Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

When must you notify a GDPR personal data breach?

Updated

Article 33(1) GDPR: notify the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware, unless unlikely to result in a risk. Article 34 is a separate high-risk individual duty. Not legal advice; does not start a clock.

GDPR jurisdiction guide, last verified 7 September 2026 against Regulation (EU) 2016/679 Articles 33 and 34, Recitals 85–88, and EDPB Guidelines 9/2022 on personal data breach notification under GDPR (Version 2.0, adopted 28 March 2023, published 4 April 2023 — regulator guidance, not the regulation). It is not legal advice, not a filing, not a determination that GDPR applies, and not a substitute for counsel.

This is GDPR Articles 33–34, not YOUR determination

Audience: a controller, a processor, a DPO, a CISO, or counsel triaging a personal-data incident that may sit under Regulation (EU) 2016/679. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that GDPR applies, that you have become aware, that a risk or high-risk threshold is met, or that you must file.

Articles 33 and 34 are legal requirements only if GDPR applies to YOUR facts. Territorial scope is Article 3 — the which-jurisdictions-apply page on this site is that applicability map. This page does not run Article 3. The UK GDPR jurisdiction guide on this site is Articles 33–34 to the Commissioner. Last verified 7 September 2026. Not legal advice.

  • Statute versus guidance: Articles 33 and 34 are legal requirements only if GDPR applies. EDPB Guidelines 9/2022 (Version 2.0) are regulator guidance on how those articles are understood; they are not the regulation. This page quotes which kind of text it is relying on.
  • This page does not start 72 hours, does not convert 'without undue delay' into a number of hours, and does not round 72 hours to three days.
  • The reporting-deadlines page on this site is the statute table of clocks. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The regulator-customer-individual page on this site is the three-stream comparison.
  • The signed-in CRA ladder tracks recorded awareness for findings the organisation classified as CRA-in-scope. That tracker is not an Article 33 clock, and it does not file with a supervisory authority.

72-hour authority notification — Article 33(1)

Article 33(1) is the controller's notice to the supervisory authority. Quote the article's words. This page does not find that you have become aware, and it does not start the 72 hours. The how-regulators-determine-knowledge page on this site is the clock-start analysis. Last verified 7 September 2026. Not legal advice.

Article 33(1) clock (legal requirement only if GDPR applies — not YOUR start time; not legal advice; does not start a clock)
ElementWhat the text saysKind of textLast verified
DutyIn the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.Legal requirement — Article 33(1). Only if GDPR applies.7 September 2026
Clock-startAfter having become aware of it. Article 33(1) itself does not say 'should have known' or 'reasonable diligence'. Recital 87: it should be ascertained whether all appropriate technological protection and organisational measures have been implemented to establish immediately whether a personal data breach has taken place.Legal requirement (the start word) plus Recital 87. Not a finding that YOU became aware.7 September 2026
Awareness (how 'aware' is described)EDPB Guidelines 9/2022 paragraph 31: a controller should be regarded as having become 'aware' when that controller has a reasonable degree of certainty that a security incident has occurred that has led to personal data being compromised. Paragraph 34: after first being informed of a potential breach, the controller may undertake a short period of investigation; during that period the controller may not be regarded as being 'aware'. Paragraph 36: in most cases those preliminary actions should be completed soon after the initial alert — it should take longer only in exceptional cases.Regulator guidance, not the regulation. The guidelines do not invent a second clock. They are not a finding that YOU have a reasonable degree of certainty.7 September 2026
Delay beyond 72 hoursWhere the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay. Article 33(4) then allows information in phases without undue further delay — that is not a licence to skip the first notice.Legal requirement — Article 33(1) second sentence, and Article 33(4).7 September 2026
Exception (no authority notice)Unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. That exception is Article 33(1), not Article 34. Article 33(5) still requires documentation even when you do not notify.Legal requirement — Article 33(1) exception. Counsel applies the test. This page does not.7 September 2026

High-risk individual notification — Article 34 versus Article 33

Article 34 is a separate duty from Article 33. The threshold is higher. The clock is 'without undue delay' with no 72-hour outer mark in that article. Do not paste Article 33(1)'s 72 hours onto the data-subject stream. EDPB Guidelines 9/2022 section IV are regulator guidance on assessing risk and high risk; they are not the regulation. Last verified 7 September 2026. Not legal advice.

