[{"data":1,"prerenderedAt":14},["ShallowReactive",2],{"article:en:the-gdpr-72-hour-breach-clock-for-a-software-company-when-awareness-starts-it-what-the-notification-contains-the-processor-s-own-clock-and-the-nis2-cra-and-dora-clocks-beside-it":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"answer":9,"body":13},"en","the-gdpr-72-hour-breach-clock-for-a-software-company-when-awareness-starts-it-what-the-notification-contains-the-processor-s-own-clock-and-the-nis2-cra-and-dora-clocks-beside-it","The GDPR 72-hour breach clock for a software company: when awareness starts it, what the notification contains, the processor's own clock, and the NIS2, CRA and DORA clocks beside it","Article 33 gives a controller 72 hours from becoming aware of a personal data breach to notify the supervisory authority, and most companies get the start wrong, the content wrong, or the role wrong. When awareness begins under the EDPB guidelines and recital 87, the four contents of Article 33(3), the phases of 33(4), the reasons-for-delay rule, the processor's duty to notify the controller without undue delay, the communication to the data subjects under Article 34 and its three exceptions, and the NIS2, CRA and DORA clocks a software company may be running from the same moment. With the free page that computes the deadline and writes the notification.","2026-09-12",{"who":10,"when":11,"do":12},"Every software company that holds personal data: as controller of its own customer and staff data it owes the 72-hour notification itself; as processor of its customers' data inside the product it owes the customer a notice without undue delay, which starts the customer's clock.","The clock runs from the moment of awareness, a reasonable degree of certainty that a breach has occurred, not from the first alert; the notification is due within 72 hours, in phases where necessary, with the reasons for any delay; the data subjects are told without undue delay where the risk to them is high.","Enter the moment of awareness on the free breach clock: it computes the deadline in your time zone, says whether the reasons-for-delay rule applies, and writes the notification with the four contents of Article 33(3) to copy or download.","\nThe 72 hours of Article 33 are the best-known number in the Regulation and the most misread one. Companies start the clock at the wrong moment, send the wrong content, and confuse the processor's duty with the controller's. This article reads Articles 33 and 34 from a software company's side and hands you the [breach clock](\u002Fgdpr\u002Fbreach-clock) that does the arithmetic and writes the notification.\n\n## When the clock starts: awareness, not the alert\n\nArticle 33(1) requires the controller to notify a personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The clock starts at awareness, and the European Data Protection Board's breach guidelines say what that means: the controller should be regarded as having become aware when it has a reasonable degree of certainty that a security incident has occurred that has led to personal data being compromised. A monitoring alert at 03:00 is not awareness; the moment the on-call engineer confirms that customer records were read by someone who should not have read them is. The investigation that produces that certainty is expected to be short, and recital 87 says so: it should be ascertained that the measures are in place to establish immediately whether a breach has taken place.\n\nThe 72 hours are not a target, they are a ceiling. Where the notification is not made within 72 hours, Article 33(1) requires it to be accompanied by reasons for the delay. The [breach clock](\u002Fgdpr\u002Fbreach-clock) computes the deadline from the moment you enter and, once it has passed, says that the reasons-for-delay rule now applies to whatever you send.\n\n## What the notification contains, and the phases\n\nArticle 33(3) fixes the minimum content in four points: (a) the nature of the breach, including where possible the categories and approximate number of data subjects and of records concerned; (b) the name and contact details of the data protection officer or another contact point; (c) the likely consequences of the breach; (d) the measures taken or proposed to address it, including, where appropriate, measures to mitigate its possible adverse effects. Article 33(4) then removes the excuse most companies reach for: where, and in so far as, it is not possible to provide the information at the same time, it may be provided in phases without undue further delay. An incomplete notification on time beats a complete one late.\n\nArticle 33(5) is the part that outlives the incident: the controller documents every breach, its facts, its effects and the remedial action taken, whether or not it was notified, in a form that enables the supervisory authority to verify compliance. That documentation is the incident record, and it is the first thing an authority asks for after a complaint.\n\n## The processor's own clock\n\nArticle 33(2) gives the processor a different duty: it notifies the controller without undue delay after becoming aware of a personal data breach. There is no hour count. For a SaaS company this is the duty that matters most, because every customer whose data sits in the product is a controller whose 72 hours begin with your notice, and the processor contract usually fixes how fast that notice is sent; [term (f) of Article 28(3)](\u002Fgdpr\u002Fprocessor-terms) is where it lives. A processor that waits to finish its own investigation before telling the customer is spending the customer's hours.\n\n## The data subjects: Article 34 and its three exceptions\n\nArticle 34(1) requires the controller to communicate the breach to the data subjects without undue delay where it is likely to result in a high risk to their rights and freedoms: identity theft, fraud, financial loss, discrimination, damage to reputation, loss of confidentiality of data protected by professional secrecy, recital 85 lists them. Article 34(2) sets the content: the nature of the breach in clear and plain language and at least the information of Article 33(3)(b), (c) and (d). Article 34(3) names the three cases where the communication is not required: the data were protected by measures such as encryption that render them unintelligible to any person not authorised to access them; the controller has taken subsequent measures so that the high risk is no longer likely to materialise; or the communication would involve disproportionate effort, in which case a public communication informs the data subjects equally effectively. Article 34(4) lets the supervisory authority require the communication where the controller has not made it.\n\n## The clocks beside it: NIS2, the CRA and DORA\n\nA software company under NIS2, the CRA or with a bank customer under DORA runs a second clock from the same moment of awareness, with a different recipient and threshold. NIS2 Article 23 gives an essential or important entity 24 hours for the early warning, 72 hours for the notification and one month for the final report, to the CSIRT or the competent authority, for a significant incident. The CRA gives a manufacturer 24 hours for the early warning, 72 hours for the notification and 14 days for the final report on an actively exploited vulnerability, to the ENISA platform. DORA gives a financial entity 4 hours from classification and 24 hours from awareness for the initial notification, 72 hours for the intermediate report and one month for the final report on a major ICT-related incident, which reaches its software vendor through the contract's incident-assistance clause. The GDPR clock is the only one of the four that turns on personal data alone; the [NIS2-or-CRA clocks piece](\u002Farticles\u002Fnis2-or-cra-which-incident-clock-runs-for-a-software-company-and-what-makes-an-incident-significant) reads the other thresholds, and one procedure with two triggers and two recipients satisfies them all.\n\n## The fine, and the record\n\nArticle 83(4)(a) sets the ceiling for a breach of Articles 33 and 34 at EUR 10 million or 2% of worldwide annual turnover. The authorities' published decisions on late notifications turn on the same three findings every time: when awareness began, whether the notification was on time or reasoned, and whether the Article 33(5) record exists. The [breach clock](\u002Fgdpr\u002Fbreach-clock) writes the first two down from the moment you enter, and the notification it produces is the third.\n",1789383984571]