GDPR Data Breach Notification: 72-Hour Rule Explained (2026)

Independently fact-checked against primary sources (last audited September 11, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 11, 2026. · 19 primary sources cited on this page. How we verify our legal content

GDPR Data Breach Notification: 72-Hour Rule Explained (2026)

Frequently Asked Questions

What is the 72-hour rule under GDPR?

Under Article 33(1), data controllers must notify their competent supervisory authority within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to individuals' rights and freedoms. The notification must be made without undue delay and, where feasible, within the 72-hour window. If it is not made within 72 hours, it must be accompanied by a reasoned justification for the delay. The clock starts when the controller has a reasonable degree of certainty that a breach has occurred, not when the investigation is complete.

Do all data breaches need to be reported to the supervisory authority?

No. Only breaches that are likely to result in a risk to individuals' rights and freedoms must be reported to the supervisory authority. However, all breaches, including those that do not meet the notification threshold, must be documented in the internal breach register under Article 33(5). When the risk assessment is uncertain, the EDPB recommends erring on the side of notifying.

What is the difference between notifying the supervisory authority and notifying data subjects?

Article 33 requires notification to the supervisory authority when a breach poses a risk to individuals (the lower threshold), within 72 hours. Article 34 requires notification to data subjects when a breach is likely to result in a high risk (the higher threshold), without undue delay. Not every breach that must be reported to the DPA also requires individual notification. Data subject notification is not required if the data was encrypted and the key was not compromised, if the risk has been effectively mitigated, or if individual contact would require disproportionate effort (in which case a public communication is required instead).

When exactly does the 72-hour clock start?

The clock starts when the controller has a reasonable degree of certainty that a security incident has occurred and that personal data was affected. For breaches detected by internal systems, awareness starts when a responsible person acknowledges the alert as indicating a likely breach. For breaches reported by a processor, awareness starts when the controller receives the notification. For external reports, awareness starts when the controller receives credible information. The clock does not wait for the investigation to finish.

What must a processor do when it discovers a breach?

Under Article 33(2), processors must notify the controller without undue delay after becoming aware of a breach. The GDPR sets no fixed hour limit on the processor. EDPB Guidelines 9/2022 paragraph 45 recommends that the processor notify the controller promptly, with further detail in phases, so that the controller can still meet its own 72-hour deadline. The 72 hours belongs to the controller, not the processor: a processor that takes 72 hours has already used up the controller's whole window. Data processing agreements under Article 28 should specify maximum notification windows (commonly 24 hours) and the minimum information the processor must provide.

Can breach notification be provided in phases?

Yes. Article 33(4) explicitly permits phased notification. If all required information is not available within 72 hours, the controller should submit an initial notification with whatever information is available within the 72-hour window and provide supplementary information without undue further delay. This mechanism exists precisely because breach investigations take time. Filing a phased notification is far better than waiting for the complete picture and missing the deadline entirely.

What information must be included in the notification to the supervisory authority?

Article 33(3) requires: the nature of the breach including the categories and approximate number of data subjects and data records affected; the name and contact details of the DPO or another contact point; a description of the likely consequences of the breach; and the measures taken or proposed to address the breach, including measures to mitigate possible adverse effects. The Meta DPC decision of December 2024 shows that incomplete notifications missing required content are treated as a separate Article 33(3) violation.

What should go in the breach register?

Article 33(5) expressly requires three things: the facts of each breach (what happened, how, when discovered), its effects on individuals, and the remedial action taken. Because the documentation must also let the supervisory authority verify compliance, the EDPB and national DPAs expect the register to record the risk assessment and its reasoning, and the rationale for notifying or not notifying the supervisory authority and the affected individuals. The register covers all breaches, not just reported ones. It must be available to the supervisory authority on request and is the primary audit trail for breach compliance.

How does the GDPR 72-hour rule compare to HIPAA and US state laws?

The GDPR's 72-hour window for supervisory authority notification is stricter than most comparable frameworks. HIPAA gives covered entities 60 days to notify affected individuals, and a breach involving 500 or more individuals must be reported to HHS at the same time; breaches involving fewer than 500 individuals may be logged and reported to HHS annually, within 60 days after the end of the calendar year. US state breach laws vary but most require notification without unreasonable delay, with some setting specific windows between 72 hours and 30 days. Australia's Notifiable Data Breaches scheme requires the statement to go to the OAIC as soon as practicable once the entity has reasonable grounds to believe an eligible data breach occurred; the 30 days in section 26WH(2) of the Privacy Act is the outer limit for assessing a merely suspected breach, not a deadline for reporting a confirmed one. Canada's PIPEDA requires notification as soon as feasible. The UK follows the same 72-hour rule as the EU GDPR under the UK GDPR.

What fines apply for missing the 72-hour deadline?

Late or missing breach notification falls under Article 83(4), which sets a maximum fine of EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. Late notification is a standalone violation: you can be fined for missing the deadline even if the underlying breach was not itself a major GDPR infringement. Notable examples include Booking.com (EUR 475,000 for notifying 22 days late) and Permanent TSB (EUR 27,500 specifically for late notification, part of a larger EUR 277,500 fine in May 2026).

Updates

Corrected the processor's deadline (the EDPB recommends prompt notification to the controller and sets no 72-hour processor target), added the rule that a non-EU controller with only an Article 27 representative must notify every supervisory authority where affected individuals reside, corrected Australia's OAIC deadline to as soon as practicable, corrected the Booking.com and Bank of Ireland enforcement details to the regulators' own decisions, noted the pending EU proposal that would move the deadline to 96 hours, and replaced four dead source links.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Expanded to evergreen explainer: added EDPB Guidelines 9/2022 detail, processor duty section, NIS2 overlap, breach register deep-dive, common pitfalls, recent enforcement (Meta EUR 251M Dec 2024, Bank of Ireland EUR 463K Mar 2022, PTSB EUR 277.5K May 2026), global comparison table, and updated statistics (443 breach notifications per day in Europe as of early 2026).

Reviewed and approved by an editor

Sources and References

  1. GDPR Full Text — Regulation (EU) 2016/679(eur-lex.europa.eu).gov
  2. EDPB Guidelines 9/2022 on Personal Data Breach Notification, v2.0 (adopted 28 March 2023)(edpb.europa.eu).gov
  3. EDPB Guidelines 01/2021 on Examples Regarding Personal Data Breach Notification(edpb.europa.eu).gov
  4. EDPB One-Stop-Shop Case Digest: Security of Processing and Data Breach Notification (2024)(edpb.europa.eu).gov
  5. Regulation (EU) 2016/679, Article 33 (EUR-Lex, Official Journal text)(eur-lex.europa.eu).gov
  6. EDPB: Data Breaches (SME Data Protection Guide)(edpb.europa.eu).gov
  7. EDPB: How to Notify a Data Breach to Your DPA(edpb.europa.eu).gov
  8. ICO — Personal Data Breaches: A Guide(ico.org.uk).gov
  9. EDPS — Personal Data Breach Notification Guidelines(edps.europa.eu).gov
  10. Irish DPC — Meta EUR 251 Million Fine (December 2024)(dataprotection.ie).gov
  11. Irish DPC — Permanent TSB EUR 277,500 Fine (May 2026)(dataprotection.ie).gov
  12. Irish DPC: Decision in Inquiry IN-19-9-5 (Bank of Ireland Group plc, 14 March 2022)(dataprotection.ie).gov
  13. DLA Piper — Personal Data Breaches in Europe Reach 443 Per Day (February 2026)(dlapiper.com)
  14. NIS2 Directive — Directive (EU) 2022/2555(eur-lex.europa.eu).gov
  15. EDPB — Summary of Guidelines 9/2022 and 01/2021 on Data Breach Notification (2025)(edpb.europa.eu).gov
  16. Irish DPC: Final Decision in Inquiry IN-19-9-5, Bank of Ireland Group plc (14 March 2022, PDF)(dataprotection.ie).gov
  17. Autoriteit Persoonsgegevens: Booking.com Fined for Delay in Reporting Data Breach (31 March 2021)(autoriteitpersoonsgegevens.nl).gov
  18. European Commission: Digital Omnibus Proposal, COM(2025) 837 final (19 November 2025)(eur-lex.europa.eu).gov
  19. OAIC: Part 4: Notifiable Data Breaches (NDB) Scheme(oaic.gov.au).gov
  20. eCFR: 45 CFR 164.408, HIPAA Breach Notification to the Secretary(ecfr.gov).gov
Share: