Reporting a Data Breach Under GDPR: Step by Step in 72 Hours

Martin Bastius
17.06.2026
5
min.

What Is a Data Breach Under GDPR?

A single wrong click or a cyberattack is all it takes — and suddenly your company is under massive pressure. Once sensitive data starts leaking, the clock is ticking. GDPR leaves controllers little room to maneuver in a crisis and demands fast, error-free action. Anyone who acts without structure risks not only reputational damage but also steep fines — especially as new regulations like the NIS2 Directive further increase the pressure on IT security in 2026. This practical guide shows you step by step how to contain a data leak in a structured way, assess the risk, and confidently meet the critical 72-hour deadline. To keep your company ready to act in an emergency, let's start with the most important foundation.

What Is a Data Breach Under GDPR?

A data breach (referred to in the legal text as a personal data breach) is any type of security incident in which personal data is accidentally or unlawfully lost, destroyed, altered, disclosed without authorization, or accessed without authorization.

Typical examples from everyday business are:

  • Hacking attacks & ransomware: Encryption or exfiltration of customer data by cybercriminals.
  • The classic e-mail mistake: Accidentally sending spreadsheets containing salary or customer data to the wrong recipient.
  • Lost hardware: Leaving a company laptop on the train or losing an unencrypted USB drive.
  • Internal missteps: Employees accessing personnel files without a legitimate reason.
  • Technical mishaps: Cloud storage misconfigurations (e.g., AWS or Azure) that leave databases exposed on the open internet.

A data breach is not automatically subject to a reporting obligation. What matters is always whether the incident creates a risk to the rights and freedoms of the affected individuals.

Reporting Obligations Under Art. 33 and 34 GDPR — An Overview

The legal basis for crisis management in data protection rests on two central pillars:

  • Art. 33 GDPR (notifying the authority): Sets out the obligation to notify the competent data protection supervisory authority of a personal data breach without undue delay — and, wherever possible, within 72 hours of becoming aware of it. This applies whenever the event poses a risk to those affected.
  • Art. 34 GDPR (notifying affected individuals): Describes when you must inform the affected individuals (customers, employees, users) directly. This is mandatory whenever the breach is likely to result in a high risk (e.g., a threat of identity theft or financial harm).

Important for when the clock starts: The 72-hour deadline begins the exact moment the data breach becomes known within the company — meaning as soon as the first employee recognizes the incident as such.

The First Hours After Discovery: The 5-Step Process

As soon as a potential data breach is on the table, a structured approach determines whether you face a fine or successfully limit the damage. Proceed chronologically:

  1. Immediately log the incident: Document the relevant facts (What happened? When was it noticed? Which categories of data are affected?).
  2. Trigger internal alerts: Immediately notify the responsible party within the company (data protection officer, IT lead, management).
  3. Contain the technical damage: Take immediate emergency measures (e.g., disconnect affected servers, lock compromised user accounts, secure backups).
  4. Conduct an initial risk assessment: Have IT and data protection jointly assess whether there's a risk to the rights of those affected.
  5. Check communications & deadlines: Determine next steps and prepare the notification to the authority to meet the 72-hour deadline.

Assessing the Data Breach: When Must You Report It?

The risk assessment is the legal crux of the matter. If you mistakenly assess the risk as "non-existent" and stay silent about the breach, you risk hefty fines.

To conduct a proper risk assessment, you need to analyze the following factors:

  • Type and sensitivity of the data: Are we talking about simple addresses, or highly sensitive data such as health data, passwords, credit card details, or bank information?
  • Extent of potential harm: How likely and how severe are the possible consequences for those affected (e.g., phishing waves, identity theft, damage to professional reputation)?
  • Recipients involved: Is the data in the hands of known, trustworthy third parties (e.g., mistakenly e-mailed to a long-standing partner who confirms deletion), or was it posted by cybercriminals on the dark web?
  • Effectiveness of protective measures: Was the data encrypted strongly enough (e.g., AES-256) that it's technically unreadable to unauthorized third parties? If so, there's usually no risk.
Practical tip: The line between a "normal" and a "high" risk is fluid and, in an emergency, nearly impossible for non-experts to assess with legal certainty. Getting this wrong can leave managing directors personally liable. To avoid wasting time during the critical 72-hour window, smart companies rely on digital compliance platforms like heyData. With an External Data Protection Officer at your side, you can professionalize your risk assessment immediately, so you make the right call in an emergency and submit a legally sound notification.

Documenting and Reporting the Data Breach

Regardless of whether a data breach ultimately has to be reported or not: under Art. 33(5) GDPR, there is a strict internal obligation to document every single data breach. If a supervisory authority ever audits you, you must be able to present this "record of sins" in full.

