When must a controller notify a personal-data breach to the authority?
Tap to reveal answer
Answer
Without undue delay and, where feasible, within 72 hours after becoming aware.
The 72-hour clock is a common EPSO number.
GDPR, Regulation (EU) 2016/679
Deep dive
72-hour data breach clock: start of the countdown
Notify without undue delay and, where feasible, within 72 hours of becoming aware. The trap: 'becoming aware' means when you have reasonable certainty, not when you confirm every detail.