Risk-threshold decision tree (Article 33 versus Article 34 — not a determination; not legal advice; EDPB 9/2022 labelled as guidance)
QuestionIf the facts point that wayWhat this page does not doSource
Is there a personal data breach (Article 4(12))?A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. EDPB 9/2022 paragraphs 13–18 (guidance) group types as confidentiality, integrity, and availability. All personal data breaches are security incidents; not all security incidents are personal data breaches.Does not decide that YOUR incident is a personal data breach. Does not start a clock.Article 4(12). EDPB 9/2022 paragraphs 13–18 are regulator guidance.
Is the breach unlikely to result in a risk to the rights and freedoms of natural persons?Article 33(1) exception may take the authority notification off the table — counsel applies that test. Article 33(5) still requires documentation of the facts, effects, and remedial action. EDPB 9/2022 paragraph 75 (guidance) gives a public-data example; paragraph 78 (guidance) discusses encrypted data that remain unintelligible where the key is intact.Does not find 'unlikely to result in a risk' on YOUR facts. Does not skip Article 33(5).Article 33(1) exception; Article 33(5). EDPB 9/2022 paragraphs 75–80 are regulator guidance.
If a risk is not unlikely — Article 33(1) authority noticeThe controller notifies the supervisory authority competent in accordance with Article 55, without undue delay and, where feasible, not later than 72 hours after having become aware. Content: Article 33(3). Phased: Article 33(4).Does not start the 72 hours. Does not convert 72 hours into three days. Does not file.Article 33(1) and 33(3)–(4). Legal requirement only if GDPR applies.
Is the breach likely to result in a high risk to the rights and freedoms of natural persons?Article 34(1): the controller shall communicate the personal data breach to the data subject without undue delay. High risk is a higher bar than Article 33(1)'s 'risk'. EDPB 9/2022 paragraphs 100–102 (guidance): authority notice unless unlikely to result in a risk; individual communication only where likely high risk. Recital 75 and Recital 85 name kinds of damage (physical, material, non-material).Does not find high risk on YOUR facts. Does not convert Article 34's 'without undue delay' into 72 hours.Article 34(1). Recitals 75 and 85. EDPB 9/2022 section IV is regulator guidance.
Article 34(3) — communication not required if a listed condition is met(a) appropriate technical and organisational protection measures were applied to the personal data affected, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption; (b) subsequent measures ensure that the high risk is no longer likely to materialise; (c) it would involve disproportionate effort — in that case a public communication or similar measure instead, whereby the data subjects are informed in an equally effective manner.Does not decide that encryption, subsequent measures, or disproportionate effort applies to YOUR facts. A public communication under (c) is not the Article 33(1) filing.Article 34(3)(a)–(c). Legal requirement only if GDPR applies.
Article 34(4) — the supervisory authority may still require communicationIf the controller has not already communicated the personal data breach to the data subject, the supervisory authority, having considered the likelihood of high risk, may require it to do so or may decide that any of the conditions in paragraph 3 are met.Does not predict what YOUR supervisory authority will require. Does not start a clock.Article 34(4).

Controller versus processor — Article 33(2) is not Article 33(1)

Different actor, different recipient, different content, different outer mark. A processor's Article 33(2) notice to the controller is not the controller's Article 33(1) notification to the supervisory authority. Last verified 7 September 2026. Not legal advice.

  • Article 33(1): the controller notifies the supervisory authority competent in accordance with Article 55 — without undue delay and, where feasible, not later than 72 hours after having become aware — unless the breach is unlikely to result in a risk. Content: Article 33(3).
  • Article 33(2): the processor shall notify the controller without undue delay after becoming aware of a personal data breach. That paragraph has no 72-hour outer mark. EDPB 9/2022 paragraph 44 (guidance): the processor does not need to first assess the likelihood of risk before notifying the controller; it is the controller that must make this assessment. Paragraph 45 (guidance): the GDPR does not provide an explicit time limit except 'without undue delay'; the EDPB recommends the processor promptly notifies the controller so the controller can meet the 72 hours.
  • Do not paste 72 hours onto the processor. Do not treat the processor's 'without undue delay' as starting the controller's 72 hours by itself — awareness is a legal and factual test for each actor. This page does not find it on YOUR facts.
  • Article 28(3)(f): the processing contract shall stipulate that the processor assists the controller in ensuring compliance with Articles 32 to 36. Assistance is not the Article 33(1) filing. EDPB 9/2022 paragraph 48 (guidance): a processor could make a notification on behalf of the controller if authorised; the legal responsibility to notify remains with the controller.
  • Article 34 is a third duty. The processor does not become the Article 34 sender by sending Article 33(2) notice. High risk is not the same test as Article 33(1)'s 'risk'.
  • Joint controllers: Article 26 requires them to determine their respective responsibilities, including Articles 33 and 34. EDPB 9/2022 paragraph 42 (guidance) recommends the arrangement name which controller takes the lead on breach notification. This page does not interpret YOUR Article 26 arrangement.

