LinkedInInstagramXTikTok

GDPR data breaches: the 72-hour notification rule and how to prepare

A laptop is stolen from a car. A misconfigured database is left open to the internet. An employee emails a spreadsheet of customer details to the wrong recipient. Each of these is a personal data breach, and each can start a clock that few organisations are ready to run: under the GDPR, a reportable breach must reach the supervisory authority within 72 hours.

What counts as a personal data breach

The GDPR defines a personal data breach broadly. It is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. That definition captures far more than hacking. It includes losing a device, deleting records without a backup, ransomware that encrypts data you can no longer reach, and sending information to the wrong person.

Breaches are usually grouped into three types: confidentiality breaches, where data is disclosed or accessed without authorisation; integrity breaches, where data is altered; and availability breaches, where data is lost or destroyed or made inaccessible. A single incident can be more than one at once – ransomware, for example, is both an availability and often a confidentiality breach.

The 72-hour rule

Article 33 requires the controller to notify the competent supervisory authority – in Sweden, the Authority for Privacy Protection (IMY) – without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach. The clock starts at awareness, not at the moment the breach occurred, and awareness means having a reasonable degree of certainty that a security incident has compromised personal data.

There is one exception to the duty to notify the authority: notification is not required where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. That is a risk assessment, and it must be made and documented for every breach, including those you decide not to report.

If the 72 hours cannot be met, the notification may be made late, but it must then be accompanied by reasons for the delay. Information may also be provided in phases where it is not all available at once, so a lack of complete facts is not a reason to stay silent past the deadline.

When you must also tell the individuals

Article 34 imposes a separate duty. Where a breach is likely to result in a high risk to the rights and freedoms of individuals, the controller must also communicate the breach to those affected, without undue delay and in clear, plain language.

There are limited exceptions: where the data was protected by measures such as strong encryption that render it unintelligible; where subsequent measures have removed the high risk; or where individual communication would involve disproportionate effort, in which case a public communication may suffice. Notifying individuals is also a matter of trust, and organisations that communicate well often preserve relationships that silence would destroy.

What the notification must contain

A notification to the authority must describe the nature of the breach, including the categories and approximate number of individuals and records concerned; the name and contact details of the data protection officer or other contact point; the likely consequences of the breach; and the measures taken or proposed to address it and to mitigate its effects. If you do not yet have all of this, you provide what you have and follow up.

Practical example: the misdirected email

An administrator at a Swedish company sends a payroll spreadsheet, containing names, salaries and personal identity numbers for two hundred employees, to an external supplier by mistake. The error is noticed within an hour.

This is a confidentiality breach, and personal identity numbers combined with salary data create a real risk. The company contacts the recipient, obtains written confirmation that the email has been deleted and not forwarded, and records that step. It then assesses the residual risk, concludes that notification to IMY is warranted, and reports within the 72-hour window. Because the recipient was a known and cooperative party and the exposure was contained quickly, the company may conclude that the high-risk threshold for notifying every employee is not met – but it documents that reasoning carefully, because the assessment is exactly what an authority will later examine.

Common mistakes companies make

Starting the clock too late. The 72 hours run from awareness, and an organisation cannot delay awareness by failing to investigate a credible report.

Assuming a processor handles it. Where a supplier acting as processor suffers the breach, it must notify the controller without undue delay, but the duty to notify the authority remains with the controller. Contracts and escalation paths must make this work in practice.

Failing to document breaches that are not reported. Article 33 requires a record of all breaches, including the facts, effects and remedial action, whatever the reporting decision. The absence of that log is itself a finding.

Treating notification as an admission of fault. Reporting is a legal obligation, and authorities distinguish sharply between organisations that report and cooperate and those that conceal.

Having no plan, so that the first 72 hours are spent deciding who is responsible rather than containing the incident.

Recommended actions

Write and rehearse an incident response plan that defines what a breach is, who must be told internally and how fast, who assesses risk, who decides on notification, and who drafts it. Make the escalation path short enough to work at night and at weekends.

Train staff to recognise and report incidents immediately, since most breaches are discovered by ordinary employees rather than security systems. Maintain a breach register from the first incident, review your processor contracts for notification timelines, and reduce the risk in advance through encryption, access controls and data minimisation – less data held, and better protected, means fewer breaches that reach the reporting threshold.

Frequently asked questions

Does every breach have to be reported?

No. Only breaches likely to result in a risk to individuals must be reported to the authority, and only high-risk breaches must be communicated to individuals. But every breach must be assessed and recorded, including those you decide not to report.

What if we discover the breach on a Friday evening?

The 72-hour period runs continuously and includes weekends. This is precisely why the response plan must function outside office hours, with a contact who can act.

What are the penalties for getting it wrong?

Failure to notify can itself be sanctioned, with administrative fines under the GDPR’s framework reaching up to €10 million or 2% of worldwide annual turnover for breaches of the notification obligations, separate from any fine for the underlying security failure.

Conclusion

The 72-hour rule rewards preparation and punishes improvisation. The organisations that handle breaches well are not the ones that never suffer them – they are the ones that recognise an incident quickly, assess the risk methodically, document every decision, and report within the deadline when required. Everything that makes that possible has to be built before the breach, not during it.

Lawgent helps organisations build and test incident response plans, assess breach risk and notification obligations, prepare notifications to IMY and to affected individuals, and strengthen the processor contracts and data governance that keep breaches contained. Get in touch to review your readiness before the clock starts.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop