What happens when you fail to report a data breach? Three enforcement cases (€475,000, €600,000, and €400,000) answer that question clearly.
Imagine discovering at 9am on a Monday that your customer database was accessed over the weekend. Names, emails, payment details. All potentially exposed. Your first instinct may be to investigate quietly before saying anything.
Under the General Data Protection Regulation (GDPR), that instinct is legally dangerous. Staying silent is not an option, and the consequences of getting notification wrong, or too late, can be severe. The GDPR's 72-hour rule is not a guideline. It is a binding legal obligation with a separate fine tier for breach.
The scale of the problem is staggering. According to the EDPB's 2024 Coordinated Enforcement Report, supervisory authorities across the EEA processed over 120,000 data breach notifications in 2023 alone, with notification failures remaining among the most frequently sanctioned violations.
This article explains exactly what qualifies as a notifiable breach, who you must notify and when, what those notifications must contain, and how organisations can build a response process that keeps them on the right side of the rule every time.
In this guide:
- What Counts as a Data Breach Under GDPR?
- The Two Notification Obligations
- When Does the 72-Hour Clock Start?
- What Must the Notification Contain?
- When Is Individual Notification Not Required?
- Real Enforcement Cases
- GDPR Breach Notification Fines at a Glance
- Step-by-Step Action Checklist: The First 72 Hours
- How Whisperly Helps
- Frequently Asked Questions
1. What Counts as a Data Breach Under GDPR?
TL;DRA personal data breach under GDPR means any security incident causing unauthorised access, loss, alteration, or destruction of personal data. It covers confidentiality, integrity, and availability failures. Not every security incident qualifies; only those involving personal data and posing a risk to individuals trigger the 72-hour notification obligation.
Article 4(12) GDPR defines a personal data breach as:
"A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed."
Three distinct harm types are covered:
- Confidentiality breach: unauthorised or accidental disclosure or access to personal data
- Integrity breach: accidental or unauthorised alteration of personal data
- Availability breach: accidental or authorised loss of access to, or destruction of, personal data
Common breach scenarios include:
- A hacker accessing a customer database
- An employee accidentally emailing sensitive data to the wrong person
- A laptop containing unencrypted personal data being stolen
- A misconfigured cloud storage bucket left publicly accessible
- A ransomware attack rendering systems and data inaccessible
Not every security incident is a notifiable breach. If personal data is not involved, or if the breach is unlikely to risk individuals' rights and freedoms, the 72-hour notification obligation may not be triggered. Risk assessment is therefore the first and most critical step after discovery.
2. The Two Notification Obligations
TL;DRGDPR imposes two distinct notification duties. Article 33 requires notifying the supervisory authority within 72 hours when a breach poses a risk to individuals. Article 34 requires direct notification to affected individuals when the risk is high. The thresholds differ: 'risk' triggers the DPA obligation, 'high risk' triggers the individual obligation.
GDPR creates two separate notification duties, each with distinct conditions, timelines, and thresholds. Both derive from Chapter IV of the GDPR (Regulation (EU) 2016/679).
Obligation 1: Notify the Supervisory Authority (Article 33) within 72 hours
Under Article 33 GDPR, if a personal data breach is likely to result in a risk to the rights and freedoms of individuals, the controller must notify the relevant Data Protection Authority (DPA) without undue delay and no later than 72 hours after becoming aware of the breach.
This is the lower threshold: a risk to individuals' rights is sufficient to trigger it. It does not require a high risk.
Obligation 2: Notify Affected Individuals (Article 34) Without Undue Delay
Under Article 34 GDPR, when a breach is likely to result in a high risk to the rights and freedoms of individuals, the controller must also notify those individuals directly, without undue delay and in plain language.
The threshold here is higher: a high risk, not merely a risk. This typically applies where the breach could lead to discrimination, identity theft, financial loss, significant reputational damage, or loss of control over personal data. The EDPB's Guidelines 01/2021 provide detailed worked examples for assessing risk level in specific scenarios.
3. When Does the 72-Hour Clock Start?
TL;DRThe 72-hour window begins when the controller becomes aware of the breach, not when the breach itself occurred. Awareness means having a reasonable degree of certainty that personal data has been compromised. If full details are unavailable within 72 hours, GDPR permits phased notification with supplementary information provided later.
The clock starts when the controller becomes aware of the breach, not when the breach occurred.
This distinction matters enormously in practice. A breach that began three weeks ago but was only discovered today triggers a 72-hour window from today, not from three weeks ago.
When a controller is 'aware' will depend on circumstances. In some cases (for example, where a third party notifies the controller with evidence of an unauthorised disclosure), awareness is immediate. In more complex cases, such as a ransomware attack where the scope of personal data affected must be forensically established, awareness may build over time. The EDPB Guidelines 9/2022 on breach notification clarify that a controller can be considered to have become 'aware' when it has a reasonable degree of certainty that a security incident has occurred that has led to personal data being compromised.
GDPR accounts for this through phased notification. If you do not have all required information within 72 hours, you may notify the DPA with what is known and supplement it subsequently. The initial notification must explain why the information is incomplete and when the full notification is expected.
Key point: Document the moment of awareness. This is what supervisory authorities examine first in an enforcement investigation. The timestamp of your internal escalation email or incident ticket is your legal anchor.
4. What Must the Notification Contain?
TL;DRDPA notifications under Article 33(3) must describe the breach nature, categories and numbers affected, DPO contact details, likely consequences, and remedial measures taken. Individual notifications under Article 34(2) require the same core information written in clear, plain language, plus guidance on steps individuals can take to protect themselves.
DPA Notification (Article 33(3))
The notification to the supervisory authority must include at a minimum (Article 33(3) GDPR):
- The nature of the breach, including the categories and approximate number of individuals and data records affected
- The name and contact details of the Data Protection Officer (DPO) or other point of contact
- The likely consequences of the breach
- The measures taken or proposed to address the breach and mitigate its possible adverse effects
Individual Notification (Article 34(2))
Notification to affected individuals must be written in clear, plain language and must describe (Article 34(2) GDPR):
- The nature of the personal data breach
- The name and contact details of the DPO or data protection contact
- The likely consequences of the breach
- Steps taken or proposed to address the breach and mitigate its effects
- Any steps individuals themselves can take to protect themselves
5. When Is Individual Notification Not Required?
TL;DRArticle 34(3) GDPR exempts controllers from notifying individuals in three cases: the data was encrypted or otherwise unintelligible before the breach, subsequent measures eliminated the high risk, or individual notification would require disproportionate effort (in which case public communication suffices). Supervisory authorities interpret these exemptions narrowly.
Under Article 34(3) GDPR, individual notification is not required where any of the following conditions are met:
- The controller had implemented appropriate technical and organisational measures (such as encryption) that render the data unintelligible to any unauthorised person
- The controller has taken subsequent measures that ensure the high risk to individuals no longer materialises
- Notification would involve disproportionate effort; in which case a public communication or equivalent measure may suffice instead
These exemptions are narrowly interpreted by supervisory authorities. Encryption is the most reliable shield, but only if it was applied to the affected data before the breach and was not itself compromised. See the ICO's guidance on personal data breaches for further worked examples on applying these exemptions.
6. Real Enforcement Cases
TL;DRThree landmark fines illustrate the cost of late notification: Booking.com (€475,000 for 22 days' delay), Uber (€600,000 for concealing a breach for over a year), and Østre Toten Municipality (€400,000 for failing to assess and notify properly). In each case, regulators penalised the notification failure more heavily than the breach itself.
Three enforcement actions illustrate what late or absent notification actually costs.
Dutch Booking.com: €475,000 fine
Booking.com (Dutch DPA, 2020) notified the Dutch DPA 22 days after becoming aware of a data breach, far exceeding the 72-hour requirement. Over 4,000 customers had their data accessed, including financial information and passport details. The fine was not for the breach itself; it was for the notification failure.
Uber: €600,000 fine
The Dutch DPA fined Uber €600,000 for failing to notify the supervisory authority and affected individuals within the required timeframe. The breach exposed the personal data of approximately 57 million users and drivers globally. Uber disclosed the incident more than a year after it occurred. The concealment, not the breach, drove the fine.
Østre Toten Municipality (Norway): €400,000 fine
The Norwegian Data Protection Authority (Datatilsynet) fined Østre Toten Municipality approximately €400,000 after a cyberattack exposed sensitive personal data of thousands of residents, including health and social service records. The authority found that the municipality failed to adequately assess the breach and notify affected individuals in a timely manner under Articles 33 and 34 GDPR. The case reinforced that both notification obligations: to the DPA and to individuals, must be discharged correctly.
The pattern across all three cases is consistent: regulators are more lenient about the breach itself and more severe about the failure to notify transparently and promptly.