The documentation must include:

  • The exact facts of the incident and its effects.
  • The categories of data affected and the number of individuals affected.
  • The remedial measures taken to mitigate the damage.
  • The justification for why the incident was, or was not, reported.

The official notification to the competent state data protection authority is typically submitted via the relevant state authority's online reporting portal (depending on the German state where the company is headquartered).

Communicating With Affected Individuals: When Is Notification Necessary?

If the risk assessment reveals a high risk to those affected, Art. 34 GDPR applies. You must inform the affected individuals without undue delay and in clear, plain language.

The notification to affected individuals must contain the following elements:

  • A clear description of the nature of the data breach.
  • The contact details of the data protection officer for follow-up questions.
  • The likely consequences of the incident for the individual.
  • Concrete recommendations: What can affected individuals do to protect themselves (e.g., change passwords, check account statements, stay alert for suspicious calls)?

Helpful Tools, Checklists, and Templates

A structured process protects you from mistakes made under time pressure. The following tools should be readily available in your data protection handbook:

  • Data breach checklist: A clear protocol that the IT department launches at the first suspicion of a breach.
  • Sample notification letters: Pre-drafted text blocks for communicating with affected individuals, so you don't waste time on wording in an emergency.
  • Internal data breach incident log: A standardized template for fulfilling the legal documentation requirement.
  • Cyber incident response platforms: Software-supported workflows that automate the notification sequence within the company.

Preparing Through Training and Processes: How to Avoid Chaos

In 2026, in addition to GDPR, stricter European IT security laws such as NIS2 (for critical and important sectors) and DORA (for the financial market) also come into play. These often require parallel initial notifications to Germany's BSI within just 24 hours in the event of an IT security incident.

You can only prevent chaos in an emergency through proactive preparation:

  • Regular employee awareness training: Most data breaches stem from human error (phishing, misdirected e-mails). Ongoing training is the best prevention.
  • Clear escalation chains: Every employee needs to know: Who do I contact if I suspect data has been leaked?
  • Tabletop simulations: Run simulated emergency scenarios (e.g., a ransomware attack on a Friday afternoon) with IT leadership, the data protection officer, and management.

Conclusion

Reporting a data breach within the GDPR deadline is a complex process under time pressure, but one that's entirely manageable with the right preparation. Closing the technical security gap, conducting the legal risk assessment, and completing the formal documentation must all go hand in hand. Companies that establish clear responsibilities, use prepared checklists, and rely on professional, technology-supported assistance can turn a potential existential crisis into a well-managed compliance process.

FAQ

What happens if I only discover a data breach after 100 hours?

The GDPR's 72-hour deadline only starts upon actual discovery ("becoming aware"). As soon as you or an employee in the company knows beyond doubt that a breach has occurred, the clock starts ticking. The time between the actual incident and its discovery isn't legally held against you as a missed deadline — unless the company was grossly negligent in failing to monitor its IT systems.

Do Saturdays and Sundays count toward the 72-hour deadline?

Yes. The GDPR doesn't distinguish between working days, public holidays, and weekends. The 72 hours run strictly by the calendar. If you discover a breach on Friday afternoon, the notification must reach the authority by Monday afternoon at the latest. An emergency process for the weekend is therefore mandatory for every company.

Do I have to submit the full notification to the authority right away?

No. If not all details have been clarified shortly after the incident, Art. 33(4) GDPR explicitly allows a step-by-step notification (notification in phases). What matters is that you submit the core facts within the 72 hours and state that you'll provide further information as soon as IT forensics delivers new findings.

Can I avoid a fine if I report the breach voluntarily?

Self-reporting doesn't provide absolute protection against fines, but data protection authorities view it extremely favorably and as a mitigating factor. Deliberately concealing or belatedly reporting a demonstrably notifiable data breach, on the other hand, almost always leads to drastically higher sanctions and reputational damage.

Who bears ultimate responsibility for the notification within the company?

Ultimate legal responsibility rests non-transferably with the management (the legal representative of the controller). The data protection officer has an advisory and supporting role but must not make the strategic and liability-relevant decision about the notification alone.

Published
17.06.2026
Martin Bastius
Co-Founder & CLO

More articles

View all articles
Compliance in Practice
8/14/26

Compliance software vs. legal expertise: What your company really needs for modern compliance

Compliance software vs. legal expertise: What your company really needs for modern compliance
Data Protection & GDPR
4/3/24

Secure Handling of Ex-Employee Emails Under GDPR

Secure Handling of Ex-Employee Emails Under GDPR
AI & Data Governance
7/11/25

Balancing Trust and Control: How to Make AI-Recorded Online Meetings GDPR-Compliant

Balancing Trust and Control: How to Make AI-Recorded Online Meetings GDPR-Compliant
Discover all stories