Home Law Article 33 GDPR (Notification of A Personal Data Breach To The Supervisory...

Article 33 GDPR (Notification of A Personal Data Breach To The Supervisory Authority)

Article 33 of GDPR: Data breach notification obligation

Article 33 of GDPR outlines the procedure to follow in the event of a personal data breach.

Under the terms of GDPR, companies are required to notify a personal data breach to the supervisory authority within 72 hours of becoming aware of the breach.

Data controller’s data breach notification obligation (Article 33(1) GDPR)

In the event of a personal data breach, the data controller is required to report the incident as soon as possible to the relevant supervisory authority but no longer than 72 hours after becoming aware of the data breach.

If a company takes longer than 72 hours to report the breach to the supervisory authority, they must also provide justification as to the cause of the delay.

The data controller will not have an obligation to report the data breach incident if the personal data breach is unlikely to pose any risk on the data subject.

Data processor’s data breach notification obligation (Article 33(2) GDPR)

Similarly, if a data processor, handling or processing personal data on behalf of the data controller becomes aware of a data breach, it must notify the data controller as soon as possible after becoming aware of the data breach.

Content of the data breach notification (Article 33(3) GDPR)

When a data breach notification is required to be sent to the supervisory authorities, GDPR makes it clear as to what the notification should contain.

The data breach notification must contain:

  1. The nature of personal data breach, including personal data categories, how many data subjects impacted and approximate number of personal data records impacted (Article 33(3)(a) GDPR)
  2. Name and contact details of the data controller’s data protection officer or point of contact (Article 33(3)(b) GDPR)
  3. The possible consequences of the data breach (Article 33(3)(c) GDPR)
  4. What measures have been taken to address the data breach and how is the adverse consequence on data subjects being handled (Article 33(3)(d) GDPR)

Information disclosure (Article 33(4) GDPR)

It may be possible that in some cases, not all the information will be available to the data controller to report to the supervisory authorities.

In such cases, the data controller can disclose the necessary information in phases as the information becomes available to it.

Personal data breach documentation (Article 33(5) GDPR)

The data controller must document any personal data breaches.

In this process, it must document:

  1. The facts surrounding the data breach
  2. The effects of the data breach
  3. The remedial actions taken in light of the data breach

As needed, the data controller must communicate its documented records of data breaches to the supervisory authority.

Recitals applicable to Article 33 of GDPR

Relevant Recitals: 85, 87, 88

GDPR Regulation article-by-article overview

Read our comprehensive overview of the GDPR Regulation, article by article, where we summarize each of the 99 articles contained in GDPR to give you a complete understanding of its content.

Cited Legislation in Article 33 or relevant recitals

None

GDPR Text: Article 33 of GDPR and Relevant Recitals

GDPR Text Source: EUR-Lex

Official GDPR Text: General Data Protection Regulation 

Official GDPR Title: REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), corrected by Corrigendum, OJL 127, 23.5.2018, p. 2 ((EU) 2016/679)

Most Popular

Certificate of Dissolution (All You Need To Know)

Starting a business requires formal paperwork, such as your certificate of incorporation or articles of incorporation. Similarly, closing out your corporation will...

Play in Adjacent Markets (Meaning Explained)

The expression “play in adjacent markets” is frequently used in business strategy discussions, investor presentations, and growth planning sessions. It often arises...

Let’s Not Boil the Ocean (Meaning Explained)

The phrase “let’s not boil the ocean” is common business jargon used in planning sessions, strategy meetings, and project discussions. It sounds...

B2C Meaning (All You Need To Know)

In business discussions, you often hear terms like B2B and B2C used to describe how companies operate. These labels are shorthand for...

B2B2C Meaning (All You Need To Know)

In the business world, you often hear terms like B2B and B2C used to describe how companies sell their products or services....

Editor's Picks

Counterpart Signatures (Are They Legally Binding)

Contracts are not always signed by all parties at the same time or in the same place. In many business transactions, signatures...

How Long Is 7 Business Days (All You Need To Know)

How Long Is 7 Business Days (All You Need To Know)

What Does ATM Mean (Meaning: All You Need To Know)

What Does ATM Mean (Meaning: All You Need To Know)

What Is Private Equity (Explained: All You Need To Know)

What Is Private Equity (Explained: All You Need To Know)

Net Operating Working Capital (What It Is And How To Calculate It)

Net Operating Working Capital (What It Is And How To Calculate It)