Content — Article 33(3) fields and phased Article 33(4)

Article 33(3) is the controller's authority-notice content list. Article 34(2) pulls a subset for the data-subject communication. Article 33(4) allows phases. Last verified 7 September 2026. Not legal advice.

  • Article 33(3) says 'shall at least'. Extra detail is allowed. EDPB 9/2022 paragraph 52 (guidance): where precise numbers are not available, approximations should not be a barrier to timely notification.
  • Article 33(4): where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay. EDPB 9/2022 paragraph 57 (guidance): the GDPR recognises that controllers will not always have all of the necessary information within 72 hours of becoming aware.
  • A phased notice is not a skipped notice. Reasons for delay still accompany a notification made after 72 hours (Article 33(1) second sentence).
  • The prepare-regulatory-report page on this site is the field checklist across regimes. Do not file an Article 33(3) form as a HIPAA Secretary notice or a Form 8-K Item 1.05.
Article 33(3) minimum fields (legal requirement only if GDPR applies — not a blended form; not legal advice)
FieldArticle 33(3) authority noticeArticle 34(2) data-subject communication
(a) NatureDescribe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned.Describe in clear and plain language the nature of the personal data breach. Article 34(2) does not copy Article 33(3)(a)'s approximate numbers into the data-subject letter.
(b) Contact pointCommunicate the name and contact details of the data protection officer or other contact point where more information can be obtained.Pulled in: at least the information in Article 33(3)(b).
(c) Likely consequencesDescribe the likely consequences of the personal data breach.Pulled in: at least the information in Article 33(3)(c).
(d) MeasuresDescribe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.Pulled in: at least the information in Article 33(3)(d).

Documentation — Article 33(5) even when there is no notice

Article 33(5): the controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article. The duty is not limited to breaches you notified. Last verified 7 September 2026. Not legal advice.

  • Document the facts, the effects, and the remedial action — including a no-notification decision and the reasons. EDPB 9/2022 paragraph 121 (guidance) quotes Article 33(5). Paragraph 122 (guidance) ties the record to Article 5(2) accountability and Article 24; the supervisory authority can request to see the records. Paragraph 122 encourages an internal register of breaches, regardless of whether they are required to be notified.
  • EDPB 9/2022 paragraph 22 (guidance): a temporary loss of availability should still be documented in accordance with Article 33(5), even where notification may or may not be required.
  • The document-your-decision page on this site is the decision record. The supporting-evidence page on this site is the evidentiary record. This page does not keep YOUR Article 33(5) register.
  • The signed-in app does not keep an Article 33(5) register and does not file one with a supervisory authority.

Lead authority and one-stop-shop — cite the articles, do not rank DPAs

This page does not rank supervisory authorities, does not pick YOUR lead authority, and does not invent a DPA ranking. The articles name the tests. Last verified 7 September 2026. Not legal advice.

Competence and one-stop-shop as the cited articles name them (not a DPA ranking; not a determination of YOUR lead authority; not legal advice)
ArticleWhat it saysWhat this page does not do
Article 55(1)Each supervisory authority shall be competent for the performance of the tasks assigned to and the exercise of the powers conferred on it in accordance with this Regulation on the territory of its own Member State. Article 33(1) points the notification to the supervisory authority competent in accordance with Article 55.Does not name YOUR competent authority. Does not rank Member State authorities.
Article 4(23)Defines 'cross-border processing': processing in the context of the activities of establishments in more than one Member State, or processing which substantially affects or is likely to substantially affect data subjects in more than one Member State.Does not decide that YOUR processing is cross-border.
Article 56(1) and 56(6)Without prejudice to Article 55, the supervisory authority of the main establishment or of the single establishment of the controller or processor shall be competent to act as lead supervisory authority for the cross-border processing carried out by that controller or processor in accordance with the procedure provided in Article 60. Article 56(6): the lead supervisory authority shall be the sole interlocutor of the controller or processor for that cross-border processing.Does not identify YOUR main establishment. Recital 36 describes main establishment; this page does not apply it. Does not invent a ranking of DPAs.
Article 60Cooperation between the lead supervisory authority and the other supervisory authorities concerned. The one-stop-shop procedure lives here. This page quotes that it exists; it does not walk YOUR cooperation file.Does not file under Article 60. Does not pick the lead for you.
Article 3(2) controllers not established in the Union — EDPB 9/2022 paragraph 73Article 3(2) still binds a controller not established in the Union, where it applies, to Articles 33 and 34. Article 27 requires a representative. EDPB 9/2022 paragraph 73 (regulator guidance, the Version 2.0 update): the mere presence of a representative in a Member State does not trigger the one-stop-shop system. For that reason the breach will need to be notified to every supervisory authority for which affected data subjects reside in their Member State.Does not decide that Article 3(2) applies. Does not list the authorities YOU must notify. The which-jurisdictions-apply page on this site is the Article 3 map. Paragraph 73 is guidance, not the article.