7. GDPR Breach Notification Fines at a Glance
TL;DRNotification failures under Articles 33 and 34 carry fines up to €10 million or 2% of global annual turnover. Deliberate concealment or underlying security failures enabling the breach can attract the higher tier: up to €20 million or 4% of turnover. The fine applies to whichever amount is greater.
| Violation | Maximum Fine | Example / Source |
|---|---|---|
| Failure to notify DPA within 72 hours (Art. 33) | Up to €10M or 2% of global annual turnover | Booking.com: €475,000 (Dutch DPA, 2020) |
| Failure to notify individuals of high-risk breach (Art. 34) | Up to €10M or 2% of global annual turnover | Østre Toten: €400,000 (Datatilsynet, 2021) |
| Concealment / deliberate delay | Up to €20M or 4% of global annual turnover | Uber: €600,000 (Dutch DPA, 2018) |
| Underlying security failure enabling the breach | Up to €20M or 4% of global annual turnover | British Airways: €22M (ICO, 2021) |
Source: GDPR Enforcement Tracker (CMS Law, updated continuously) · EDPB enforcement actions
For the full GDPR penalty framework, see the GDPR Guidebook penalties section.
8. Step-by-Step Action Checklist: The First 72 Hours
TL;DRA compliant breach response follows six stages within 72 hours: contain and document the incident, assess the risk to individuals, engage your DPO, notify the supervisory authority with available information, notify affected individuals if the risk is high, then remediate and follow up with corrective measures and updated documentation.
Step 1: Contain and document (Hour 0)
- Isolate affected systems to prevent ongoing data loss
- Record the time and method of discovery. This is your awareness timestamp
- Identify the categories of data involved and the approximate number of individuals affected
- Preserve logs and evidence for the investigation
Step 2: Assess the risk (Hours 0 to 6)
- Determine whether personal data is involved
- Evaluate the likelihood and severity of risk to individuals' rights and freedoms
- Classify: no notification required / notify DPA only / notify DPA and individuals
- Document your risk assessment reasoning, even if you decide not to notify
The EDPB's risk assessment guidelines provide a detailed framework for this step, including worked examples across healthcare, financial, and HR data categories.
Step 3: Engage your DPO (Hours 0 to 6)
- Notify your Data Protection Officer immediately. They should lead the response
- If you do not have a DPO, engage legal counsel or a GDPR adviser
- Establish a breach response team across IT, legal, and communications
Step 4: Notify the DPA (Hours 6 to 72)
- Submit notification to the relevant DPA. Partial notification is permitted if investigation is incomplete
- Include all available information under Article 33(3): nature of breach, DPO contact, likely consequences, measures taken
- If the full notification will take more than 72 hours, explain why and provide a timeline
- Keep a record of all notification communications and timestamps
Find your national supervisory authority on the EDPB members page.
Step 5: Notify affected individuals if required (Hours 24 to 72)
- If the breach poses a high risk to individuals, notify them directly, in clear, plain language per Article 34(2)
- Explain the breach, its likely effects, and any steps they can take to protect themselves
- Consider whether public communication is appropriate or required
Step 6: Remediate and follow up (Post-72 hours)
- Complete the full investigation and update the DPA with any information not included in the initial notification
- Implement corrective measures: patch vulnerabilities, update access controls, revise security procedures
- Update your Records of Processing Activities (RoPA) to reflect the incident
- Document the full incident record. Article 33(5) GDPR requires controllers to document all breaches, including those below the notification threshold
- Review whether a DPIA is needed for the affected processing activity going forward
9. How Whisperly Helps
Meeting the 72-hour notification requirement depends on having your data privacy compliance infrastructure in place before a breach occurs, not scrambling to build it during one.
Whisperly automates the documentation and workflow processes that make fast, compliant breach response possible:
- RoPA automation: know exactly what data you hold and where, so you can assess breach scope within hours, not days
- DPIA automation software: pre-assess high-risk processing activities before a breach occurs, reducing risk classification time in an incident
- Incident logging and documentation: automated audit trail of breach discovery, risk assessment, and notification decisions
- Vendor assessment: identify sub-processor breach risks, respond to vendor security questionnaires, and ensure Article 28 GDPR processor obligations are contractually covered
- Trust Center: demonstrate your security posture proactively to customers and regulators
Bring all your GDPR compliance documentation: RoPA, DPIAs, DPA templates, breach logs. Together in Whisperly's data privacy compliance platform. Everything you need for a compliant breach response, ready before you need it.
10. Frequently Asked Questions
Does every data breach need to be reported under GDPR?
No. Only breaches that are likely to result in a risk to the rights and freedoms of individuals must be reported to the DPA (Article 33 GDPR). Breaches very unlikely to result in such a risk do not trigger the obligation. However, all breaches must be documented internally under Article 33(5) regardless of whether external notification is required.
What is the 72-hour rule exactly?
Under Article 33 GDPR, a controller must notify its supervisory authority of a reportable personal data breach within 72 hours of becoming aware of it. If notification is not possible within 72 hours, it must be submitted without undue delay and accompanied by reasons for the delay. Phased notification is permitted. You may submit what you know and supplement it later.
