Reporting a Data Breach: The 72-Hour Deadline Under Art. 33 GDPR

The 72-hour clock for a data breach does not start with the attack, but with its discovery: an attack on Monday, discovered on Thursday, only starts the deadline running on Thursday. Under Art. 33 GDPR, you must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless a risk to the individuals concerned is unlikely.
From the Provimedia editorial team. As of: July 2026. This article is general information, not legal advice.
When is a data breach subject to mandatory reporting?
A data breach must be reported if it is likely to result in a risk to the rights and freedoms of the individuals concerned. Only if a risk is unlikely does the reporting obligation not apply, and you must be able to demonstrate this (Art. 33(1) GDPR).
Art. 4(12) GDPR defines a personal data breach as the destruction, loss, alteration, or unauthorized disclosure of, or unauthorized access to, personal data. That ranges from a lost company laptop, through a phishing attack on an email inbox, to an applicant list sent to the wrong recipient.
If the affected data was effectively encrypted and the key remained under your control, a risk often does not exist, but this must be assessed and documented case by case, not assumed as a blanket rule. For you, that means: assess every incident individually instead of ruling out a report too hastily.
When does the 72-hour deadline begin?
The deadline begins when the breach becomes known, not when the incident happens. A data breach is considered known to the controller only once a responsible person is sufficiently certain that a reportable event has occurred; a vague suspicion is not enough for that.
This is exactly where the critical bottleneck lies: if an anomaly sits unnoticed in an inbox or on a desk for days, valuable time passes before the clock even starts running.
Under Art. 33(5) GDPR, you must document every breach in any case, including the facts, its effects, and the remedial action taken, one building block of the general accountability obligation under the GDPR. For you, that means: the faster an incident is internally recognized as a data breach, the more room you retain within the 72 hours.
What must the notification to the supervisory authority contain?
The notification under Art. 33(3) GDPR must contain at least four elements:
- a description of the nature of the breach, including, where possible, the categories and approximate number of individuals concerned and the data records affected;
- the name and contact details of the data protection officer or another point of contact;
- a description of the likely consequences of the breach;
- a description of the measures taken or proposed to address and mitigate the breach.
If not all information is available at the time of notification, Art. 33(4) GDPR allows it to be provided in phases, without undue further delay.
The competent authority is the supervisory authority in whose territory you have your main establishment, or the one competent for the specific case under Art. 55 GDPR, in Germany the respective state data protection authority depending on the federal state, usually via an online reporting portal. For you, that means: do not wait to report until all four points are complete; report on time and add details later.
When must the individuals concerned be informed?
You only have to inform the individuals concerned if there is a high risk, a higher threshold than for the notification obligation to the authority (Art. 34(1) GDPR). The notification must be made without undue delay, in clear and plain language, and contain the same core information as the notification to the authority.
Art. 34(3) GDPR names three exceptions where an individual notification is not required:
- appropriate technical protection measures such as encryption rendered the data unintelligible to unauthorized persons;
- subsequent measures have eliminated the high risk;
- individual notification would involve disproportionate effort; in that case, a public communication or a similar measure is sufficient.
For you, that means: check the risk threshold for every data breach twice, once for the authority, once for the individuals concerned.
What happens if a notification is late?
If the 72-hour deadline is exceeded, Art. 33(1) sentence 2 GDPR requires the notification to be accompanied by reasons for the delay. A late but justified notification is therefore expressly provided for, not an automatic breach of duty.
If, on the other hand, no notification is made at all, or the delay is not plausibly explained, the supervisory authority can impose a fine under Art. 83(4) GDPR: up to EUR 10 million or, for companies, up to 2 percent of total worldwide annual turnover for the preceding financial year, whichever amount is higher.
On top of that comes the effort of a regulatory review and the loss of trust among customers and employees. For you, that means: a late, justified notification protects you better than no notification at all.
Why are trained employees the decisive factor?
Trained employees are the decisive factor because the 72-hour deadline only starts running once someone within the company recognizes the data breach as such and reports it internally. Without this first step, the deadline cannot be met at all.
