GDPR Data Breach: Mastering the 72-Hour Notification Deadline
Learn how to report a GDPR data breach within the 72-hour deadline in a legally sound way and shield your business from fines with an emergency plan.

What is a GDPR data breach? The worst case for mid-sized companies
An IT security incident is a shock for any company, yet not every disruption is automatically a reportable data breach. Under Article 33 of the General Data Protection Regulation (GDPR), a data breach occurs when there is a breach of the protection of personal data[1]. In concrete terms this means: data belonging to real people, whether customers, employees or suppliers, was accidentally or unlawfully deleted, lost, altered or disclosed to unauthorised third parties.
As a managing director or IT lead in a mid-sized company, you have to decide in an instant during an emergency whether there is a risk to the rights and freedoms of natural persons. A mere loss of data with no sensitive potential often remains non-reportable. However, if sensitive data such as passwords, bank details or health data falls into the wrong hands, those affected face financial harm, identity theft or considerable personal disadvantage. In such cases the statutory notification duty kicks in immediately.
Drawing the line: when you have to act
The boundary between an internal nuisance and a reportable emergency is sometimes narrow. A classic example is the loss of hardware: if an employee loses a USB stick, whether you have to report depends on how it was secured. If the stick is unencrypted and contains customer lists, you have to report the incident to the supervisory authority[1]. If, on the other hand, it is encrypted to the current state of the art, misuse is practically impossible and the notification duty falls away. Things get more complex with cyberattacks: a ransomware attack on a mid-sized company not only blocks your IT, it almost always comes with an unauthorised data leak and must be reported.
| Scenario | Risk to those affected | Notification duty under Art. 33 GDPR |
|---|---|---|
| Loss of an unencrypted USB stick with personnel files | High: risk of identity theft and misuse | Yes, mandatory within 72 hours |
| Theft of a laptop with AES-256 disk encryption | Low: unauthorised access to the data is technically impossible | No, an entry in the internal register is enough |
| Successful phishing attack on an M365 admin account | Very high: full access to sensitive business and customer data | Yes, notify the authority and possibly those affected |
Regardless of whether an incident is reportable or not, you are legally required to document every data protection breach internally and without gaps[1]. To avoid getting into this predicament in the first place, proactive protection helps. The Cybersecurity and Managed IT services from CAVRIX support mid-sized companies in systematically closing security gaps, fending off attacks and keeping complete IT documentation ready for the authorities in an emergency.
The clock is ticking: understanding the 72-hour notification duty correctly
When a suspected GDPR data breach comes up in your company, every second counts. Article 33 of the General Data Protection Regulation states unambiguously that such an incident must be reported to the competent supervisory authority without undue delay and, where feasible, within 72 hours. That this is no theoretical obligation is borne out by practice among German mid-sized companies: in 2023 alone, 24,749 data breaches were officially reported to the German supervisory authorities[2]. Given these high figures, it is clear that hesitation in an emergency can prove costly. On top of that, failing to meet the deadlines can trigger personal liability for management under NIS2, if your business falls within the statutory cyber directives.
When the deadline starts: the trigger point of becoming aware
A widespread misunderstanding is the question of when the 72-hour deadline actually begins. The legislator ties the starting point to so-called awareness. This means: the clock starts ticking as soon as you or another responsible person in your company has reasonable certainty that a security incident endangering personal data has occurred. However, you cannot artificially delay the deadline by looking the other way at warning signs. A late discovery caused by inadequate IT monitoring or missing security controls is generally not accepted by the authorities as an excuse.
The weekend trap and late notifications
Another critical point concerns weekends and public holidays. Because the 72-hour requirement is a deadline measured in hours at EU level, it is calculated according to the European regulation on time limits[3]. As a result, Saturdays, Sundays and public holidays all count without interruption. If your IT department gains certainty about a ransomware attack on a Friday afternoon at 4:00 pm, for example, the notification deadline ends exactly on Monday afternoon at 4:00 pm. The deadline does not shift to the next working day.
- Starts on becoming aware: the deadline begins as soon as there is certainty about the data risk. Organisational negligence does not protect you from the deadline starting.
- Weekends count in full: because the deadline is calculated in hours, the clock keeps running continuously over the weekend and on public holidays[3].
- Duty to justify an overrun: if you exceed the 72 hours, you still have to submit the notification, but you must accompany it with a solid justification for the delay.
