Data breaches: when you must report and to whom
How to decide whether an incident is notifiable, who must be told beyond the regulator, and the order in which to tell them.
The short answer
When a security incident touches personal data, there are usually four audiences with different triggers and deadlines. The supervisory authority must be notified within seventy-two hours of becoming aware, unless you can demonstrate the breach is unlikely to result in a risk to people’s rights and freedoms; a later notification must state the reasons for the delay. The people affected must be told without undue delay when the risk is likely to be high, unless an exception applies such as the data being unintelligible through encryption or subsequent measures removing the risk. Business customers whose data you process must be told under the timelines in your processing agreements, which are often shorter than the regulator’s and occasionally measured in hours. And your insurer must be notified under the policy’s clause, where late notice can reduce or void cover. Those clocks run at the same time, which is why the decision should follow a written test rather than a feeling, and why the reasoning is recorded whether or not you notify. A phased notification within the deadline is expressly permitted and always better than a complete one that is late.
The decision, in order
| Question | If yes | If no |
|---|---|---|
| Is personal data involved, including loss of availability? | Continue | Still an incident; handle and record |
| Was the data effectively protected, for example strongly encrypted with keys uncompromised? | Risk may be reduced; assess and record | Continue |
| Can you demonstrate the breach is unlikely to result in a risk to people’s rights and freedoms? | Document the assessment and the reasons; do not notify | Notify the supervisory authority within 72 hours of awareness |
| Is a high risk likely? | Also inform the people affected without undue delay | Individual notice not required; consider it anyway if it helps them |
| Is any of the data processed on behalf of a business customer? | Notify them under the agreement’s timeline, usually faster | No contractual notification |
| Does a cyber policy cover this? | Notify the insurer per the policy | No |
| Are payment, platform or sector rules engaged? | Follow those procedures | No |
Getting the order right
- Contain first: stop the exposure before communicating anything.
- Establish the facts you can: what data, whose, how many, when, how.
- Start the clocks: record the moment of awareness in writing.
- Check the contractual timelines in your processing agreements; they usually bite first.
- Notify business customers within their timeline with what you know.
- Notify the supervisory authority within seventy-two hours, in phases if needed.
- Notify the insurer per the policy.
- Inform affected individuals where the risk is high, in plain language, with what they should do.
- Record everything, including decisions not to notify and why.
- Review the cause and change what allowed it.
Telling people well
When individual notice is required, be direct and early: what happened, when, what data was involved, what could follow, what you have done, what they should do, and a named contact who will answer. Avoid minimising, avoid technical detail that obscures, and do not wait for complete information if that means waiting days. People and regulators both judge the handling more than the incident, and a clear early message is the most effective thing you can do for your position and for the people affected.
What this means for you
Decide notifiability with a written test: personal data involved, protection applied, risk likely, high risk likely, and then work outwards to customers, insurers and sector rules. Record the moment of awareness and the reasoning either way. Notify the authority within seventy-two hours where required, in phases if necessary, meet the shorter contractual deadlines, and tell affected people plainly when the risk is high. This is general information rather than legal advice.
Frequently asked questions
How do we decide whether it is notifiable to the regulator?
Assess the risk to the rights and freedoms of the people whose data is involved: the type of data, how identifiable they are, how many, the ease of misuse, the severity of the consequences, and whether the data was protected, for example by encryption. If a risk is likely, notify within seventy-two hours of awareness. If a high risk is likely, also tell the individuals. If neither, document the assessment and keep it; the decision not to notify must be justifiable later.
Who else has to be told?
Business customers whose data you process, under the timelines in your processing agreements, which are frequently twenty-four or forty-eight hours and sometimes shorter. Your insurer, under the notification clause of your cyber policy, where late notice can void cover. Payment providers and platforms if their data or systems are involved, under their own rules. And in some sectors, a regulator other than the data protection authority. Map these in advance, because the clock runs on several of them at once.
What if we are not sure yet?
Notify in phases. The regulation expressly allows providing information in stages when it is not all available, and a phased notification within the deadline is better than a complete one that is late. For contractual notifications, tell the customer what you know and when you will update them. Silence while you investigate is the choice that causes the most damage to trust and to your legal position.
Sources
- EUR-Lex: Regulation (EU) 2016/679, Articles 33 and 34 (accessed 2026-09-14)
- Autoriteit Persoonsgegevens: Data breaches (accessed 2026-09-12)