Data breach notification is the legal and operational obligation to inform supervisory authorities and, where there is a high risk, affected individuals after a breach of personal data. Frameworks such as the UK and EU GDPR require controllers to report qualifying breaches to the regulator without undue delay, typically within seventy-two hours of becoming aware, and to document the breach regardless of whether it is reportable. The duty turns an internal security incident into a regulated disclosure event, with timing, content and assessment of risk all prescribed by law.
Overview
- A security incident becomes a notifiable event once personal data is compromised in a way that risks individuals’ rights and freedoms.
- Controllers must assess severity quickly, decide whether the regulator and data subjects must be told, and act within statutory deadlines.
- All breaches must be documented internally even when they do not meet the reporting threshold, creating an auditable record.
- Failure to notify correctly is itself an enforcement risk, often weighed alongside the underlying breach.
Key aspects
- Trigger and threshold: a personal-data breach causing risk to individuals starts the clock.
- Timing: notification to the authority without undue delay, with a commonly cited seventy-two-hour benchmark.
- Content: nature of the breach, categories and approximate numbers of records, likely consequences and remedial measures.
- Individual notice: direct communication to affected people when the risk to their rights is high.
Applications
- Enterprise privacy and security programmes integrating breach playbooks into incident response.
- Regulatory reporting workflows that route confirmed breaches to legal and compliance teams.
- Vendor and processor contracts mandating prompt breach reporting up the chain.
- Auditing and governance, where breach registers demonstrate accountability.