← Knowledge

GDPR

Data Breach on a Friday Afternoon: the 72-Hour Clock

06 August 2026 · 5 min read

The 72 hours do not start with the incident but the moment the controller becomes aware of the breach — that is, as soon as someone at the company knows about it with reasonable certainty. The weekend counts (Art. 33 GDPR). A report to the supervisory authority is required only where the breach is likely to result in a risk to the people affected; documenting it internally is required for every breach, including the ones you don't have to report (Art. 33(5) GDPR). A timely initial report with what you know, followed by supplementary information, beats a perfect but late one.

Friday, 4:30pm: a colleague notices that an email with the payroll list went out to an external distribution list. When does the 72-hour clock in Art. 33 GDPR actually start — at the moment of sending? At the moment it's noticed? And does the weekend count?

The answers: the deadline starts the moment the controller becomes “aware” of the breach — that is, the moment someone at the company knows about the incident with reasonable certainty. And yes, the weekend counts. If you discover a breach on a Friday, you can't wait until Monday and start calmly from there.

Not every breach must be reported — but every one must be documented

A report to the supervisory authority is required when the breach is likely to result in a risk to the people affected. An encrypted laptop hard drive that's immediately remote-wiped is typically not a reportable case — a payroll list sent to the wrong recipients typically is. Where the risk is high, notifying the affected individuals is also required (Art. 34 GDPR).

Often overlooked: even breaches that don't need to be reported must still be documented internally (Art. 33(5) GDPR). The supervisory authority is entitled to inspect this record — and an empty one rarely looks convincing.

What belongs in the report

A report needs four building blocks: the nature of the breach (what happened, to which data, roughly how many people affected), the name and contact details of a point of contact, the likely consequences, and the measures taken and planned to address it. Important: you're allowed to report in stages. A timely initial report with what you know, followed by supplementary information, beats a perfect but late report.

The same logic, incidentally, applies even more strictly under NIS2: significant security incidents require an early warning within 24 hours (Section 32 BSIG). If you have to satisfy both regimes, you need one process, not two forms.

The process beats the form

In practice, reports rarely fail because of the form and almost always because of the workflow: who spots a breach? Who decides whether it must be reported? Who is allowed to speak to the authority? These questions are better answered before the real thing happens — and the workflow is better rehearsed once in advance.

The reporting assistant in Compliverse walks you through exactly this workflow: log the incident, assess the risk, run the GDPR (72h) and NIS2 (24h / 72h / 1 month) deadline countdowns in parallel, and track status through to the closing report.

The next step

Want to know what applies to your company? The scope check takes thirty seconds.

Start the check

Further reading