GDPR & privacy
Breach notification
A personal data breach is the most time-critical obligation in the platform. The deadline is short, it starts earlier than most people assume, and missing it is itself a separate infringement.
Transcript
A personal data breach is the most time-critical obligation in the platform, which is why it has its own countdown.
GDPR Article 33 requires notification to your supervisory authority without undue delay and, where feasible, within seventy-two hours of becoming aware. Notify later and you must justify the delay.
The clock starts at awareness, not at certainty. Record the moment you knew: that timestamp is the first thing a regulator examines.
The form captures exactly GDPR's Article 33, paragraph 3 fields: the nature of the breach, the categories and approximate number of people affected, the likely consequences, and the measures taken.
You are not expected to wait for a finished investigation. GDPR's Article 33, paragraph 4 explicitly allows information to be provided in phases as it becomes available.
The breach is now logged with its countdown running, and escalated to the dashboard. GDPR's Article 33, paragraph 5 requires you to document every breach, notifiable or not, so this register is itself a legal requirement.
As the investigation moves, update its status directly: in progress once you're working it, notified to DPA the moment the authority notification actually goes out. Attach the notification itself, or any supporting evidence, right on the record.
Where the breach is likely to cause high risk to individuals, GDPR's Article 34 requires you to tell them directly, tracked here as its own field separate from the authority clock. Mark it high-risk, then mark it notified once you've actually reached them, and the badge updates immediately. If a high-risk AI system was involved, Article 73 of the AI Act adds a separate report to a different authority.
Why this is required
Article 33 requires notification to your supervisory authority without undue delay and, where feasible, within seventy-two hours of becoming aware of the breach. If you notify later, you must give reasons for the delay.
The clock starts at awareness, not at certainty. You are considered aware once you have a reasonable degree of certainty that a security incident occurred leading to personal data being compromised. You are expected to notify on what you reasonably know and supply further detail in phases under Article 33(4); waiting until the investigation concludes is a common and expensive mistake.
The only exception is where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. That is a judgement you must be able to justify.
Article 33(5) requires you to document every breach (the facts, its effects and the remedial action taken) whether or not it was notifiable. The internal register is a legal requirement in its own right, not merely good practice.
Article 34 adds a second duty: where the breach is likely to result in a high risk to individuals, you must communicate it to them directly, without undue delay and in clear and plain language.
A breach is not only a hack. Article 4(12) covers accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data, which includes an email sent to the wrong recipient, a lost laptop or a misconfigured storage bucket.
What EuroCompliant does
Each logged breach starts a visible seventy-two hour countdown from the date of awareness you record.
The form captures exactly GDPR's Article 33(3) fields: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed, so the record you keep is the record you send.
Article 34 is tracked as its own field, separate from the Article 33 authority clock: mark whether the breach is high-risk to individuals, then mark and timestamp when you've notified them directly. A breach flagged high-risk shows a distinct Article 34 status badge until it's cleared.
Active breaches escalate to the dashboard's urgent alerts, and the register generates the breach notification report for your evidence pack.
Deadlines
Walking through it
Log the breach as soon as you are aware
Record the date and time of awareness accurately. That timestamp is what the seventy-two hours runs from, and it is the first thing a regulator will examine.
Open /privacy-hub →Assess risk to individuals
This determines both whether you must notify the authority and whether GDPR's Article 34 requires you to tell the individuals themselves.
Notify the authority within seventy-two hours
Notify on what you know. GDPR's Article 33(4) explicitly allows information to be provided in phases as it becomes available.
Communicate to individuals where the risk is high
GDPR's Article 34 requires clear, plain language describing the likely consequences and the measures you are taking. Mark the breach as high-risk in its record, then mark it as notified once you've actually contacted the affected individuals. The platform timestamps that separately from the authority notification.
Open /privacy-hub →Check the AI Act incident duty separately
If a high-risk AI system was involved, Article 73 of the AI Act may impose its own reporting duty on a different timescale to a different authority.
Open /operations →The law
Notification to the supervisory authority
Without undue delay and where feasible within 72 hours of awareness, unless the breach is unlikely to result in a risk to individuals.
Contents of the notification
Nature of the breach, categories and approximate numbers affected, likely consequences, and measures taken or proposed.
Internal documentation
All breaches must be documented regardless of whether they were notifiable.
Communication to the data subject
Required without undue delay where the breach is likely to result in a high risk to individuals.
Serious incident reporting
A parallel duty to report serious incidents involving high-risk AI systems to the market surveillance authority.
Penalties for non-compliance
Breach of Articles 33 and 34 attracts fines of up to €10 million or 2% of worldwide annual turnover. Where the underlying failure also breaches the Article 5 principles or Article 32 security duty, the higher tier of €20 million or 4% applies.
Frequently asked
Does the seventy-two hours include weekends?
Yes. It is seventy-two clock hours, not three working days. A Friday evening discovery is due by Monday evening.
What if we are not sure it is a reportable breach?
Log it regardless. Article 33(5) requires you to document every breach anyway. If in doubt on notification, the practical position taken by most supervisory authorities is that a notification made in good faith is far cheaper than a late one.
Our processor was breached, not us.
Article 33(2) requires the processor to notify you without undue delay, and your seventy-two hours then runs from the point you become aware. You notify the authority; the obligation stays with the controller.
Related guides
GDPR & privacy
How data protection obligations run alongside the AI Act, and the parts of the GDPR that carry operational consequences.
Serious incident reporting
The Article 73 duty when a high-risk AI system causes serious harm, with deadlines that tighten to two days in the worst cases.
Data subject requests (DSARs)
Tracking Articles 15 to 22 requests against the one-month statutory clock, including the automated-decision right that bites hardest on AI.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial