> ## Content Index
> Fetch the complete content index at: https://www.thedelatorrereview.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# GDPR Data Breaches Explained: Security Incidents, Risk Assessment and Notification Requirements
- URL: https://www.thedelatorrereview.com/gdpr-data-breaches-explained-security-incidents-risk-assessment-and-notification-requirements/
- Published: 2019-03-18T23:12:00.000Z
- Updated: 2026-08-15T23:58:57.000Z
- Description: A personal data breach can trigger significant obligations under the GDPR. Learn what constitutes a breach, how to assess risks to individuals, when the 72-hour notification rule applies, when affected individuals must be informed, and what organizations must document.
- Author: Lydia
- Tags: Data Protection Officer (DPO), Data Breach, Encryption, Cybersecurity, GDPR, EU, NIS Directive, ePrivacy Directive, Incident Response, Transparency, Accountability, Data Protection Law

> **Key Points**: (1) A **personal data breach** occurs when a security incident compromises the confidentiality, integrity, or availability of personal data. (2) Controllers must **assess the risk to individuals** whenever a breach occurs. (3) Breaches likely to create a **risk** must generally be reported to the supervisory authority **within 72 hours**.(4) Breaches likely to create a **high risk** must generally also be communicated to affected individuals **without undue delay**.(5) **Processors must notify controllers without undue delay** after becoming aware of a breach. (6) Controllers must **document all personal data breaches**, including those that do not require notification. (7) Other regimes, including **NIS2, ePrivacy, and national laws**, may impose additional incident-reporting obligations.

---

## What Is a Security Incident and What Is a Personal Data Breach?

Not every security incident is necessarily a personal data breach. A personal data breach occurs when a security incident compromises the confidentiality, integrity, or availability of personal data.

The distinction matters because once a security incident qualifies as a personal data breach under the GDPR, the controller must assess the breach under [Article 33](https://gdpr-info.eu/art-33-gdpr/?ref=thedelatorrereview.com) and [Article 34](https://gdpr-info.eu/art-34-gdpr/?ref=thedelatorrereview.com) to determine whether it must be notified to the competent supervisory authority and, in some circumstances, communicated to affected individuals.

Under the GDPR, a personal data breach is defined as:

> “a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.”  
> — [**GDPR, Article 4(12)**](https://gdpr-info.eu/art-4-gdpr/?ref=thedelatorrereview.com)

In practical terms, a personal data breach may occur whenever personal data is **lost, destroyed, altered, corrupted, disclosed without authorization, accessed by an unauthorized person, or made unavailable**.

Importantly, a breach does not have to involve a hacker, cyberattack, or other malicious activity. **Personal data breaches can result from either accidental or deliberate acts.** For example, an employee mistakenly emailing personal information to the wrong recipient can constitute a personal data breach just as an external attacker obtaining unauthorized access to a database can.

Similarly, a breach is not limited to the unauthorized disclosure of information. Because the GDPR definition encompasses confidentiality, integrity, and availability, incidents affecting the accuracy or accessibility of personal data may also qualify. For example, ransomware that encrypts personal data and makes it unavailable can constitute a personal data breach even if there is no evidence that the attacker actually accessed or extracted the data.

Common examples include:

- **Unauthorized access:** an employee, contractor, attacker, or other third party accesses personal data without authorization.
- **Unauthorized disclosure:** personal data is emailed, mailed, uploaded, or otherwise disclosed to the wrong recipient.
- **Lost or stolen devices:** a laptop, smartphone, USB drive, or other device containing personal data is lost or stolen.
- **Unauthorized alteration:** personal data is changed, corrupted, or otherwise modified without authorization.
- **Loss or destruction:** personal data is accidentally or deliberately deleted or destroyed.
- **Loss of availability:** an organization cannot access personal data when needed, including where ransomware encrypts the data or a system failure makes it unavailable.

## What Are the GDPR Breach Notification Requirements?

The GDPR establish two separate breach-notification obligations: notification to the supervisory authority and, for more serious breaches, communication to affected individuals.

