GuidelinesFinal · v2.0

EDPB 9/2022

Guidelines 9/2022 on personal data breach notification under GDPR

What it covers

These guidelines explain the mandatory breach notification obligations under Articles 33 and 34 GDPR, including when a controller becomes 'aware' of a breach, what information must be provided to supervisory authorities and data subjects, and how to assess risk and high risk. They include an annex with a flowchart and worked examples of different breach scenarios and who must be notified.

Why it matters

It is the primary operational reference for security and incident response teams and DPOs deciding whether, when and how to notify a personal data breach.

Refer to it when

  • responding to a suspected or confirmed data breach
  • deciding whether a breach must be notified to a supervisory authority or communicated to data subjects
  • handling a cross-border breach involving a lead supervisory authority
  • documenting a breach for the internal register required by Article 33(5)

Questions this document addresses

  • When does a controller become 'aware' of a personal data breach for the purposes of the 72-hour clock?
  • What information must be included in a notification to a supervisory authority?
  • When is a breach unlikely to result in a risk such that notification is not required?
  • How should cross-border breaches and breaches at non-EU establishments be notified?
  • What role does the DPO play in the breach response process?

Topics

  • Personal data breaches
  • Security of processing
  • Supervisory authorities
  • Enforcement

Official EDPB page for this document

The updated core guidance on breach notification: what counts as a personal data breach, the 72-hour deadline, notifying individuals, record-keeping, and notification duties of controllers not established in the EU.

Inline PDF preview is not supported in this browser. Open the PDF instead.

Mapped GDPR Articles

Reproduced from official EDPB publications for reference. Not legal advice.