A data breach is one of the few situations in data protection with a running clock. For a DPO managing a portfolio of clients, the first 72 hours decide whether the file stays clean or whether a slow response becomes an aggravating factor. This guide summarises the deadline, the minimum content of the notification to the supervisory authority, and an actionable checklist, with every GDPR article verified.
Direct answer: the deadline is a maximum of 72 hours from the moment the controller becomes aware of the breach, not from when it happened (Art. 33.1 GDPR). A breach is only notified to the supervisory authority if it is likely to result in a risk to the rights and freedoms of natural persons. Phased notification is allowed when not all information is available (Art. 33.4). The minimum content (Art. 33.3) is: nature of the breach, categories and approximate number of data subjects and records, contact details of the DPO, likely consequences, and measures taken or proposed. If there is a high risk, the breach must also be communicated to the affected individuals (Art. 34).
When does the 72-hour clock start?
It starts when the controller becomes aware of the breach, not when it occurred. Article 33.1 GDPR requires the controller to notify the supervisory authority “without undue delay and, where feasible, not later than 72 hours after having become aware of it”. The phrase “where feasible” and the reference to giving reasons for any delay confirm that the clock begins with knowledge, not with the incident itself.
This has a practical consequence for your portfolio: the moment a client “becomes aware” must be recorded. If a technician spots the incident on a Friday and does not escalate it until Monday, the clock may have started earlier than the client thinks. That is why the first step in the checklist is to log the exact time the breach became known.
Not every breach is notified. Art. 33.1 exempts notification where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Even then, Art. 33.5 requires it to be documented internally.
First-72-hours checklist
The first thing a DPO does is contain, assess the risk, and decide whether notification is required, all at once. This is the working order:
- Record the time of awareness. Note the exact date and time the controller became aware. This is the start of the clock.
- Contain. Coordinate with IT to cut off the vector (revoke credentials, isolate systems, close the improper access). Document every action and its timestamp.
- Assess the risk. Determine the nature of the data, the volume, the categories of data subjects, and whether special categories are involved (health, financial data). This drives the decision to notify or not, and whether there is a high risk to the individuals.
- Decide on notification to the supervisory authority. If there is a risk, prepare the notification with the minimum content of Art. 33.3. If data is still missing, use phased notification (Art. 33.4).
- Decide on communication to data subjects. If there is a high risk, prepare the notice to the affected individuals (Art. 34), unless an exception applies.
- Document everything in the breach register (Art. 33.5): facts, effects and corrective measures. This is the trail the authority can request to verify compliance.
The costliest mistake is usually not the breach itself, but a slow or undocumented response. Supervisory authorities value diligence in the reaction.
What gets notified to the supervisory authority?
You notify the minimum content set out in Article 33.3 GDPR. As a minimum, the notification must:
- a) Describe the nature of the breach, including where possible the categories and approximate number of data subjects concerned, and the categories and approximate number of personal data records concerned.
- b) Communicate the name and contact details of the data protection officer or other point of contact.
- c) Describe the likely consequences of the breach.
- d) Describe the measures taken or proposed to address the breach, including, where appropriate, measures to mitigate its possible adverse effects.
In Spain the notification is filed electronically through the AEPD’s online office, and the European Data Protection Board provides cross-EU guidance. Useful official references: the EDPB’s data breaches guide for SMEs and the consolidated GDPR text, Regulation (EU) 2016/679.
When must the breach be communicated to data subjects?
Only when the breach is likely to result in a high risk to the rights and freedoms of natural persons. Article 34.1 GDPR requires the controller to communicate the breach to the data subject without undue delay when a high risk is likely. The communication must be “in clear and plain language” and contain, at a minimum, the information in points b), c) and d) of Art. 33.3 (DPO contact, consequences and measures).
Art. 34.3 sets out exceptions, including:
- a) The controller has applied measures that render the data unintelligible to unauthorised parties, such as encryption.
- b) Subsequent measures have been taken to ensure the high risk is no longer likely to materialise.
- c) It would involve a disproportionate effort, in which case a public communication or similar equally effective measure is used instead.
Encryption of the affected data therefore does more than reduce risk: it can be the difference between having to notify thousands of individuals or not.
By sector: which clients carry the highest breach risk
The highest-risk clients are those running private areas, customer portals or internet-facing query forms: banking, insurance and fintech first. Two recent AEPD rulings in Spain illustrate the criterion worth reviewing with your portfolio:
- Banking and fintech with a customer portal. The AEPD sanctioned CaixaBank over a breach linked to access-control failures on documents, based on Articles 5.1.f) (integrity and confidentiality), 25 (data protection by design) and 32 (security of processing) GDPR. The criterion: a user being able to see another user’s documents is not a minor patch, it is a sanctionable security failure. Official source: ruling on aepd.es. (Verify the amount and per-article breakdown in the PDF before quoting figures.)
- Insurance with brokers or intermediaries. The AEPD sanctioned Generali over a breach whose vector was a brute-force attack against a query form using an intermediary’s credentials. The message for your portfolio: a partner’s legitimate access does not exempt anyone from Art. 32; you need to review attempt limits, rate-limiting and traceability of third-party access. (The exact case number and amount should be confirmed against the source ruling on aepd.es before citing.)
If you serve clients in banking, insurance or fintech with a customer portal, these rulings are the moment to check whether their per-client access controls are tested and whether an incident response protocol exists.
The value of the audit trail
The trail is what you show if a supervisory authority asks why you acted as you did. Art. 33.5 requires every breach, its effects and the corrective measures to be documented “in a manner that enables the supervisory authority to verify compliance”. For an external DPO, that trail has an extra layer: for each client, recording when a new criterion was reviewed (such as the CaixaBank or Generali rulings) and what was checked. That is the difference between reacting to a breach and being able to prove everything was done correctly and on time.
Frequently asked questions
When does the 72-hour clock start for notifying a breach?
From the moment the controller becomes aware of the breach, not when it happened. Art. 33.1 GDPR sets a maximum of 72 hours after becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
Does every data breach have to be notified?
No. A breach is only notified to the supervisory authority when it is likely to result in a risk to the rights and freedoms of natural persons (Art. 33.1 GDPR). If a risk is unlikely, it is not notified, but it must still be documented internally in the breach register (Art. 33.5).
What if I cannot gather all the information within 72 hours?
The GDPR allows phased notification (Art. 33.4): where the information cannot be provided at the same time, it may be provided in phases without undue further delay. If the notification is later than 72 hours, it must be accompanied by the reasons for the delay (Art. 33.1).
When must the breach be communicated to the affected individuals?
When the breach is likely to result in a high risk to the rights and freedoms of natural persons (Art. 34.1 GDPR). The communication must be in clear and plain language. There are exceptions, for example if the data was encrypted and is unintelligible to unauthorised parties (Art. 34.3.a).
Do you manage data protection for several clients and want every new supervisory-authority criterion to reach you already cross-referenced with the clients in your portfolio it affects, with the official source ready for the file? Reserve your place in the Vigía DPO founding group: vigiadpo.com/#reserva.