GDPR
GDPR breach notification: when you must report within 72 hours
Updated September 26, 2026
A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. It covers an email sent to the wrong person as much as a cyberattack.
Report to the authority within 72 hours, unless unlikely to cause a risk
Article 33 requires the controller to notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, unless it is unlikely to result in a risk to individuals' rights and freedoms. If you notify later, you must explain the delay.
Processors must notify their controller without undue delay after becoming aware of a breach (Art. 33(2)).
What the notification contains
If you do not have all the information yet, you may provide it in phases (Art. 33(4)).
- the nature of the breach, including the categories and approximate number of individuals and records concerned;
- the name and contact details of the data protection officer or other contact point;
- the likely consequences of the breach;
- the measures taken or proposed to address it and mitigate its effects.
Tell the individuals when the risk is high
Where the breach is likely to result in a high risk to individuals, you must also inform them without undue delay, in clear and plain language (Art. 34). This is not required if the data was encrypted and unintelligible to the recipient, if follow-up measures removed the high risk, or if individual notification would involve disproportionate effort, in which case a public communication is used instead.
Record every breach
Article 33(5) requires you to document every breach, including those you decide not to report: the facts, the effects and the remedial action. The register shows the authority that you assessed each case.
In Estonia, breaches are reported to the Data Protection Inspectorate (AKI). Our GDPR kit includes a breach procedure with the 72-hour timeline, a notification form and a breach register.
Where does your company stand on GDPR?
Free assessment, about 10 minutes, score for every area of the law.
Start the free assessmentThis guide is general information, not legal advice.