Who must be notified: the DPA, the individuals, or both?
It depends on the risk level. A breach posing a risk to individuals' rights triggers DPA notification (Article 33). A breach posing a high risk additionally requires individual notification (Article 34). The risk assessment, conducted promptly after discovery, determines which obligations are triggered.
What if we don't have all the information within 72 hours?
GDPR expressly permits phased notification. Submit what you know within 72 hours and provide a timeline for the full notification. The initial submission must include an explanation of why the information is incomplete. The EDPB Guidelines 9/2022 confirm this approach and provide practical guidance on phased submissions.
Do processors also have notification obligations?
Yes. Under Article 33(2) GDPR, a data processor that becomes aware of a breach must notify the controller without undue delay. The controller then assesses whether to notify the DPA. Processor notification obligations should be set out in your Data Processing Agreements (DPAs).
What does a DPO do in a breach response?
The Data Protection Officer (DPO) is the central coordinator in any breach response. They advise on risk classification and notification thresholds, liaise with the supervisory authority, oversee internal documentation, and ensure the response meets GDPR requirements. If you are unsure whether your organisation needs a DPO, use our DPO requirement checker.
How do we document a breach if we decide not to notify?
Under Article 33(5) GDPR, controllers must document all personal data breaches, including those that do not meet the notification threshold. The documentation must record the facts of the breach, its effects, and the remedial action taken. It must also explain the reasoning for not notifying the DPA. This internal record is the first thing a supervisory authority will request in any subsequent investigation.
Your data processing agreements should specify breach notification timelines and responsibilities between controllers and processors.
Breach notification records and response history are among the 12 areas regulators examine. For the full pre-audit checklist, see our GDPR audit readiness guide.
Further Reading on Whisperly
Questions & Answers
Does every data breach need to be reported under GDPR?+
No. Only breaches that are likely to result in a risk to the rights and freedoms of individuals must be reported to the DPA (Article 33 GDPR). Breaches very unlikely to result in such a risk do not trigger the obligation. However, all breaches must be documented internally under Article 33(5) regardless of whether external notification is required. For a full overview of GDPR compliance requirements, see the GDPR compliance guide.
What is the 72-hour rule exactly?+
Under Article 33 GDPR, a controller must notify its supervisory authority of a reportable personal data breach within 72 hours of becoming aware of it. If notification is not possible within 72 hours, it must be submitted without undue delay and accompanied by reasons for the delay. Phased notification is permitted. For guidance on building compliant processes, see the GDPR Guidebook.
Who must be notified: the DPA, the individuals, or both?+
It depends on the risk level. A breach posing a risk to individuals' rights triggers DPA notification (Article 33). A breach posing a high risk additionally requires individual notification (Article 34). The risk assessment, conducted promptly after discovery, determines which obligations are triggered. A DPIA conducted beforehand helps classify risk faster during an incident.
What if we don't have all the information within 72 hours?+
GDPR expressly permits phased notification. Submit what you know within 72 hours and provide a timeline for the full notification. The initial submission must include an explanation of why the information is incomplete. The EDPB Guidelines 9/2022 confirm this approach and provide practical guidance on phased submissions.
Do processors also have notification obligations?+
Yes. Under Article 33(2) GDPR, a data processor that becomes aware of a breach must notify the controller without undue delay. The controller then assesses whether to notify the DPA. Processor notification obligations should be set out in your Data Processing Agreements (DPAs). For more on processor obligations, see the GDPR Guidebook.
What does a DPO do in a breach response?+
The Data Protection Officer (DPO) is the central coordinator in any breach response. They advise on risk classification and notification thresholds, liaise with the supervisory authority, oversee internal documentation, and ensure the response meets GDPR requirements. If you are unsure whether your organisation needs a DPO, use the DPO requirement checker.
How do we document a breach if we decide not to notify?+
Under Article 33(5) GDPR, controllers must document all personal data breaches, including those that do not meet the notification threshold. The documentation must record the facts of the breach, its effects, and the remedial action taken. It must also explain the reasoning for not notifying the DPA. This internal record is the first thing a supervisory authority will request in any subsequent investigation. Automate this process with a data privacy compliance platform.

Written by
Marta Lukovic
Marta Luković is an Attorney at Law specialising in Data Protection, IT Law, and AI Law. She advises companies across Southeast Europe on GDPR compliance, cross-border data transfers, and regulatory risk management. Recognised for her practical, commercially aware approach to privacy law, she works closely with technology companies navigating complex regulatory environments across multiple jurisdictions.
Reviewed by: Anja Beric