- **Notification to the supervisory authority —** [Article 33](https://gdpr-info.eu/art-33-gdpr/?ref=thedelatorrereview.com). A controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. If notification occurs after 72 hours, the controller must explain the delay.
- **Communication to affected individuals —** [Article 34](https://gdpr-info.eu/art-34-gdpr/?ref=thedelatorrereview.com). A higher threshold applies to notifying data subjects. The controller must communicate a breach to affected individuals without undue delay when it is **likely to result in a high risk to their rights and freedoms**. The communication must use clear and plain language and explain the nature of the breach, its likely consequences, relevant contact information, and the measures being taken in response.

The GDPR therefore creates a risk-based escalation framework: all breaches must be documented; breaches presenting a risk generally must be reported to the supervisory authority; and breaches presenting a high risk generally must also be communicated to affected individuals.

**GDPR notification requirements may** **not be the only reporting obligations** triggered by a personal data breach. Depending on the organization, sector, and circumstances, additional notification or incident-reporting requirements may apply under EU or Member State law, including rules governing electronic communications and cybersecurity.

Organizations **should also consider whether the incident should be reported to relevant third parties**, such as law enforcement, insurers, professional bodies, banks, or payment-card providers, particularly where doing so could help mitigate harm or financial loss to affected individuals.

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/08/ChatGPT-Image-Aug-15--2026-at-04_52_52-PM.png)

### Reporting a Personal Data Breach to the Supervisory Authority

Once a controller becomes aware of a personal data breach, it must assess the **likelihood and severity of the risk to individuals’ rights and freedoms**. The assessment should focus on the potential consequences for the people whose personal data has been affected.

As Recital 85 of the GDPR recognizes, a breach may cause physical, material, or non-material harm, including loss of control over personal data, discrimination, identity theft or fraud, financial loss, reputational damage, loss of confidentiality, or other significant economic or social disadvantages.

Not every breach creates the same level of risk. The assessment must therefore be made case by case, taking into account the nature of the incident, the data involved, the individuals affected, and the potential consequences.

> **Example:** Theft of customer data that could be used for identity fraud is likely to create a risk requiring notification. By contrast, the accidental loss or alteration of an internal staff telephone list may present little or no risk and may not require notification.

#### When and How to Notify the Supervisory Authority of a Data Breach

The basic rule is:

- If the breach is likely to result in a risk to individuals’ rights and freedoms, the controller must notify the competent supervisory authority.
- If the breach is unlikely to result in a risk, notification is not required.
- If notification is required, it must be made without undue delay and, where feasible, within 72 hours after the controller becomes aware of the breach.

For cross-border processing, the controller may need to determine the lead supervisory authority under the GDPR’s one-stop-shop framework.

Even when a controller concludes that notification is unnecessary, that decision should be **documented and capable of being justified**. Indeed, Article 33(5) requires controllers to document personal data breaches in a manner that enables the supervisory authority to verify compliance.

At a minimum, the notification must include:

- a description of the **nature of the personal data breach**, including, where possible, the categories and approximate number of affected individuals and personal data records;
- the **name and contact details of the DPO** or another contact point;
- a description of the **likely consequences** of the breach; and
- a description of the **measures taken or proposed** to address the breach and, where appropriate, mitigate its adverse effects.

Controllers do not need to delay an initial notification until every detail of the incident has been established. When all required information is not immediately available, it may be provided in phases without undue further delay. This allows the controller to meet the 72-hour deadline while the investigation continues.

### When and How Must Affected Individuals Be Notified?

Under[ Article 34 GDPR](https://gdpr-info.eu/art-34-gdpr/?ref=thedelatorrereview.com), a controller must communicate a personal data breach directly to affected individuals **without undue delay when the breach is likely to result in a high risk to their rights and freedoms**. One of the principal purposes of this notification is to give individuals the information they need to take steps to protect themselves from potential harm.

The “high risk” threshold is higher than the threshold for notifying a supervisory authority under Article 33\. Controllers should consider both the severity of the potential consequences for affected individuals and the likelihood that those consequences will occur. The more serious or likely the potential harm, the greater the risk.

> **Example:** A hospital accidentally discloses patient records containing sensitive health information. Given the sensitivity of the information and the potential consequences of its disclosure, the breach is likely to present a **high risk**, requiring notification to affected patients.