Checklist

This is a question list, not a filing, and not YOUR notice. Walk it with counsel. The first-72-hours page on this site is the operational 72-hour plan. The reporting-deadlines page on this site is the statute table. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The document-your-decision page on this site is the decision record.

  • Does GDPR apply? Article 3 is the territorial test. The which-jurisdictions-apply page on this site is that walk. This page does not run it. The UK GDPR jurisdiction guide on this site is Articles 33–34 to the Commissioner.
  • Are you the controller or the processor for this processing? Article 33(1) is not Article 33(2). Joint controllers: Article 26.
  • Awareness (UTC): the minute you currently believe the organisation became aware, in Article 33(1)'s words. Do not treat reading this page as becoming aware. This page does not find that minute.
  • Risk: is the breach unlikely to result in a risk (Article 33(1) exception)? High risk for Article 34 is a separate, higher test. Quote which test you applied. EDPB 9/2022 section IV is guidance on that assessment, not the article.
  • Authority notice: quote Article 33(3) fields. If information is incomplete, Article 33(4) phases, with reasons for delay if past 72 hours. Do not round 72 hours to three days.
  • Individual communication: only if Article 34(1) high risk, unless an Article 34(3) condition is met. Do not convert 'without undue delay' into 72 hours.
  • Article 33(5) record: facts, effects, remedial action — including a no-notification decision. The document-your-decision page on this site is that field list.
  • Lead authority: if cross-border processing may apply, Article 56 plus Article 60. Do not invent a DPA ranking. If you are not established in the Union and Article 3(2) may apply, EDPB 9/2022 paragraph 73 (guidance) says a representative does not by itself open one-stop-shop.
  • Who is authorised to file, and who is not. A named human files. The product does not. This page does not file.

Glossary

These are teaching labels for this page. They are not legal conclusions about YOUR facts.

Terms used on this page (teaching labels — not a determination)
TermHow this page uses it
Personal data breachArticle 4(12): a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Not every security incident.
Article 33(1)Controller → supervisory authority. Without undue delay and, where feasible, not later than 72 hours after having become aware, unless unlikely to result in a risk. Not three days.
Article 33(2)Processor → controller, without undue delay after becoming aware. Not Article 33(1). No 72-hour outer mark in that paragraph.
Article 33(3)Minimum content of the controller's authority notice: nature (including categories and approximate numbers where possible), DPO or contact point, likely consequences, measures.
Article 33(4)Phased provision of Article 33(3) information without undue further delay, where it is not possible to provide it at the same time.
Article 33(5)Document any personal data breaches — facts, effects, remedial action — even when you do not notify. Enables the supervisory authority to verify compliance with Article 33.
Article 34Controller → data subject when the breach is likely to result in a high risk. Without undue delay — not 72 hours. Content: Article 34(2). Exceptions: Article 34(3).
Risk versus high riskArticle 33(1) uses 'risk' (notify unless unlikely to result in a risk). Article 34(1) uses 'high risk' (communicate to the data subject when likely to result in a high risk). They are not the same threshold.
Became awareClock-start language in Article 33(1). EDPB 9/2022 paragraph 31 (guidance) describes a reasonable degree of certainty that personal data have been compromised.
Lead supervisory authority / one-stop-shopArticle 56 (lead of the main or single establishment for cross-border processing) plus Article 60 (cooperation). Not a ranking of DPAs. A representative under Article 27 does not, on EDPB 9/2022 paragraph 73 (guidance), open one-stop-shop by itself.
EDPB Guidelines 9/2022Regulator guidance, Version 2.0, adopted 28 March 2023. Not the regulation. The Version 2.0 change is paragraph 73 on non-EU establishments.

Where this shows up in ShipReady Metrics

The signed-in app does not decide that GDPR applies, does not start an Article 33 clock, does not start an Article 34 clock, does not assess risk or high risk, does not keep an Article 33(5) register, and does not file with a supervisory authority. None of the surfaces below is an Article 33 notice, an Article 34 communication, or an instruction to submit a filing.

If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organization has classified as CRA-in-scope. That is one product tracker for the CRA actively-exploited ladder. It is not a GDPR Article 33 clock, not an Article 34 communication, and not a DPA filing. It tracks a clock the organization already recorded. It is not a determination that CRA applies. A named human still submits.

