Article 33 of the GDPR is one of the most cited and least precisely understood parts of the regulation. "72 hours" sounds simple until you actually have an incident and start asking: 72 hours from what, exactly? Notify who? With what level of detail, when you may not even know the full scope yet? Here's what the rule actually requires.

What counts as a "personal data breach"

GDPR's definition (Article 4(12)) is broader than most people expect. A personal data breach is any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data. That covers a lot more than a hacker exfiltrating a database — it includes an employee emailing a spreadsheet of customer data to the wrong recipient, a lost unencrypted laptop, a misconfigured storage bucket left publicly accessible, or a ransomware attack that encrypts data even if nothing was copied out.

Confidentiality breaches (unauthorized access or disclosure) get the most attention, but integrity breaches (unauthorized alteration) and availability breaches (data becoming inaccessible or destroyed, including from a ransomware attack with no working backup) count too.

When the clock actually starts

This is the detail most people get wrong: the 72 hours starts from when your organization becomes aware of the breach, not from when the breach actually occurred. If an attacker was in your systems for three weeks before you detected it, your notification clock starts at detection, not intrusion. "Awareness" generally means having a reasonable degree of certainty that a breach has occurred — a vague anomaly in a log isn't necessarily awareness, but confirming that log entry represents unauthorized access is.

72 hours is not a lot of time once you're in it, particularly across a weekend or when the scope is still unclear. This is why having an incident response process that defines who makes the call, and how, matters more than having the notification template ready — by the time you need the template, you should already know who's authorized to send it.

Who you have to notify

Two separate obligations, triggered differently:

What the notification has to contain

Article 33(3) sets out the minimum content for the supervisory authority notification:

If you don't have every detail yet, that's expected — the phased approach exists precisely because full forensic detail rarely exists within 72 hours. What matters is that you notify with what you know and commit to follow-up.

Exceptions to notifying data subjects

Article 34(3) lets you skip individual notification in three situations: the affected data was encrypted or otherwise unintelligible to anyone without the key; you've taken subsequent measures that eliminate the high risk; or individual notification would involve disproportionate effort, in which case a public communication (a notice on your site, for example) can substitute for direct notice.

A practical readiness checklist

An Incident Response Plan that names an owner and a process is the foundation for meeting this deadline.

Generate a GDPR Incident Response Plan