Skip to content
compliancebase
GDPRChapter IV — Communication of a Personal Data Breach

Article 34

Communication of a Personal Data Breach

GDPR · Regulation (EU) 2016/679 · Last verified August 2026

Objective

Communicate high-risk personal data breaches to affected individuals without undue delay, using clear information about consequences, response, and protective steps.

Points of focus

  • Assess whether a breach is likely to create high risk
  • Prepare clear communications with required content
  • Document exceptions such as effective protection or disproportionate effort

Implementation notes

Add individual-harm scoring and notification drafting to incident response, maintain approved communication channels, and validate whether encryption or containment genuinely rendered data unintelligible. Operationalize assess whether a breach is likely to create high risk in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain breach risk assessment and notification decision with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that the team waits for exact impact counts before drafting an urgent high-risk notice Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample breach risk assessment and notification decision with dates and named reviewers. Be ready to walk through how you detect and correct: the team waits for exact impact counts before drafting an urgent high-risk notice

Evidence auditors typically request:

  • Breach risk assessment and notification decision
  • Approved individual communication and delivery metrics
  • Evidence supporting encryption or another Article 34 exception

Common gaps

  • The team waits for exact impact counts before drafting an urgent high-risk notice
  • Encryption is cited as an exception without confirming that keys were unaffected

Cross-Framework Mapping

FrameworkRequirementImplementation note
GDPRArticle 34This control
SOC 2CC3.2, CC6.1Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness.
ISO 27001A.5.34, A.8.10ISO privacy and security controls can implement parts of this duty when mapped to processing.
HIPAA164.308(a)(1)HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data.

Primary sources

Frequently Asked Questions

Communication of a Personal Data Breach applies to the systems and commitments in your GDPR scope. Translate the requirement into concrete operating workflows — assess whether a breach is likely to create high risk — with evidence stored where auditors and customers can sample it.

Lead with breach risk assessment and notification decision and pair it with approved individual communication and delivery metrics. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because the team waits for exact impact counts before drafting an urgent high-risk notice Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679

Last verified: August 2026 · Primary sources linked above