Skip to content

Incidents

Personal data breach: organising the first 72 hours so you can act

Not every security incident is notifiable. But every suspicion needs a fast, documented assessment of data, consequences and countermeasures.

Back to Data protection

8 minute read · Content as of 21.07.2026

The clock starts with reliable awareness

The organisation must escalate incidents so that privacy, security, legal and the business can assess them in time. Where a notification is required, the GDPR in principle provides for a notification where feasible within 72 hours of becoming aware.

Assessment and containment run in parallel

Affected data and persons, scale, safeguards, possible consequences and countermeasures already taken are documented continuously. The decision not to notify also needs a traceable justification.

  • Secure the event and limit further disclosure
  • Determine data types, affected persons and possible consequences
  • Assess notification and communication obligations
  • Log decisions, timings and measures

Sources used

Back to Data protection