Article 33
Notification of a personal data breach to the supervisory authority
GDPR · Regulation (EU) 2016/679 · Last verified July 2026
Objective
In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after becoming aware of it, notify the competent supervisory authority, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; processors shall notify the controller without undue delay after becoming aware.
Points of focus
- Controllers notify the supervisory authority without undue delay and within 72 hours where feasible when risk is not unlikely
- Include Article 33(3) content: nature of breach, contacts, likely consequences, measures taken or proposed
- Reason delayed notifications beyond 72 hours when applicable
- Document breaches including facts, effects, and remedial action (Article 33(5))
- Processors notify the controller without undue delay after becoming aware
Implementation notes
Article 33 is a legal notification duty layered on top of security incident response. Define when your organisation is 'aware' of a personal data breach, who owns the risk assessment, and how the 72-hour controller clock is tracked in tickets. Maintain a breach register even when you conclude notification is not required because risk to people is unlikely — Article 33(5) expects documentation of facts, effects, and remedies. If you are a SaaS processor, contract and operationalise without-undue-delay notice to the customer-controller with enough detail for them to meet their own Article 33/34 duties. Train on-call engineers that containment and forensics continue in parallel with notification analysis — waiting for perfect root cause is a common cause of late filings. Align templates with your lead supervisory authority's submission channels and with Article 34 data-subject notices when risk is higher.
Audit tip: Walk a tabletop: time of awareness → risk assessment → SA notify/no-notify decision with written rationale and draft Article 33(3) content.
Evidence auditors typically request:
- Breach response playbook with awareness definition and 72-hour timeline
- Personal-data-breach register / log with risk rationale for notify vs not notify
- Draft supervisory notification template covering Article 33(3) elements
- Processor-to-controller notification clause and on-call escalation path
- Tabletop exercise proving the clock and decision tree
Common gaps
- IR plan covers 'security incidents' but never defines personal data breach or SA notification
- No breach log for near-misses and non-notifiable events
- Processor delays telling the controller while 'still investigating'
- Assuming SOC 2 incident handling alone satisfies Article 33 clocks
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 33 | This control |
| ISO 27001 | A.5.24, A.5.26, A.5.27 | Incident planning, response, and learning |
| SOC 2 | CC7.3, CC7.4, CC7.5 | Event evaluation, incident response, and recovery |
| HIPAA | 164.400, 164.404, 164.408 | Breach Notification Rule — different thresholds and timelines |