Data Breach Procedure
We assess personal data breaches under Articles 33 and 34 GDPR with clear legal analysis
Data Breach Procedure: GDPR Reporting Thresholds
6 mins read • Vilgot Sahlholm • GDPR • 2 July 2026
When a personal data breach occurs, the organisation must quickly determine whether the incident must be reported to the Data Protection Agency and whether the affected individuals must also be informed. These are two closely related questions, but they are governed by different thresholds under the GDPR. For many businesses, this is an assessment where support from a GDPR lawyer can be important, as the deadlines are short and incorrect decisions may have both legal and practical consequences.
A common misconception is that the same risk assessment determines both questions. Article 33 GDPR, which concerns notification to the supervisory authority, has a lower threshold than Article 34 GDPR, which concerns communication to data subjects. This means that, in many cases, an incident must be reported to the Data Protection Agency even where there is no obligation to inform the affected individuals.
What Is a Personal Data Breach?
A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data. It may involve anything from a misdirected email to a system intrusion, a lost laptop or incorrect access controls.
The decisive issue is not whether the incident was caused by a technical attack or human error. The question is whether personal data has been affected in a way that may create a risk to the rights and freedoms of natural persons.
Data Breach Procedure: Reporting When Risk Is Not Unlikely
Under Article 33 GDPR, a personal data breach must be notified to the Data Protection Agency unless it is unlikely to result in a risk to the rights and freedoms of natural persons. Notification may therefore only be omitted where such risk is unlikely.
This means that the threshold for reporting to the Data Protection Agency is relatively low. The organisation does not need to establish that the risk is high. It is sufficient that there is a real risk that cannot be dismissed as unlikely.
- Lower risk level: High risk is not required; a risk to the rights and freedoms of data subjects is sufficient.
- Strict assessment: Notification may only be omitted if it is unlikely that the incident will result in risk.
- Short deadline: Notification must be made without undue delay and, where feasible, no later than 72 hours after the organisation became aware of the incident.
Informing Data Subjects Where the Risk Is High and Likely
Article 34 GDPR concerns communication directly to the individuals whose data is affected. The threshold is higher. Data subjects must be informed where the personal data breach is likely to result in a high risk to their rights and freedoms.
The threshold for providing information is therefore higher than the threshold of risk not being unlikely. The risk must be both sufficiently serious and likely. Typical circumstances that may indicate high risk include special categories of personal data, large volumes of data, financial or identity-related data, risk of fraud, reputational damage or other concrete impact on the individual.
- Higher risk level: High risk is required, not merely risk.
- Individual-focused assessment: The assessment must focus on the possible consequences for the affected individuals.
- Risk-reducing measures: The assessment may be affected by certain measures, for example where the data has been rendered unreadable.
A Data Breach Procedure Requires Two Separate Legal Assessments
The distinction between Article 33 and Article 34 is important in practice. An incident may be notifiable to the Data Protection Agency without any requirement to inform data subjects. This may be the case, for example, where the incident involves some risk, but that risk does not reach the level of high risk.
The organisation should therefore not use a single overall conclusion to answer both questions. The assessment should be divided into two stages:
- Article 33: Must the incident be reported to the Data Protection Agency because it is not unlikely to result in risk?
- Article 34: Must data subjects be informed because the incident is likely to result in high risk?
The first question may therefore be answered in the affirmative while the second is answered in the negative. This is not a contradiction, but a consequence of the GDPR applying different thresholds.
Common Pitfalls in Incident Assessments
In many organisations, problems arise when the incident process is too simplified. If internal procedures only ask whether the incident is “serious”, there is a risk that Article 33 and Article 34 will be conflated. This may result in a failure to notify the Data Protection Agency even where notification should have been made.
Common shortcomings include the organisation:
- assessing only whether the incident involves high risk and missing the lower threshold for notification to the Data Protection Agency,
- lacking clear criteria for what should be considered in the risk assessment,
- documenting the decision too briefly, particularly where notification is not made,
- involving legal, technical and operational expertise too late,
- missing the 72-hour deadline due to unclear internal escalation routes.
How Businesses Can Act
An effective incident process should make it easy to act quickly, while remaining sufficiently structured for the assessment to withstand scrutiny afterwards. This is particularly important because, under the GDPR, the organisation must be able to demonstrate how it has reasoned.
- Maintain a clear incident procedure: The procedure should distinguish between notification to the Data Protection Agency and communication to data subjects.
- Use separate decision stages: Assess Article 33 first, followed by Article 34.
- Document decisions not to notify: The documentation should show which circumstances were considered and why the risk was assessed as unlikely.
- Secure the right expertise: Legal, information security, IT and operational teams often need to contribute different elements of the assessment.
- Test the process: Incident management works better when roles, responsibilities and deadlines have been tested before a real incident occurs.
The Right Data Breach Procedure Reduces Regulatory and Practical Risk
The distinction between notification to the Data Protection Agency and communication to data subjects is more than a technical detail. It affects how the organisation manages deadlines, internal escalation, documentation, communication and compliance.
By treating Article 33 and Article 34 as two separate assessments, the organisation reduces the risk of both over-reporting to individuals and under-reporting to the supervisory authority. It also creates a more robust incident process and better control over the organisation’s data protection risks.
At Morling Consulting, our GDPR lawyers help businesses assess personal data breaches, develop incident procedures and ensure that notifications, documentation and communication are handled correctly under the GDPR. We operate in and support clients across Europe.
When a personal data breach occurs, the organisation must quickly determine whether the incident must be reported to the Data Protection Agency and whether the affected individuals must also be informed. These are two closely related questions, but they are governed by different thresholds under the GDPR. For many businesses, this is an assessment where support from a GDPR lawyer can be important, as the deadlines are short and incorrect decisions may have both legal and practical consequences.
A common misconception is that the same risk assessment determines both questions. Article 33 GDPR, which concerns notification to the supervisory authority, has a lower threshold than Article 34 GDPR, which concerns communication to data subjects. This means that, in many cases, an incident must be reported to the Data Protection Agency even where there is no obligation to inform the affected individuals.
What Is a Personal Data Breach?
A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data. It may involve anything from a misdirected email to a system intrusion, a lost laptop or incorrect access controls.
The decisive issue is not whether the incident was caused by a technical attack or human error. The question is whether personal data has been affected in a way that may create a risk to the rights and freedoms of natural persons.
Data Breach Procedure: Reporting When Risk Is Not Unlikely
Under Article 33 GDPR, a personal data breach must be notified to the Data Protection Agency unless it is unlikely to result in a risk to the rights and freedoms of natural persons. Notification may therefore only be omitted where such risk is unlikely.
This means that the threshold for reporting to the Data Protection Agency is relatively low. The organisation does not need to establish that the risk is high. It is sufficient that there is a real risk that cannot be dismissed as unlikely.
- Lower risk level: High risk is not required; a risk to the rights and freedoms of data subjects is sufficient.
- Strict assessment: Notification may only be omitted if it is unlikely that the incident will result in risk.
- Short deadline: Notification must be made without undue delay and, where feasible, no later than 72 hours after the organisation became aware of the incident.
Informing Data Subjects Where the Risk Is High and Likely
Article 34 GDPR concerns communication directly to the individuals whose data is affected. The threshold is higher. Data subjects must be informed where the personal data breach is likely to result in a high risk to their rights and freedoms.
The threshold for providing information is therefore higher than the threshold of risk not being unlikely. The risk must be both sufficiently serious and likely. Typical circumstances that may indicate high risk include special categories of personal data, large volumes of data, financial or identity-related data, risk of fraud, reputational damage or other concrete impact on the individual.
- Higher risk level: High risk is required, not merely risk.
- Individual-focused assessment: The assessment must focus on the possible consequences for the affected individuals.
- Risk-reducing measures: The assessment may be affected by certain measures, for example where the data has been rendered unreadable.
A Data Breach Procedure Requires Two Separate Legal Assessments
The distinction between Article 33 and Article 34 is important in practice. An incident may be notifiable to the Data Protection Agency without any requirement to inform data subjects. This may be the case, for example, where the incident involves some risk, but that risk does not reach the level of high risk.
The organisation should therefore not use a single overall conclusion to answer both questions. The assessment should be divided into two stages:
- Article 33: Must the incident be reported to the Data Protection Agency because it is not unlikely to result in risk?
- Article 34: Must data subjects be informed because the incident is likely to result in high risk?
The first question may therefore be answered in the affirmative while the second is answered in the negative. This is not a contradiction, but a consequence of the GDPR applying different thresholds.
Common Pitfalls in Incident Assessments
In many organisations, problems arise when the incident process is too simplified. If internal procedures only ask whether the incident is “serious”, there is a risk that Article 33 and Article 34 will be conflated. This may result in a failure to notify the Data Protection Agency even where notification should have been made.
Common shortcomings include the organisation:
- assessing only whether the incident involves high risk and missing the lower threshold for notification to the Data Protection Agency,
- lacking clear criteria for what should be considered in the risk assessment,
- documenting the decision too briefly, particularly where notification is not made,
- involving legal, technical and operational expertise too late,
- missing the 72-hour deadline due to unclear internal escalation routes.
How Businesses Can Act
An effective incident process should make it easy to act quickly, while remaining sufficiently structured for the assessment to withstand scrutiny afterwards. This is particularly important because, under the GDPR, the organisation must be able to demonstrate how it has reasoned.
- Maintain a clear incident procedure: The procedure should distinguish between notification to the Data Protection Agency and communication to data subjects.
- Use separate decision stages: Assess Article 33 first, followed by Article 34.
- Document decisions not to notify: The documentation should show which circumstances were considered and why the risk was assessed as unlikely.
- Secure the right expertise: Legal, information security, IT and operational teams often need to contribute different elements of the assessment.
- Test the process: Incident management works better when roles, responsibilities and deadlines have been tested before a real incident occurs.
The Right Data Breach Procedure Reduces Regulatory and Practical Risk
The distinction between notification to the Data Protection Agency and communication to data subjects is more than a technical detail. It affects how the organisation manages deadlines, internal escalation, documentation, communication and compliance.
By treating Article 33 and Article 34 as two separate assessments, the organisation reduces the risk of both over-reporting to individuals and under-reporting to the supervisory authority. It also creates a more robust incident process and better control over the organisation’s data protection risks.
At Morling Consulting, our GDPR lawyers help businesses assess personal data breaches, develop incident procedures and ensure that notifications, documentation and communication are handled correctly under the GDPR. We operate in and support clients across Europe.
Speak to a GDPR lawyer
Do you need to assess a personal data breach under the GDPR? Contact us and we will assess the reporting obligations and communication requirements
"*" indicates required fields