It has happened: somebody has pasted a customer list, a job application or a meeting transcript into a public AI tool. This is not a catastrophe and in most cases it is manageable — but a clock is running. This page is written as a set of instructions, not as an essay.
By Patrick de Kathen, Founder of KlarComply · Reviewed on
Not every mistaken entry is a personal data breach. Work through two questions in order.
If only an anonymised calculation or a product description went in, there is no personal data breach. What may remain is the trade secrets question — see trade secrets and AI tools — but the 72-hour clock is not running.
That provision covers any breach of security leading to unauthorised disclosure of, or access to, personal data. Where customer data are entered into a tool for which there is no sound legal basis and no processor contract, that is normally an unauthorised disclosure to the provider. A breach therefore exists — even if nobody read the data.
If the tool was used with a business agreement and a processor contract, and simply for a category of data not internally approved, you have a breach of your internal rule — but not necessarily a disclosure to an unauthorised recipient. The assessment then comes out considerably milder.
If a personal free account was used, there is usually no contractual basis at all. That is the more serious case, and it is the more common one.
Article 33(1) GDPR requires notification to the supervisory authority unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Note the structure: notification is the rule, refraining from it is the exception, and it is the exception you have to justify.
| Factor | Raises the risk | Lowers the risk |
|---|---|---|
| Type of data | health, finances, job applications, special categories under Art. 9 | a name and a business address with nothing further |
| Volume | a complete customer list, many data subjects | a single individual, a single data point |
| Contractual position | personal account, no agreement | business agreement with processor contract, training use disabled |
| Where the data now sit | history cannot be deleted, retention unclear | history deleted, deletion confirmed, short retention period |
| Identifiability | real names with contact details | pseudonyms or placeholders, no route back to a person |
Record the reasoning in five to ten sentences. In any later review that reasoning matters more than the outcome, because it shows that you assessed rather than guessed.
Article 33(1) GDPR: notification is made without undue delay and, where feasible, not later than 72 hours after having become aware of the breach. Four points are regularly misunderstood:
Where not all the information is available, notify on time with what you have and supply the rest later — Article 33(4) expressly allows that. Supervisory authorities provide online forms for this. Which authority is competent depends on where you are established, and in several member states on the region as well; if you operate across borders, identify your lead supervisory authority before you need it, not on the day.
Article 34 GDPR requires communication to the data subjects where the breach is likely to result in a high risk to their rights and freedoms. The threshold is therefore higher than for notifying the authority.
It falls away, among other cases, where the data are unintelligible to unauthorised persons through appropriate measures such as encryption, where subsequent measures ensure the high risk is no longer likely to materialise, or where individual communication would involve disproportionate effort — in which case a public communication takes its place.
For a typical mistaken entry of individual customer details into an AI tool, a high risk can often be ruled out — often, not always. With health data, application documents or financial data the assessment looks different. If you are unsure, speak to the supervisory authority; it can order communication under Article 34(4) in any event.
Technical damage limitation runs in parallel with the legal assessment. Four steps, in this order:
Complete and verifiable removal from a model that has already been trained generally cannot be assured. So do not tell the supervisory authority or the affected customer that the data have been “fully deleted” when what you obtained was deletion of the history. Describe precisely what was deleted and what remains open. Honesty here is also the safer strategy, because the opposite is checkable.
Article 33(5) GDPR requires you to document all personal data breaches, comprising the facts, their effects and the remedial action taken. That applies whether or not you notified. The documentation must enable the supervisory authority to verify compliance.
In practice: an incident register with one line per case, and a file per case. The most common failing in reviews is not the missing notification. It is the missing documentation of the cases where you decided against notifying.
So that the abstract test becomes usable — without this classification replacing your own assessment:
| Facts | Typical assessment |
|---|---|
| A single customer name with a company address, entered into a tool with a business agreement and training use disabled | Breach doubtful, or risk very low; document it, notification usually unnecessary — record the reasoning |
| A customer list of fifty names, email addresses and turnover figures in a personal free account | A breach has occurred and risk cannot be excluded; notification under Article 33 is normally indicated |
| A complete job application with CV in a personal account | A breach has occurred; risk elevated because of the type of data, and communication under Article 34 should be seriously considered |
The boundaries are fluid, and supervisory authorities do not assess identically. If you are wavering, notify. A notification that later proves unnecessary carries no sanction. An omitted one that was necessary does.
Every reported incident exposes a gap nobody could see beforehand. Four questions, a week later:
Feed the result into the AI policy and into the training. An incident that turns into a rule has paid for itself.
“Anyone who has inadvertently entered confidential or personal data into an AI tool must report it to [role] without delay. A prompt self-report carries no employment consequences.”
Without the second sentence you do not hear about incidents — and without awareness you cannot meet the Article 33 GDPR deadline, which runs from awareness. That is exactly why the sentence belongs in every policy, and exactly why it is missing from most of them.
Whether that reporting route exists in your organisation is one of the points in the free quick check. If you are reviewing your external channels in the same session, the free AI labels cover the disclosures for chat windows and AI images.
Record the facts in writing, secure evidence with screenshots, stop further entries, involve the data protection officer and note the time you became aware. The Article 33 GDPR clock runs from that awareness. Do not sanction anyone, or the next case will not be reported.
From the point at which the controller becomes aware of the breach, not from the incident itself. The period runs on calendar time, so weekends and public holidays count. 72 hours is the ceiling; the provision requires notification without undue delay.
Notification is the rule. It falls away under Article 33(1) GDPR only where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. You have to reason and document that assessment — and in a review the reasoning matters more than the outcome.
Only where a high risk is likely, under Article 34 GDPR. The threshold is higher than for notifying the authority. For individual contact details a high risk can often be ruled out; for health, application or financial data, less so. The supervisory authority can order communication in any event.
It is a necessary step but not a complete remedy. Request deletion from the provider as well and obtain written confirmation. Never assure anyone of complete removal from a model that has already been trained — that generally cannot be assured.
Yes. Article 33(5) GDPR requires documentation of all breaches with the facts, their effects and the remedial action, independently of notification. The most common failing in reviews is not the missing notification but the missing documentation of cases where notification was deliberately not made.
Normally not. The serious incident reporting duty in Article 73 of the AI Act is addressed to providers of high-risk systems. For a deploying company in the situation described here it is not engaged; Articles 33 and 34 GDPR are what govern.
The one competent for you, which depends on where you are established and in several member states on the region as well. If you process across borders, identify your lead supervisory authority in advance rather than on the day. Check your customer contracts too — many contain their own notification deadline, sometimes shorter than 72 hours.
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free