Incidents
Personal data breach: organising the first 72 hours so you can act
Not every security incident is notifiable. But every suspicion needs a fast, documented assessment of data, consequences and countermeasures.
8 minute read · Content as of 21.07.2026
The clock starts with reliable awareness
The organisation must escalate incidents so that privacy, security, legal and the business can assess them in time. Where a notification is required, the GDPR in principle provides for a notification where feasible within 72 hours of becoming aware.
Assessment and containment run in parallel
Affected data and persons, scale, safeguards, possible consequences and countermeasures already taken are documented continuously. The decision not to notify also needs a traceable justification.
- Secure the event and limit further disclosure
- Determine data types, affected persons and possible consequences
- Assess notification and communication obligations
- Log decisions, timings and measures
Sources used
- General Data Protection Regulation (EU) 2016/679 · EU · check the consolidated version
- Guidelines for Controllers and Processors · EDPB
- Privacy management, RoPA, DPIA and incident templates · KaitoSec