Back to the hub

GDPR Article 33: when must you report a data breach?

Under Article 33 of the GDPR, a controller must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to people's rights and freedoms. A later notification needs reasons.

Applies to: Controllers and processors subject to the GDPR that experience a personal data breach; the controller notifies the supervisory authority, while a processor notifies the controller.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

The 72-hour clock is the part of the GDPR that turns a bad week into a compliance failure. Article 33 does not give you three days to decide whether to report; it gives you three days from the moment you become aware, and the clock does not pause while you investigate. Knowing the rule before an incident is the only way to meet it during one.

When does the 72-hour rule apply?

Article 33(1) requires a controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it. The one exception is where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. So the default is to notify, and you only stay silent when you can justify that the breach carries no real risk. If you do miss the 72 hours, Article 33(1) still requires you to notify, but now accompanied by the reasons for the delay.

What has to be in the notification?

Article 33(3) sets the minimum content, and you can send it in phases if you do not have everything at once. You describe the nature of the breach, including the categories and approximate number of data subjects and records concerned. You give the name and contact details of your data protection officer or another contact point. You describe the likely consequences of the breach. And you set out the measures you have taken or propose to take, including steps to mitigate harm. A processor that suffers a breach does not notify the regulator directly; under Article 33(2) it notifies the controller without undue delay, and the controller carries the reporting duty.

When must you also tell the individuals?

This is a separate, higher bar, and it is set by Article 34 rather than Article 33. The trigger there is a high risk to rights and freedoms, not merely a risk, and there is no hour count attached to it. The three exceptions in Article 34(3) and the required content of the communication are covered in full on GDPR Article 34.

The duty that applies even when you do not report

Article 33(5) requires you to document every personal data breach, its effects, and the remedial action taken, whether or not you notify the regulator. That record is how a supervisory authority checks your judgement later, so a decision not to report has to be written down and defensible. Getting a fine wrong here compounds quickly, since failure to notify is itself an infringement. See GDPR fines and penalties for the exposure, and GDPR for SaaS for how the regulation reaches you in the first place.

Next step

If you process personal data of people in the EU, the free 2-minute Obligation Scan checks whether the GDPR reaches you and flags the breach-response, documentation, and notification duties Articles 33 and 34 impose, so an incident does not become a missed-deadline fine. The GDPR compliance hub puts the breach rules in order with your other obligations.

The official text of Article 33

The consolidated text of Regulation (EU) 2016/679 on EUR-Lex reads as follows.

33(1). "In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay."

33(2). "The processor shall notify the controller without undue delay after becoming aware of a personal data breach."

33(3). "The notification referred to in paragraph 1 shall at least: (a) describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned; (b) communicate the name and contact details of the data protection officer or other contact point where more information can be obtained; (c) describe the likely consequences of the personal data breach; (d) describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects."

33(4). "Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay."

33(5). "The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article."

Three details in that text are worth reading twice. Paragraph 1 sets the exemption as a double negative: you notify unless the breach is "unlikely to result in a risk", so uncertainty resolves towards notifying. Missing 72 hours does not remove the duty; it adds one, because the late notification must carry reasons for the delay. And paragraph 3(b) asks for the "name and contact details" of the data protection officer, which is more than the contact details Article 13(1)(b) requires in a privacy notice.

Compliance checklist

  • Set a detection-to-notification clock: the 72 hours in Article 33 starts when you become aware of the breach, not when you finish investigating it.
  • Assess the risk to individuals; you must notify the supervisory authority unless the breach is unlikely to result in any risk to their rights and freedoms.
  • Prepare the Article 33(3) content: the nature of the breach, the categories and approximate numbers affected, your data protection officer or contact point, the likely consequences, and the measures taken.
  • If the risk is high, tell affected data subjects without undue delay under Article 34, unless an exemption such as strong encryption applies.
  • Document every breach, its effects, and your remedial action, as Article 33(5) requires, even for breaches you decide not to report.

Sources

Last verified: 2026-09-08

Informational, not legal advice.