Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How do you document your reporting decision?
Updated
Document the notify or no-notify decision even when you do not notify. GDPR Art. 33(5) records any personal data breach — facts, effects, remedial action — so a later reader can verify Article 33. This page is not legal advice.
Operational guidance, last verified 7 September 2026 against Regulation (EU) 2016/679 Article 33(5) (the controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken; that documentation shall enable the supervisory authority to verify compliance with Article 33) and Article 5(2) (accountability), EDPB Guidelines 9/2022 on personal data breach notification under GDPR (Version 2.0, adopted 28 March 2023 — regulator guidance on documenting breaches irrespective of notification), and NIST SP 800-61 Revision 3 (April 2025, current final Incident Response Recommendations and Considerations for Cybersecurity Risk Management: a CSF 2.0 Community Profile; Revision 2 is superseded). This page is not legal advice, not a downloadable form, does not start a clock, and is not a substitute for counsel.
Document even if you do not notify — this is not your determination
Audience: a CISO, compliance lead, incident commander, or counsel recording why the organisation notified, or why it did not. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Keeping a record is not a determination that any regime applies, that a clock has started, or that you must notify.
GDPR Article 33(5) is a documentation duty, not a notification duty. Article 33(1) is the notification: the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Article 33(5) has no such 'unless'. It says the controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken, and that documentation shall enable the supervisory authority to verify compliance with Article 33. The documentation duty can exist even when you do not notify. That is a legal requirement only if GDPR applies. This page does not decide that GDPR applies to YOUR facts. Last verified 7 September 2026. Not legal advice.
EDPB Guidelines 9/2022 (Version 2.0) are regulator guidance on how Article 33 is understood; they are not the regulation. Paragraph 121: regardless of whether or not a breach needs to be notified to the supervisory authority, the controller must keep documentation of all breaches, as Article 33(5) explains. Paragraph 122: this is linked to the accountability principle in Article 5(2); the purpose of recording non-notifiable breaches, as well as notifiable breaches, also relates to Article 24; controllers are therefore encouraged to establish an internal register of breaches, regardless of whether they are required to notify. Footnote 47: a separate register is not required provided the information relevant to the breach is clearly identifiable and can be extracted upon request. Last verified 7 September 2026. Not legal advice.
- Article 33(5) legal requirement (only if GDPR applies): document any personal data breach — facts, effects, remedial action — so the supervisory authority can verify Article 33. The article does not say 'only the ones you notified'.
- Article 33(1) legal requirement (only if GDPR applies): notify unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. A no-notify decision is still a decision under that test. Article 34 is a separate high-risk communication to data subjects. Do not collapse 33(1) 'risk' into 34 'high risk'.
- Regulator guidance, not the article: EDPB Guidelines 9/2022 paragraphs 121–125. Document reasoning for the decisions taken. If a breach is not notified, document why the controller considers it unlikely to result in a risk. An internal register is encouraged; a separate register is not required.
- Guidance / best practice, not Article 33(5): NIST SP 800-61 Revision 3 (April 2025) is the current final incident-response community profile and supersedes Revision 2 (August 2012). It is not a documentation statute and not an internal breach register.
- This page does not invent YOUR form, does not start a clock, does not decide that you must notify, and is not legal advice.
Decision-record field list — not a downloadable form
This is a field list, not a template file this product ships. That file does not exist. Work it with counsel. Each row is a class of record, not a required attachment and not YOUR pack. The legal-requirement column is a legal requirement only if the cited instrument applies to YOUR facts. EDPB materials are regulator guidance. NIST SP 800-61r3 is guidance, not a statute. Last verified 7 September 2026. Not legal advice.