To avoid panicking in an emergency, a working interplay of monitoring and processes is indispensable. With our Cybersecurity service, CAVRIX offers continuous monitoring and a fast response to threats so that incidents are detected immediately. Our Managed IT service ensures complete, compliance-ready IT documentation in parallel. Together with the Compliance service and the Command Center, you keep all obligations in view and can respond without delay in an emergency.
Step by step: the action plan in the event of a data breach
When a data breach is suspected, a relentless countdown begins. From the moment it becomes known, you have exactly 72 hours to analyse the situation, contain it and report it to the competent supervisory authority[4]. In the hectic daily routine of mid-sized companies, this time pressure often leads to panicked, uncoordinated reactions. A structured action plan is your most important tool for staying calm, meeting your legal obligations without gaps and, at the same time, setting the course for complete documentation.
Step 1: contain the damage and isolate IT systems
Immediate damage control has top priority. If sensitive data has been siphoned off or IT systems encrypted, you have to isolate the affected systems at once to prevent it from spreading through the company network. That means, for example: disconnect infected servers from the network and deactivate compromised user accounts. It is important, however, that in doing so you do not destroy valuable evidence for the later forensic analysis. Do not delete system logs and do not simply hard-power-off affected machines, as this loses volatile data in memory. Professional support through Managed IT and modern Cybersecurity ensures that infected endpoints are isolated automatically in an emergency while important log files are preserved for the supervisory authority.
Step 2: carry out a risk analysis for those affected
Not every data breach has to be reported. What matters is the risk to the rights and freedoms of the affected persons[5]. You have to assess which categories of data are affected (for instance simple contact details compared with highly sensitive financial or health data) and how great the danger of identity theft or financial harm is. If there is likely to be no risk, the notification duty falls away, but you still have to document the incident internally. If there is a risk, notifying the authority is mandatory. In the case of a particularly high risk, you additionally have to inform the affected persons without delay. At this stage, be sure to bring in your data protection officer or specialised services such as Compliance to ensure a legally sound assessment.
Step 3: fill in and submit the notification form
If the risk analysis concludes that a notification duty exists, you have to submit the report via the official online portal of the data protection authority in your federal state[4]. The notification must be precise, factual and transparent. Since in the first few hours it is often still unclear which data was exactly siphoned off, the GDPR also allows a so-called preliminary notification or the gradual submission of information later. The important thing is that the initial notification arrives within the 72-hour deadline, so as to avoid painful fines for missing the deadline.
- Nature of the data breach: description of the category and the approximate number of affected persons and records.
- Contact details: name and contact details of your data protection officer or another point of contact for follow-up questions.
- Likely consequences: description of the probable consequences of the data breach for those affected (such as identity theft or attempted fraud).
- Measures taken: an outline of the steps already initiated or planned to remedy the breach and minimise the damage.
Once the notification has been sent, the work is not yet done. You have to record the entire incident, including all remedial measures taken, in your internal documentation. A structured emergency plan, established as part of a comprehensive Cybersecurity concept, ensures that you run through each of these steps flawlessly and without losing time in an emergency.
The documentation duty: why silence is not always golden
When, after a thorough analysis, it turns out that a data breach poses no notable risk to the rights and freedoms of the affected persons, many managing directors breathe a sigh of relief. But be careful: just because you do not have to report the incident to the supervisory authority, you must under no circumstances simply sweep it under the rug. Article 33(5) of the GDPR requires complete and unconditional internal documentation of every single data protection breach[1]. Anyone who neglects this obligation commits a separate, fineable violation of the legal requirements that can become expensive in an emergency.
What belongs in the internal documentation register?
