Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How do regulator, customer, and individual notices differ?
Updated
Regulator, customer (controller or processor), and individual (data subject) notices are three different streams. Each has its own who, threshold, clock, content, and channel. This comparison is not legal advice and does not start a clock.
Three-stream comparison, last verified 7 September 2026 against Regulation (EU) 2016/679 Articles 33(1)–(3), 33(2), and 34; HIPAA 45 CFR §§164.404, 164.406, and 164.408; and Cal. Civ. Code §1798.82(d). It is not legal advice, not a filing, and not a substitute for counsel.
Three streams, not one email
Audience: a compliance lead, CISO, incident commander, or counsel who has to pick content, timing, and channel for more than one addressee. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a column is not a determination that any duty applies, that a threshold is met, or that you must send a notice.
One incident can open three streams at once — a regulator filing, a customer (controller/processor) notice, and an individual (data subject) communication — with different thresholds, different clocks, and different required content. Sending one never discharges the others. Last verified 7 September 2026. Not legal advice.
- GDPR Article 33(1) is the controller's notice to the supervisory authority. Article 33(2) is the processor's notice to the controller. Article 34 is the controller's communication to the data subject. Those three articles are distinct duties. Do not paste one email into all three.
- HIPAA 45 CFR §164.404 (individuals), §164.406 (media), and §164.408 (the Secretary) are that regime, not GDPR. §164.406 is a HIPAA media stream — not the customer stream, and not Article 34. §164.410 (business associate to covered entity) is the HIPAA analog of a customer/controller notice.
- The who-to-notify page on this site is the recipient-class map. The prepare-regulatory-report page on this site is the field checklist. A dedicated GDPR jurisdiction and HIPAA jurisdiction guide is not on this site yet. Naming them is not a link. The do-I-have-to-report page on this site is the class map. The reporting-decision-tree page on this site is the branching tree. The reporting-deadlines page on this site is the statute table of clocks.
- This page does not start a clock. Awareness, discovery, and 'without undue delay' are legal and factual tests. Counsel applies YOUR facts.
Three-column comparison — regulator, customer, individual
Work this table with counsel. Each cell is a legal requirement only if that instrument applies to YOUR facts. GDPR Article 33(1), Article 33(2), and Article 34 are called out as distinct. HIPAA §§164.404, 164.406, and 164.408 are labelled as that regime, not as GDPR. Last verified 7 September 2026. Not legal advice.
| Row | Regulator | Customer (controller/processor) | Individual (data subject) |
|---|---|---|---|
| Who | GDPR Article 33(1): the supervisory authority competent in accordance with Article 55. HIPAA §164.408 (that regime, not GDPR): the Secretary. Filing one never discharges the other. | GDPR Article 33(2): the controller — the processor notifies the controller. HIPAA §164.410 (that regime, not GDPR): the covered entity — the business associate notifies the covered entity. Cal. Civ. Code §1798.82(b): the owner or licensee of the information, when you maintain data you do not own. A DPA clause can add a contractual customer notice on top; that clause is not Article 33(1). | GDPR Article 34(1): the data subject. HIPAA §164.404 (that regime, not GDPR): each individual whose unsecured protected health information has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed as a result of the breach. Cal. Civ. Code §1798.82(a): a California resident whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person (or encrypted information plus the encryption key, with a reasonable belief the key could render it readable). |
