The written walkthrough
The data breach announced by email: the written walkthrough
The email announcing a data breach is not a courtesy, it is an article of a regulation. The 72 hours run towards the authority, the warning owes you plain language and specific content, and the complaint is lodged in your own country.
Law as verified onJuly 29, 2026
This walkthrough contains the answers. It is here so you can read the situation without playing it, print it, and so the content stays complete without JavaScript.
Item no. 1 · 18:06, a careful email
Three years of logging your runs in the same app: email address, routes, the times you leave the house. You live in Belgium, the service is established in another country of the Union.
At 18:06 an email arrives. It is signed, it is calm, and it says almost nothing.
This email: what is it, exactly?
Correct answer · A piece of evidence: I keep it as it is, with its date, and I read it as an act required by a regulation.
This email is not a courtesy, it is a written obligation When a breach is likely to put you at high risk, the company does not get to choose whether to tell you: the communication is owed, without undue delay. This message exists because an article demands it. And an act required by a regulation gets kept: it is the first piece of everything that follows.
“1. When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.”
In plain words: if the leak can hurt you, they have to tell you, personally, directly and without dragging their feet. This email is a legal document, not a newsletter.
Article 34(1) · Regulation (EU) 2016/679, Article 34 (Communication of a personal data breach to the data subject), paragraph 1 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679Myth · If it were serious, they would not send a mere email. I delete it.
The myth: “no registered letter, no real problem” The official EU page says exactly the opposite: when the breach carries serious risks, the company must inform you directly. A discreet email is not a weak signal, it is the channel the rules provide for. Deleting it means throwing away item number one of a file that has just opened itself.
“the data controller (the person or body handling your personal data) must report it to the national data protection authority. The data controller must also inform you directly if there are serious risks related to your personal data or privacy due to the breach.”
In plain words: this message is a legal obligation addressed to you. A legal obligation gets filed, not binned.
Section “Unauthorised access to your data” · Data protection: unauthorised access to your data (data breach) · https://europa.eu/youreurope/citizens/consumers/internet-telecoms/data-protection-online-privacy/index_en.htmMyth · They talk about an “internal incident”, not a hack: that is not a real breach.
The myth: “a breach necessarily means hackers” The Regulation defines a personal data breach far more broadly than a heist movie: destruction, loss, alteration, unauthorised disclosure or unauthorised access, whether accidental or unlawful. A laptop forgotten on a train fits the definition. The word “incident” does not walk anyone out of the text.
“‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;”
In plain words: no hooded hackers required. An internal mistake, a loss, one access too many: the definition covers all of it, and the obligations that come with it apply.
Article 4(12) · Regulation (EU) 2016/679, Article 4 (Definitions), point 12 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679Item no. 2 · The number everyone knows wrong
That evening, a message from a friend arrives: he received the same email.
The 72 hours: what exactly do they time?
Correct answer · The notification to the AUTHORITY. What I am owed is a communication “without undue delay”, with no number attached.
72 hours towards the authority, undue delay towards you The Regulation starts two separate clocks. The first one, with a number on it, runs towards the supervisory authority: notification without undue delay and, where feasible, not later than 72 hours, failing which the notification must carry the reasons for the delay. The second one runs towards you when the risk is high: without undue delay, no number. Knowing which clock is which means aiming straight from the very first letter.
“1. In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.”
In plain words: the 72 hours are their appointment with the authority, not with you. You are owed a warning without delay once the risk is high, and the authority can check their timesheet.
Article 33(1) · Regulation (EU) 2016/679, Article 33 (Notification of a personal data breach to the supervisory authority), paragraph 1 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679Myth · They had to warn ME within 72 hours: deadline missed, automatic compensation.
The myth: “72 hours to warn me, or jackpot” The 72 hours of Article 33 time the notification to the supervisory authority, not the email addressed to you. And the text provides for no automatic compensation: a late notification to the authority calls for reasons, not a cheque. Building your claim on the wrong deadline hands the company the easiest answer in the world: “that deadline does not concern you”, and it will be right.
“Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.”
In plain words: even when they are late towards the authority, the written sanction is a justification to provide, not a sum that falls from the sky. Your real card is elsewhere: the content of the warning, and the complaint in your own country.
Article 33(1) · Regulation (EU) 2016/679, Article 33 (Notification of a personal data breach to the supervisory authority), paragraph 1 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679No effect · I forward the email to my entire address book, subject: READ THIS. Public information mission accomplished.
Informing the public is already an obligation, and it is not yours The Regulation has planned for the case where warning each person would take disproportionate effort: it is then up to the company to make a public communication, as effective as a direct message. Your address book is not an official channel, and your dentist was not affected. Save the energy for the only list that matters: what the warning owes you, personally.
“it would involve disproportionate effort. In such a case, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.”
In plain words: when the individual email is impossible, the text requires a public statement that informs just as well. Spreading the warning is an organised obligation, not a chain letter.
Article 34(3) · Regulation (EU) 2016/679, Article 34 (Communication to the data subject), paragraph 3, points (a) and (c) · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679Item no. 3 · What the email does not say
You reread the email, this time with the Regulation's list beside it. You tick off what is there. It goes quickly.
- Nature of the breach
- “a security incident”, no other detail
- Contact point
- missing
- Likely consequences
- missing
- Measures taken
- “our systems have been reinforced”, no detail
- Advice given
- “no action is required”
What do you reply, and what do you demand?
Correct answer · I reply demanding the missing pieces: the contact point, the likely consequences, the detail of the measures.
The warning has a shopping list, and it is written down The communication you are owed must contain at least three things, the same ones as the notification to the authority: a contact point where more information can be obtained, the likely consequences of the breach, and the measures taken or proposed to address it. “No action is required” replaces none of the three. What is missing gets claimed, piece by piece.
“3. The notification referred to in paragraph 1 shall at least: […] (b) communicate the name and contact details of the data protection officer or other contact point where more information can be obtained; (c) describe the likely consequences of the personal data breach; (d) describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.”
In plain words: a contact for your questions, an honest statement of what you risk, and an account of what they are doing. Those three lines are owed to you, and Article 34 imports them word for word into the email addressed to you.
Article 33(3) · Regulation (EU) 2016/679, Article 33 (Notification to the supervisory authority), paragraph 3, points (b) to (d) · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679Myth · The investigation is ongoing: they are not allowed to tell me more, confidentiality rules.
The myth: “they cannot say anything, it is confidential” The Regulation has already arbitrated between discretion and your information: the communication addressed to you describes the nature of the breach, in clear and plain language, and contains at least the contact point, the likely consequences and the measures taken. That list is the legal minimum, not a post-crisis favour. A company invoking secrecy to empty it is reciting its internal policy, not the text.
“2. The communication to the data subject referred to in paragraph 1 of this Article shall describe in clear and plain language the nature of the personal data breach and contain at least the information and measures referred to in points (b), (c) and (d) of Article 33(3).”
In plain words: the minimum content of the warning is set by the Regulation itself. What is missing can be claimed, and the company cannot hold its own investigation against you.
Article 34(2) · Regulation (EU) 2016/679, Article 34 (Communication to the data subject), paragraph 2 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679Myth · It is a technical subject, jargon is unavoidable: my job to keep up.
The myth: “a breach can only be explained in jargon” “In clear and plain language”: five words of the Regulation, placed exactly there, in the article describing the warning email. Clarity is not a stylistic effort left to the company's goodwill, it is a legal requirement on the form of the message. An incomprehensible text is not a compliant text, and you can ask for a readable version.
“The communication to the data subject referred to in paragraph 1 of this Article shall describe in clear and plain language the nature of the personal data breach”
In plain words: being understandable is their job, being an engineer is not yours. The law imposes the clarity of the message just as much as its content.
Article 34(2) · Regulation (EU) 2016/679, Article 34 (Communication to the data subject), paragraph 2 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679Item no. 4 · The one who received nothing
A colleague uses the same app. She received no email at all. Searching around, you find a statement published on the service's website.
She is furious: “no personal email, that is illegal, right?”
Following the recently identified security incident, we confirm that passwords were protected by robust encryption.
Users whose data may have been affected have been contacted individually. No action is required for anyone else.
No email for her: automatic infringement?
Correct answer · Not automatic: the text provides written ways out, and I know who can check them.
If the company excused itself from the email, the authority can catch it The Regulation provides cases where the individual email is not required: measures such as encryption, subsequent measures that remove the risk, or a public communication when writing to everyone would be disproportionate. But it also names the referee: the supervisory authority can consider whether the risk was high, and require the communication, or endorse the exception. Neither your colleague nor the company gets the last word alone.
“4. If the controller has not already communicated the personal data breach to the data subject, the supervisory authority, having considered the likelihood of the personal data breach resulting in a high risk, may require it to do so or may decide that any of the conditions referred to in paragraph 3 are met.”
In plain words: the company's silence is not the end of the story. An authority can check its reasoning and force it to write the email it never sent.
Article 34(4) · Regulation (EU) 2016/679, Article 34 (Communication to the data subject), paragraph 4 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679Myth · No personal email = infringement, full stop. She demands immediate compensation.
The myth: “no email for me, so certain infringement” The text spells out, in black and white, the cases where the individual communication is not required: protection measures such as encryption applied to the data affected, or a public communication that is just as effective when writing to each person would take disproportionate effort. Fuming at a written exception costs you the next argument. The right question is not “why not me?”, it is “does the exception hold?”, and that question has a judge.
“3. The communication to the data subject referred to in paragraph 1 shall not be required if any of the following conditions are met: (a) the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption;”
In plain words: properly encrypted data can excuse the individual email. The exception exists, it is precise, and it can be checked: better to know that before writing the letter.
Article 34(3) · Regulation (EU) 2016/679, Article 34 (Communication to the data subject), paragraph 3, points (a) and (c) · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679Myth · If they write that it was encrypted, case closed: nobody can go and check.
The myth: “their press statement counts as proof” A statement is a declaration, not a verification. Yet the national data protection authority has already been told: the notification is owed to it as soon as the breach happens. It knows the file, it can hold the statement up against the facts, and it can require the individual communication if the risk was high. Giving up because the company declared itself blameless is mistaking the defendant for the clerk of the court.
“the data controller (the person or body handling your personal data) must report it to the national data protection authority.”
In plain words: your country's authority is already in the loop, by obligation. What the company tells the public, it must be able to prove to someone with the power to check.
Section “Unauthorised access to your data” · Data protection: unauthorised access to your data (data breach) · https://europa.eu/youreurope/citizens/consumers/internet-telecoms/data-protection-online-privacy/index_en.htmItem no. 5 · Three weeks later
Phishing emails now land in the mailbox you only ever used for that app. They know your first name. The line between the breach and your inbox has drawn itself.
You want someone to examine this file. The question is who, and where.
Where do you take the file?
Correct answer · I lodge a complaint with the data protection authority of my own country.
The complaint is lodged where you live, not where the service is established The article gives you three places to choose from, and the first is your habitual residence; the others are your place of work and the place of the alleged infringement. The company's head office is not on the list. And the authority you seise then owes you news: the progress and the outcome of your complaint, including the possibility of a judicial remedy.
“1. Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes this Regulation.”
In plain words: you complain in your country, in your language, to your authority. The geography of the file is yours to choose.
Article 77(1) and (2) · Regulation (EU) 2016/679, Article 77 (Right to lodge a complaint with a supervisory authority) · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679Myth · Without a proven, quantified loss, no complaint is admissible. I will wait until I have lost money.
The myth: “to complain, you first need an invoice” The entry condition is not a loss, it is a reasoned opinion: you think your rights have not been respected, and you can complain directly to your national authority, which will investigate and answer within three months. Waiting to be robbed before reporting the open door gets the order wrong: the complaint exists precisely so the file gets examined before things get worse.
“If you think your data protection rights have not been respected, you can make a complaint directly to your national data protection authority which will investigate your complaint and give you a response within 3 months.”
In plain words: “if you think” is enough. No loss to prove before walking through the authority's door.
Section “Making a complaint” · Data protection: making a complaint · https://europa.eu/youreurope/citizens/consumers/internet-telecoms/data-protection-online-privacy/index_en.htmMyth · Files like this never go anywhere without a lawyer or a class action. I pass.
The myth: “only an army of lawyers can take on a breach” A complaint to the authority is not a lawsuit: it is an administrative procedure you start on your own, and the text obliges the authority to keep you informed of the progress and the outcome, including the possibility of a judicial remedy afterwards. Court remains an option, never a prerequisite. The file you hold, vague email included, is enough to begin.
“2. The supervisory authority with which the complaint has been lodged shall inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Article 78.”
In plain words: once the complaint is lodged, the authority works and reports back to you. You have engaged no fees, no lawyer, no trial.
Article 77(1) and (2) · Regulation (EU) 2016/679, Article 77 (Right to lodge a complaint with a supervisory authority) · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679Verdict · What a three-sentence email was worth
A careful email arriving at 18:06, a checklist that emptied it in thirty seconds, a statement to be verified, and an authority seised from your own country.
File EU 2016/679
The items in this file
Every item has its own page. The situation is played here; what you keep, what you send and what you re-read live next door.