Under the GDPR, when your processor discovers a breach of your customers' data, who must notify whom, and when does your 72-hour clock start?
answer
- the processor tells the controller
- no fixed hours in the text
- no risk triage by processor
- controller aware once informed
- the contract fills the gap
basics
~20 sUnder GDPR Art. 33(2), the processor notifies the controller without undue delay, with no risk assessment first. Per EDPB guidance, the controller is in principle aware once informed, and then owns the Art. 33 and 34 decisions.
solid answer
~40 sUnder **Art. 33(2)** the processor has one breach duty: tell the **controller** *without undue delay* after becoming aware. It has no duty of its own to notify the supervisory authority or the individuals, and the EDPB says it should **not** first assess risk. It only establishes that a breach occurred and reports it. The Regulation sets no hour count for this. **Art. 28(3)(f)** requires the processing contract to make the processor assist the controller with Arts. 32-36, and that contract is where early-notice terms are set. Per EDPB Guidelines 9/2022 the controller is *in principle* aware once the processor informs it, so the controller's Art. 33(1) clock runs from then. The processor may file the notice on the controller's behalf if authorised, but **legal responsibility stays with the controller**.
go deeper
Recall that under Art. 33(2) the processor tells the controller, and that only the controller notifies the authority and the individuals.
Explain when the controller becomes aware of a processor-side breach, why the processor does not triage risk, and what Art. 28(3)(f) requires the contract to contain.
Show how contract terms on early notice, phased updates and who files protect the controller's 72-hour window when many controllers share one processor's incident.
Judge how much breach-notice commitment to demand from processors against the leverage a controller really has, and where residual timing risk is simply accepted.
## The roles, briefly Under the GDPR a **controller** decides the purposes and means of processing. A **processor** processes personal data on the controller's behalf. The breach Articles give each of them a different duty: | Party | Duty | Source | |---|---|---| | Processor | notify the **controller** *without undue delay* after becoming aware of a breach | Art. 33(2) | | Controller | notify the **supervisory authority** without undue delay and, where feasible, within 72 hours, unless the breach is unlikely to result in a risk | Art. 33(1) | | Controller | communicate to **data subjects** when the breach is likely to result in a high risk | Art. 34(1) | | Controller | document every breach | Art. 33(5) | The processor's duty points in one direction: towards its controller. ## A scenario A company uses an outside ticketing service to handle customer support. The service is a **processor**. Its engineers find an authorisation bug that let any logged-in user of the service read other tenants' tickets, which contain names, emails and order details. The service has hundreds of customer companies. Each of them is a controller. 1. **The processor's job.** It must tell **each affected controller** without undue delay. The EDPB guidelines say a processor serving several controllers hit by the same incident reports to each one. It does not weigh whether the exposure is "risky enough". The guidelines state that the processor does not need to assess the likelihood of risk before notifying; that assessment belongs to the controller. 2. **The controller's clock.** The EDPB says the controller *"should be considered as 'aware' once the processor has informed it of the breach"*. From that moment the controller's Art. 33(1) window runs. It assesses risk, may investigate further, and decides on notifying the authority and the individuals. 3. **If there is no evidence of exploitation**, the guidelines note that a notifiable breach may not have occurred for a given controller. The flaw is still likely recordable, or a matter of Art. 32 non-compliance. ## Why "without undue delay" needs a contract behind it The GDPR gives the processor **no explicit time limit**, only "without undue delay". The EDPB recommends that the processor notify promptly and send further information **in phases** as it emerges. The tool for making that concrete is the processing contract: - **Art. 28(3)(f)** requires the contract to stipulate that the processor *"assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36"*; - the EDPB guidelines say the contract should specify how Art. 33(2) is met, including requirements for **early notification** that support the controller's own 72-hour obligation. A controller that agrees vague breach terms leaves itself a window it cannot control. The processor's delay does not move the controller's legal duty; it only shortens the time left to meet it. ## Delegating the filing, not the duty The guidelines allow a processor to **make the notification on the controller's behalf**, provided the controller has authorised it and this is part of their contract. The notice must still meet Arts. 33 and 34, and *"the legal responsibility to notify remains with the controller."* Two related rules: - **Joint controllers** under **Art. 26** must decide between themselves who handles Arts. 33 and 34. The EDPB recommends writing it into their arrangement. - A processor outside the EU that is caught by **Art. 3(2)** is still bound by the Art. 33(2) duty to its controller. ## Where candidates go wrong 1. Saying the processor notifies the supervisory authority within 72 hours. That is the controller's duty under Art. 33(1). 2. Letting the processor triage risk before telling the controller. The EDPB says the processor reports once it has established a breach; the risk call is the controller's. 3. Believing the Regulation sets a fixed number of hours for the processor. It does not; the contract does. 4. Thinking an authorised processor filing moves the liability. It does not.
- Under the GDPR, your processor told you about a breach four days after finding it. Did your 72 hours expire?Per the EDPB, the controller is in principle aware once the processor informs it, so the controller's Art. 33(1) window starts then. The processor's delay is a separate question: whether it met 'without undue delay' under Art. 33(2) and the contract. The controller should raise that failure under the contract.
- Under the GDPR, could the controller learn it still holds a copy of data the processor lost?Yes. The EDPB notes the controller may investigate further because the processor may not know all the facts. For example, the controller may still hold a copy or backup of data the processor lost. That can change the availability risk and so whether notification is needed.
saying these in an interview costs you the question
- The processor must notify the supervisory authority within 72 hours itself.
- A processor should assess risk first and only report serious breaches.
- The controller's 72 hours began when the processor first spotted the breach.
- The GDPR gives processors a fixed 24-hour deadline to tell the controller.
- If the processor files the notice for you, the legal duty moves to it.