
You must report likely personal data breaches to your regulator within seventy-two hours of becoming aware of them. This rule focuses on timely transparency rather than waiting for full investigation. It applies to any organisation processing EU resident data, regardless of where you are located.
The Leaking Pipe Analogy
Imagine your data protection system is a complex network of water pipes under a city. A breach is not just a burst pipe flooding the streets. It is also a slow leak in a basement that no one sees. The GDPR notification rule is the requirement to call the city engineer the moment you smell dampness or hear dripping. You do not wait for the floor to collapse. You do not wait to identify exactly which pipe is faulty. You act on the suspicion of a leak because the risk of structural damage is real.
This analogy helps you understand why the timer starts so early. In cybersecurity, waiting for proof of exfiltration is like waiting for the ceiling to fall in. By then, the damage is irreversible. The regulation prioritises early warning over perfect information.

Defining the Incident
You must distinguish between a security incident and a personal data breach. A security incident is any event that compromises the confidentiality, integrity, or availability of systems. A personal data breach is a specific type of incident where personal data is accessed, lost, or altered without authorisation.
Not every security incident is a reportable breach. If a hacker scans your firewall but finds no personal data, you have had a security incident, but not a data breach. Conversely, if a staff member accidentally deletes a backup of customer records, that is a breach of availability, even if no one stole the data. You must classify the event correctly to determine your next steps.
The Seventy-Two Hour Clock
The rule requires notification to the supervisory authority within seventy-two hours of becoming aware of the breach. Becoming aware is the critical trigger. This is the moment your security team identifies an anomaly that suggests a breach has occurred. It is not the moment you finish your forensic investigation.
This tight window exists to allow regulators to assess risk and coordinate responses. It also forces organisations to have rapid detection capabilities. If you rely on manual log reviews that take days, you will likely miss the deadline. Automated tools like database activity monitoring can help surface these anomalies faster, reducing the time between incident and awareness.
When You Can Skip Reporting
You are not required to notify the authority if the breach is unlikely to result in a risk to the rights and freedoms of natural persons. This is a high bar. You must document your reasoning for not reporting.
Suppose a single encrypted laptop is lost. If the encryption key was stored separately and remains secure, the risk to the data subjects is minimal. You might decide not to report. However, if the encryption was weak or the key was compromised, the risk is high, and you must report. This decision requires technical confidence. You should review your encryption at rest policies to ensure they meet this standard.
The Mini Glossary
| Term | Plain meaning |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person. |
| Data Breach | A security incident leading to unauthorised access, loss, or alteration of personal data. |
| Supervisory Authority | The national regulatory body responsible for enforcing data protection laws. |
| Controller | The entity that determines the purposes and means of processing personal data. |
| Processor | The entity that processes personal data on behalf of the controller. |
| Awareness | The point in time when the controller knows or should reasonably know of the breach. |
See also: Serverless Incident Response: Containment, Recovery and Prevention Steps · Rainbow Table Attack Response: Contain, Recover and Prevent Credential Theft
Communicating with Affected People
If the breach is likely to result in a high risk to individuals, you must also communicate this directly to them. This is distinct from the regulatory notification. The communication should be clear, concise, and free of jargon.
You should explain what happened, what data was involved, and what steps the individual can take. This might include advice on changing passwords or watching for suspicious activity. For guidance on crafting these messages, see our section on customer breach notification letters. The goal is to empower the individual to protect themselves, not to assign blame.
Common Points of Confusion
Many organisations confuse the GDPR with other notification requirements. For example, fraud alerts are financial warnings, not regulatory notifications. Misdirected emails are a common cause of breaches, but the notification rule applies regardless of the cause.
Another confusion is the scope. The GDPR applies to any organisation processing the data of EU residents, even if the organisation is not based in the EU. You cannot ignore the rule because your servers are elsewhere. If you handle EU data, you are subject to the rule.
Try This Now
- Map your data flows to identify where personal data is stored and processed. You cannot protect what you cannot see.
- Test your incident response plan with a simulated breach. Measure the time from detection to awareness.
- Review your encryption standards. Ensure that full disk encryption is enabled on all devices holding personal data.
Key takeaways
- Awareness triggers the timer, not confirmation of harm.
- Not every incident requires immediate regulatory reporting if risk is low.
- Clear definitions of personal data and breach prevent costly delays.
The clock starts when you suspect a breach, not when you prove it. Implement automated monitoring to reduce detection time and avoid regulatory penalties.
Frequently asked questions
Do I need to report if I am not based in Europe?
Yes, if you process the personal data of individuals in the European Union, the GDPR applies to you regardless of your physical location.
What if I am still investigating the scope of the breach?
You must still notify within seventy-two hours. You can provide initial information and then submit a subsequent communication with more details as they become available.
Does this apply to employee data?
Yes, employee data is personal data. A breach involving staff records is subject to the same notification requirements as customer data.
Who is the supervisory authority?
It is the national data protection agency in the EU country where your main establishment is located, or where the breach primarily occurred.
How this guide was produced: written by the Payload Report editorial team with AI assistance, checked against the public references listed below, and reviewed when the facts change. See our editorial policy or report an error.



