When must a personal data breach be reported, and to whom?
Under the GDPR the controller notifies the supervisory authority within 72 hours of becoming aware, unless the breach is unlikely to result in a risk, and notifies the affected people without undue delay where the risk is high. In the United States the duty is set by state law and runs to the affected residents and often to the attorney general.
This answer differs by jurisdiction — see EU, US, SE, NO and DE below.
The answer per jurisdiction
EU
Article 33: 72 hours to the supervisory authority from awareness, with reasons for any delay. Article 34: notice to the individuals without undue delay where the risk to their rights is high.
Regulation (EU) 2016/679 · Europeiska unionens publikationsbyråUnited States
California requires notice to affected residents in the most expedient time possible without unreasonable delay, and notice to the attorney general above 500 affected residents.
Cal. Civ. Code § 1798.82 · California Legislative CounselSweden
Notification goes to the Authority for Privacy Protection through its reporting form, and the internal breach register is expected at inspection.
IMY, anmälan av personuppgiftsincident · IntegritetsskyddsmyndighetenNorway
Notification goes to Datatilsynet within the same 72 hours, through the authority's reporting route.
Datatilsynet, avviksmelding · DatatilsynetGermany
Notification goes to the competent state authority, or to the federal commissioner for federal bodies and telecommunications.
BfDI, Meldung nach Art. 33 DSGVO · Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit
Sources
- Article 33(1): notification without undue delay and, where feasible, within 72 hours of becoming aware.
- Article 33(5): the controller documents every breach, including the facts, the effects and the remedial action.
- Article 34(3): no notice to the individuals where the data was encrypted or the risk has been mitigated afterwards.
What it means for the company
Fix the moment of awareness in writing, because the clock starts there and not at the incident, and keep the internal register even for breaches you decide not to report.
| Jurisdiction | Requirement | Source |
|---|---|---|
| EU | 72 hours to the authority, high risk also to the individuals | Regulation (EU) 2016/679 |
| United States | State law, expedient notice to residents and attorney general in California | Cal. Civ. Code § 1798.82 |
| Sweden | Report to the Authority for Privacy Protection, keep an internal register | IMY, anmälan av personuppgiftsincident |
| Norway | Report to Datatilsynet within 72 hours | Datatilsynet, avviksmelding |
| Germany | Report to the competent state or federal authority | BfDI, Meldung nach Art. 33 DSGVO |
What it means for the individual
A notice must describe the breach in clear language, name a contact point and state the likely consequences and the measures taken.
Sources
- General Data Protection RegulationRegulation (EU) 2016/679 · Europeiska unionens publikationsbyrå · read 2026-08-24 · proof d868d41762dea567Official source
- California data breach notification statuteCal. Civ. Code § 1798.82 · California Legislative Counsel · read 2026-08-24 · proof d868d41762dea567Official source
- NIS2 DirectiveDirective (EU) 2022/2555 · Europeiska unionens publikationsbyrå · read 2026-08-24 · proof d868d41762dea567Official source
- Swedish Authority for Privacy Protection, breach reportingIMY, anmälan av personuppgiftsincident · Integritetsskyddsmyndigheten · read 2026-08-24 · proof d868d41762dea567Official source
- Norwegian Data Protection Authority, breach reportingDatatilsynet, avviksmelding · Datatilsynet · read 2026-08-24 · proof d868d41762dea567Official source
- German Federal Data Protection Commissioner, breach reportingBfDI, Meldung nach Art. 33 DSGVO · Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit · read 2026-08-24 · proof d868d41762dea567Official source
Next step
Read the 72 hour duty together with the 24 hour early warning under NIS2, because an entity in scope of both reports twice, on two clocks.
The page reports what the sources say, with identifier and address to the publisher. It is not legal advice and does not assess an individual matter.
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.