7.7 Breach Communications to Regulators, Individuals & Other Stakeholders

Key Takeaways

  • Indicator VI.B.2 requires communicating to stakeholders in compliance with jurisdictional, global and business requirements — the audiences and clocks are different for each.
  • GDPR Article 33(3) fixes the content of a regulator notification: nature of the breach, categories and approximate numbers of individuals and records, DPO contact, likely consequences, and measures taken or proposed.
  • Article 34 requires communication to individuals without undue delay only where the breach is likely to result in a HIGH risk to their rights and freedoms — a higher bar than the Article 33 regulator threshold.
  • Article 34(3) provides three exceptions: data rendered unintelligible by measures such as encryption, subsequent measures making high risk unlikely, or disproportionate effort — which requires a public communication instead.
  • Processors notify their controller without undue delay under Article 33(2); they do not notify the supervisory authority on the controller's behalf.
Last updated: August 2026

Different Audiences, Different Thresholds, Different Clocks

Competency VI.B's second indicator is communicate to stakeholders in compliance with jurisdictional, global and business requirements. The exam tests whether you know that "notify" is not one action. A single incident can generate a regulator filing on one clock, individual notices on a different threshold, customer notifications on contractual deadlines shorter than any statute, and internal and market communications with no statutory basis at all.

The two GDPR thresholds

Article 33 — supervisory authorityArticle 34 — data subjects
TriggerA personal data breach, unless unlikely to result in a risk to rights and freedomsLikely to result in a high risk to rights and freedoms
ClockWithout undue delay and, where feasible, within 72 hours of becoming awareWithout undue delay
If lateNotify anyway, with reasons for the delay
ContentArticle 33(3) listNature of the breach in clear and plain language, plus Art. 33(3)(b),(c),(d) elements

The asymmetry is the point: the regulator threshold is any risk, the individual threshold is high risk. A breach can be notifiable to the authority and not to individuals; the reverse is not how the tiers work.

Article 33(3) fixes the content of the regulator notification: the nature of the breach including, where possible, the categories and approximate number of data subjects and of personal data records concerned; the name and contact details of the DPO or other contact point; the likely consequences; and the measures taken or proposed, including mitigation. Article 33(4) permits providing information in phases where it is not all available at once, which is the answer to the common panic that you cannot possibly know everything within 72 hours.

The three Article 34 exceptions

Communication to individuals is not required where:

  1. The controller had applied appropriate technical and organisational protection measures to the affected data — in particular measures rendering it unintelligible, such as strong encryption with keys not compromised;
  2. The controller has taken subsequent measures ensuring the high risk is no longer likely to materialise; or
  3. It would involve disproportionate effort — in which case there must instead be a public communication or similar measure by which individuals are informed in an equally effective manner.

Note what exception one actually requires: the encryption must have rendered the data unintelligible to the attacker. Encrypted data whose key was taken in the same incident gets no benefit.

Everyone else who must be told

AudienceBasisTypical timing
Supervisory authoritiesStatuteGDPR 72 hours; other regimes vary
Affected individualsStatute, at the high-risk thresholdWithout undue delay
Controller (if you are the processor)Article 33(2) — without undue delayContract often sets 24-48 hours
Business customersContract, often stricter than statuteFrequently 24-72 hours by DPA
MediaHIPAA requires prominent media notice for breaches affecting 500+ residents of a state or jurisdictionWithin 60 days of discovery
Sector regulators, exchanges, insurersSectoral rules, listing rules, policy conditionsVaries — often immediate
Internal: executives, board, support, salesBusiness necessityAs soon as facts are stable

The processor row is heavily tested. A processor's duty under Article 33(2) is to notify its controller without undue delay; it does not notify the supervisory authority in the controller's place. Conversely, a controller cannot outsource its own notification duty to its processor.

The internal row is underrated. If support and sales learn about a breach from the customer notification email, the organization will spend the next week generating inconsistent answers — which is itself a regulatory and reputational risk. Brief the front line before the external send, with an approved holding statement.

The multi-jurisdiction matrix

For an incident spanning several regimes, build the matrix during preparation, not during the incident:

ColumnContent
JurisdictionWhere affected individuals are resident
Trigger definitionWhat counts as personal information and as a breach there
Harm thresholdRisk-based, or notification regardless of harm
Regulator clockDeadline and recipient
Individual clockDeadline and required content
Extra recipientsConsumer reporting agencies, state AGs, media
Content requirementsMandatory elements and any prescribed template

When deadlines conflict, the operational answer is to work to the shortest applicable clock and the union of content requirements, then tailor per jurisdiction.

Writing the individual notice

Article 34(2) requires clear and plain language. A usable notice states what happened and when, what data was involved, what the likely consequences are, what the organization has done, what the individual should do — in concrete steps, not "remain vigilant" — and how to get help, with a real contact point that is staffed. Avoid the two failure modes the exam likes: minimising language that misstates severity, and legal hedging so dense the reader cannot tell whether they are affected.

Worked scenario

A processor detects unauthorised access to a database holding one controller's EU customer records, encrypted at rest with keys held in the same compromised environment. The processor notifies the controller within 12 hours per its DPA. The controller's clock starts on becoming aware, files under Article 33 within 72 hours using phased information under Article 33(4), and cannot rely on the Article 34(3)(a) encryption exception because the keys were compromised — so individuals must be notified without undue delay. Meanwhile the controller's own business customers get contractual notice on a 24-hour clock, and support receives an approved holding statement before any external send.

Test Your Knowledge

A controller suffers a breach of a database that was encrypted at rest. The attacker obtained the encryption keys from the same compromised environment. The breach is otherwise likely to result in high risk to individuals. What is the correct notification position?

A
B
C
D
Test Your Knowledge

A processor discovers a breach affecting a controller's data. Under GDPR, what is the processor's notification duty?

A
B
C
D