Under GDPR Art. 33, when does the 72-hour clock start, and what must the notification to the supervisory authority contain?
answer
- starts at awareness, not at the incident
- reasonable degree of certainty
- where feasible, not an absolute cap
- four minimum contents
- phases allowed; late notice needs reasons
basics
~20 sUnder GDPR Art. 33(1), the controller notifies without undue delay and, where feasible, within 72 hours of becoming aware of the breach. The notice gives at least the Art. 33(3) items and may be completed in phases.
solid answer
~50 sArt. 33(1) requires the controller to notify the competent supervisory authority "without undue delay and, where feasible, not later than 72 hours after having become aware" of a breach, unless it is unlikely to result in a risk to individuals. EDPB Guidelines 9/2022 treat the controller as **aware** once it has a *reasonable degree of certainty* that a security incident has compromised personal data. A short initial investigation is allowed, but it must start at once. The notice must at least cover the four items in **Art. 33(3)**: the nature of the breach with approximate categories and numbers, the DPO or another contact point, the likely consequences, and the measures taken or proposed. If the facts are incomplete, **Art. 33(4)** allows notification in phases. A notice sent after 72 hours must give reasons for the delay.
go deeper
Recall the numbers and triggers: 72 hours, measured from awareness, 'without undue delay' as the main standard, and the risk-based exception for breaches unlikely to cause any risk.
Explain what 'aware' means in the EDPB guidance, list the four Art. 33(3) minimum contents, and show how Art. 33(4) phased notification fits an incomplete picture.
Show how detection and escalation must be fast enough that the short investigation window is real, and how to document reasons when a notice is late or phased.
Argue how a controller operating in several Member States decides its lead authority in advance, so a breach never starts with a search for the right regulator.
## What Art. 33(1) actually says Under **Art. 33(1)** of the GDPR, *"the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons."* Four things follow from that sentence: - The duty sits with the **controller**. A processor's duty is different: under Art. 33(2) it tells the controller. - The primary standard is **without undue delay**. The 72 hours are an outer limit "where feasible", not a grace period. - The clock runs from **awareness**, not from when the breach happened. - Notification is the default. The only exit is a breach **unlikely to result in a risk**. The period is expressed in hours, not working days, so nothing in Art. 33 stops it over a weekend. ## When is a controller "aware"? The Regulation does not define awareness. EDPB Guidelines 9/2022 say a controller becomes aware when it has **a reasonable degree of certainty that a security incident has occurred that has led to personal data being compromised**. | Situation (from the EDPB examples) | When awareness starts | |---|---| | An unencrypted USB stick is lost | when the loss is realised, since an availability breach is certain even if access is not | | A third party proves it received a customer's data by mistake | immediately: clear evidence of a confidentiality breach | | A possible intrusion is investigated and personal data is confirmed compromised | at confirmation | | An attacker demands a ransom and the controller confirms the attack | once the attack is confirmed | Before that point the guidelines allow a **short period of investigation** to establish whether a breach has happened. It must start as soon as possible. The guidelines also warn that a controller which fails to act promptly on an alert may be treated as having failed to notify. The investigation window is for finding out, not for waiting. ## What the notification must contain **Art. 33(3)** sets a minimum. The notification shall *at least*: 1. describe the **nature of the breach**, including where possible the categories and approximate number of data subjects and of personal data records concerned; 2. give the **name and contact details of the DPO** or another contact point; 3. describe the **likely consequences**; 4. describe the **measures taken or proposed** to address the breach, including measures to mitigate its adverse effects. The words "where possible" and "approximate" matter. The EDPB says missing exact numbers should not hold up a timely notification. ## Incomplete facts: phases and late notice Two provisions deal with a picture that is still forming: - **Art. 33(4)**: *"Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay."* The guidelines recommend saying in the first notice that more detail will follow, and agreeing with the authority how it will be sent. - **Art. 33(1), last sentence**: a notification made after 72 hours *"shall be accompanied by reasons for the delay."* A late notice is still a notice. Missing the window is not a reason to skip notifying. The EDPB also notes that a controller can update the authority if a follow-up investigation shows no breach happened, and that there is no penalty for reporting an incident that turns out not to be a breach. ## To which authority Art. 33(1) points to the authority *competent under Art. 55*. For **cross-border processing** by a controller with an EU establishment, the EDPB guidelines say the controller notifies its **lead supervisory authority** (Art. 56). A controller with no EU establishment that is caught by Art. 3(2) does not get the one-stop shop just by appointing an Art. 27 representative. It notifies every authority in whose Member State affected data subjects live. ## Common traps - Treating the 72 hours as starting only once the full forensic report is in. - Holding the notice back until every Art. 33(3) field is final, when phased notification exists for exactly this. - Thinking a missed deadline makes notifying pointless. - Assuming every breach goes to the authority: a breach unlikely to result in a risk is recorded (Art. 33(5)) but not notified.
- Under the GDPR, a notified incident later turns out not to have been a breach. What then?EDPB Guidelines 9/2022 say the controller can update the supervisory authority with the new findings and have the incident recorded as not a breach. There is no penalty for reporting an incident that turns out not to be a breach, which is one reason the guidelines advise notifying when in doubt.
- Under the GDPR, a controller has no EU establishment but is caught by Art. 3(2). Where does it notify?Appointing an Art. 27 representative does not trigger the one-stop shop, so EDPB Guidelines 9/2022 say the controller must notify every supervisory authority in whose Member State affected data subjects live. The controller keeps the responsibility for notifying, though the representative can help if its mandate says so.
- Under the GDPR, can several similar breaches be notified together?The EDPB allows a 'bundled' notification for several breaches involving the same type of personal data breached in the same way over a relatively short time. Breaches of different data in different ways are notified individually. Bundling is an exception, not routine practice.
saying these in an interview costs you the question
- The 72 hours start only once the forensic investigation is complete.
- 72 hours means three working days, so a weekend pauses the clock.
- You must wait until every Art. 33(3) detail is final before notifying.
- If the 72 hours are missed, it is too late to notify at all.
- Every personal data breach must be notified to the supervisory authority.