Data breach notification requirements

Last updated:
14.10.2024
Even before the GDPR, there were mandatory reporting and notification requirements for data breaches, both to data protection authorities and to the affected individuals. Neglecting these reporting obligations in the event of a data incident was already subject to fines. However, the GDPR, which has been in effect since May 25, 2018, imposes stricter requirements in this area, and the scope for fines has been increased drastically. Companies must pay closer attention to their protocols and procedures for reporting such breaches. Proactive action is required from businesses to meet these heightened demands in their day-to-day operations.
Data breach notification requirements
Key Takeaways
  • The GDPR drastically increases reporting requirements and fines for data protection violations.
  • Data breaches must be reported within 72 hours.
  • Article 33 of the GDPR governs reporting to authorities, while Article 34 covers notification to affected individuals.
  • The reporting obligation applies regardless of whether the company is at fault.
  • Violations can result in fines of up to 20 million EUR or 4% of annual turnover.

Reporting obligations for data breaches – Regulations under the EU GDPR

Since May of last year, two provisions in the GDPR have set the legal framework for reporting data breaches. While Article 33 GDPR addresses the obligation to notify supervisory authorities of personal data breaches, Article 34 GDPR governs the obligation to inform the affected individuals. The GDPR goes significantly further than the previous regulations under Section 42a of the German Federal Data Protection Act (BDSG). Article 33 GDPR covers not only breaches involving sensitive personal data but applies to all personal data. The only exception to the reporting requirement is if the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The controller must make this risk assessment. Typically, the Data Protection Officer conducts a risk evaluation and provides a recommendation after reviewing the facts, but the final responsibility always rests with the controller.

Under the new regulations, data breaches must be reported to the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Article 33(5) GDPR details the documentation requirements that must accompany a breach notification. This includes documenting not only the breach itself but also its consequences and the measures taken to prevent further damage. Affected individuals must also be informed of the breach without undue delay. This information must be provided in clear and plain language that is easily understood by the individuals concerned. In principle, notification to the affected individuals must be made on an individual basis; a public announcement is only permitted as an exception if individual notification would involve disproportionate effort. You can download a guide here on how to respond immediately in the event of a data breach.

Furthermore, the obligation to inform applies regardless of fault; even if the company is not responsible for the data loss, the required notifications must still be made. While the GDPR does not prescribe a specific format for the notification, it is advisable to provide it in text form (if only for evidentiary purposes).

Reporting obligations for data breaches – high fines at stake

Previously, violations of data breach reporting obligations were subject to fines of up to 300,000 EUR. The EU General Data Protection Regulation significantly increases this threshold. Such violations are now subject to fines of up to 20 million EUR or 4% of the total worldwide annual turnover of the preceding financial year. Even though it remains to be seen how this framework will be applied in practice, companies must ensure that their data breach reporting processes are fully GDPR-compliant moving forward. Since May 2018, the obligation to report data breaches to authorities and affected individuals has become more critical than ever. Consequently, companies may need to implement updated technical measures to monitor all data processing, as the scope is no longer limited to sensitive personal data.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in