When must a controller notify a personal-data breach to the authority?
Tap to reveal answer
Answer
Without undue delay and, where feasible, within 72 hours after becoming aware.
The 72-hour clock is a common EPSO number.
GDPR, Regulation (EU) 2016/679
Deep dive
72-hour data breach clock: start of the countdown
Notify without undue delay and, where feasible, within 72 hours of becoming aware. The trap: 'becoming aware' means when you have reasonable certainty, not when you confirm every detail.
We use essential cookies to run the site. With your permission, we also use analytics and personalized advertising. Advertising consent allows us to share hashed contact details and location details with Google to match trial and lifetime conversions. Read our
Privacy Policy.