Data breach reporting under Regulation (EU) 2016/679 (the EU General Data Protection Regulation) represents one of the most critical operational duties for data controllers and data protection officers (DPOs). When a security incident impacts personal data, organisations face strict legal deadlines, complex risk assessment thresholds, and severe administrative penalties under Article 83(4)(a) for failure to notify.
This practitioner guide breaks down Articles 33 and 34 of the GDPR, incorporating the official European Data Protection Board guidelines (EDPB Guidelines 9/2022 and Guidelines 01/2021) as well as CJEU landmark jurisprudence. Whether you are preparing for a DPO certification exam (such as CIPP/E or DPO EU certificate) or establishing an incident response protocol, this article provides verified legal clarity on every notification rule.
What constitutes a personal data breach under the GDPR?
Under Article 4(12) of the GDPR, a personal data breach is defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
As clarified in EDPB Guidelines 9/2022 on Personal Data Breach Notification, personal data breaches are categorized into three classic security dimensions:
- Confidentiality breach: Unauthorised or accidental disclosure of, or access to, personal data (e.g., email sent to wrong recipient, phishing attack compromising credentials).
- Integrity breach: Unauthorised or accidental alteration of personal data (e.g., malware corrupting customer records).
- Availability breach: Accidental or unauthorised loss of access to, or destruction of, personal data (e.g., ransomware encrypting database backups without secondary restore option).
Crucially, a security incident is not automatically a personal data breach. An incident involving servers containing exclusively non-personal system logs does not constitute a personal data breach under Article 4(12). However, as explained in our general EU GDPR Overview Guide, the moment personal identifiers are impacted, GDPR duties apply immediately.
How does the 72-hour notification deadline under Article 33 work?
Under Article 33(1) GDPR, the data controller must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, no later than 72 hours after having become aware of it, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.
Understanding when the 72-hour clock starts and how it operates in practice is a frequent exam question and operational stumbling block:
- The Awareness Standard: A controller is deemed "aware" when it has a reasonable degree of certainty that a security incident has occurred and that personal data has been compromised (EDPB Guidelines 9/2022). Initial unverified system alerts trigger an immediate investigation; formal awareness begins once preliminary triage confirms data compromise.
- Continuous Clock: The 72-hour timeframe runs in consecutive calendar hours. It does not pause for weekends, statutory holidays, or outside office hours.
- Delayed Notifications: If a notification cannot be made within 72 hours, it must be accompanied by a documented, legitimate reason for the delay (Article 33(1), sentence 2).
- Phased Information Provision: Under Article 33(4), where information cannot be provided all at once, the controller may submit information in phases without undue further delay as investigation details become available.
What are the notification obligations of a data processor under Article 33(2)?
Under Article 33(2) GDPR, a data processor must notify the data controller without undue delay after becoming aware of a personal data breach.
Data processors do not notify supervisory authorities directly, nor do they perform the final risk assessment. The processor's legal duty is to inform the controller without undue delay so that the controller can fulfill its statutory 72-hour obligation under Article 33(1). While practical execution can be assisted by processors, the controller's legal responsibility cannot be delegated. In data processing agreements negotiated under Article 28 (detailed in our Article 6 & Data Processing Guide), controllers often specify strict contractual deadlines (e.g., 24 to 48 hours) for processors to report security incidents.
Article 33 vs Article 34: When must data subjects be notified?
Data subjects must be notified under Article 34(1) GDPR without undue delay when the personal data breach is likely to result in a high risk to their rights and freedoms, unless one of the exceptions in Article 34(3) applies, whereas supervisory authorities must be notified under Article 33(1) whenever there is any risk beyond an unlikely risk.
The GDPR establishes a two-tiered threshold for breach reporting. The supervisory authority receives notification for any standard risk, whereas affected individuals are notified only when the risk crosses the higher threshold of "high risk" (e.g., threat of identity theft, financial loss, severe reputational damage, or exposure of special category data under Article 9).
| Legal Dimension | Supervisory Authority (Article 33) | Data Subjects (Article 34) |
|---|---|---|
| Trigger Threshold | Any risk to rights and freedoms (unless unlikely) | Likely to result in a high risk to rights & freedoms |
| Statutory Deadline | Without undue delay, max 72 calendar hours after awareness | Without undue delay (promptly to enable protective action) |
| Recipient | Competent Lead Supervisory Authority (DPA) | Individual affected data subjects |
| Mandatory Contents | Nature of breach, categories/approx. numbers of records & subjects, DPO contact, likely consequences, remedial measures taken | Clear & plain language summary of breach nature, DPO contact, likely consequences, recommended user protective measures |
| Statutory Exemptions | Exempt if the breach is unlikely to result in a risk to rights and freedoms (Art 33(1)); however, all breaches must be internally logged under Art 33(5) | 3 statutory exemptions under Art 34(3) (Encryption, post-mitigation, public notice) |
What exceptions relieve controllers from notifying affected data subjects under Article 34(3)?
