Skip to main content
Praxikon

Guideline

Guidelines 9/2022 on personal data breach notification under GDPR

Date
Status
final
Body
European Data Protection Board (EDPB)
Reference
Guidelines 9/2022, versie 2.0

What it is about

These guidelines are a slightly updated version of WP250 rev.01 of the Article 29 Working Party. References to WP250 are now to be read as references to Guidelines 9/2022. They describe when a breach must be notified, the 72 hour deadline and communication to data subjects. Version 1.0 was adopted on 10 October 2022 for a targeted consultation. Version 2.0, adopted on 28 March 2023 and published on 4 April 2023, clarifies the following: merely having a representative in the EU does not trigger the one-stop-shop. A controller not established in the EU must therefore notify every supervisory authority of a Member State where affected data subjects reside.

What this means in practice

You must have a procedure to detect, assess and notify a breach within 72 hours of becoming aware of it. Processors must inform you without undue delay; put that in the processing agreement. If a high risk is likely you also inform the data subjects themselves. If you are not established in the EU, do not rely on a single lead authority: notify every relevant national supervisory authority.

The GDPR articles concerned

Source: EDPB guideline page and version 2.0 PDFchecked on 15 September 2026

Summary and practical reading by Praxikon. Not legal advice; the source prevails.

Connections

What connects to this development

Case law

Guidelines

Enforcement and fines

Legislation in motion