Data breach report to the supervisory authority: The 72-hour path according to Art. 33 GDPR
Art. 33 GDPR requires a data breach to be reported within 72 hours of becoming aware of it. This guide shows the path, the thresholds, the documentation and the connection to Art. 34 GDPR, cleanly and comprehensibly.
Art. 33 GDPR obliges those responsible to report a violation of the protection of personal data to the responsible supervisory authority immediately, if possible within 72 hours of becoming aware of it. The deadline does not begin with the incident itself, but with knowledge of it. Anyone who does not properly document the time of knowledge loses the most important line of defence against the auditor and risks a fine according to Art. 83 Para. 4 lit. a GDPR.
This guide describes the operational reporting path: triage, threshold check, content of the report, connection to Art. 34 GDPR in the event of high risk, late reports, internal documentation and reporting line to management. CIVAC bundles these steps in the compliance platform and provides the templates that you can use immediately as a data protection officer or external DPO. Deadline begins as soon as we become aware of it.
Key Takeaways
- The 72-hour period according to Art. 33 GDPR starts with knowledge of the violation, not with the triggering event.
- A report is only unnecessary if the violation is unlikely to pose a risk to the rights and freedoms of natural persons, and this must be justified and documented.
- If the risk is likely to be high, Art. 34 GDPR also applies, informing those affected in clear and simple language.
When does the 72 hour period actually begin?
The EDPB has specified in Guidelines 9/2022 that the period under Article 33 (1) GDPR begins from the moment when the controller has sufficient certainty about a breach of the protection of personal data. A vague suspicion is not enough, a confirmed anomaly is enough. In between there is a short, documented evaluation phase that should rarely last longer than 24 hours.
In practical terms, this means: As soon as IT, SOC or the department confirms an incident involving personal data, the clock starts. Input channel, time, reporting person and initial assessment belong in the incident register. This micro-documentation later decides whether the supervisory authority recognises the deadline as having been met or sanctions a failure in accordance with Art. 83 GDPR.
Processors report immediately to the person responsible in accordance with Art. 33 Paragraph 2 GDPR, not directly to the authority. The order processing contract must bindingly regulate this escalation path with the time, contact point and content of the initial report. Otherwise, the deadline begins too late for the person responsible and the fault remains within the company.
Weekends and public holidays do not interrupt the deadline. The supervisory authorities in Bavaria and North Rhine-Westphalia expressly expect in their FAQ that a standby regulation exists. Anyone who does not have a 24/7 reporting channel must organizationally justify how they can still meet the deadline, and this is increasingly being examined critically.
The CIVAC role of data protection officer documents the level of knowledge with a time stamp, source and evaluation in one step. The auditor calls, the evidence is ready.
Anyone who allows the deadline to pass must justify the delay in the late report in accordance with Article 33 Para. 1 Sentence 2 GDPR. This justification is mandatory, not optional, and it becomes part of the record that supports or weakens any subsequent order or fine.
Threshold: When is a report unnecessary
Art. 33 Para. 1 GDPR provides for an exception if the violation is unlikely to pose a risk to the rights and freedoms of natural persons. The burden of proof lies with the person responsible. A general assessment is not effective; what is required is a documented risk assessment that includes the type, scope, sensitivity and number of data records affected.
The EDPB recommends a three-stage scale in guidelines 9/2022: no risk, risk, high risk. Encrypted devices with verifiable key control often fall into the first level, a lost laptop without full encryption almost never does. The assessment must be completed before the 72-hour mark and justified in writing.
Even an unnecessary report is not without consequences. Art. 33 Para. 5 GDPR requires documentation of every violation, regardless of the reporting obligation. The internal incident register must contain the facts, effects, remedial measures and the justification for non-reporting, otherwise the failure to report can be sanctioned.
Sensitive data categories according to Art. 9 GDPR shift the threshold significantly. Even small amounts of health, applicant or creditworthiness data trigger a reportable risk. Anyone who answers in the negative should complete the risk analysis using the CIVAC workspace in the four-eyes principle and have it countersigned by the data protection officer.
A typical mistake is the subsequent upgrading of the assessment as soon as the supervisory authority asks questions. Such corrections become visible in the versioning and weaken the position. A conservative initial report with subsequent clarification is better than a denial that has to be accepted later.
If in doubt, the principle of the supervisory authorities applies: if in doubt, report it. A report that later turns out to be unfounded is not sanctioned; failure to report is rare. The board and management should understand this asymmetry before ordering political non-reporting.
Content of an effective initial report
Art. 33 Para. 3 GDPR defines the minimum content: type of violation, categories and approximate number of data subjects and data sets, name and contact of the data protection officer, likely consequences, measures taken or proposed. If an item is missing, most authorities will accept a subsequent submission as long as the delay is justified and the rest remains reliable.
The facts should be presented chronologically and in simple language. Authority forms, such as the LDA Bavaria or LfDI Baden-Württemberg, are structured largely uniformly, but free text fields require discipline. A proven structure: What happened, when did it become known, what data and how many people, what immediate measures, what further steps.
Numbers should be realistic estimates, not glossed over. The supervisory authorities accept ranges, around 12,000 to 15,000 affected email addresses, but reject blanket statements such as a small number. If the final number is later corrected significantly upwards without there being a technical justification, it appears negligent.
The measures column is the most important. This shows whether the company has a plan or is reacting. Concrete steps with responsible persons, deadlines and status, such as password reset for 3,400 accounts by 6:00 p.m., signal operational maturity and significantly reduce later orders.
CIVAC provides a pre-filled report template in the workspace with the mandatory fields according to Art. 33 Para. 3 GDPR, coordinated with the forms of the relevant supervisory authority. Audit-proof, documented, Art. 33-proof.
After sending, the authority confirms receipt using the file number. This file number is a mandatory part of all follow-up communication and belongs in the incident register, as does a copy of the submitted report in PDF/A format for audit-proof storage.
Connection to Art. 34 GDPR: Notification of those affected
Art. 34 GDPR applies if the violation is likely to pose a high risk to the rights and freedoms of natural persons. Unlike Article 33, Article 34 does not have a rigid deadline, but requires promptness. In practice, the supervisory authorities interpret this as days, not weeks, once the matter has been clarified and the recipient list is available.
The notification must be made in clear and simple language, without legal complexities. The EDSA recommends a maximum reading time of two minutes. Mandatory content includes the type of violation, possible consequences, measures taken and concrete recommendations for action, such as changing your password, blocking your credit card or being particularly vigilant with phishing emails.
The delivery channel should correspond to usual communication. If the business relationship is digital, email with secured delivery is sufficient. In high-risk cases, such as the disclosure of health data, a written notification makes sense, ideally with a return channel via a hotline or an FAQ at a dedicated URL.
An exception under Article 34 (3) GDPR exists if suitable protective measures, such as strong encryption, subsequently reduce the risk to an unlikely level. This exception must be interpreted narrowly and justified in writing, otherwise it will be canceled upon examination. A public announcement only replaces individual notification if this would be disproportionate.
In cross-border cases, the one-stop shop mechanism applies in accordance with Art. 56 GDPR. The authority in the country of headquarters is in charge; the supervisory authorities involved are informed via the IMI system. In the CIVAC model, this coordination is carried out by the appointed or licensed external data protection officer in coordination with the legal department.
Notification of those affected is also a PR question. The tone decides whether trust is maintained. Clear language, concrete help, visible acceptance of responsibility. Marketing phrases make the damage worse, as do legal evasions.
Late notifications and updates
Art. 33 Para. 4 GDPR allows gradual reporting if not all information is available within 72 hours. The prerequisite is an initial report with the status available at that time and an announcement as to which points will be added later. A complete delay is only permissible with justification, for example if forensic analyses only clarify the damage after days.
Typical late reports concern the number of those affected, the scope of the data categories, the effectiveness of the immediate measures or newly identified attack vectors. Each subsequent report is kept under the original file number and should have the same structural structure as the initial report so that the auditor can quickly understand the development.
If the facts change fundamentally, for example from an internal misoperation to an external attack, the supervisory authority must be expressly informed of this. Such re-classifications change the legal assessment and can trigger additional reporting obligations according to NIS-2 or the BSI Act, which must be observed in parallel.
The final report after the incident has concluded contains the final figures, the final balance of measures and the lessons learned. This balance sheet should coincide with the internal incident register and be countersigned by the DSB. The supervisory authorities often use them as a starting point for subsequent orders or the closure of the process.
In the CIVAC workspace, the initial, interim and final reports are automatically versioned with a time stamp, author and content difference. The supervisory authority not only sees the current status, but also the genesis of the knowledge. This strengthens the defence against the accusation that facts were withheld.
A subsequent report that occurs more than 30 days after the initial report should be justified internally. Experience has shown that the authorities ask why the analysis took so long. A plausible justification, such as the complexity of forensic investigations, is acceptable; a lack of justification seems negligent.
Relationship to NIS-2, TTDSG and sectoral reporting requirements
A data breach can also be an NIS 2 reportable security breach. According to Section 32 BSIG-E, the NIS2UmsuCG requires an early warning within 24 hours and a follow-up report to the BSI within 72 hours. The deadlines run parallel to Art. 33 GDPR and must be observed separately, even if the facts are identical.
Telecommunications and telemedia services also have reporting obligations in accordance with Section 169 TKG in the event of violations of the protection of users' personal data. The deadline is immediately, in practice also 24 hours. The addressee is the BNetzA, not the supervisory authority according to the GDPR. The same applies here: two reports, one issue, double documentation.
Financial institutions fall under DORA and the relevant BaFin circulars. Payment service providers also report in accordance with Art. 96 PSD2. Hospitals, KRITIS operators and energy companies have their own paths according to BSIG, EnWG or the Hospital Future Act. The responsible addressees and deadlines sometimes differ considerably.
The CIVAC role of information security officer and the DPO role share a common incident log in the workspace. This avoids contradictions in content between the GDPR and NIS 2 reports and ensures that both paths are fed from the same facts.
Anyone who uses several paths at the same time should maintain a uniform incident ID internally and use it as an internal reference in every report. This means that the references can be made later without any effort for cross-checks or orders. The appointment certificate, signed, filed, verifiable.
The supervisory authorities are increasingly exchanging information with the BSI and BaFin. Contradictions between the reports, such as different numbers of those affected or different times of incidents, are noticeable and lead to questions. Consistency is not a style issue here, but a line of defence.
Fines and responsibility of management
Art. 83 Para. 4 lit. a GDPR provides for a fine of up to 10 million euros or 2 percent of global group sales for violations of reporting obligations, whichever is higher. In recent years, the supervisory authorities in Germany have repeatedly imposed fines in the six-figure range simply because of late reports, even without a core data protection violation being identified.
According to Section 9 OWiG and Section 130 OWiG, the responsibility lies with the management. A delegation to the DPO does not relieve the burden because the DPO is not allowed to assume ultimate responsibility according to Art. 38 Para. 6 GDPR. Anyone who ignores this risks personal liability on the part of the organs and, in exceptional cases, criminal consequences according to Section 42 BDSG.
The assessment of the fine takes cooperation into account. An open, rapid report, a substantial balance of measures and a documented learning process have the effect of reducing fines in accordance with Art. 83 Para. 2 GDPR. Defensive communication, incomplete information or delaying the initial report have an aggravating effect. The difference is often a factor of three to five.
Documented risk management, regular tabletop exercises and proven training further reduce the likelihood of a fine. The supervisory authorities assess this as an indication of the duty of care in accordance with Article 5 Para. 2 GDPR and reduce accordingly. CIVAC documents this maturity with 490 ready-to-use audit templates and an audit-proof reporting line to management.
Insurance policies do not cover fines in Germany; this also applies to D&O policies. The financial burden remains with the company, and the damage to its reputation comes on top of that. For this reason alone, investing in a reliable reporting path is more worthwhile than the hope of risk transfer.
Management should receive a quarterly report on the status of incidents and reporting practices. This report is part of the proper business organisation and will be requested by the auditor in an emergency. If it is missing, an essential component of the defence is missing.
Operational checklist: From incident to report in 24 hours
Hour 0 to 4: Triage. The incident is recorded in the central input channel, the DSB is informed and an initial assessment is created. IT, SOC, data protection and a management member are involved. Immediate measures such as account suspension, system isolation or patch roll-out run in parallel. Everything with a time stamp in the incident register.
Hour 4 to 12: Clarification of the facts. Forensics clarifies the scope, time of entry, data categories and affected persons. The risk assessment according to Articles 32 and 33 GDPR is carried out in writing. A draft of the authority report is created. The legal department checks parallel reporting paths according to NIS-2, TKG, PSD2 or BSIG.
Hour 12 to 24: Voting. Management, DSB and press office coordinate. The report to the supervisory authority is being finalized and the file number is awaited. At the same time, the preparation of the notification of those affected begins in accordance with Art. 34 GDPR if there is a high risk. Communication with the processor is documented.
Hour 24 to 72: Reporting and follow-up communication. The report to the authorities is sent and the file number is entered in the register. Late registrations will be announced. If the risk is high, those affected are notified via the appropriate channel with hotline backup. Lessons learned are initially collected.
After 72 hours: completion and learning. An incident retrospective clarifies what worked and what didn't. Weak points in the reporting path are reflected in the next training course and in updating the templates. The management report is created, the CIVAC FAQ page with updated practical examples is shared internally.
This choreography only works if it is practiced. CIVAC recommends at least one tabletop exercise per year with real roles, real templates and real escalation paths. Anyone who plays through the emergency for the first time loses the first 24 hours.
How CIVAC carries out the reporting path operationally
CIVAC is a compliance platform and officer-as-a-service. You can licence the workspace for your internal representatives, or you can have our representatives order it. In both variants you receive the same reporting path: incident register, risk assessment according to Art. 33 GDPR, authority form, versioning, file number tracking and connection to Art. 34.
The 490 ready-to-use audit templates include initial report, subsequent report, notification of those affected in clear language, internal incident register according to Art. 33 Para. 5 GDPR, management report and tabletop scripts. All templates have been coordinated with the German supervisory authorities and are updated promptly in the event of official circulars or EDSA guidelines.
The appointed or licensed data protection officer works in the reporting line to management, with a documented appointment certificate, a clear escalation matrix and an SLA of two working days for the initial response. Others run compliance like a filing cabinet. We run it like software.
EU data residency of all incident data is standard. The incident master is shared with the ISB role so that an NIS 2 report to the BSI is possible in parallel and consistently. This prevents contradictions between reports and reduces the risk of additional orders.
If you would like to check today whether your reporting path meets the requirements of Articles 33 and 34 of the GDPR, please contact us. Turn reading into a mandate.: info@civac.de or the contact form on civac.de. An initial assessment will be made within two working days, including information about acute gaps.
If you have a current incident, choose the express route. The appointed DPO takes over communication with the authorities, the workspace provides the templates, and the reporting line to management is in place from day one. The auditor calls, the evidence is ready.
FAQ
When exactly does the 72-hour period begin according to Art. 33 GDPR?
The period begins with the knowledge of the person responsible, not with the triggering event. Knowledge exists when there is sufficient certainty about a breach of personal data protection. A short, documented assessment period is permitted, but should rarely last longer than 24 hours.
What happens if I exceed the 72 hour limit?
You must justify the delay in the report in accordance with Article 33 Para. 1 Sentence 2 GDPR. An unjustified or implausible delay can trigger a fine in accordance with Article 83 (4) (a) GDPR, in Germany regularly in the five to six-digit range, even without any further data protection violation.
Does every data breach have to be reported to the supervisory authority?
No, a report is unnecessary if the violation is unlikely to pose a risk to the rights and freedoms of natural persons. This assessment must be documented. Regardless of this, according to Article 33 Para. 5 GDPR, every violation must be recorded in the internal incident register.
Who is responsible for reporting within the group?
The person responsible within the meaning of Art. 4 No. 7 GDPR is usually the legal entity that controls data processing. In the case of joint responsibility according to Art. 26 GDPR, the agreement regulates the person required to report. Processors report exclusively to the person responsible, not directly to the authority.
When do I also have to notify those affected?
If the violation is likely to pose a high risk to the rights and freedoms of natural persons, Art. 34 GDPR applies. The notification must be immediate, in clear and simple language, with specific recommendations for action and a feedback channel for questions.
How can CIVAC operationally support the reporting path?
CIVAC provides 37 audit templates, a versioned incident register, EU data residency, and a two-business day SLA in the workspace. You licence the workspace for your internal representatives or have our representatives order it. Contact: info@civac.de or form on civac.de.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.