GDPR: all pages

GDPR · the breach clock

The breach clock: 72 hours from awareness

The moment you became aware, your role and the risk to the people concerned; the deadline is computed from Article 33, the notification is written from Article 33(3), and Article 34 says whether the people themselves are told.

Your role for the data concerned
Is the breach likely to result in a high risk to the people concerned?

Article 34(1): identity theft, fraud, financial loss, discrimination, damage to reputation, loss of confidentiality of data under professional secrecy; encrypted data with the key intact usually is not (Article 34(3)(a)).

1. The clock

Enter the moment of awareness above; the deadline and the notification follow.

A software company under NIS2 or the CRA runs a second clock from the same moment of awareness, with a different recipient and threshold: which incident clock runs for a software company

The clock started by the event, not by whoever noticed

StandardOS opens the 72-hour clock the moment an incident is recorded, keeps the Article 33(5) documentation as the incident record itself, and runs the NIS2 and CRA clocks from the same event where they apply.

The hours, the contents of the notification and the exceptions are read from Articles 33 and 34 of the Regulation, never typed on this page. Whether the risk is high is the company's own reading. This is a document, not legal advice.