| Threshold | GDPR Article 33(1): a personal data breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. HIPAA §164.408: a breach of unsecured PHI; 500 or more individuals → contemporaneous Secretary notice (§164.408(b)); fewer than 500 → annual log, not later than 60 days after the end of the calendar year (§164.408(c)). Those 500-person marks are HIPAA, not GDPR, and not a customer threshold. | GDPR Article 33(2): a personal data breach. Article 33(2) does not copy Article 33(1)'s 'unless unlikely to result in a risk' exception. HIPAA §164.410: a breach of unsecured PHI discovered by the business associate. Cal. Civ. Code §1798.82(b): unauthorized acquisition of personal information you maintain but do not own. Contractual customer notice is whatever YOUR DPA or MSA says — this page does not interpret it. | GDPR Article 34(1): when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons — a higher bar than Article 33(1)'s 'risk'. Article 34(3) then lists cases where that communication is not required (encryption that renders the data unintelligible; subsequent measures that mean the high risk is no longer likely to materialise; disproportionate effort, with a public communication instead). HIPAA §164.404: each individual whose unsecured PHI was involved. Cal. Civ. Code §1798.82(a): unauthorized acquisition of the personal information that statute defines. |
| Clock-start | GDPR Article 33(1): without undue delay and, where feasible, not later than 72 hours after having become aware of it. Where the notification is not made within 72 hours, it shall be accompanied by reasons for the delay. Article 33(4) allows information in phases. HIPAA §164.408 uses the discovery rule in §164.404(a)(2) (known, or by reasonable diligence would have been known); 500+ is contemporaneous with individual notice; the annual log is a different mark. Those clocks are not averaged. This page does not start one. | GDPR Article 33(2): without undue delay after becoming aware of a personal data breach — no 72-hour outer mark in that paragraph. HIPAA §164.410(b): without unreasonable delay and in no case later than 60 calendar days after discovery, except as provided in §164.412. Cal. Civ. Code §1798.82(b): immediately following discovery. A DPA's 24-hour or 48-hour customer clause is a contract clock, not Article 33(1)'s 72 hours. This page does not interpret YOUR contract and does not start a clock. | GDPR Article 34(1): without undue delay. Article 34 does not convert that phrase into 72 hours — do not paste Article 33(1)'s outer mark onto the data-subject stream. HIPAA §164.404(b): without unreasonable delay and in no case later than 60 calendar days after discovery, except as provided in §164.412. Cal. Civ. Code §1798.82(a)(2): within 30 calendar days of discovery or notification of the data breach, subject to law-enforcement delay or restoring reasonable integrity of the data system. 72 hours, 60 calendar days, and 30 calendar days are different clocks. This page does not start one. |
| Content required (cite the article) | GDPR Article 33(3): the notification referred to in paragraph 1 shall at least (a) describe the nature of the personal data breach including where possible the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned; (b) communicate the name and contact details of the data protection officer or other contact point; (c) describe the likely consequences; (d) describe the measures taken or proposed to address the breach, including, where appropriate, measures to mitigate its possible adverse effects. HIPAA §164.408 does not copy Article 33(3); Secretary notice is in the manner specified on the HHS website. Do not file an Article 33(3) form as a HIPAA Secretary notice. | GDPR Article 33(2) does not copy the Article 33(3) list. The processor notifies the controller of the personal data breach; Article 28(3)(f) is a separate processor duty to assist the controller with Articles 32 to 36 — assistance is not the Article 33(1) filing. HIPAA §164.410(c): to the extent possible, the identification of each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed, plus any other available information the covered entity is required to include under §164.404(c), at the time of notification or promptly thereafter. Cal. Civ. Code §1798.82(b) names the owner/licensee notice, not the resident-content headings in §1798.82(d). | GDPR Article 34(2): the communication shall describe in clear and plain language the nature of the personal data breach and contain at least the information and measures referred to in points (b), (c) and (d) of Article 33(3) — DPO/contact point, likely consequences, and measures. It does not copy Article 33(3)(a)'s approximate numbers into the data-subject letter. HIPAA §164.404(c) (that regime, not GDPR), to the extent possible: (A) a brief description of what happened, including the date of the breach and the date of discovery if known; (B) the types of unsecured PHI involved; (C) any steps individuals should take to protect themselves; (D) what the covered entity is doing to investigate, mitigate harm, and protect against further breaches; (E) contact procedures including a telephone number, an e-mail address, Web site, or postal address as that paragraph specifies — written in plain language. Cal. Civ. Code §1798.82(d): titled 'Notice of Data Breach', with the headings What Happened?, What Information Was Involved?, What We Are Doing, What You Can Do, and For More Information, plus the minimum elements in §1798.82(d)(2). A dedicated US-state-laws guide is not on this site yet. |
