77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
All tools
Data breaches

72-hour breach deadline calculator

After a personal data breach you have 72 hours to notify the supervisory authority. The clock starts when you become aware of it — not when the incident happened. Enter the moment you became aware and you get the exact deadline.

No signup · runs in your browser · nothing you enter is transmitted

Moment of becoming aware

When did you have reasonable certainty that personal data was affected?

Enter the moment of awareness to see the deadline.

Legal basis
Art. 33 GDPR

Art. 33(1) GDPR requires the controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it. Notification is only dispensable where the breach is unlikely to result in a risk to the rights and freedoms of natural persons — an assessment you must be able to evidence. Where the notification is made later than 72 hours, it has to be accompanied by reasons for the delay. Regardless of notification, Art. 33(5) GDPR requires every breach to be documented internally.

Orientation only — not legal advice. Whether a notification duty exists at all depends on a case-by-case risk assessment; this tool only calculates the deadline. It does not replace the separate assessment of whether the data subjects must also be informed under Art. 34 GDPR.

Frequently asked

When does the 72-hour clock start?
On becoming aware, not at the time of the incident. Awareness exists once the controller has a reasonable degree of certainty that a security incident has led to personal data being compromised. A short investigation period to establish whether a breach occurred at all is permitted and does not yet start the clock — but it must not become a delaying tactic.
Do weekends and public holidays count?
Yes. The 72 hours are calendar hours and run continuously, including Saturdays, Sundays and public holidays. Becoming aware on a Friday afternoon therefore means a deadline that expires on Monday afternoon. This is precisely why the notification process has to work outside office hours.
What happens if I miss the deadline?
You still have to notify — a missed deadline does not extinguish the duty. Under the second sentence of Art. 33(1) GDPR the late notification must be accompanied by reasons for the delay. Breaching the notification duty itself can be fined up to EUR 10 million or 2 % of total worldwide annual turnover under Art. 83(4)(a) GDPR.
Do I have to notify every breach?
No. The duty falls away where the breach is unlikely to result in a risk to the rights and freedoms of natural persons — for example properly encrypted data whose key was not compromised. You must be able to justify and document that assessment, though; internally, Art. 33(5) GDPR requires every breach without exception to be documented.
How does this differ from Art. 34 GDPR?
Art. 33 governs notification to the supervisory authority, Art. 34 communication to the data subjects. The latter only applies where there is likely to be a high risk, and it has no 72-hour deadline — it requires communication without undue delay, which in practice can be sooner than the notification to the authority.
What applies to processors?
Processors do not notify the supervisory authority themselves. Under Art. 33(2) GDPR they must inform the controller without undue delay — with no 72-hour deadline of their own, because the controller's clock only starts once the controller is aware. In practice this is why concrete notification deadlines belong in the data processing agreement.