The internal documentation serves as your proof to the supervisory authority that you take the GDPR requirements seriously and acted professionally in an emergency[6]. A mere one-liner along the lines of "no risk identified" is never enough in an official inspection. You have to set out the entire life cycle of the incident in detail and in a comprehensible way. This also protects you against questions about personal compliance being raised after the fact, which is a critical issue especially with regard to management liability in mid-sized companies.
| Area | Mandatory content under the GDPR | Practical tip for mid-sized companies |
|---|---|---|
| Facts & scope | Precise description of the incident, the nature of the affected data and the number of affected persons. | Have your IT team secure all technical logs and affected systems right away. |
| Impact | Description of the potential or already realised consequences for the affected persons. | Assess factually whether financial harm, identity theft or reputational damage is looming. |
| Remedial measures | Documentation of all immediate measures taken as well as long-term corrections. | Link the measures directly to your IT ticketing systems. |
The justification for not reporting
The most important part of your register is the legal and technical justification for why you decided against notifying the supervisory authority[6]. You have to set out coherently why, according to your risk analysis, there is no risk to the affected persons. A typical example is losing a company laptop: if it is encrypted to the current state of the art, there is generally no risk to the data, since unauthorised third parties cannot gain access to it[6]. If this justification is missing from the register, the documentation is deemed incomplete.
Audit-proof archiving and IT support
The GDPR does not prescribe a specific tool, but it does require that, under the accountability principle, the documentation must be available to the supervisory authority at all times. It should therefore be archived in an audit-proof way so that subsequent manipulation is ruled out. Many mid-sized companies reach their organisational limits here, as they lack the necessary structures. This is where an integrated solution like Compliance from CAVRIX helps, automatically linking IT documentation, security events and legal requirements and thereby creating an audit-proof data foundation. Together with a solid Cybersecurity concept, you minimise the risk of fines and ensure that you can present the right evidence immediately in an emergency.
The IT emergency plan: prevention instead of crisis mode
In the event of a data breach, panic is a poor advisor. As soon as personal data is affected, the relentless 72-hour deadline for the official notification to the competent supervisory authority starts running[7]. A structured IT emergency plan that has been rehearsed in advance decisively shortens your response time in an emergency. When every move is right, you prevent momentous delays and at the same time lower the risk of momentous personal liability for management in Germany's mid-sized companies.
Defining roles and responsibilities precisely
An emergency plan only works if everyone involved knows their exact tasks. The IT leads, data protection officers and management act as a closely coordinated team. In an emergency, no time may be lost clarifying responsibilities or looking up the authorities' contact details. With a professional Cybersecurity solution for mid-sized companies, you establish clear procedures with which your team can quickly isolate threats and initiate the necessary steps.
Automated patch management minimises attack surfaces
The best defence against a data breach is proactively closing security gaps. Outdated software is one of the most common causes of successful attacks. Through the Managed IT service from CAVRIX, your infrastructure is continuously monitored. Automated patch management ensures that critical security updates are installed directly and without delay. This takes away the attackers' foothold while, at the same time, creating compliance-compliant IT documentation.
Fast alerting via the Command Center
To meet the 72-hour notification duty, you need immediate clarity about the scope of an incident. This is where the CAVRIX Command Center comes in. This interface bundles security events and the current compliance status in one central place. You are alerted in real time via common communication channels such as Slack or Teams. This way you see immediately which systems are affected and can document the incident precisely.
- Clear responsibilities: structured assignment of tasks for IT administrators, data protection officers and management in an emergency.
- Automated patch management: continuous protection of systems against known vulnerabilities for active damage prevention.
- Real-time visibility: fast detection and immediate alerting via the Command Center to meet statutory deadlines.
Frequently asked questions
When does the 72-hour deadline start in a data breach?
The deadline starts the moment you, as the controller, have certainty about the data protection breach. This is the case as soon as there is sufficient evidence of the incident.
Does every GDPR data breach have to be reported?
No. A notification duty to the supervisory authority only exists if the incident is likely to result in a risk to the rights and freedoms of natural persons. If there is no such risk, you only have to document the incident internally.
What happens if I miss the 72-hour deadline?
If you exceed the 72-hour deadline, you have to accompany the late notification with a solid justification for the delay. Unjustified delays can result in additional fines.
How many data breaches are reported in Germany each year?
In 2023, the German supervisory authorities recorded a slight peak with 24,749 data breaches reported under Art. 33 GDPR. This shows that security incidents are an everyday occurrence for mid-sized companies.
What role does an IT emergency plan play in minimising risk?
An emergency plan sets clear roles and drastically shortens the response time. Through fast processes, you can minimise damage, meet deadlines and thereby lower the likelihood of fines.
What must a notification to the data protection authority contain?
The notification must describe the nature of the data breach, the categories and the approximate number of affected persons as well as the affected data categories. In addition, you must state the name of your data protection officer, the possible consequences and the remedial measures taken.