Quick answerBreach response and reporting is the structured handling of a privacy or security incident – discovery, evaluation, communication, recording and remediation. Under GDPR, breaches likely to result in risk must be reported to the supervisory authority within 72 hours of awareness; high-risk breaches must also be communicated to affected individuals. POPIA and most modern regimes apply similar duties.
Definition
A ‘personal data breach’ under GDPR is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This is broader than most teams expect: a misdirected email containing personal data is a breach. A laptop lost on a train is a breach. A ransomware incident that encrypts personal data is a breach, even if no data is exfiltrated. The trigger is unauthorised access or loss of confidentiality, integrity or availability – not just data theft.
Timeframes and obligations
Under GDPR Article 33, breaches likely to result in risk to data subjects must be notified to the lead supervisory authority within 72 hours of awareness. If notification is delayed, the reasons for delay must accompany the notification. Article 34 requires direct communication to affected individuals where the breach is likely to result in high risk. POPIA: ‘as soon as reasonably possible’ (interpreted as days, not weeks). CCPA / state laws: vary, typically tied to specific data types.
What good breach response includes
- Intake of suspected and confirmed incidents from any source – IT, employees, third parties, regulators, affected individuals
- Initial triage – what data, how many subjects, what risk
- Containment and forensic investigation
- Severity assessment and notification decision
- Regulator notification (where applicable) within statutory window
- Communication to affected individuals (where high-risk)
- Post-incident review and remediation tasks
- Evidence retention for audit and regulator scrutiny
The 72-hour clock
GDPR’s 72-hour window runs from the moment the controller becomes aware of the breach – typically interpreted as the moment there is a ‘reasonable degree of certainty’ that a breach has occurred. The clock does not pause for weekends or holidays. The notification can be staged: an initial notification within 72 hours with the information available, and supplementary information provided as the investigation progresses. Delayed notification is not automatically a violation – but the reasons for the delay must be documented.
Notification thresholds
Regulator notification (Article 33)
Required where the breach is ‘likely to result in a risk’ to data subjects. Most breaches involving personal data meet this threshold – a high bar of confidence is required to conclude otherwise.
Individual notification (Article 34)
Required where the breach is ‘likely to result in a high risk’. Notification to individuals is not required if (a) appropriate technical measures rendered the data unintelligible (e.g. strong encryption), (b) subsequent measures ensured the high risk is no longer likely to materialise, or (c) it would involve disproportionate effort – in which case public communication suffices.
Documentation (Article 33(5))
All breaches must be documented internally – facts, effects, remedial action – regardless of whether notification thresholds are met. This is the personal-data-breach register.
Common pitfalls
- Treating the 72-hour clock as starting only when the investigation is complete
- Failing to maintain a breach register for incidents below the notification threshold
- Communicating with individuals before regulator notification (the order matters)
- Sharing speculative early findings that change materially during investigation
- No post-incident review – the same root cause recurs because nothing changed
- Confusing security incidents with personal data breaches – not every incident is a breach, and not every breach is a security incident
How PrivIQ approaches breach response
PrivIQ provides structured intake for suspected and confirmed incidents, severity assessment workflow, notification decision support aligned to GDPR Articles 33-34, communication templates, and a retained evidence pack usable across GDPR, POPIA, CCPA and similar regimes. The breach register is maintained as a matter of routine, not assembled in panic.
- The 72-hour clock runs from awareness, not from investigation completion.
- All breaches must be documented internally – even those below the notification threshold.
- Notification to individuals is only required for high-risk breaches and can be avoided where appropriate encryption renders the data unintelligible.
- Most breach response failures are documentation failures, not investigation failures.
PrivIQ helps organisations and consultants put this into practice — with policies, controls, evidence, tasks, registers and reporting that survive audit.
More on Privacy Compliance.
Is every security incident a personal data breach?
No. A security incident becomes a personal data breach when it affects the confidentiality, integrity or availability of personal data. A DDoS that takes down a website without affecting personal data is a security incident; it may not be a breach. A ransomware incident that encrypts personal data is a breach even without exfiltration, because availability is affected.
When does the 72-hour clock start?
At the moment the controller becomes aware of the breach – typically interpreted as the moment there is a reasonable degree of certainty that a breach has occurred. Not when the investigation finishes.
Do I notify individuals or the regulator first?
Regulator first. Individual notification follows, where the breach is likely to result in high risk. Notifying individuals before the regulator can complicate the investigation and the regulator’s own response.
Does encryption avoid notification?
It can avoid individual notification under Article 34(3)(a) – where the affected data was rendered unintelligible to unauthorised persons through encryption or equivalent measures, and the key is not compromised. Regulator notification under Article 33 may still apply.
What happens if I notify late?
Late notification is permitted under GDPR if the reasons for delay are documented. Regulator response varies – late notification is treated more leniently than no notification, but persistently late or incomplete notifications attract enforcement action.