| Channel | GDPR Article 33(1): notify the supervisory authority competent under Article 55. That is not a customer email and not a data-subject letter. HIPAA §164.408: in the manner specified on the HHS website. HIPAA §164.406 (media; that regime, not GDPR, and not the customer stream): prominent media outlets serving the State or jurisdiction when the breach involves more than 500 residents of that State or jurisdiction — same 60-calendar-day outer mark as §164.404, content matching §164.404(c). Do not treat media notice as individual notice, and do not treat it as Article 34. | GDPR Article 33(2): the processor notifies the controller. The article does not name a portal. YOUR processing contract is often the channel; this page does not interpret it. HIPAA §164.410: the business associate notifies the covered entity. A customer security questionnaire on this product is not that channel. | GDPR Article 34: communication to the data subject; if Article 34(3)(c) (disproportionate effort) applies, a public communication or similar measure instead. HIPAA §164.404(d): written notification by first-class mail to the last known address, or electronic mail if the individual agrees; substitute notice when contact information is insufficient or out of date (different rules under 10 vs 10 or more individuals); additional telephone or other means in urgent situations, on top of written notice. Cal. Civ. Code §1798.82(j): written notice, electronic notice consistent with 15 U.S.C. §7001, or substitute notice when the statutory cost, class-size, or missing-contact tests are met. Those methods are not interchangeable with an Article 33(1) SA filing. |
Processor-to-controller is not controller-to-authority
GDPR Article 33(2) is not Article 33(1). The processor shall notify the controller without undue delay after becoming aware of a personal data breach. The controller shall, under Article 33(1), notify the supervisory authority — unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons — without undue delay and, where feasible, not later than 72 hours after having become aware. Different actor, different recipient, different content, different outer mark. Last verified 7 September 2026. Not legal advice.
- A processor's Article 33(2) email to the controller is not the controller's Article 33(1) notification to the supervisory authority. Do not forward the processor email to the SA and call it done. Article 33(3) content is the controller's authority notice, not the processor's 33(2) sentence.
- Article 33(2) has no 72-hour outer mark. Article 33(1) does. Do not paste 72 hours onto the processor. Do not treat the processor's 'without undue delay' as starting the controller's 72 hours by itself — awareness is a legal and factual test for each actor. This page does not find it on YOUR facts, and it does not start a clock.
- Article 34 is a third duty. The controller communicates to the data subject when the breach is likely to result in a high risk. The processor does not become the Article 34 sender by sending Article 33(2) notice. High risk is not the same test as Article 33(1)'s 'risk'.
- HIPAA's analog of processor-to-controller is §164.410 (business associate to covered entity) — that regime, not GDPR. HIPAA's analog of controller-to-authority is §164.408 (covered entity to the Secretary). HIPAA's analog of individual notice is §164.404. HIPAA §164.406 is media, not a customer notice and not Article 34. Do not relabel those sections as GDPR articles.
- A dedicated GDPR jurisdiction guide is not on this site yet. A dedicated HIPAA jurisdiction guide is not on this site yet. Naming them is not a link.
Checklist per stream
This is a question list, not a filing, and not YOUR notice. Walk each stream with counsel. A yes on one stream does not skip the others. The first-72-hours page on this site is the operational 72-hour plan. The who-to-call page on this site is the contact order. The who-to-notify page on this site is the recipient-class map. The prepare-regulatory-report page on this site is the field checklist. The supporting-evidence page on this site is the evidentiary record.
- Regulator stream: which authority, under which article (GDPR Article 33(1); HIPAA §164.408 as that regime; others as counsel maps). Quote the threshold and the clock-start the article names. Quote Article 33(3) or the HIPAA Secretary manner — do not invent a blended form. Who is authorised to file? A named human files. The product does not.
- Customer stream: are you a processor (Article 33(2)), a business associate (§164.410), a maintainer of data you do not own (§1798.82(b)), or a party to a DPA/MSA notice clause? Those are different instruments. Quote the clock the instrument names. Do not paste Article 33(1)'s 72 hours onto Article 33(2). Do not treat a customer questionnaire as the notice.
- Individual stream: is the Article 34 high-risk test, the HIPAA §164.404 unsecured-PHI test, or a US-state resident-acquisition test the one that may apply? Quote the content list the article names (Article 34(2) citing 33(3)(b)–(d); HIPAA §164.404(c); Cal. Civ. Code §1798.82(d)). Quote the channel. Do not convert Article 34's 'without undue delay' into 72 hours.
- HIPAA media (§164.406) is a fourth stream in that regime when more than 500 residents of a State or jurisdiction are involved. It is not the customer column and not GDPR. If HIPAA may apply, walk it separately with counsel.
- Document a no-notification decision where the article requires it (GDPR Article 33(5) is the example, only if GDPR applies). Mapping is not filing. This page does not start a clock.
Glossary
These are teaching labels for this page. They are not legal conclusions about YOUR facts.
| Term | How this page uses it |
|---|---|
| Regulator stream | Notice to a supervisory authority, Secretary, or similar public authority. GDPR Article 33(1) and HIPAA §164.408 are examples in different regimes. |
| Customer stream | Notice along a controller/processor or covered-entity/business-associate chain, or to the owner/licensee of data you maintain. GDPR Article 33(2), HIPAA §164.410, and Cal. Civ. Code §1798.82(b) are examples. A DPA clause can add a contractual overlay. Not a regulator filing. |
| Individual stream | Communication to the natural person whose data is involved. GDPR Article 34, HIPAA §164.404, and Cal. Civ. Code §1798.82(a) and (d) are examples. Not the customer stream. |
| Article 33(1) | Controller → supervisory authority. 72-hour outer mark from awareness, unless the breach is unlikely to result in a risk to rights and freedoms. Content: Article 33(3). |
| Article 33(2) | Processor → controller, without undue delay after becoming aware. Not Article 33(1). No 72-hour outer mark in that paragraph. Not the Article 33(3) content list. |
| Article 34 | Controller → data subject when the breach is likely to result in a high risk. Without undue delay — not 72 hours. Content: Article 34(2), which pulls Article 33(3)(b)–(d), not (a). |
| HIPAA §164.404 / §164.406 / §164.408 | That regime's individual, media, and Secretary streams. Not GDPR Articles 33 or 34. §164.410 is the business-associate-to-covered-entity analog of a customer notice. |
Where this shows up in ShipReady Metrics
The signed-in app does not send regulator, customer, or individual notices. It does not start these clocks, does not decide whether you must notify, does not file with a regulator, and does not interpret YOUR facts. None of the surfaces below is a breach notice, a customer notification channel, or an instruction to submit a filing.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organization has classified as CRA-in-scope. That is one product tracker for the CRA actively-exploited ladder. It is not a GDPR Article 33 clock, not an Article 34 communication, not a HIPAA §164.404 / §164.406 / §164.408 notice, and not a customer notice. It tracks a clock the organization already recorded. It is not a determination that CRA applies. A named human still submits.
ShipReady Passport is a shareable posture artifact. It is not a breach notice, not a regulator filing, not a customer notification, and not an individual communication. signed-in app → Compliance → Questionnaires drafts answers to customer security questions from recorded posture; those are customer questionnaires, not a notification channel, and they do not send a customer, individual, or regulator notice. The obligation map lists frameworks the organization has marked in-scope. That mark is not a legal opinion that a notification duty applies. The cyber risk register lives under Security. None of those surfaces files a GDPR Article 33 or 34 notice, a HIPAA §164.404 / §164.406 / §164.408 notice, or a California §1798.82 disclosure.
