Guideline
Guidelines 9/2022 on personal data breach notification under GDPR
- Date
- Status
- final
- Body
- European Data Protection Board (EDPB)
- Reference
- Guidelines 9/2022, versie 2.0
What it is about
These guidelines are a slightly updated version of WP250 rev.01 of the Article 29 Working Party. References to WP250 are now to be read as references to Guidelines 9/2022. They describe when a breach must be notified, the 72 hour deadline and communication to data subjects. Version 1.0 was adopted on 10 October 2022 for a targeted consultation. Version 2.0, adopted on 28 March 2023 and published on 4 April 2023, clarifies the following: merely having a representative in the EU does not trigger the one-stop-shop. A controller not established in the EU must therefore notify every supervisory authority of a Member State where affected data subjects reside.
What this means in practice
You must have a procedure to detect, assess and notify a breach within 72 hours of becoming aware of it. Processors must inform you without undue delay; put that in the processing agreement. If a high risk is likely you also inform the data subjects themselves. If you are not established in the EU, do not rely on a single lead authority: notify every relevant national supervisory authority.
The GDPR articles concerned
Source: EDPB guideline page and version 2.0 PDFchecked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Themes where this returns
The counterpart in the other law
Case law
- Interim judge suspends DPA penalty order against Northwave: exhaust powers against the hosting provider first
2024-03-26 · final, Rechtbank Midden-Nederland, voorzieningenrechter (zittingsplaats Utrecht)
Guidelines
- EDPB Template for personal data breach notification
2026-06-10 · adopted, European Data Protection Board (EDPB)
- Guidelines 01/2021 on Examples regarding Personal Data Breach Notification
2021-12-14 · final, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR
2023-02-14 · final, European Data Protection Board (EDPB)
- EDPB and EDPS adopt Joint Opinion 2/2026 on the Digital Omnibus
2026-02-10 · final, European Data Protection Board en European Data Protection Supervisor
Enforcement and fines
- Clearview AI: 30.5 million euro fine and penalty orders for illegal facial database
2024-05-16 · final, Autoriteit Persoonsgegevens
Legislation in motion
- Proposal: breach notification only for high risk, within 96 hours, via a single entry point (Article 33 GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
2026-06-22 · under negotiation, Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper
- Commission publishes Digital Omnibus proposal COM(2025) 837
2025-11-19 · proposal, Europese Commissie