Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: EN

Article 33 Notification of a personal data breach to the supervisory authority


Summary What does Article 33 of the GDPR regulation say?

This article sets out the notification obligations that apply following a personal data breach.

It is closely linked to Article 34, which deals with communicating breaches directly to data subjects, while this article focuses on the duty to notify the supervisory authority.

The core requirement is that controllers must report a breach to the competent supervisory authority within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.

The article also brings processors into the picture, requiring them to alert the controller without undue delay upon discovering a breach.

Beyond the timing requirements, the article specifies the minimum content of the notification and adds a documentation obligation, ensuring there is a verifiable record of every breach and the response taken.

Important points:

  • Notify the competent supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to pose a risk to individuals' rights and freedoms. If the 72-hour deadline is missed, reasons for the delay must be provided.
  • Processors are required to notify the controller without undue delay upon becoming aware of a personal data breach.
  • Document all personal data breaches, including the facts, effects, and remedial action taken, in a manner that allows the supervisory authority to verify compliance.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.

    1. The processor shall notify the controller without undue delay after becoming aware of a personal data breach.

    1. The notification referred to in paragraph 1 shall at least:

      1. describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;

      2. communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;

      3. describe the likely consequences of the personal data breach;

      4. describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.

    1. Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.

    1. The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod