New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
Documentation

GDPR & privacy

Breach notification

A personal data breach is the most time-critical obligation in the platform. The deadline is short, it starts earlier than most people assume, and missing it is itself a separate infringement.

Transcript

A personal data breach is the most time-critical obligation in the platform, which is why it has its own countdown.

GDPR Article 33 requires notification to your supervisory authority without undue delay and, where feasible, within seventy-two hours of becoming aware. Notify later and you must justify the delay.

The clock starts at awareness, not at certainty. Record the moment you knew: that timestamp is the first thing a regulator examines.

The form captures exactly GDPR's Article 33, paragraph 3 fields: the nature of the breach, the categories and approximate number of people affected, the likely consequences, and the measures taken.

You are not expected to wait for a finished investigation. GDPR's Article 33, paragraph 4 explicitly allows information to be provided in phases as it becomes available.

The breach is now logged with its countdown running, and escalated to the dashboard. GDPR's Article 33, paragraph 5 requires you to document every breach, notifiable or not, so this register is itself a legal requirement.

As the investigation moves, update its status directly: in progress once you're working it, notified to DPA the moment the authority notification actually goes out. Attach the notification itself, or any supporting evidence, right on the record.

Where the breach is likely to cause high risk to individuals, GDPR's Article 34 requires you to tell them directly, tracked here as its own field separate from the authority clock. Mark it high-risk, then mark it notified once you've actually reached them, and the badge updates immediately. If a high-risk AI system was involved, Article 73 of the AI Act adds a separate report to a different authority.

Why this is required

Article 33 requires notification to your supervisory authority without undue delay and, where feasible, within seventy-two hours of becoming aware of the breach. If you notify later, you must give reasons for the delay.

The clock starts at awareness, not at certainty. You are considered aware once you have a reasonable degree of certainty that a security incident occurred leading to personal data being compromised. You are expected to notify on what you reasonably know and supply further detail in phases under Article 33(4); waiting until the investigation concludes is a common and expensive mistake.

The only exception is where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. That is a judgement you must be able to justify.

Article 33(5) requires you to document every breach (the facts, its effects and the remedial action taken) whether or not it was notifiable. The internal register is a legal requirement in its own right, not merely good practice.

Article 34 adds a second duty: where the breach is likely to result in a high risk to individuals, you must communicate it to them directly, without undue delay and in clear and plain language.

A breach is not only a hack. Article 4(12) covers accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data, which includes an email sent to the wrong recipient, a lost laptop or a misconfigured storage bucket.

What EuroCompliant does

Each logged breach starts a visible seventy-two hour countdown from the date of awareness you record.

The form captures exactly GDPR's Article 33(3) fields: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed, so the record you keep is the record you send.

Article 34 is tracked as its own field, separate from the Article 33 authority clock: mark whether the breach is high-risk to individuals, then mark and timestamp when you've notified them directly. A breach flagged high-risk shows a distinct Article 34 status badge until it's cleared.

Active breaches escalate to the dashboard's urgent alerts, and the register generates the breach notification report for your evidence pack.

Deadlines

72 hours from awarenessNotification to the supervisory authority under Article 33. Later notification requires a documented explanation for the delay.
Without undue delayCommunication to affected individuals under Article 34 where the breach poses a high risk to them.

Walking through it

1

Log the breach as soon as you are aware

Record the date and time of awareness accurately. That timestamp is what the seventy-two hours runs from, and it is the first thing a regulator will examine.

Open /privacy-hub →
2

Assess risk to individuals

This determines both whether you must notify the authority and whether GDPR's Article 34 requires you to tell the individuals themselves.

3

Notify the authority within seventy-two hours

Notify on what you know. GDPR's Article 33(4) explicitly allows information to be provided in phases as it becomes available.

4

Communicate to individuals where the risk is high

GDPR's Article 34 requires clear, plain language describing the likely consequences and the measures you are taking. Mark the breach as high-risk in its record, then mark it as notified once you've actually contacted the affected individuals. The platform timestamps that separately from the authority notification.

Open /privacy-hub →
5

Check the AI Act incident duty separately

If a high-risk AI system was involved, Article 73 of the AI Act may impose its own reporting duty on a different timescale to a different authority.

Open /operations →

The law

Penalties for non-compliance

Breach of Articles 33 and 34 attracts fines of up to €10 million or 2% of worldwide annual turnover. Where the underlying failure also breaches the Article 5 principles or Article 32 security duty, the higher tier of €20 million or 4% applies.

Frequently asked

Does the seventy-two hours include weekends?

Yes. It is seventy-two clock hours, not three working days. A Friday evening discovery is due by Monday evening.

What if we are not sure it is a reportable breach?

Log it regardless. Article 33(5) requires you to document every breach anyway. If in doubt on notification, the practical position taken by most supervisory authorities is that a notification made in good faith is far cheaper than a late one.

Our processor was breached, not us.

Article 33(2) requires the processor to notify you without undue delay, and your seventy-two hours then runs from the point you become aware. You notify the authority; the obligation stays with the controller.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial