Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

When must a personal data breach be reported, and to whom?

Under the GDPR the controller notifies the supervisory authority within 72 hours of becoming aware, unless the breach is unlikely to result in a risk, and notifies the affected people without undue delay where the risk is high. In the United States the duty is set by state law and runs to the affected residents and often to the attorney general.

This answer differs by jurisdiction — see EU, US, SE, NO and DE below.

The answer per jurisdiction

Sources

  • Article 33(1): notification without undue delay and, where feasible, within 72 hours of becoming aware.
  • Article 33(5): the controller documents every breach, including the facts, the effects and the remedial action.
  • Article 34(3): no notice to the individuals where the data was encrypted or the risk has been mitigated afterwards.

What it means for the company

Fix the moment of awareness in writing, because the clock starts there and not at the incident, and keep the internal register even for breaches you decide not to report.

Comparison across jurisdictions
JurisdictionRequirementSource
EU72 hours to the authority, high risk also to the individualsRegulation (EU) 2016/679
United StatesState law, expedient notice to residents and attorney general in CaliforniaCal. Civ. Code § 1798.82
SwedenReport to the Authority for Privacy Protection, keep an internal registerIMY, anmälan av personuppgiftsincident
NorwayReport to Datatilsynet within 72 hoursDatatilsynet, avviksmelding
GermanyReport to the competent state or federal authorityBfDI, Meldung nach Art. 33 DSGVO

What it means for the individual

A notice must describe the breach in clear language, name a contact point and state the likely consequences and the measures taken.

Sources

  • General Data Protection Regulation
    Regulation (EU) 2016/679 · Europeiska unionens publikationsbyrå · read 2026-08-24 · proof d868d41762dea567
    Official source
  • California data breach notification statute
    Cal. Civ. Code § 1798.82 · California Legislative Counsel · read 2026-08-24 · proof d868d41762dea567
    Official source
  • NIS2 Directive
    Directive (EU) 2022/2555 · Europeiska unionens publikationsbyrå · read 2026-08-24 · proof d868d41762dea567
    Official source
  • Swedish Authority for Privacy Protection, breach reporting
    IMY, anmälan av personuppgiftsincident · Integritetsskyddsmyndigheten · read 2026-08-24 · proof d868d41762dea567
    Official source
  • Norwegian Data Protection Authority, breach reporting
    Datatilsynet, avviksmelding · Datatilsynet · read 2026-08-24 · proof d868d41762dea567
    Official source
  • German Federal Data Protection Commissioner, breach reporting
    BfDI, Meldung nach Art. 33 DSGVO · Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit · read 2026-08-24 · proof d868d41762dea567
    Official source

Next step

Read the 72 hour duty together with the 24 hour early warning under NIS2, because an entity in scope of both reports twice, on two clocks.

All global questions

The page reports what the sources say, with identifier and address to the publisher. It is not legal advice and does not assess an individual matter.

Next step

Three ways to put the register to work in your own practice.

Start with your task