Most data breaches do not look like a hacking attack. They look like a Tuesday afternoon: a group email with an open recipient list, a payslip to the wrong address, a laptop left on a train. What matters then is not the mistake — but whether the organisation is capable of acting within 72 hours. And that is decided in the first minute: by reporting.
By Patrick de Kathen, Founder of KlarComply · Reviewed on
The law calls it a “personal data breach”: any event leading to the destruction, loss, alteration or unauthorised disclosure of personal data — accidental or deliberate. The SME classics:
| Incident | Breach? |
|---|---|
| Group email to customers with all addresses in CC instead of BCC | Yes — disclosure of the addresses to all recipients |
| Payslip or quotation to the wrong recipient | Yes |
| Unencrypted laptop or USB stick lost | Yes |
| Customer list entered into a public AI tool | Yes — transfer to a third party without a basis |
| Properly encrypted laptop lost, key safe | Document the incident; risk often low |
Notifiable breaches must reach the supervisory authority within 72 hours of awareness (Art. 33). Two points are regularly underestimated. First: the clock starts as soon as anyone in the company knows of the incident — not once management hears of it. Second: not every breach is notifiable — notification is waived where the breach is unlikely to result in a risk to those affected. That assessment is made by the responsible person, not at the desk where it happened. At high risk, informing the affected individuals comes on top (Art. 34).
For the responsible person to assess and notify within 72 hours, one rule applies to everyone else: report internally at once — what happened, which data, since when. And for that reflex to work, the second rule matters just as much: honest, immediate reporting never gets anyone into trouble. A concealed breach robs the company of every option to respond — that is the real risk, not the typo in the address field.
Contain (lock access, ask recipients to delete — staying honest: deletion only works going forward), assess (risk to those affected?), decide (notify or not), document. The documentation duty applies always — including for breaches that need no notification (Art. 33(5)): incident, effects, remedy. That internal log is your later proof that the organisation works.
72 hours are comfortably enough — if three things stand beforehand: a named contact everyone knows; a team that recognises breaches and reports without fear (exactly what data protection training drills); and the contact details of the competent supervisory authority within reach. Whoever googles those on the day of the breach loses half the deadline to jurisdiction questions.
The free 2-minute check shows whether your reporting basics stand. In the subscription (from €49/month) your team trains the reporting reflex with a verifiable record per person — including your company's named contact right inside the course.
On awareness within the company — as soon as anyone notices the incident, not once management is informed. That makes immediate internal reporting the single most important measure in the whole process.
No. Notification is waived where the breach is unlikely to result in a risk to those affected — say, the loss of a properly encrypted device. Every breach must be documented, though, including the non-notifiable ones (Art. 33(5) GDPR).
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free