| Field | Why it matters | Legal requirement vs guidance vs best practice | Limit |
|---|---|---|---|
| Facts relating to the breach | What happened, on which systems, which personal data, what is still unknown. Article 33(5) names facts. EDPB paragraph 123: causes, what took place, and the personal data affected. | Legal requirement (only if GDPR applies): Article 33(5) facts. Guidance: EDPB Guidelines 9/2022 paragraph 123. This page does not invent a headcount. | Do not fill a gap with a round number. List unknowns as unknowns. Do not tidy the ticket thread after the fact. |
| Effects | What the facts did, or may do, to people and to the organisation. Article 33(5) names effects. The notify / no-notify test sits on whether those effects are likely to result in a risk to rights and freedoms. | Legal requirement (only if GDPR applies): Article 33(5) effects. Article 33(3)(c) likely consequences is a notification-content cell, not a substitute for the internal record. Guidance: EDPB paragraph 123. | Do not write the verdict first and the effects after. Do not convert Article 33(1) 'risk' into Article 34 'high risk' without saying so. |
| Remedial action | What was taken or proposed: token revoked, session killed, access removed, hold placed. Article 33(5) names remedial action. A containment ticket is not automatically the whole limb. | Legal requirement (only if GDPR applies): Article 33(5) remedial action; Article 33(3)(d) measures taken or proposed on the notice itself, if you notify. Guidance: EDPB paragraph 123. | Do not claim eradication that is not done. Do not destroy the pre-remediation image to prove you cleaned it. The supporting-evidence page on this site is the evidentiary record. |
| Risk analysis | Likelihood and severity of impact on the rights and freedoms of natural persons, and the factors used. The notify / do-not-notify decision sits on this assessment. EDPB section IV is regulator guidance on assessing risk and high risk, not the article. | Legal requirement (only if GDPR applies): Article 33(1) unless unlikely to result in a risk; Article 5(2) accountability is the duty to be able to demonstrate that assessment. Guidance: EDPB Guidelines 9/2022 section IV and paragraph 125. This page does not run YOUR risk test. | Do not treat ENISA's severity methodology as a statute. Keep the reasons, not only the verdict. Re-evaluate if the facts change. |
| Threshold reasoning (notify or no-notify) | Why the facts are, or are not, likely to result in a risk — and, separately, whether they are likely to result in a high risk for Article 34. A no-notification breach record is still a record. EDPB paragraph 125: if a breach is not notified, a justification for that decision should be documented, including reasons why the controller considers the breach is unlikely to result in a risk. | Guidance (EDPB paragraph 125), not a named cell in Article 33(5). Article 33(5) still requires the facts, effects, and remedial action irrespective of the outcome. Legal requirement (only if GDPR applies and you do notify late): Article 33(1) second sentence — reasons for the delay on the notification itself. | Do not skip the reasons because you decided not to notify. Do not treat 'unlikely to result in a risk' as a licence to skip Article 33(5). The how-regulators-determine-knowledge page on this site is the clock-start analysis. |
| Timestamp of awareness (UTC) | When the organisation became aware. Clocks in the cited articles run from awareness or a named determination, not from this page. A UTC stamp is how a later reader sees sequence. The reporting-deadlines page on this site is the statute table of clocks. | Legal requirement (only if GDPR applies): Article 33(1) runs from becoming aware; Article 33(5) documents facts, which include when you knew. Guidance: EDPB Guidelines 9/2022 on 'aware'. Best practice: one UTC commander log, not a Slack reconstruction. | Do not back-date awareness. Do not treat reading this page as becoming aware. This page does not start a clock. The how-regulators-determine-knowledge page on this site is the clock-start analysis. |
| Timestamp of the decision (UTC) | When the notify / no-notify decision was taken, and by whom in role terms. Separate from awareness. A decision taken days after awareness is a fact the record should show, not hide. | Best practice / guidance, not a named Article 33(5) cell. EDPB paragraph 125 asks for reasoning for the decisions taken. A UTC decision stamp is how a later reader sees that the reasons existed at the time, not only in a later tidy rewrite. | Do not collapse awareness and decision into one stamp. Do not back-date the decision to the awareness minute. |
| Approver | The named human who accepted the notify or no-notify decision. Practice on this cluster: a named reviewer signs. Article 33(5) does not name an approver field. This page does not invent it as one. | Best practice, not Article 33(5). For CRA drafts in the product, a named reviewer must verify and submit; that is a product rule for those drafts, not a GDPR field. | Do not treat a Slack thumbs-up as the approver. This page does not name YOUR approver. The product does not approve the decision. |
Legal requirement vs guidance vs best practice
Statute, regulator guidance, and a NIST community profile are different kinds of text. Quote which kind you are relying on. This page is none of those. Last verified 7 September 2026. Not legal advice.