By contrast, if a university accidentally deletes alumni contact information but promptly restores it from a backup, with no indication that the information was accessed or otherwise compromised, the incident may be unlikely to create a high risk. In that case, communication to the affected individuals may not be required.

When notification is required, the controller must describe the breach in clear and plain language and provide at least:

- the **name and contact details of the DPO** or another contact point where additional information can be obtained;
- a description of the **likely consequences** of the breach; and
- a description of the **measures taken or proposed** to address the breach, including measures intended to mitigate possible adverse effects.

Importantly, a decision that individuals do not need to be notified does not necessarily mean that the supervisory authority does not need to be notified. The thresholds are different: notification to the supervisory authority is generally required where there is a risk, while communication to individuals is required where there is a high risk.

The supervisory authority may also require the controller to notify affected individuals if it determines that the breach is likely to result in a high risk. Controllers should therefore document their risk assessment and the reasons for their notification decisions as part of their broader GDPR accountability obligations.

## What Happens If an Organization Fails to Notify a Breach?

Failure to comply with the GDPR’s breach-notification requirements can result in administrative fines of up to €10 million or 2% of the undertaking’s total worldwide annual turnover for the preceding financial year, whichever is higher. Supervisory authorities may impose these fines alongside their other corrective powers under [Article 58 GDPR](https://gdpr-info.eu/art-58-gdpr/?ref=thedelatorrereview.com).

Organizations should therefore maintain a robust incident-response and breach-notification process that enables them to promptly detect, assess, document, remediate, and, where required, report personal data breaches.

## What Is the Processor’s Role in a Data Breach?

Under [Article 33(2) GDPR](https://gdpr-info.eu/art-33-gdpr/?ref=thedelatorrereview.com), a processor that becomes aware of a personal data breach must **notify the controller without undue delay**. The processor does not generally make the Article 33 notification to the supervisory authority itself; responsibility for assessing the breach and determining whether notification is required rests with the controller.

The controller-processor agreement should establish appropriate breach-detection, reporting, and cooperation procedures, including how and when the processor will provide the information the controller needs to meet its own GDPR obligations.

> **Example:** A company uses an IT provider to store customer records. If the provider discovers that an attacker has unlawfully accessed those records, it must promptly notify the company. The company, as controller, then assesses the risk and determines whether the breach must be reported to the supervisory authority and affected individuals.

### Record-Keeping and Documentation Requirements

Under [Article 33(5) GDPR](https://gdpr-info.eu/art-33-gdpr/?ref=thedelatorrereview.com), controllers must document personal data breaches, including those that do not require notification. Records should describe the facts surrounding the breach, its effects, and the remedial action taken. This documentation supports the GDPR’s accountability principle and enables supervisory authorities to verify compliance with breach-notification requirements.

Organizations should also investigate security incidents and identify their root causes, whether they result from human error, technical failures, or systemic problems. Lessons from an incident should inform appropriate corrective measures, such as improved procedures, additional employee training, or stronger technical and organizational safeguards.

## EU Data Security and Breach Notification Beyond the GDPR

The GDPR is not the only EU framework that may impose security and incident-reporting obligations. Depending on the organization and the services involved, **EU cybersecurity and electronic communications rules may apply alongside the GDPR**.

#### NIS and NIS2

The NIS Directive (Directive (EU) 2016/1148) was the EU’s first horizontal cybersecurity legislation and established security and incident-reporting requirements for certain operators of essential services and digital service providers. It has since been repealed and replaced by the NIS2 Directive (Directive (EU) 2022/2555), which significantly expands the organizations and sectors subject to EU cybersecurity requirements and strengthens incident-reporting obligations.

Organizations within the scope of NIS2 may therefore face cybersecurity incident-reporting requirements in addition to their GDPR breach-notification obligations. Importantly, the two regimes address different concerns: not every cybersecurity incident is necessarily a personal data breach, and not every GDPR personal data breach necessarily constitutes a reportable incident under NIS2.

