7.7 Breach Communications to Regulators, Individuals & Other Stakeholders
Key Takeaways
- Indicator VI.B.2 requires communicating to stakeholders in compliance with jurisdictional, global and business requirements — the audiences and clocks are different for each.
- GDPR Article 33(3) fixes the content of a regulator notification: nature of the breach, categories and approximate numbers of individuals and records, DPO contact, likely consequences, and measures taken or proposed.
- Article 34 requires communication to individuals without undue delay only where the breach is likely to result in a HIGH risk to their rights and freedoms — a higher bar than the Article 33 regulator threshold.
- Article 34(3) provides three exceptions: data rendered unintelligible by measures such as encryption, subsequent measures making high risk unlikely, or disproportionate effort — which requires a public communication instead.
- Processors notify their controller without undue delay under Article 33(2); they do not notify the supervisory authority on the controller's behalf.
Different Audiences, Different Thresholds, Different Clocks
Competency VI.B's second indicator is communicate to stakeholders in compliance with jurisdictional, global and business requirements. The exam tests whether you know that "notify" is not one action. A single incident can generate a regulator filing on one clock, individual notices on a different threshold, customer notifications on contractual deadlines shorter than any statute, and internal and market communications with no statutory basis at all.
The two GDPR thresholds
| Article 33 — supervisory authority | Article 34 — data subjects | |
|---|---|---|
| Trigger | A personal data breach, unless unlikely to result in a risk to rights and freedoms | Likely to result in a high risk to rights and freedoms |
| Clock | Without undue delay and, where feasible, within 72 hours of becoming aware | Without undue delay |
| If late | Notify anyway, with reasons for the delay | — |
| Content | Article 33(3) list | Nature of the breach in clear and plain language, plus Art. 33(3)(b),(c),(d) elements |
The asymmetry is the point: the regulator threshold is any risk, the individual threshold is high risk. A breach can be notifiable to the authority and not to individuals; the reverse is not how the tiers work.
Article 33(3) fixes the content of the regulator notification: the nature of the breach including, where possible, the categories and approximate number of data subjects and of personal data records concerned; the name and contact details of the DPO or other contact point; the likely consequences; and the measures taken or proposed, including mitigation. Article 33(4) permits providing information in phases where it is not all available at once, which is the answer to the common panic that you cannot possibly know everything within 72 hours.
The three Article 34 exceptions
Communication to individuals is not required where:
- The controller had applied appropriate technical and organisational protection measures to the affected data — in particular measures rendering it unintelligible, such as strong encryption with keys not compromised;
- The controller has taken subsequent measures ensuring the high risk is no longer likely to materialise; or
- It would involve disproportionate effort — in which case there must instead be a public communication or similar measure by which individuals are informed in an equally effective manner.
Note what exception one actually requires: the encryption must have rendered the data unintelligible to the attacker. Encrypted data whose key was taken in the same incident gets no benefit.
Everyone else who must be told
| Audience | Basis | Typical timing |
|---|---|---|
| Supervisory authorities | Statute | GDPR 72 hours; other regimes vary |
| Affected individuals | Statute, at the high-risk threshold | Without undue delay |
| Controller (if you are the processor) | Article 33(2) — without undue delay | Contract often sets 24-48 hours |
| Business customers | Contract, often stricter than statute | Frequently 24-72 hours by DPA |
| Media | HIPAA requires prominent media notice for breaches affecting 500+ residents of a state or jurisdiction | Within 60 days of discovery |
| Sector regulators, exchanges, insurers | Sectoral rules, listing rules, policy conditions | Varies — often immediate |
| Internal: executives, board, support, sales | Business necessity | As soon as facts are stable |
The processor row is heavily tested. A processor's duty under Article 33(2) is to notify its controller without undue delay; it does not notify the supervisory authority in the controller's place. Conversely, a controller cannot outsource its own notification duty to its processor.
The internal row is underrated. If support and sales learn about a breach from the customer notification email, the organization will spend the next week generating inconsistent answers — which is itself a regulatory and reputational risk. Brief the front line before the external send, with an approved holding statement.
The multi-jurisdiction matrix
For an incident spanning several regimes, build the matrix during preparation, not during the incident:
| Column | Content |
|---|---|
| Jurisdiction | Where affected individuals are resident |
| Trigger definition | What counts as personal information and as a breach there |
| Harm threshold | Risk-based, or notification regardless of harm |
| Regulator clock | Deadline and recipient |
| Individual clock | Deadline and required content |
| Extra recipients | Consumer reporting agencies, state AGs, media |
| Content requirements | Mandatory elements and any prescribed template |
When deadlines conflict, the operational answer is to work to the shortest applicable clock and the union of content requirements, then tailor per jurisdiction.
Writing the individual notice
Article 34(2) requires clear and plain language. A usable notice states what happened and when, what data was involved, what the likely consequences are, what the organization has done, what the individual should do — in concrete steps, not "remain vigilant" — and how to get help, with a real contact point that is staffed. Avoid the two failure modes the exam likes: minimising language that misstates severity, and legal hedging so dense the reader cannot tell whether they are affected.
Worked scenario
A processor detects unauthorised access to a database holding one controller's EU customer records, encrypted at rest with keys held in the same compromised environment. The processor notifies the controller within 12 hours per its DPA. The controller's clock starts on becoming aware, files under Article 33 within 72 hours using phased information under Article 33(4), and cannot rely on the Article 34(3)(a) encryption exception because the keys were compromised — so individuals must be notified without undue delay. Meanwhile the controller's own business customers get contractual notice on a 24-hour clock, and support receives an approved holding statement before any external send.
A controller suffers a breach of a database that was encrypted at rest. The attacker obtained the encryption keys from the same compromised environment. The breach is otherwise likely to result in high risk to individuals. What is the correct notification position?
A processor discovers a breach affecting a controller's data. Under GDPR, what is the processor's notification duty?