| Source | Kind | What it does here | What it does not do |
|---|---|---|---|
| GDPR Article 33(5) | Legal requirement — only if GDPR applies | Document any personal data breach: facts, effects, remedial action, so the supervisory authority can verify Article 33. No 'unless you notified' clause. | Does not name a form, a retention period, an approver, or a chain of custody. Does not start the 72 hours. Does not decide that GDPR applies to YOU. |
| GDPR Article 33(1) and Article 34 | Legal requirement — only if GDPR applies | 33(1): notify the supervisory authority unless unlikely to result in a risk. 34: communicate to the data subject when likely to result in a high risk. Those are notification duties, not the documentation duty. | Does not waive Article 33(5) when you do not notify. Does not make this page YOUR risk test. |
| GDPR Article 5(2) and Article 24 | Legal requirement — only if GDPR applies | Accountability: be able to demonstrate compliance. EDPB paragraph 122 links the internal breach record to these articles. | Does not specify the fields on this page. Does not make the product's cyber risk register an Article 33(5) log. |
| EDPB Guidelines 9/2022 (Version 2.0, 28 March 2023) | Regulator guidance, not the regulation | Paragraphs 121–125: document all breaches irrespective of notification; record reasoning; if not notified, document why unlikely to result in a risk; internal register encouraged; separate register not required (footnote 47). | Not a statute. Not YOUR DPA's form. Not a downloadable template this product ships. |
| NIST SP 800-61 Revision 3 (April 2025) | Guidance / best practice, not a statute | Current final. Incident Response Recommendations and Considerations for Cybersecurity Risk Management: a CSF 2.0 Community Profile. How to fold incident response into cybersecurity risk management. Cite r3 as current. | Supersedes NIST SP 800-61 Revision 2 (August 2012), Computer Security Incident Handling Guide. Cite r2 as superseded. Neither revision is an Article 33(5) internal breach register or a filing statute. |
Checklist
This is a question list, not a filing and not a downloadable form. The supporting-evidence page on this site is the evidentiary record. The prepare-regulatory-report page on this site is the field checklist. The reporting-deadlines page on this site is the statute table of clocks. The failure-to-report-consequences page on this site is the maxima table. The how-regulators-determine-knowledge page on this site is the clock-start analysis.
- Did you document the facts, effects, and remedial action even if you decided not to notify. Article 33(5) is a documentation duty (only if GDPR applies), not a skip when the outcome is no-notice.
- Are the reasons for the notify / no-notify decision on the record, or only the verdict. EDPB paragraph 125 is regulator guidance on documenting that reasoning.
- Are awareness (UTC) and decision (UTC) two stamps, or one collapsed time. Do not back-date either.
- Who is the named approver of the decision. This page does not name that person. The product does not approve it.
- Which job is this row doing — accountability documentation (Article 33(5) / 5(2), only if GDPR applies) or forensic exhibit (NIST SP 800-86 / chain of custody). The supporting-evidence page on this site is that split. Do not collapse them.
- This page does not start a clock. Keeping a decision record is not a filing.
Glossary
These are teaching labels for this page. They are not legal conclusions about YOUR facts.
| Term | How this page uses it |
|---|---|
| Decision record | The internal account of why the organisation notified, or why it did not: facts, effects, remedial action, risk analysis, threshold reasoning, timestamps, approver. Not a downloadable form this product ships. |
| Article 33(5) | GDPR duty to document any personal data breach — facts, effects, remedial action — so the supervisory authority can verify Article 33. Separate from the Article 33(1) notification. Legal requirement only if GDPR applies. Exists even when you do not notify. |
| No-notification breach record | The Article 33(5) record of a personal data breach the controller decided not to notify, including (as EDPB paragraph 125 recommends) why it was considered unlikely to result in a risk. Not a skip of documentation. |
| Internal breach register | EDPB paragraph 122 encouragement: an internal register of breaches, regardless of whether they are required to be notified. Footnote 47: a separate register is not required if the information is clearly identifiable. This product's cyber risk register is not that log. |
| Threshold reasoning | Why the facts meet, or do not meet, the cited notify test (Article 33(1) 'risk'; Article 34 'high risk'; other regimes as counsel names). Guidance to record; not a named Article 33(5) cell. |
| NIST SP 800-61r3 | April 2025 current final. Incident Response Recommendations and Considerations for Cybersecurity Risk Management: a CSF 2.0 Community Profile. Supersedes SP 800-61r2 (August 2012). Guidance, not a statute, not Article 33(5). |
Where this shows up in ShipReady Metrics
The signed-in app does not keep an Article 33(5) internal breach register, does not produce a notify / no-notify decision form, does not ship a downloadable decision-record template, does not decide whether you must notify, and does not file with a regulator. That register does not exist in this product. The cyber risk register is not an Article 33(5) log.
