GDPR Article 34: communication of a personal data breach to the data subject
GDPR Article 34 requires a controller to communicate a personal data breach to affected data subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms. Three exceptions apply: effective encryption, subsequent measures removing the high risk, or disproportionate effort.
Applies to: Controllers subject to the GDPR that have suffered a personal data breach and must decide whether the affected individuals have to be told, separately from notifying the supervisory authority.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanMost breach planning stops at the regulator. Article 34 is the second decision, it uses a higher threshold than Article 33, and it is the one that reaches your customers directly.
The trigger: high risk, not risk
Article 34(1) provides that when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.
Compare that with Article 33, which requires notifying the supervisory authority unless the breach is unlikely to result in a risk. Two different words carry the whole distinction. Article 33 has a low bar and a hard deadline of 72 hours where feasible. Article 34 has a higher bar and no hour count at all, only "without undue delay". A breach can therefore be reportable to a regulator and not communicable to individuals, and treating the two as one decision is how controllers end up either over-notifying customers or missing the duty entirely.
What the communication must contain
Article 34(2) states that the communication to the data subject shall describe in clear and plain language the nature of the personal data breach and contain at least the information and measures referred to in points (b), (c) and (d) of Article 33(3).
Those three imported items are: the name and contact details of the data protection officer or other contact point where more information can be obtained; a description of the likely consequences of the personal data breach; and a description of the measures taken or proposed to be taken by the controller to address the breach, including, where appropriate, measures to mitigate its possible adverse effects.
Note what is not imported. Point (a) of Article 33(3), the categories and approximate numbers of data subjects and records concerned, is owed to the supervisory authority but is not part of the minimum content for the individual. The regulator gets the statistics; the individual gets the plain-language explanation, who to contact, what it may mean for them, and what you are doing about it.
The three exceptions in Article 34(3)
The communication shall not be required if any of the following conditions are met:
(a) the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption;
(b) the controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects referred to in paragraph 1 is no longer likely to materialise;
(c) it would involve disproportionate effort. In such a case, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.
Exception (a) is the one most often claimed and most often claimed loosely. The wording is doubled on purpose: the measures must have been implemented, and they must have been applied to the personal data affected by this breach. Disk encryption on a server that was accessed through an authenticated application session does not render the exported data unintelligible to the person who exported it. That is the practical link back to Article 32, which is where the measures are supposed to come from in the first place.
Exception (c) is not a way out. It is a substitution: the public communication has to inform data subjects in an equally effective manner, which is a standard, not a formality.
The supervisory authority can overrule you
Article 34(4) provides that if the controller has not already communicated the breach to the data subject, the supervisory authority, having considered the likelihood of the breach resulting in a high risk, may require it to do so or may decide that any of the conditions in paragraph 3 are met.
So the decision you record under Article 34(3) is a provisional one. A regulator reviewing your Article 33 notification can direct you to communicate anyway. That is a further reason to write down the reasoning at the time, alongside the documentation Article 33(5) already requires for every breach.
How the two duties run together
In practice the sequence is: contain, assess risk, notify the supervisory authority under Article 33 if the breach is not unlikely to result in a risk, then assess high risk separately and communicate under Article 34 if it clears that higher bar. Failing either is itself an infringement, and the exposure is set out in GDPR fines and penalties.
Next step
If you hold personal data of people in the EU and have not decided in advance who makes the high-risk call, the free 2-minute Obligation Scan checks whether the GDPR reaches you and flags the breach-response duties in Articles 33 and 34 that attach to your processing. The GDPR compliance hub sets them alongside your other obligations.
Compliance checklist
- Assess the high-risk question separately from the Article 33 risk question, because a breach can be notifiable to the regulator without being communicable to individuals.
- Write the communication in clear and plain language describing the nature of the breach, as Article 34(2) requires, not in incident-response jargon.
- Include the three items Article 34(2) imports from Article 33(3): your data protection officer or contact point, the likely consequences, and the measures taken or proposed.
- If you rely on the encryption exception, be able to show the protection measures were actually applied to the affected data, not merely available in the environment.
- If individual contact would involve disproportionate effort, prepare a public communication or similar measure that informs data subjects in an equally effective manner.
Sources
- Regulation (EU) 2016/679 (GDPR), Article 34 (communication of a personal data breach to the data subject), official consolidated text on EUR-Lex
- Regulation (EU) 2016/679 (GDPR), official text, EUR-Lex
Last verified: 2026-09-08
Informational, not legal advice.