GDPR is a bundled framework in the catalog (`gdpr`, labelled GDPR (2016/679) readiness — a starter subset, not the full regulation). The obligation map lists frameworks the organization has marked in-scope. That in-scope mark is not a determination that GDPR applies, not an Article 3 territorial analysis, and not a legal opinion that Articles 33–34 have been triggered. The GDPR starter control set is crosswalked to canonical controls; evidence collection and the evidence-review overlay record control-mapped artifacts for that starter subset. Those rows are not an Article 33(3) pack and not an Article 33(5) register. The cyber risk register lives under Security. None of those surfaces files a GDPR Article 33 notice, an Article 34 communication, or a UK ICO notice.

Primary sources (last verified 7 September 2026)

Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

Regulation (EU) 2016/679 Articles 33 and 34 are legal requirements only when GDPR applies. Article 33(1) is controller-to-authority (72 hours from becoming aware, unless unlikely to result in a risk). Article 33(2) is processor-to-controller (without undue delay). Article 33(3) is the authority-notice content list. Article 33(4) allows phases. Article 33(5) is the documentation duty even when there is no notice. Article 34 is controller-to-data-subject when likely high risk, with Article 34(3) exceptions. Recitals 85–88 sit with those articles. Articles 3, 4(12), 4(23), 26, 27, 28(3)(f), 55, 56, and 60 are cited where this page names territorial scope, the definition of a personal data breach, cross-border processing, joint controllers, the representative, processor assistance, competence, lead authority, and one-stop-shop. EDPB Guidelines 9/2022 on personal data breach notification under GDPR (Version 2.0, adopted 28 March 2023, published 4 April 2023) are regulator guidance, not the regulation; paragraph 73 is the Version 2.0 update on non-EU establishments. The UK GDPR jurisdiction guide on this site is Articles 33–34 to the Commissioner. These are the GDPR articles this page treats, not a complete world list of breach laws. Not legal advice.

The reporting-deadlines page on this site is the statute table of clocks. The regulator-customer-individual page on this site is the three-stream comparison. The which-jurisdictions-apply page on this site is the Article 3 applicability map. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The prepare-regulatory-report page on this site is the field checklist. The document-your-decision page on this site is the decision record. The supporting-evidence page on this site is the evidentiary record. The failure-to-report-consequences page on this site is the maxima table. The NIS2 incident-reporting guide on this site. The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. The CRA Article 14 reporting guide on this site. The UK GDPR jurisdiction guide on this site is Articles 33–34 to the Commissioner. A dedicated US-state-laws, SEC cyber-disclosure, HIPAA, Canada PIPEDA, Australia NDB, India DPDP / CERT-In, and UAE/Dubai guide is not on this site yet. Naming them is not a link. A dedicated CRA Article 14 feature page is not on this site yet.

Frequently asked questions

When must you notify a GDPR personal data breach?

Article 33(1): the controller notifies the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Article 34 is a separate high-risk communication to the data subject, without undue delay — not 72 hours. Last verified 7 September 2026. Not legal advice.

Is this legal advice?

No. It is a GDPR jurisdiction guide distilled from Regulation (EU) 2016/679 Articles 33 and 34 and EDPB Guidelines 9/2022 (Version 2.0, regulator guidance, not the regulation). Whether GDPR applies, whether you have become aware, and whether a risk or high-risk threshold is met are legal questions for counsel on your facts. This page does not start a reporting clock.

Does ShipReady file Art. 33?

No. The signed-in app does not file Article 33 with a supervisory authority, does not send Article 34 communications, and does not start those clocks. Compliance → CRA reporting tracks the Article 14 ladder from recorded awareness for findings the org classified as CRA-in-scope — one product tracker, not Article 33. The obligation map is frameworks marked in-scope, not a determination that GDPR applies.

Does the processor's notice to the controller satisfy the 72-hour authority notice?

No. Article 33(2) is not Article 33(1). The processor notifies the controller without undue delay; the controller notifies the supervisory authority under Article 33(1), with Article 33(3) content and a 72-hour outer mark from the controller's awareness. Forwarding the processor email to the authority is not the Article 33(1) filing. Not legal advice.

Is UK GDPR the same as this page?

No. This page is Regulation (EU) 2016/679 Articles 33–34. UK GDPR is a separate UK legal requirement. The UK GDPR jurisdiction guide on this site is Articles 33–34 to the Commissioner. The which-jurisdictions-apply page on this site is the applicability map, including UK GDPR Article 3 as a separate class. Not legal advice.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.