If you already have a session: signed-in app → Security holds the cyber risk register. It is a cyber risk register. It is not a GDPR Article 33(5) internal breach register, not a no-notification breach record, and not the accountability trail EDPB paragraph 122 describes. Compliance surfaces hold evidence artifacts: control-mapped collection and a human evidence review overlay (accept can render a manual row as met; reject as gap). That met-verdict overlay is a compliance artifact for SOC 2 / ISO 27001-style programs — a timestamped evidence record for controls. It is not an Article 33(5) log and not a decision record.
Signed-in app → Compliance → CRA reporting produces draft ladder text (24-hour early warning, 72-hour notification, 14-day final report) from recorded awareness for findings the organization has classified as CRA-in-scope. Each draft is marked DRAFT and states that a named reviewer must verify and submit; nothing in that surface has been sent to any authority. Status is the literal 'draft'. Those drafts are one product tracker from recorded awareness. They are not a GDPR Article 33 pack, not an Article 33(5) register, not a NIS2 Article 23 pack, and not a DORA RTS pack. The obligation map lists frameworks the organization marked in-scope; that mark is not a legal opinion. A named human still decides whether to notify and still submits.
Primary sources (last verified 7 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2016/679 Article 33(5) is a legal requirement only when GDPR applies: document any personal data breach (facts, effects, remedial action) so the supervisory authority can verify Article 33. Article 33(1) is the separate notification duty, unless unlikely to result in a risk. Article 5(2) is accountability. EDPB Guidelines 9/2022 on personal data breach notification under GDPR (Version 2.0, adopted 28 March 2023) are regulator guidance on documenting breaches irrespective of notification; they are not the regulation. NIST SP 800-61 Revision 3 (April 2025) is the current final incident-response community profile and supersedes Revision 2 (August 2012). These are examples, not a complete world list. Not legal advice.
The supporting-evidence page on this site is the evidentiary record. The prepare-regulatory-report page on this site is the field checklist. The reporting-deadlines page on this site is the statute table. The who-to-notify page on this site is the recipient-class map. The do-I-have-to-report page on this site is the class map. The reporting-decision-tree page on this site is the branching tree. The regulator-customer-individual page on this site is the three-stream comparison. The which-jurisdictions-apply page on this site is the applicability map. The preserve-evidence page on this site is the capture list. The chain-of-custody page on this site is the handling record. The failure-to-report-consequences page on this site is the maxima table. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The GDPR breach-notification guide on this site is the jurisdiction treatment of Articles 33–34. The NIS2 incident-reporting guide on this site. The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. A dedicated CRA, UK GDPR, US-state-laws, SEC cyber-disclosure, HIPAA, Canada PIPEDA, Australia NDB, India DPDP / CERT-In, and UAE/Dubai guide is not on this site yet. Naming them is not a link. A dedicated CRA Article 14 feature page is not on this site yet.
Frequently asked questions
How do you document a notify or no-notify decision?
Record the facts, effects, and remedial action, plus the risk analysis, threshold reasoning, UTC timestamps of awareness and of the decision, and the named approver. GDPR Article 33(5) is the documentation duty (only if GDPR applies), even when you do not notify. EDPB Guidelines 9/2022 recommend documenting the reasons. This page is a field list, not a downloadable form. Last verified 7 September 2026. Not legal advice.
Is this legal advice?
No. It is operational guidance distilled from GDPR Article 33(5) and Article 5(2), EDPB Guidelines 9/2022 (Version 2.0), and NIST SP 800-61 Revision 3 (current final; Revision 2 is superseded). Whether any duty applies, what you must retain, and whether a clock has started are legal questions for counsel on your facts. This page does not start a reporting clock.
Do I still document if we do not notify?
If GDPR applies, Article 33(5) says the controller shall document any personal data breaches — facts, effects, remedial action — with no 'unless you notified' clause. EDPB Guidelines 9/2022 paragraph 121: regardless of whether or not a breach needs to be notified, keep documentation of all breaches. Paragraph 125 recommends recording why a no-notify decision was taken. This page does not decide that GDPR applies to you. Not legal advice.
Does ShipReady keep an Article 33(5) internal breach register?
No. The cyber risk register under Security is a cyber risk register, not a GDPR Article 33(5) log. Compliance evidence review and the met-verdict overlay are compliance artifacts (accept can render met; reject, gap), not a decision record. CRA ladder drafts are one tracker from recorded awareness, not an internal breach register. A named human still decides whether to notify.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.