Under Article 34(3) GDPR, controllers are exempted from directly communicating a personal data breach to data subjects if render-unintelligible protection was applied, if immediate post-breach measures eliminated the high risk, or if individual notification would involve disproportionate effort.
The three statutory exemptions under Article 34(3) operate as follows:
- Technical Protection Measures (Art 34(3)(a)): The controller implemented appropriate technical and organizational protection measures prior to the breach, making the data unintelligible to unauthorized persons—specifically state-of-the-art encryption (e.g. AES-256) where key management was uncompromised.
- Subsequent Remedial Action (Art 34(3)(b)): The controller took immediate follow-up measures ensuring that the high risk to data subjects is no longer likely to materialise (e.g. immediately invalidating stolen session tokens before unauthorized access occurred).
- Disproportionate Effort (Art 34(3)(c)): Direct individual communication would involve disproportionate effort (e.g. contact details destroyed or non-existent). In such cases, the controller must issue a public communication or similar effective public measure informing data subjects in an equally effective manner.
Note for Exam Candidates: Even if a controller claims an exemption under Article 34(3), the supervisory authority has statutory power under Article 34(4) to order the controller to notify data subjects if the DPA disagrees with the controller’s risk assessment.
What documentation and burden of proof are required for data breaches?
Article 33(5) GDPR requires data controllers to document all personal data breaches—including the facts relating to the breach, its effects, and the remedial action taken—enabling the supervisory authority to verify compliance with Article 33.
This internal breach register is mandatory for every incident, even when the controller concludes that notification to the supervisory authority was unnecessary due to an absence of risk.
Regarding security standards under Article 32, the Court of Justice of the European Union (CJEU) clarified the burden of proof in Case C-340/21 (Natsionalna agentsia za prihodite):
- The occurrence of a data breach resulting from a cyberattack by external hackers does not automatically prove that the controller failed to implement appropriate technical and organizational measures under Article 32.
- However, under the accountability principle (Article 5(2)) and CJEU precedent, the legal burden of proof lies entirely on the controller to demonstrate that its security measures were appropriate at the time of the breach.
- If a controller fails to prove appropriate security measures or fails to document breach decisions, affected individuals may seek financial compensation for non-material damage under Article 82 (as detailed in our GDPR Non-Material Damage Guide). Similar principles apply to cross-border incidents involving International Data Transfers or Subject Access Requests.
Frequently Asked Questions About GDPR Breach Reporting
Does the 72-hour GDPR breach notification deadline include weekends and holidays?
Yes, the 72-hour clock under Article 33(1) GDPR runs continuously in consecutive calendar hours once awareness is established. It does not pause for weekends, public holidays, or non-business hours.
When does a data controller legally become "aware" of a personal data breach?
According to EDPB Guidelines 9/2022, awareness occurs when a controller has a reasonable degree of certainty that a security incident has occurred and that personal data has been compromised. Mere suspicion triggers an immediate internal investigation, but formal awareness starts when breach facts are reasonably verified.
Does a data processor notify the supervisory authority directly after a breach?
No. Under Article 33(2) GDPR, the processor must notify the data controller without undue delay. The controller remains legally responsible under Article 33(1) for evaluating the risk and submitting the notification to the competent supervisory authority. While the practical task of notifying may be delegated, the legal responsibility cannot be transferred.
If stolen data was strongly encrypted, do controllers still need to notify data subjects?
Under Article 34(3)(a) GDPR, if the controller rendered the data unintelligible to unauthorized persons (such as state-of-the-art AES-256 encryption where keys remain secure), notification to data subjects is generally not required because the incident is unlikely to result in a high risk.
What is the penalty for failing to report a personal data breach under Article 33 or 34?
Failing to report a breach or maintain internal breach documentation under Article 33(5) falls under Article 83(4)(a) GDPR, carrying administrative fines of up to €10,000,000 or 2% of total worldwide annual turnover, whichever is higher.
Is a cyberattack proof that a company violated GDPR security requirements?
Not necessarily. The CJEU ruled in Case C-340/21 (Natsionalna agentsia za prihodite) that the occurrence of a data breach by third-party hackers does not automatically mean the controller’s security measures were inadequate under Article 32, though the controller bears the legal burden of proving its measures were appropriate.
Test Your Data Breach Knowledge with DPO Exam Questions
Practice realistic, multiple-choice questions on Articles 33 & 34, 72-hour deadlines, and EDPB guidelines with instant AI legal feedback.
Start Practice Quiz Free →