When does the GDPR 72-hour breach notification clock start?
Do not start the Article 33 clock from every raw security alert. The EDPB says a controller becomes aware when it has a reasonable degree of certainty that a security incident has occurred and has led to personal data being compromised.
The controller must use that short investigation period promptly to establish whether personal data was breached, contain the incident, assess risk to individuals, and notify the if Article 33 is triggered. A can affect confidentiality, integrity, or availability, so confirmed loss or destruction can trigger awareness even when unauthorized access has not been proved.
- Record the first alert, who received it, and why it was or was not immediately enough to establish a .
- Record the awareness timestamp separately: the point when the controller had reasonable certainty that personal data was compromised.
- Assess whether the breach is unlikely to result in a risk to rights and freedoms; if not, prepare supervisory-authority notification without undue delay and, where feasible, within 72 hours after awareness.
- Keep the Article 34 high-risk assessment separate from the Article 33 authority notification threshold; communication to data subjects is triggered by likely .
When does the GDPR 72-hour breach notification clock start?
The GDPR 72-hour clock starts when the controller becomes aware of a . EDPB guidance treats awareness as the point when the controller has a reasonable degree of certainty that a security incident occurred and personal data was compromised. The controller may briefly investigate an alert first, but must act promptly and notify the without undue delay and, where feasible, within 72 hours after awareness unless the breach is unlikely to create risk for individuals.
Article 33 sets the controller's supervisory-authority notification duty, the 72-hour timing after awareness, the risk exception, delayed-notification reasons, processor escalation, phased information, and breach documentation duty.
EDPB guidance explains that awareness requires a reasonable degree of certainty that a security incident occurred and personal data was compromised.