Back to the hub

When must you report a data breach under GDPR Article 33?

Under Article 33 of the GDPR, a controller must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to people's rights and freedoms. A later notification needs reasons.

Applies to: Controllers and processors subject to the GDPR that experience a personal data breach; the controller notifies the supervisory authority, while a processor notifies the controller.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

The 72-hour clock is the part of the GDPR that turns a bad week into a compliance failure. Article 33 does not give you three days to decide whether to report; it gives you three days from the moment you become aware, and the clock does not pause while you investigate. Knowing the rule before an incident is the only way to meet it during one.

When does the 72-hour rule apply?

Article 33(1) requires a controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it. The one exception is where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. So the default is to notify, and you only stay silent when you can justify that the breach carries no real risk. If you do miss the 72 hours, Article 33(1) still requires you to notify, but now accompanied by the reasons for the delay.

What has to be in the notification?

Article 33(3) sets the minimum content, and you can send it in phases if you do not have everything at once. You describe the nature of the breach, including the categories and approximate number of data subjects and records concerned. You give the name and contact details of your data protection officer or another contact point. You describe the likely consequences of the breach. And you set out the measures you have taken or propose to take, including steps to mitigate harm. A processor that suffers a breach does not notify the regulator directly; under Article 33(2) it notifies the controller without undue delay, and the controller carries the reporting duty.

When must you also tell the individuals?

This is a separate, higher bar. Article 34 requires you to communicate the breach to the affected data subjects only when it is likely to result in a high risk to their rights and freedoms, and then without undue delay and in plain language. You do not have to tell individuals if you had applied strong protection such as encryption that renders the data unintelligible, if you have since taken steps so the high risk is no longer likely, or if reaching everyone individually would take disproportionate effort, in which case a public communication can substitute.

The duty that applies even when you do not report

Article 33(5) requires you to document every personal data breach, its effects, and the remedial action taken, whether or not you notify the regulator. That record is how a supervisory authority checks your judgement later, so a decision not to report has to be written down and defensible. Getting a fine wrong here compounds quickly, since failure to notify is itself an infringement. See GDPR fines and penalties for the exposure, and GDPR for SaaS for how the regulation reaches you in the first place.

Next step

If you process personal data of people in the EU, the free 2-minute Obligation Scan checks whether the GDPR reaches you and flags the breach-response, documentation, and notification duties Articles 33 and 34 impose, so an incident does not become a missed-deadline fine. The GDPR compliance hub puts the breach rules in order with your other obligations.

Compliance checklist

  • Set a detection-to-notification clock: the 72 hours in Article 33 starts when you become aware of the breach, not when you finish investigating it.
  • Assess the risk to individuals; you must notify the supervisory authority unless the breach is unlikely to result in any risk to their rights and freedoms.
  • Prepare the Article 33(3) content: the nature of the breach, the categories and approximate numbers affected, your data protection officer or contact point, the likely consequences, and the measures taken.
  • If the risk is high, tell affected data subjects without undue delay under Article 34, unless an exemption such as strong encryption applies.
  • Document every breach, its effects, and your remedial action, as Article 33(5) requires, even for breaches you decide not to report.

Sources

Last verified: 2026-08-03

Informational, not legal advice.