Regulation (EU) 2016/679

The GDPR 72-hour breach assessment

A practical, source-led way to separate detection, awareness, risk assessment, notification, documentation, and communication.

Written and reviewed by Fredrik Surtell ·

When does the GDPR 72-hour clock begin?

The supervisory-notification clock begins when the controller becomes aware of a personal-data breach. Awareness is a factual threshold: a reasonable degree of certainty that a security incident compromised personal data.

Operating sequence

  1. 01

    Record when and how the organisation first obtained reasonable certainty.

  2. 02

    Identify affected data, people, systems, processors, geography, and likely consequences.

  3. 03

    Decide notification risk, record the reasoning, and submit available information without waiting for perfect certainty.

Failure modes to avoid

  • Treating the security team’s first alert as automatically identical to legal awareness.
  • Waiting for a full investigation before starting the regulatory assessment.
  • Failing to document why an incident was not notified.

The source remains the authority.

EDPB Guidelines 9/2022 on personal data breach notification