Skip to content
compliancebase
GDPRChapter IV — Notification of a personal data breach to the supervisory authority

Article 33

Notification of a personal data breach to the supervisory authority

GDPR · Regulation (EU) 2016/679 · Last verified July 2026

Objective

In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after becoming aware of it, notify the competent supervisory authority, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; processors shall notify the controller without undue delay after becoming aware.

Points of focus

  • Controllers notify the supervisory authority without undue delay and within 72 hours where feasible when risk is not unlikely
  • Include Article 33(3) content: nature of breach, contacts, likely consequences, measures taken or proposed
  • Reason delayed notifications beyond 72 hours when applicable
  • Document breaches including facts, effects, and remedial action (Article 33(5))
  • Processors notify the controller without undue delay after becoming aware

Implementation notes

Article 33 is a legal notification duty layered on top of security incident response. Define when your organisation is 'aware' of a personal data breach, who owns the risk assessment, and how the 72-hour controller clock is tracked in tickets. Maintain a breach register even when you conclude notification is not required because risk to people is unlikely — Article 33(5) expects documentation of facts, effects, and remedies. If you are a SaaS processor, contract and operationalise without-undue-delay notice to the customer-controller with enough detail for them to meet their own Article 33/34 duties. Train on-call engineers that containment and forensics continue in parallel with notification analysis — waiting for perfect root cause is a common cause of late filings. Align templates with your lead supervisory authority's submission channels and with Article 34 data-subject notices when risk is higher.

Audit tip: Walk a tabletop: time of awareness → risk assessment → SA notify/no-notify decision with written rationale and draft Article 33(3) content.

Evidence auditors typically request:

  • Breach response playbook with awareness definition and 72-hour timeline
  • Personal-data-breach register / log with risk rationale for notify vs not notify
  • Draft supervisory notification template covering Article 33(3) elements
  • Processor-to-controller notification clause and on-call escalation path
  • Tabletop exercise proving the clock and decision tree

Common gaps

  • IR plan covers 'security incidents' but never defines personal data breach or SA notification
  • No breach log for near-misses and non-notifiable events
  • Processor delays telling the controller while 'still investigating'
  • Assuming SOC 2 incident handling alone satisfies Article 33 clocks

Cross-Framework Mapping

FrameworkRequirementImplementation note
GDPRArticle 33This control
ISO 27001A.5.24, A.5.26, A.5.27Incident planning, response, and learning
SOC 2CC7.3, CC7.4, CC7.5Event evaluation, incident response, and recovery
HIPAA164.400, 164.404, 164.408Breach Notification Rule — different thresholds and timelines

Primary sources

Frequently Asked Questions

When the controller becomes aware of a personal data breach. Awareness generally means the organisation has a reasonable degree of certainty a breach occurred. Processors notifying you late can compress your remaining time — define awareness and escalation in the DPA and IR plan.

No. Notification is required for personal data breaches unless unlikely to result in a risk to rights and freedoms. Security incidents without personal data may still need SOC 2 handling without Article 33 filing. Document the risk decision either way.

Notify in phases: provide known Article 33(3) information within 72 hours where required, explain the delay for missing elements, and follow up as details emerge. Silence past 72 hours without reason is the compliance failure mode.

Processors notify the controller without undue delay after becoming aware of a personal data breach. They do not notify the supervisory authority instead of the controller (unless separately required). Speed and factual clarity to the controller are essential.

Article 33 is notification to the supervisory authority. Article 34 is communication to data subjects when the breach is likely to result in a high risk. Thresholds differ; both may apply to the same incident.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679

Last verified: July 2026 · Primary sources linked above