Back to glossaryLaw & regulation

Data breach notification (72 hours)

The GDPR obligation to report a data breach to the supervisory authority within seventy-two hours, and to affected individuals where the risk is high.

Definition

Data breach notification is one of the most operational obligations of the General Data Protection Regulation. Where a breach is likely to give rise to a risk to the rights and freedoms of individuals, the controller must notify the competent supervisory authority, in France the CNIL, within seventy-two hours of becoming aware of it, under Article 33. Where the breach is likely to give rise to a high risk, the controller must in addition inform the affected individuals without undue delay, under Article 34. This very short deadline requires organizations to have a rapid detection and response capability, and makes the handling of the first hours of an incident a legal as much as a technical issue. For cyber insurance, these obligations constitute a loss item in their own right, covering forensic analysis costs to characterize the breach, legal advice to assess notification duties, the notification costs themselves and the management of the relationship with the regulator and affected individuals. The complexity grows for companies active in several countries, which must contend with a mosaic of authorities and requirements, placing notification compliance at the heart of incident response.

Example

A company discovers on a Sunday evening that a customer database has been exfiltrated. The seventy-two-hour countdown forces it to urgently mobilize forensics, lawyers and management to characterize the breach and prepare the notification to the CNIL on time.

Related terms
Related articles
Also known as

notification de violation, data breach notification, obligation de notification RGPD