8 July 2026 · Legal position as of: August 2026

Data breach: the 72-hour deadline runs from awareness

Most data protection breaches are not hacking attacks but everyday occurrences: an email with an open distribution list, a lost laptop, a network folder with the wrong permissions. Legally that makes no difference – the notification duty does not depend on the cause.

What starts the clock

A personal data breach must be reported to the data protection authority within 72 hours of becoming aware of it, provided it poses a risk to the individuals concerned. What matters is the point at which the organisation can establish with sufficient certainty that an incident has occurred – not the completion of the internal investigation. Waiting for the full analysis is regularly too late; the notification can expressly be supplemented in stages.

Where the risk is high, the individuals concerned must also be informed, without undue delay and in clear, plain language.

Incidents that need no notification still need documenting

Every incident must be documented internally – including those that are not reported. That documentation is the evidence that an assessment took place. Without it, the suggestion in any review is that no assessment was made at all.

A procedure that must exist beforehand

72 hours are not enough to first work out who is responsible. A short, practised procedure helps:

  • Who reports internally, and to whom? A named point of contact, reachable on a Friday afternoon too.
  • Who assesses the risk? By the type of data, the number of people affected and the possible consequences.
  • Who decides on notification, and who drafts it?
  • Who informs those affected, and through which channel?
  • Where is it documented? A simple form is enough; it only has to exist and be used.

Involving processors

If the incident occurs at a service provider – payroll, IT support, cloud storage – they must inform you without undue delay; the duty to notify the authority remains yours. That is precisely why this information duty belongs in every processor agreement, with a concrete deadline rather than the usual formula "without undue delay".

This information is general in nature and does not replace legal advice on an individual case.

More on this practice area: Data Protection Law (GDPR)