Data breach notification requirements

- The GDPR drastically increases reporting requirements and fines for data protection violations.
- Data breaches must be reported within 72 hours.
- Article 33 of the GDPR governs reporting to authorities, while Article 34 covers notification to affected individuals.
- The reporting obligation applies regardless of whether the company is at fault.
- Violations can result in fines of up to 20 million EUR or 4% of annual turnover.
Reporting obligations for data breaches – Regulations under the EU GDPR
Since May of last year, two provisions in the GDPR have set the legal framework for reporting data breaches. While Article 33 GDPR addresses the obligation to notify supervisory authorities of personal data breaches, Article 34 GDPR governs the obligation to inform the affected individuals. The GDPR goes significantly further than the previous regulations under Section 42a of the German Federal Data Protection Act (BDSG). Article 33 GDPR covers not only breaches involving sensitive personal data but applies to all personal data. The only exception to the reporting requirement is if the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The controller must make this risk assessment. Typically, the Data Protection Officer conducts a risk evaluation and provides a recommendation after reviewing the facts, but the final responsibility always rests with the controller.
Under the new regulations, data breaches must be reported to the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Article 33(5) GDPR details the documentation requirements that must accompany a breach notification. This includes documenting not only the breach itself but also its consequences and the measures taken to prevent further damage. Affected individuals must also be informed of the breach without undue delay. This information must be provided in clear and plain language that is easily understood by the individuals concerned. In principle, notification to the affected individuals must be made on an individual basis; a public announcement is only permitted as an exception if individual notification would involve disproportionate effort. You can download a guide here on how to respond immediately in the event of a data breach.
Furthermore, the obligation to inform applies regardless of fault; even if the company is not responsible for the data loss, the required notifications must still be made. While the GDPR does not prescribe a specific format for the notification, it is advisable to provide it in text form (if only for evidentiary purposes).
Reporting obligations for data breaches – high fines at stake
Previously, violations of data breach reporting obligations were subject to fines of up to 300,000 EUR. The EU General Data Protection Regulation significantly increases this threshold. Such violations are now subject to fines of up to 20 million EUR or 4% of the total worldwide annual turnover of the preceding financial year. Even though it remains to be seen how this framework will be applied in practice, companies must ensure that their data breach reporting processes are fully GDPR-compliant moving forward. Since May 2018, the obligation to report data breaches to authorities and affected individuals has become more critical than ever. Consequently, companies may need to implement updated technical measures to monitor all data processing, as the scope is no longer limited to sensitive personal data.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.













