Not every security incident is a personal-data breach — but when it is, a 72-hour clock starts. GDPR breach notification is the obligation to report a qualifying personal-data breach to the supervisory authority within 72 hours of becoming aware of it, and to tell the affected individuals when the risk to them is high. This guide covers what counts as a breach, when the duty applies, and what each notification must contain. It sits inside the wider practice of cyber incident management.
GDPR breach notification is the requirement to notify a personal-data breach to the supervisory authority within 72 hours of awareness where it is likely to result in a risk to individuals — and to inform the affected data subjects without undue delay where that risk is high.
GDPR defines a personal-data breach as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data. That covers three overlapping failure modes: a confidentiality breach (unauthorized access or disclosure), an integrity breach (unauthorized alteration), and an availability breach (loss of access to, or destruction of, the data).
The availability case is the one teams often miss. Ransomware that encrypts a database of personal data is a breach even if nothing is exfiltrated, because the data has been rendered unavailable. The trigger is the compromise of personal data, not whether an attacker walked out with a copy.
The clock runs from awareness — the point at which you have a reasonable degree of certainty that a security incident has compromised personal data — not from when the breach happened. From that moment, a controller must notify the competent supervisory authority within 72 hours where the breach is likely to result in a risk to the rights and freedoms of individuals. Where a breach is unlikely to result in such a risk, notification to the authority is not required, though you should still document the breach and your reasoning.
A notification does not have to be complete on day one. GDPR allows information to be provided in phases, and if you notify later than 72 hours the notification must be accompanied by the reasons for the delay. At a minimum it should describe the nature of the breach, the categories and approximate numbers of data subjects and records affected, the name and contact of your data protection officer or other contact point, the likely consequences, and the measures taken or proposed to address it.
This is the EU baseline; national transposition varies. It's informational, not legal advice — verify the specifics that bind you with qualified counsel.
Notifying the authority is a separate duty from notifying the people affected. Where a breach is likely to result in a high risk to the rights and freedoms of individuals, the controller must communicate it to the affected data subjects without undue delay, in clear and plain language. There are limited exceptions: where the data was protected by measures such as encryption that render it unintelligible to anyone unauthorized, where you have since taken steps ensuring the high risk is no longer likely to materialize, or where individual communication would involve disproportionate effort — in which case a public communication or similar measure can substitute.
Responsibility for notifying the authority sits with the controller. But a processor — a vendor handling personal data on your behalf — must notify the controller without undue delay after becoming aware of a breach. In practice that means a large share of breaches reach you second-hand, from a supplier, and your 72-hour clock effectively depends on how quickly they tell you. That makes vendor selection, contract terms, and due diligence part of your breach-notification readiness, not a separate exercise. The GDPR solution page covers how classifying vendors by the personal data they hold surfaces exactly which processors sit inside this obligation.
A single incident that exposes personal data at a regulated firm can be a GDPR breach, a DORA major incident, and a NIS2 significant incident at once — three deadlines running in parallel from the same awareness point. Our incident clocks guide lays the three regimes side by side, and the coordination that keeps them all on time is the substance of cyber incident management.
Polestead's Critical Incident Intelligence Center maps your profile to the regimes that bind you, and on classification it starts the GDPR 72-hour clock to the supervisory authority, drafts the notification, and runs it alongside any DORA or NIS2 duties the same incident triggers.
How CIIC works →It is the duty to notify a personal-data breach to the supervisory authority within 72 hours of becoming aware of it where the breach is likely to result in a risk to individuals, and to inform the affected data subjects without undue delay where that risk is high.
At awareness — when you have a reasonable degree of certainty that a security incident has compromised personal data — not when the breach happened. If you notify later than 72 hours, you must give reasons for the delay.
No. Notification to the supervisory authority is required where the breach is likely to result in a risk to individuals' rights and freedoms; where it is unlikely to, you need not notify the authority but should still document the breach and your assessment.
Where the breach is likely to result in a high risk to their rights and freedoms, and without undue delay. This is the EU baseline; national transposition varies, and this is informational, not legal advice.