In practice, the reporting obligation rarely fails because of how the notification text is worded; it fails because suspicious behavior is never even recognized as a reportable incident: an unusual login, a misdirected email, a USB stick left lying around.
Employees who know the definition of a data breach and know exactly whom to contact internally shorten precisely the time span between the incident and its discovery that matters legally. For you, that means: a clear internal reporting path is not an administrative detail, it is the precondition for the 72-hour deadline being achievable at all.
What should you prepare today?
The 72-hour deadline cannot be improvised in an emergency; it has to be prepared before anything even happens. Four steps lay the groundwork:
- Define an internal reporting path: who reports a suspicion, to whom, and within what time must the internal report be made?
- Bookmark the reporting portal of the responsible state authority, so that nobody has to search for it in an emergency.
- Keep the data protection officer's contact details in a central place and make them accessible to all employees.
- Create a documentation template under Art. 33(5) GDPR, so that facts, effects, and measures are captured from the first minute.
For you, that means: whoever has prepared these four points does not lose time on organization in an emergency and can focus on recognizing and reporting.
| Notification to the supervisory authority (Art. 33) | Notification to the individuals concerned (Art. 34) | |
|---|---|---|
| Trigger | Risk to the rights and freedoms of the individuals concerned | High risk to the rights and freedoms of the individuals concerned |
| Deadline | Without undue delay, where feasible within 72 hours of becoming aware | Without undue delay, no fixed hourly deadline |
| Content | Nature of the breach, number/categories of individuals concerned, DPO contact, consequences, measures | Clear language, DPO contact, likely consequences, measures taken |
| Exception | Risk demonstrably unlikely | Encryption, follow-up measures, or disproportionate effort |
Frequently asked questions (FAQ)
Do weekends and public holidays count toward the 72 hours?
Yes. The deadline runs in hours, not business days; a weekend or a public holiday does not interrupt it. If this delays the notification, you should attach a brief explanation (Art. 33(1) GDPR).
Who is obligated to submit the notification?
You, as the controller, are obligated to notify the supervisory authority, which usually means your company itself. A processor who discovers a breach on their own systems must inform you without undue delay under Art. 33(2) GDPR, so that you can report on time.
Can I add to a notification afterward?
Yes. Art. 33(4) GDPR allows information to be provided in phases if not all details are available at the time of notification. Report on time first and provide any missing information without undue further delay.
Do I also have to report a breach if only employee data is affected?
Yes. Employee data is personal data within the meaning of the GDPR, and the same reporting obligation applies as for customer or prospect data. An internal data breach too, such as a payroll list sent to the wrong person, must be assessed against the four criteria in Art. 33(3) GDPR.
Whether a notification is possible within the deadline is not decided by the reporting form but by how responsive the workforce is: only someone who recognizes a data breach as such and knows where to report it internally actually starts the 72-hour deadline running. It is exactly this recognizing and reporting that Provimedia's GDPR fundamentals training teaches in a hands-on way, with a certificate of attendance as proof for employees and companies.
Sources
Share this article
Stay up to date
Get the latest articles, insights and industry updates straight to your inbox.
Decide for yourself what Google shows you
Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.
Add provimedia.de to my preferred sourcesRelated articles
More articles you might find interesting.
Phishing and Social Engineering: How Your Employees Can Spot an Attack
Phishing, spear phishing, CEO fraud, and smishing target people, not systems. The warning signs a phishing employee training should teach, and why a successful attack quickly turns into a reportable data breach.
GDPR Fines: Real Cases from Germany and What Companies Can Learn from Them
Four real GDPR fine cases from Germany show how authorities calculate the amount, and that courts can also significantly reduce them afterward.
Information Security Training vs. GDPR Training: What Companies Actually Need
Information security protects systems and information, data protection protects people and their data. The difference, the overlap under Art. 32 GDPR, and what the new NIS2 training duty means for management boards.
Bereit für den dokumentierten Schulungsnachweis?
Die DSGVO-Grundlagenschulung für Ihr Team – online, in rund 90 Minuten, mit datiertem Teilnahmezertifikat je Person.