Agent · gdpr-2016-679-33
GDPR artikel 33: Notification of a personal data breach to the supervisory authority
Operativt tre, håndskrevet ut fra artikkelens vilkår.
CELEX 32016R0679 · 2026-08-18 · Vekt 106 · minimal-risk
PremiumHand written or high weight rule tree. Metered per call at the edge once metering is switched on, at the same address and with the same answer as today.
- Hva siden er
- Agent, GDPR artikel 33
- Lest mot offisiell kilde
- 2026-08-18Fersk
- Ansvarlig utgiver
- ExploreWorld Legal, redaksjonenAnsvarsposisjon
Kort svar
What does GDPR Article 33 require, and what outcome does the rule tree give?
GDPR Article 33 is tested here by a deterministic rule tree of 4 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with No breach, carrying paragraph citation, content hash and read date 2026-08-18 against CELEX 32016R0679. The outcome is a machine classification, not a compliance decision.
GDPR Article 33Lest mot utgiveren 2026-08-18Offisiell tekst
- No breach. The duty to notify is not triggered.
- No notification required, documentation required. Where the breach is unlikely to result in a risk it need not be notified, but it shall be documented under Article 33(5).
- The 72 hour deadline has passed. The notification shall still be made, accompanied by the reasons for the delay under Article 33(1).
En kildehenvisning, ikke juridisk rådgivning.
Jurisdiksjon
Samme agent, lest med ett lands øyne.
Inndata
- breachA personal data breach has occurredboolean
- risk_to_rightsThe breach may result in a risk to rights and freedomsboolean
- hours_since_awareHours since becoming awarenumber
Regeltre
Hvis: breach = false
No breach
The duty to notify is not triggered.
Punkt 1
Hvis: risk_to_rights = false
No notification required, documentation required
Where the breach is unlikely to result in a risk it need not be notified, but it shall be documented under Article 33(5).
Punkt 1, 5
Hvis: hours_since_aware >= 72
The 72 hour deadline has passed
The notification shall still be made, accompanied by the reasons for the delay under Article 33(1).
Punkt 1
Hvis: risk_to_rights = true
Notification to the supervisory authority is required
The notification shall be made without undue delay and within 72 hours of becoming aware, with the content in Article 33(3).
Punkt 1, 3
Hvis ingen regel treffer: None of the article's conditions are met with the facts supplied. Supply more facts or read the article in full.
Artikkelteksten som ble lest
- 11. In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.
- 22. The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 33. The notification referred to in paragraph 1 shall at least:
- 4(a)
- 5describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- 6(b)
- 7communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- 8(c)
- 9describe the likely consequences of the personal data breach;
- 10(d)
- 11describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- 124. Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 135. The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
Opphav
Grensesnitt
Hasher
Artefakter
Ingen rådgivning. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Sitering: 32016R0679 art. 33, Notification of a personal data breach to the supervisory authority. ExploreWorld Legal, https://legal.exploreworldai.com/agent/gdpr-2016-679/artikel-33 (hämtad 2026-08-18, bevis sha256:da4a2e91fa09a70c, bygge legal-2026-08-25).