Article 34
Communication of a Personal Data Breach
GDPR · Regulation (EU) 2016/679 · Last verified August 2026
Objective
Communicate high-risk personal data breaches to affected individuals without undue delay, using clear information about consequences, response, and protective steps.
Points of focus
- Assess whether a breach is likely to create high risk
- Prepare clear communications with required content
- Document exceptions such as effective protection or disproportionate effort
Implementation notes
Add individual-harm scoring and notification drafting to incident response, maintain approved communication channels, and validate whether encryption or containment genuinely rendered data unintelligible. Operationalize assess whether a breach is likely to create high risk in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain breach risk assessment and notification decision with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that the team waits for exact impact counts before drafting an urgent high-risk notice Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample breach risk assessment and notification decision with dates and named reviewers. Be ready to walk through how you detect and correct: the team waits for exact impact counts before drafting an urgent high-risk notice
Evidence auditors typically request:
- Breach risk assessment and notification decision
- Approved individual communication and delivery metrics
- Evidence supporting encryption or another Article 34 exception
Common gaps
- The team waits for exact impact counts before drafting an urgent high-risk notice
- Encryption is cited as an exception without confirming that keys were unaffected
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 34 | This control |
| SOC 2 | CC3.2, CC6.1 | Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness. |
| ISO 27001 | A.5.34, A.8.10 | ISO privacy and security controls can implement parts of this duty when mapped to processing. |
| HIPAA | 164.308(a)(1) | HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data. |
Primary sources
- EUR-Lex GDPR Article 34: Regulation (EU) 2016/679, Article 34 — Communication of a Personal Data Breach