Procedure
Something has happened here
A personal data breach leaves 72 hours. They pass quickly, because in that time the facts have to be established, the attack has to be repelled and the notification under Art. 33 GDPR has to be prepared. Whatever is not settled beforehand costs hours that nobody has left.
The incident hits a running business
An incident hits an organisation while the business is running. The technology has to be secured, the damage has to be contained and operations have to be restored. Whether a notification also falls due, and to whom, is a separate examination. It falls in the same days.
A duty to notify always has to be examined
Whether to notify is often treated as an open judgement. The wording does not support that, because Art. 33(1) GDPR frames the exception negatively. Notification is owed unless the breach is unlikely to result in a risk.
Three levels therefore stand side by side. Where a risk is unlikely, notification falls away altogether.
No likely risk
Notification falls away under Art. 33(1) GDPR. The documentation under Art. 33(5) GDPR remains, because it is the record of that decision.
A risk
The supervisory authority has to be notified, where possible within 72 hours. This is the range in which the authority is notified but the individuals are not.
A high risk
The individuals concerned also have to be informed without undue delay under Art. 34(1) GDPR, in language a layperson can follow.
What separates the two notifications
| Notifying the authority | Merkmal | Communicating to data subjects |
|---|---|---|
| 72 hours | Deadline | Without undue delayNo fixed number of hours, and in practice often earlier than the notification to the authority. |
| One | Exceptions | ThreeArt. 34(3) GDPR names effective encryption, a risk subsequently removed, and disproportionate effort, the last with a public communication as a substitute. |
| The controller | Who decides last | The authority tooUnder Art. 34(4) GDPR it can require a communication that was not made. |
Documentation under Art. 33(5) GDPR is owed in both cases, including for the incident that was not notified. Deciding against notification is therefore not a saving of paperwork but a document of its own.
That documentation is the part which falls away in day-to-day practice, and it is the part a supervisory authority asks for first. Art. 33(5) GDPR expressly requires it to enable the authority to verify compliance.
Further reporting duties alongside the GDPR
Which channels run alongside is decided not by the incident but by the entity. For essential and important entities the cascade in section 32(1) BSIG stands next to Art. 33 GDPR, and it has a different recipient, different deadlines and a different triggering event.
The cascade in section 32(1) BSIG
24 hours
Early warning
To the joint reporting office of the Federal Office for Information Security and the Federal Office of Civil Protection. It states whether unlawful action is suspected and whether cross-border effects are possible.
72 hours
Incident notification
Confirming or updating the early warning, with an initial assessment of severity and impact and, where available, indicators of compromise.
On request
Intermediate report
Status updates, where the Federal Office asks for them.
One month
Final report
Description, root cause, measures taken and ongoing. Where the incident is still running, a progress report takes its place.
The two cascades attach to different events, and that is what gets overlooked when it matters. Art. 33 GDPR turns on becoming aware of the breach, section 32(1) BSIG on obtaining knowledge of a significant security incident. An incident without personal data triggers only the second, a misdirected mailing only the first. A ransomware attack on an HR system triggers both, possibly at different moments.
Frequently asked questions
Do we have to report twice?
Where both regimes apply, yes. The notification under Art. 33 GDPR concerns the protection of personal data, the one under section 32 BSIG the security of information technology. Recipients, deadlines and content differ, and one does not replace the other.
Should we report the matter to the police?
That is a judgement call, and it belongs in the preparation rather than in the incident. A criminal complaint can be useful for the insurer and for the record. It can at the same time lead to systems being seized and so to a longer outage.
When does the period start if a service provider reports?
When their report reaches you. Under Art. 33(2) GDPR the processor has to notify you without undue delay, and under the guidelines of the European Data Protection Board the controller is in principle to be regarded as aware from that notification. The processor does not assess the risk. That assessment stays with you.
What if nothing is settled after 72 hours?
Then what is settled gets reported. Art. 33(4) GDPR expressly allows the information to be provided in phases, and under Art. 33(1), second sentence, GDPR a late notification has to be accompanied by reasons for the delay. Waiting for the investigation to conclude is not such a reason.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.