KlarComply
HomeKnowledge › Data breach & 72 hours

The data breach: what counts, what 72 hours mean — and the one reflex that saves everything

Most data breaches do not look like a hacking attack. They look like a Tuesday afternoon: a group email with an open recipient list, a payslip to the wrong address, a laptop left on a train. What matters then is not the mistake — but whether the organisation is capable of acting within 72 hours. And that is decided in the first minute: by reporting.

By , Founder of KlarComply · Reviewed on

Infographic: The data breach: 72 hours, one reflex — Most breaches look like a Tuesday afternoon — the first minute decides.
The key points of this article as a graphic — feel free to share or download it.

What a breach is — the honest definition

The law calls it a “personal data breach”: any event leading to the destruction, loss, alteration or unauthorised disclosure of personal data — accidental or deliberate. The SME classics:

IncidentBreach?
Group email to customers with all addresses in CC instead of BCCYes — disclosure of the addresses to all recipients
Payslip or quotation to the wrong recipientYes
Unencrypted laptop or USB stick lostYes
Customer list entered into a public AI toolYes — transfer to a third party without a basis
Properly encrypted laptop lost, key safeDocument the incident; risk often low

The 72-hour deadline — and when it starts

Notifiable breaches must reach the supervisory authority within 72 hours of awareness (Art. 33). Two points are regularly underestimated. First: the clock starts as soon as anyone in the company knows of the incident — not once management hears of it. Second: not every breach is notifiable — notification is waived where the breach is unlikely to result in a risk to those affected. That assessment is made by the responsible person, not at the desk where it happened. At high risk, informing the affected individuals comes on top (Art. 34).

The reflex that saves the day: report internally, immediately

For the responsible person to assess and notify within 72 hours, one rule applies to everyone else: report internally at once — what happened, which data, since when. And for that reflex to work, the second rule matters just as much: honest, immediate reporting never gets anyone into trouble. A concealed breach robs the company of every option to respond — that is the real risk, not the typo in the address field.

What actually happens in the 72 hours

Contain (lock access, ask recipients to delete — staying honest: deletion only works going forward), assess (risk to those affected?), decide (notify or not), document. The documentation duty applies always — including for breaches that need no notification (Art. 33(5)): incident, effects, remedy. That internal log is your later proof that the organisation works.

Preparation beats improvisation

72 hours are comfortably enough — if three things stand beforehand: a named contact everyone knows; a team that recognises breaches and reports without fear (exactly what data protection training drills); and the contact details of the competent supervisory authority within reach. Whoever googles those on the day of the breach loses half the deadline to jurisdiction questions.

Where to start

The free 2-minute check shows whether your reporting basics stand. In the subscription (from €49/month) your team trains the reporting reflex with a verifiable record per person — including your company's named contact right inside the course.

Frequently asked questions

When does the 72-hour deadline start for a data breach?

On awareness within the company — as soon as anyone notices the incident, not once management is informed. That makes immediate internal reporting the single most important measure in the whole process.

Must every data breach be notified to the authority?

No. Notification is waived where the breach is unlikely to result in a risk to those affected — say, the loss of a properly encrypted device. Every breach must be documented, though, including the non-notifiable ones (Art. 33(5) GDPR).

Where does your company stand?

The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.

Start the quick check — free
Read on AI literacy obligation → Building an AI inventory → Labelling AI content (Art. 50) → The AI Act for SMEs → Writing an AI policy → AI in hotels → AI in the beauty salon → Appointing an AI lead → ChatGPT at work and the GDPR → Approving AI tools → Finding shadow AI → AI and employee representation → Classifying AI risk → The AI supplier questionnaire → Customer data in an AI tool → Penalties under Article 99 → Trade secrets and AI tools → AI in physiotherapy practices → AI in dental practices → AI in tax and accounting firms → AI in hair salons → AI in advertising agencies → AI for estate agents → AI in car repair shops → AI in trades businesses → AI in law firms → DPO requirements → Records of processing → DPA (Art. 28) → GDPR staff training → US tools & transfers →
Sources:
Article 33 GDPR — notification to the supervisory authority
Article 34 GDPR — communication to the data subject
Reviewed on 1 September 2026 · Reflects the Digital Omnibus · This article is general information and not legal advice.