#### ePrivacy Directive

The ePrivacy Directive (Directive 2002/58/EC) also contains security and personal data breach requirements applicable to certain providers of publicly available electronic communications services.

Under Article 4, covered providers may have obligations to:

- inform subscribers about particular security risks;
- notify the competent national authority of personal data breaches;
- notify affected subscribers or individuals where a breach is likely to adversely affect their personal data or privacy; and
- maintain an inventory of personal data breaches, including their circumstances, effects, and remedial measures.

Notification to affected individuals may not be required where appropriate technological protections have rendered the compromised data unintelligible to unauthorized persons, subject to the applicable requirements.

The ePrivacy regime is supplemented by [Commission Regulation (EU) No 611/2013](https://eur-lex.europa.eu/eli/reg/2013/611/oj/eng?ref=thedelatorrereview.com), which establishes more detailed requirements for personal data breach notifications by covered electronic communications providers.

For organizations subject to multiple EU regulatory regimes, a single security incident can therefore trigger parallel reporting obligations under the GDPR, NIS2, ePrivacy rules, and potentially applicable national or sector-specific law**s**.

## Additional Resources

The following resources provide additional guidance on **personal data breaches, cybersecurity incidents, notification requirements, and incident response** under EU, U.S., and Canadian law.

### European Union

**GDPR Provisions**

For the GDPR framework governing personal data breaches, see in particular:

- [**Article 33**](https://gdpr-info.eu/art-33-gdpr/?ref=thedelatorrereview.com) — Notification of a personal data breach to the supervisory authority
- [**Article 34**](https://gdpr-info.eu/art-34-gdpr/?ref=thedelatorrereview.com) — Communication of a personal data breach to the data subject
- [**Article 58**](https://gdpr-info.eu/art-58-gdpr/?ref=thedelatorrereview.com) — Powers of supervisory authorities
- [**Article 83**](https://gdpr-info.eu/art-83-gdpr/?ref=thedelatorrereview.com) — Administrative fines
- [**Recital 75**](https://gdpr-info.eu/recitals/no-75/?ref=thedelatorrereview.com) **\-** Risks to the Rights and Freedoms of Natural Persons\*
- [**Recital 85**](https://gdpr-info.eu/recitals/no-85/?ref=thedelatorrereview.com)**\-** Notification Obligation of Breaches to the Supervisory Authority\*
- [**Recital 87**](https://gdpr-info.eu/recitals/no-87/?ref=thedelatorrereview.com) **\-** Promptness of Reporting / Notification\*
- [**Recital 88**](https://gdpr-info.eu/recitals/no-88/?ref=thedelatorrereview.com) **\-** Format and Procedures of the Notification\*

**EU Legislation**

- [Commission Regulation (EU) No 611/2013](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32013R0611&ref=thedelatorrereview.com) — Detailed rules for notification of personal data breaches under the ePrivacy framework.
- [NIS2 Directive (Directive (EU) 2022/2555)](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=thedelatorrereview.com) — EU cybersecurity framework establishing risk-management and incident-reporting obligations for covered entities across numerous sectors.
- [ePrivacy Directive (Directive 2002/58/EC)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32002L0058&ref=thedelatorrereview.com) — Includes security and breach-notification requirements applicable to certain electronic communications providers.

**European Data Protection Board (EDPB)**

The Article 29 Working Party (WP29), the EDPB's predecessor, developed important guidance on GDPR breach notification that was subsequently endorsed by the EDPB:

- [Guidelines on Personal Data Breach Notification under Regulation 2016/679](https://ec.europa.eu/newsroom/article29/items/612052?ref=thedelatorrereview.com)
- [Guidelines for Identifying a Controller or Processor's Lead Supervisory Authority](https://ec.europa.eu/newsroom/document.cfm?doc%5Fid=44102&ref=thedelatorrereview.com)
- [Lead Supervisory Authority FAQs](https://ec.europa.eu/information%5Fsociety/newsroom/image/document/2016-51/wp244%5Fannexii%5Fen%5F40858.pdf?ref=thedelatorrereview.com)
- [EDPB Guidelines 01/2021 on Examples Regarding Personal Data Breach Notification](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-012021-examples-regarding-personal-data-breach%5Fen?ref=thedelatorrereview.com) — Practical scenarios illustrating how the GDPR's breach-notification rules apply.

