The 72-hour breach notification rule (Art 33): a runbook
Article 33 of GDPR is short and unforgiving: when a personal-data breach occurs, the controller must notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of it. If you miss that window without a good reason, you must explain the delay. Article 34 adds a second obligation: where the breach is likely to result in a high risk to individuals, you must tell those individuals too, without undue delay.
Seventy-two hours sounds generous until a breach actually happens on a Friday night. The teams that cope are the ones who decided what to do before the clock started. This is that plan.
The clock starts at 'awareness', not 'certainty'
A crucial subtlety: the 72 hours run from when you become aware that a breach has, with reasonable certainty, occurred, not from when you have finished investigating. You are allowed to notify in phases. A first notification with what you know, followed by updates as you learn more, is expressly permitted and is far better than staying silent while you chase perfect information.
The runbook
- Contain and record the time. The moment you confirm a breach, note the timestamp. That is your clock. Contain the incident so it stops getting worse.
- Assess the scope. What personal data, whose, how many people, and what could happen to them? Special-category data and data that enables fraud or identity theft raise the risk sharply.
- Decide: is authority notification required? Notify the supervisory authority unless the breach is unlikely to result in a risk to individuals' rights and freedoms. If in doubt, notify.
- Decide: is individual notification required? If the breach is likely to result in a high risk to individuals, notify them too, in clear plain language, with advice on how to protect themselves.
- Draft the notification. Article 33(3) sets the content: the nature of the breach, categories and approximate numbers affected, the likely consequences, the measures taken, and the contact point (usually your DPO).
- File within 72 hours. Submit to the competent authority, in phases if you must. Log everything.
- Record it regardless. Every breach goes in your internal breach register, even the ones you decide not to notify, with the reasoning. Article 33(5) requires this.
You will never regret notifying an hour early. You can very much regret notifying a day late. When the risk assessment is a coin toss, notify.
Turning the runbook into a system
A runbook in a wiki is a runbook nobody finds at 2am. Compliance One turns this into a live workflow: a pre-seeded supervisory-authority contact so you know where to file, a structured risk assessment that guides the notify-or-not decision, dual authority and data-subject notification templates that already contain the Article 33(3) fields, a countdown against the 72-hour deadline, and a retained breach record that satisfies Article 33(5) automatically. The point is that when the bad day comes, the process runs itself and you spend your energy on the incident, not on remembering what GDPR expects.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map this to your environment.