2025-01-16 · adopted, European Data Protection Board (EDPB)
- EDPB and EDPS adopt Joint Opinion 2/2026 on the Digital Omnibus
2026-02-10 · final, European Data Protection Board en European Data Protection Supervisor
Enforcement and fines
- HAN University of Applied Sciences fined 175,000 euros for inadequate security
2025-12-15 · final, Autoriteit Persoonsgegevens
Legislation in motion
- Proposal: breach notification only for high risk, within 96 hours, via a single entry point (Article 33 GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
2026-06-22 · under negotiation, Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper
- Commission publishes Digital Omnibus proposal COM(2025) 837
2025-11-19 · proposal, Europese Commissie