EDPB 9/2022
Guidelines 9/2022 on personal data breach notification under GDPR
What it covers
These guidelines explain the mandatory breach notification obligations under Articles 33 and 34 GDPR, including when a controller becomes 'aware' of a breach, what information must be provided to supervisory authorities and data subjects, and how to assess risk and high risk. They include an annex with a flowchart and worked examples of different breach scenarios and who must be notified.
Why it matters
It is the primary operational reference for security and incident response teams and DPOs deciding whether, when and how to notify a personal data breach.
Refer to it when
- responding to a suspected or confirmed data breach
- deciding whether a breach must be notified to a supervisory authority or communicated to data subjects
- handling a cross-border breach involving a lead supervisory authority
- documenting a breach for the internal register required by Article 33(5)
Questions this document addresses
- When does a controller become 'aware' of a personal data breach for the purposes of the 72-hour clock?
- What information must be included in a notification to a supervisory authority?
- When is a breach unlikely to result in a risk such that notification is not required?
- How should cross-border breaches and breaches at non-EU establishments be notified?
- What role does the DPO play in the breach response process?
Topics
- Personal data breaches
- Security of processing
- Supervisory authorities
- Enforcement
The updated core guidance on breach notification: what counts as a personal data breach, the 72-hour deadline, notifying individuals, record-keeping, and notification duties of controllers not established in the EU.
Mapped GDPR Articles
Reproduced from official EDPB publications for reference. Not legal advice.