Editorial explainer · official sourcesmedium
The 72-hour rule, explained properly: what the GDPR actually requires after a breach
"You have 72 hours to notify" is the line everyone repeats and few explain. This explainer lines up what the GDPR actually says: when the clock starts, the difference between notifying the supervisory authority (Art. 33) and informing data subjects (Art. 34), why not every breach is notifiable, and the duty that applies regardless — documentation. Not the attack of the day, but the legal frame every personal-data incident eventually meets.
An explainer, not the attack of the day
Every time we publish a dossier on a data theft, the same question comes from the side of those who hold the data: and now, what am I obliged to do? The European answer sits in two GDPR articles, 33 and 34, and in a number that became a slogan — 72 hours — often quoted wrong. It is worth explaining properly, at the source.
First: what a "breach" is
The GDPR defines a personal data breach broadly: not only theft or disclosure (a confidentiality breach), but also unauthorized alteration (integrity) and loss of access or destruction (availability). A ransomware that encrypts an archive without exfiltrating it is still a breach, because it puts the availability of the data at risk. The first step, then, is not "were we robbed?", but "did an event occur that compromises the confidentiality, integrity or availability of personal data?".
The 72 hours: what they actually count
Article 33 requires the controller to notify the breach to the supervisory authority — in Italy the Garante — without undue delay and, where feasible, within 72 hours of becoming aware of it. Two clarifications change everything. The clock starts from awareness of the breach, not from when it happened; and notification is not due if the breach is unlikely to result in a risk to the rights and freedoms of individuals. If the 72 hours are exceeded, the notification must still be made, accompanied by the reasons for the delay.
- Moment of awarenessThe clock starts
Not from when it happened, but from when the controller becomes aware.
- Within 72 hoursNotify the Garante (Art. 33)
Unless the risk to individuals is unlikely.
- Without delayInform the data subjects (Art. 34)
Only if the risk is high.
Notifying the authority is not warning the people
This is the most common confusion. Article 33 concerns the authority; Article 34 concerns the people whose data was breached, and triggers at a different, higher threshold: communication to data subjects is due only when the breach is likely to result in a high risk to their rights and freedoms, and must happen without undue delay, in clear language. The GDPR also provides exceptions — for example if the data was encrypted so as to be unintelligible to whoever obtained it, or if the controller took subsequent measures that avert the high risk.
The duty that applies regardless: documentation
There is a duty that does not depend on risk and is often forgotten: the controller must document any breach, including the circumstances, effects and measures taken, even when it decides — legitimately — not to notify it. That documentation is what lets the Garante verify after the fact that the risk assessment was done, and done well. In practice: the decision not to notify is not a non-action, it is an assessment that must be put in writing.
At the source, always
This article frames the mechanism; concrete decisions on a real incident should be made on the text of Regulation (EU) 2016/679 and on the operational guidance of the Garante and the EDPB, in particular the guidelines on breach notification. It is the same method as our technical dossiers: the primary source before the summary. A note of care: this is a general regulatory explainer, not legal advice on a specific case.