Legal sources with official primary sources

Printed ·

Skip to main content
Skip to the answer

GDPR — 33: Notification of a personal data breach to the supervisory authority

GDPR — 33: Notification of a personal data breach to the supervisory authority seen through the obligations: the source row from the register, the obligations it carries, the roles it reaches and the steps it belongs to. The legal text stays with the source — here you get the link, the address and the reading date.

Share this page

Source row from the register

  • Notify a personal data breach to the supervisory authority.

Obligations

  • Controller: Notify a personal data breach to the supervisory authority.
  • Processor: Notify the controller without undue delay after becoming aware of a breach.

Recitals interpreting the article

  • 85: What a personal data breach is and when it is likely to result in risk — the basis of the 72-hour duty.

What forces a redo

  • The node hash changes — the text behind the row is no longer the same.
  • The reading date moves forward — the row has been re-read against the source.
  • A timeline passes — the requirement starts to apply or tightens.

As data

  • The same node as data: add ?format=json to the address, or ?format=agent for receipt and dependencies.

Roles

Workflows

Relations

Metadata

Acts
GDPR
Articles
1
Reading date
2026-08-31
Freshness
74/100
Hash
b3c3e53f61549c0e
Corpus version
legal-2026-08-25
Next check
CELEX
32016R0679

Next step

Three ways to put the register to work in your own practice.

Start with your task