**CNIL (France)**

- [Personal Data Breach Guidance](https://www.cnil.fr/en/personal-data-breaches?ref=thedelatorrereview.com) — Guidance from the French data protection authority on identifying, documenting, and reporting personal data breaches.

**Data Protection Commission (Ireland)**

- [Guidance Note: A Quick Guide to GDPR Data Breach Notifications](https://www.dataprotection.ie/sites/default/files/uploads/2019-08/190812%20GDPR%20Breach%20Notification%20Quick%20Guide.pdf?ref=thedelatorrereview.com) (August 2019)
- [A Practical Guide to Personal Data Breach Notifications under the GDPR — Full Guidance Note](https://www.dataprotection.ie/sites/default/files/uploads/2019-10/Data%20Breach%20Notification%5FPractical%20Guidance%5FOct19.pdf?ref=thedelatorrereview.com) (October 2019)

### Canada

The Canadian federal privacy framework also contains breach reporting, individual notification, and record-keeping requirements:

- **Office of the Privacy Commissioner of Canada:** [*What You Need to Know About Mandatory Reporting of Breaches of Security Safeguards* — guidance on breach requirements under PIPEDA.](https://www.priv.gc.ca/en/privacy-topics/privacy-for-businesses/privacy-breaches-at-your-business/gd%5Fpb%5F201810/?ref=thedelatorrereview.com)

### Data Guidance

[**PIPEDA v. GDPR**](https://www.dataguidance.com/sites/default/files/gdpr%5Fv%5Fpipeda.pdf?ref=thedelatorrereview.com)— comparative resource examining the Canadian and EU approaches.

### United States

Unlike the GDPR's generally applicable EU framework, the United States has a combination of **state breach-notification statutes and federal or sector-specific requirements**.

- [Security Breach Notification Laws — National Conference of State Legislatures (NCSL)](https://www.ncsl.org/technology-and-communication/security-breach-notification-laws?ref=thedelatorrereview.com) — Overview of state data breach notification laws.
- [The Sedona Conference — Commentary on Attorney-Client Privilege and Work Product Protection in the Cybersecurity Context](https://thesedonaconference.org/node/9212?ref=thedelatorrereview.com) — Discussion of privilege and work-product issues arising during cybersecurity investigations.
- [O'Melveny State-by-State Guide to U.S. Data Breach Notification Laws](https://www.omm.com/omm%5Fdistribution/client%5Falert/cyber%5Fsec%5Fstate%5Fdata%5Fbreach%5Fdoc.pdf?ref=thedelatorrereview.com) — Comparative guide to state breach-notification requirements.

### California

- [California Attorney General — Data Security Breach Reporting](https://oag.ca.gov/privacy/databreach/reporting?ref=thedelatorrereview.com) — Information concerning California breach reporting requirements.
- [California Attorney General — Data Breach Reports](https://oag.ca.gov/privacy/databreach/reporting?ref=thedelatorrereview.com) — Resources relating to breaches reported under California law.

### New Jersey

- [State of New Jersey Data Breach Report Form](https://www.cyber.nj.gov/breach?ref=thedelatorrereview.com) — Information and reporting resources for data breaches subject to New Jersey requirements.

### New York

- [**New York SHIELD Act** ](https://ag.ny.gov/resources/organizations/data-breach-reporting/shield-act?ref=thedelatorrereview.com)— New York's breach-notification and reasonable data-security requirements.
- [New York Department of Financial Services Cybersecurity Regulation](https://www.dfs.ny.gov/industry-guidance/cybersecurity?ref=thedelatorrereview.com) — Cybersecurity and incident-notification requirements applicable to covered financial services entities.

### Cryptography and Security

- [OWASP Cryptographic Storage Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic%5FStorage%5FCheat%5FSheet.html?ref=thedelatorrereview.com) — Practical guidance on cryptographic storage, encryption, key management, and related security considerations.

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/08/Screenshot-2026-07-04-at-4.45.19---PM-3.jpeg)