Primary sources (last verified 7 September 2026)
Every regulatory claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2016/679 Articles 33(1)–(3), 33(2), and 34 are legal requirements only when GDPR applies. Article 33(1) is controller-to-authority; Article 33(2) is processor-to-controller; Article 34 is controller-to-data-subject. EDPB Guidelines 9/2022 are regulator guidance on personal data breach notification, not the regulation. HIPAA 45 CFR §§164.404 (individuals), 164.406 (media), and 164.408 (Secretary) — and §164.410 (business associate) — are that US health regime, not GDPR. Cal. Civ. Code §1798.82(d) is a California individual-notice content statute, last checked in the official Legislative Counsel text, including the 1 January 2026 amendment; §1798.82(b) is the owner/licensee (customer-stream analog) notice. These are examples, not a complete world list. Not legal advice.
The do-I-have-to-report page on this site is the class map. The reporting-decision-tree page on this site is the branching tree. The reporting-deadlines page on this site is the statute table. The who-to-notify page on this site is the recipient-class map. The which-jurisdictions-apply page on this site is the applicability map. The prepare-regulatory-report page on this site is the field checklist. The supporting-evidence page on this site is the evidentiary record. The document-your-decision page on this site is the decision record. A dedicated failure-to-report-consequences, how-regulators-determine-knowledge, GDPR, NIS2, DORA, CRA, UK GDPR, US-state-laws, SEC cyber-disclosure, HIPAA, Canada PIPEDA, Australia NDB, India DPDP / CERT-In, and UAE/Dubai guide is not on this site yet. Naming them is not a link.
Frequently asked questions
How do regulator, customer, and individual notices differ?
They are three streams, not one email. GDPR Article 33(1) is controller-to-supervisory-authority (72 hours from awareness, Article 33(3) content). Article 33(2) is processor-to-controller (without undue delay, no 72-hour mark in that paragraph). Article 34 is controller-to-data-subject (high risk, without undue delay, Article 34(2) content). HIPAA §§164.404, 164.406, and 164.408 are that regime's individual, media, and Secretary streams — not GDPR. Last verified 7 September 2026. Not legal advice.
Is this legal advice?
No. It is a three-stream comparison distilled from GDPR Articles 33(1)–(3), 33(2), and 34, HIPAA 45 CFR §§164.404, 164.406, and 164.408, and Cal. Civ. Code §1798.82. Whether any duty applies, which stream is open, and whether a clock has started are legal questions for counsel on your facts. This page does not start a reporting clock.
Does this page start a reporting clock?
No. GDPR Article 33(1) runs from becoming aware; Article 33(2) is without undue delay after the processor becomes aware; Article 34 is without undue delay and is not 72 hours; HIPAA §§164.404 and 164.408 run from discovery. Reading a public page is none of those events. The signed-in CRA ladder tracks recorded awareness for CRA-in-scope findings; it is not a GDPR Article 33 clock.
Is a processor notice to the controller the same as the 72-hour authority notice?
No. Article 33(2) is not Article 33(1). The processor notifies the controller without undue delay; the controller notifies the supervisory authority under Article 33(1), with Article 33(3) content and a 72-hour outer mark from the controller's awareness. Forwarding the processor email to the authority is not the Article 33(1) filing. Not legal advice.
Does ShipReady send regulator, customer, or individual notices?
No. The signed-in app does not send notices, does not file with a regulator, and does not start these clocks. ShipReady Passport is a shareable posture artifact, not a breach notice. Compliance → Questionnaires drafts answers to customer security questions from recorded posture; that is not a notification channel. Compliance → CRA reporting tracks the Article 14 ladder from recorded awareness for CRA-in-scope findings — one product tracker, not GDPR Article 33 or 34.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.