Data Security & Breach Notification
General Data Protection Regulation — security of processing and personal data breach notification
European Union · May 25, 2018
Art. 33 requires notifying the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to people's rights and freedoms; a late notification must carry reasons for the delay. Art. 34 separately requires telling affected individuals without undue delay where the breach is likely to result in a HIGH risk to them — the two thresholds are different, and only the authority-facing one has a clock. Art. 32 is the standing obligation the other two hang off: security appropriate to the risk, judged against state of the art and cost. Two practical points a reviewer should confirm for a specific business: the 72 hours run from awareness that a breach has probably occurred, not from full technical certainty (EDPB Guidelines 9/2022), and the one-stop-shop only applies if you have a main establishment in the EU — a controller relying on an Art. 27 representative may have to notify each affected member state's authority separately.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.