GDPR Incident Reporting

We draft and review processor agreements for effective GDPR incident reporting

GDPR Incident Reporting in Processor Agreements – What Applies in Practice?

View as Markdown
3 mins read • Legal Writer • GDPR • 25 March 2026

GDPR incident reporting is a central requirement in data processing agreements under the General Data Protection Regulation. But what is actually required, and what should the agreement regulate? Incident management is not only about regulatory compliance; it is about protecting data subjects from harm and minimising risks for the organisation. For this reason, both routines and allocation of responsibilities must be clear.

Deficiencies in GDPR incident reporting can have serious consequences, not least in the form of administrative fines or reputational damage. A processor agreement should therefore create a practical framework for how suspected personal data breaches are identified, escalated, reported and documented.

    1. GDPR Incident Reporting Requires a Defined Reporting Deadline
      Under Article 33 GDPR, personal data breaches must be notified to the Data Protection Agency within 72 hours where notification is required. This means that the data processor must report the incident to the controller in sufficient time before that deadline, often within 24 hours.
      The agreement should therefore specify an exact deadline for GDPR incident reporting from the processor to the controller. A vague obligation to report “without undue delay” may be insufficient in practice if the controller needs time to assess the risk, gather information and decide whether data breach reporting to the authority is necessary.
    2. What a GDPR Incident Reporting Notice Should Contain
      An incident report must be sufficiently detailed for the controller to assess the risks. It should normally include the sequence of events, the categories of personal data affected, the affected data subjects and proposed remedial measures.

Effective GDPR incident reporting should also make clear what is known, what remains uncertain and what further information will follow. In practice, the first report may be preliminary, but it must still provide the controller with enough information to decide on immediate actions and, where required, data breach reporting.

  1. Routines for Fast Action and Clear Responsibility
    A data processing agreement should also regulate how reporting is to take place, including contact channels, responsible roles and availability. Clear routines reduce the risk of misjudgements and delays at the critical moment. When a personal data breach occurs, all parties involved need to know what is expected of them, as time is limited.

For GDPR incident reporting to work in practice, a good clause in the data processing agreement is not enough. Staff at the processor must also know how to act. The agreement should therefore be supported by internal instructions, training and, where appropriate, checklists.

Many businesses choose to conduct exercises or simulations to ensure that the process works under pressure. This can save valuable time when a real incident occurs and can make data breach reporting more accurate, consistent and defensible.
Another aspect that is often overlooked is the documentation of the handling process itself. GDPR requires organisations to document how an incident has been assessed and what measures have been taken. The agreement should therefore require the processor to contribute to the preparation of such documentation.

With clear roles, fixed timeframes and tested routines, GDPR incident reporting becomes a predictable process rather than a source of stress. It also gives the controller a stronger basis for assessing whether data breach reporting is required and for demonstrating compliance afterwards.

At Morling Consulting, our GDPR lawyers help companies across Europe draft and review data processing agreements that meet both regulatory requirements and practical business needs.

Speak to a GDPR lawyer

Do you need help with GDPR incident reporting? Contact us and we will review your agreement

"*" indicates required fields