Notification of a personal data breach to the supervisory authority
Summary
Controllers must notify the supervisory authority of a personal data breach without undue delay, and where feasible within 72 hours, unless unlikely to result in risk; processors must notify the controller without undue delay.
breach notification72 hourssupervisory authority
Read the full official text: https://gdpr-info.eu/art-33-gdpr/
← Article 32
Security of processing
Article 34 →
Communication of a personal data breach to the data subject
Track GDPR article 33 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial