Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

Agent · gdpr-2016-679-33

GDPR artikel 33: Notification of a personal data breach to the supervisory authority

Operative tree, written by hand from the article's conditions.

CELEX 32016R0679 · 2026-08-18 · Weight 106 · minimal-risk

PremiumHand written or high weight rule tree. Metered per call at the edge once metering is switched on, at the same address and with the same answer as today.

GDPROfficial source

What this page is
Agent, GDPR artikel 33
Checked against the official source
2026-08-18Current
Responsible publisher
ExploreWorld Legal, editorial deskLiability position

Jurisdiction

The same agent, read through one country's lens.

Inputs

  • breachA personal data breach has occurredboolean
  • risk_to_rightsThe breach may result in a risk to rights and freedomsboolean
  • hours_since_awareHours since becoming awarenumber

Rule tree

  1. If: breach = false

    No breach

    The duty to notify is not triggered.

    Paragraph 1

  2. If: risk_to_rights = false

    No notification required, documentation required

    Where the breach is unlikely to result in a risk it need not be notified, but it shall be documented under Article 33(5).

    Paragraph 1, 5

  3. If: hours_since_aware >= 72

    The 72 hour deadline has passed

    The notification shall still be made, accompanied by the reasons for the delay under Article 33(1).

    Paragraph 1

  4. If: risk_to_rights = true

    Notification to the supervisory authority is required

    The notification shall be made without undue delay and within 72 hours of becoming aware, with the content in Article 33(3).

    Paragraph 1, 3

If no rule matches: None of the article's conditions are met with the facts supplied. Supply more facts or read the article in full.

The article text as read

  1. 11. In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.
  2. 22. The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
  3. 33. The notification referred to in paragraph 1 shall at least:
  4. 4(a)
  5. 5describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
  6. 6(b)
  7. 7communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
  8. 8(c)
  9. 9describe the likely consequences of the personal data breach;
  10. 10(d)
  11. 11describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
  12. 124. Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
  13. 135. The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.

Lineage

treatyTFEU art. 288 (förordning)
act32016R0679
chapterIV. Controller and processor
article33
paragraphs13
jurisdictionEuropean Union (EU)
supervisorIMY — Sweden
national

Interface

callhttps://legal.exploreworldai.com/api/public/v1/agents/gdpr-2016-679-33/run
methodGET
outputmatched, outcome, trace, missing, hash
Quota60 anrop per minut och adress, utan nyckel
stabilityRegelträdet versioneras. En ändring byter artefakthash, aldrig adress.

Hashes

textsha256:c2be83eeef83d1f714f1ef9e3b3e7b57a0a7081235f4e908d05bba7a412b6aca
scriptsha256:d1ddc5d24e08ced070cd93b8cb2fbcf47f409c43f430f9aeaeeabf7fe452f1ae
enginesha256:0a4bd50d21f8ec9be383fc091511008b76ad61909cbfb674eab56fe567fbd7a0
agentsha256:ba45f8d361d56305d9dbf77d4aa0703da4e37062ae1c929307ec6cc54537a297
versionagent-engine-1+legal-2026-08-25 / ba45f8d361d56305

Artefacts

No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.

Citation: 32016R0679 art. 33, Notification of a personal data breach to the supervisory authority. ExploreWorld Legal, https://legal.exploreworldai.com/agent/gdpr-2016-679/artikel-33 (hämtad 2026-08-18, bevis sha256:da4a2e91fa09a70c, bygge legal-2026-08-25).