Home GDPR

How to handle data breaches under GDPR requirements to protect your business and customers

If you discover or suspect a data breach, the first rule under GDPR is to act quickly and carefully. You must contain the breach, assess its impact, and notify the relevant data protection authority within 72 hours if the breach poses a risk to individuals. Handling this process correctly safeguards your business from fines and protects your customers’ trust. This guide walks you through the exact steps and timelines you need to follow, so you can respond confidently and stay compliant. I just

8 min read

If you discover or suspect a data breach, the first rule under GDPR is to act quickly and carefully. You must contain the breach, assess its impact, and notify the relevant data protection authority within 72 hours if the breach poses a risk to individuals. Handling this process correctly safeguards your business from fines and protects your customers’ trust. This guide walks you through the exact steps and timelines you need to follow, so you can respond confidently and stay compliant.

I just found a data breach—what’s my very first move?

As soon as you discover a breach, your top priority is to stop any further data loss or damage. This might mean shutting down a compromised server, changing passwords, or isolating affected systems. At the same time, preserve all evidence like logs and alerts that show when and how the breach happened. Don’t delete or alter any files until you’ve completed a proper assessment. Quick containment limits harm, and keeping evidence intact helps with investigations and any required reporting later.

How do I know if this incident qualifies as a GDPR breach?

A GDPR personal data breach means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to personal data. Personal data includes anything that identifies or could identify someone—names, emails, IP addresses, health information, and more. If the incident only involves anonymous data or no personal information was exposed, it might not be a GDPR breach. For example, if customer names and emails leaked online, that’s a clear breach. But if only internal logs without personal details were affected, it may not be. Carefully checking whether personal data is involved is crucial because GDPR rules apply only in that case.

When and how must I notify the data protection authority?

You must notify the relevant data protection authority within 72 hours of becoming aware of a breach, unless it’s unlikely to cause risk to individuals. The notification should clearly describe the breach’s nature, the categories and approximate number of affected data subjects and records, likely consequences, and the measures you’ve taken or plan to take to address it. If you don’t have all details within 72 hours, submit what you know and update the authority as more information becomes available. Missing this deadline or providing incomplete info can lead to fines, so act promptly and maintain clear communication with regulators.

Who else needs to be informed and when?

You must inform affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms. This includes cases where sensitive data like financial or health information is exposed. Your communication should explain what happened, potential consequences, and what steps they can take to protect themselves, such as changing passwords or monitoring accounts. Notification isn’t required if the data was encrypted or if you’ve taken measures that eliminate the risk. Also, if your partners or suppliers are involved, they should be informed promptly. Transparent communication helps maintain trust and enables people to respond appropriately.

How do I assess the risk and impact of the breach?

To assess severity, consider how likely and how serious the harm to individuals might be—such as identity theft, financial loss, or discrimination. Evaluate what type of data was involved, how sensitive it is, how many records were affected, and who might have accessed it. For instance, a breach exposing a few email addresses usually poses less risk than one involving medical records or payment details. Also factor in how quickly you found and contained the breach. This assessment guides whether you need to notify individuals, what actions to take, and how to communicate with regulators. Being thorough here prevents underestimating or overreacting to the breach.

What should my breach report to the authority include?

Your report must cover key details: what happened, how and when; categories and approximate number of people and data records affected; possible consequences for those individuals; and what you’ve done or plan to do to contain and fix the breach. Avoid vague language—be specific about the data involved and your response. If you don’t have full information yet, notify within 72 hours with what you know and update the authority as new facts emerge. Clear and honest reporting builds trust and helps regulators evaluate the situation properly.

Failing to handle a breach properly can cost you serious fines—up to 4% of your annual global turnover or €20 million, whichever is higher. Beyond financial penalties, poor handling damages your reputation and customer trust, which can hurt your business long term. Delaying notification or giving incomplete information invites regulatory scrutiny and enforcement. On the flip side, a timely, transparent response shows responsibility and might reduce penalties. Remember, GDPR’s goal is to protect people’s data and your business’s credibility, not just punish mistakes.

How can I prevent future breaches and improve my response plan?

A breach is a strong signal to review your security and incident response plans. Strengthen technical protections like firewalls, encryption, and access controls. Train your staff regularly on data protection and spotting phishing, since human error often causes breaches. Update your response plan with clear roles, communication lines, and checklists for quick action. Run practice drills to test your readiness. Document what you learned from the breach to avoid repeating mistakes. Preparing well reduces the chance of future breaches and ensures you can react swiftly if something happens again.

What common mistakes do companies make during breach handling?

Many businesses delay detecting or reporting breaches, losing valuable time and increasing risks. Some underestimate the breach’s impact and fail to notify affected individuals when required. Others submit incomplete or vague reports to authorities, which can worsen regulatory consequences. Some forget to preserve evidence properly, making investigations harder. Avoid these mistakes by acting quickly, assessing risks thoroughly, communicating openly, and keeping detailed records. GDPR expects a timely and reasonable response—not perfection—so focus on being thorough and prompt.

A small business owner examining common mistakes made during data breach reporting.

Where can I find reliable resources and support for GDPR breach management?

Start with your national data protection authority’s website—they usually offer clear guidance, notification templates, and FAQs specific to your country. The European Data Protection Board (EDPB) provides useful materials on GDPR compliance as well. Professional associations and consulting firms often publish practical checklists and sample documents. Involve legal counsel or a data protection officer early if you have them. There are also training providers and incident response experts who can help you prepare and manage breaches. Using trusted sources keeps you aligned with current rules and best practices.

Conclusion

When you discover a breach, contain it immediately and preserve evidence—that’s your foundation. If personal data is involved, assume it’s a GDPR breach and notify the data protection authority within 72 hours. Inform affected individuals if there’s a high risk to their rights and freedoms. Honest, timely reporting protects you legally and maintains trust. After managing the immediate crisis, focus on improving your security and response plans to reduce future risks. Handling a breach well shows you care about your customers and your business’s future.

Frequently Asked Questions

What counts as a personal data breach under GDPR?

A personal data breach is any accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to personal data—information that identifies or can identify a person. Examples include hacking, lost devices with customer info, or sending data to the wrong recipient.

How quickly must I report a data breach to the authorities?

You must notify your national data protection authority within 72 hours of becoming aware of the breach, unless it’s unlikely to cause risk to individuals. If you don’t have all details in that time, send what you know and update later.

Do I always have to inform affected customers about a breach?

No. You only need to inform affected individuals if the breach is likely to cause a high risk to their rights and freedoms, such as when sensitive data like payment details or health records are exposed. If the risk is low or the data was encrypted, notification may not be required.

What happens if I delay reporting or provide incomplete information?

Delaying or submitting incomplete reports can lead to fines and regulatory sanctions and damage your reputation. GDPR requires timely and thorough notifications—failing to do so increases regulatory scrutiny and penalties.

Where can I get templates or guidance for GDPR breach notifications?

Your national data protection authority’s website is the best place to find official templates and detailed guidance. The European Data Protection Board also offers useful resources. Legal or data protection advisors can provide tailored support for your situation.