Skip to content
English
By RightEuropean rights, in situation
ODERSA association · Taking Part programmeIndependent educational site. Not an official website of the European Union.

The sheet to print

Data breach: the sheet to keep

Seven reflexes, in the order they serve, from the warning email to the complaint. Each one carries the text it stands on.

File EU 2016/679

This page is made to be printed: when printing, the whole screen around it disappears.

Law as verified onJuly 29, 2026

  1. 01

    Keep the warning email, with its date

    Communicating a high-risk breach is a legal obligation: that message is a piece of evidence. Screenshot, timestamp, full text, before any other step.

    Article 34(1) · Regulation (EU) 2016/679, Article 34 (Communication of a personal data breach to the data subject), paragraph 1 · eur-lex.europa.eu
  2. 02

    Do not let the word “incident” reassure you

    The official definition covers destruction, loss, alteration, unauthorised disclosure or access, whether accidental or unlawful. The company's choice of vocabulary does not change the legal category.

    Article 4(12) · Regulation (EU) 2016/679, Article 4 (Definitions), point 12 · eur-lex.europa.eu
  3. 03

    Check the three things owed, and claim what is missing

    A contact point where more information can be obtained, the likely consequences, the measures taken or proposed: the warning must contain at least these three elements, in clear and plain language.

    Article 34(2) · Regulation (EU) 2016/679, Article 34 (Communication to the data subject), paragraph 2 · eur-lex.europa.eu
  4. 04

    Know the two clocks

    Not later than 72 hours, where feasible, to notify the supervisory authority, failing which the notification carries the reasons for the delay. Towards you, no number: without undue delay, once the risk is high. Never build a claim on the wrong clock.

    Article 33(1) · Regulation (EU) 2016/679, Article 33 (Notification of a personal data breach to the supervisory authority), paragraph 1 · eur-lex.europa.eu
  5. 05

    Question the contact point, that is what it is for

    The text requires communicating the name and contact details of the data protection officer or another contact point where more information can be obtained. Which data, which consequences, which measures: that is where you ask.

    Article 33(3) · Regulation (EU) 2016/679, Article 33 (Notification to the supervisory authority), paragraph 3, points (b) to (d) · eur-lex.europa.eu
  6. 06

    No email received? Check the exceptions before taking offence

    Encryption applied to the data affected, subsequent measures that remove the risk, or a public communication when writing to each person would be disproportionate: the ways out exist and are written down. The supervisory authority can check them and require the communication.

    Article 34(3) · Regulation (EU) 2016/679, Article 34 (Communication to the data subject), paragraph 3, points (a) and (c) · eur-lex.europa.eu
  7. 07

    Lodge your complaint in your own country

    Habitual residence, place of work or place of the infringement: you choose the authority. No quantified loss to prove in order to seise it, and it owes you the progress and the outcome.

    Article 77(1) and (2) · Regulation (EU) 2016/679, Article 77 (Right to lodge a complaint with a supervisory authority) · eur-lex.europa.eu

General information on the European baseline, not legal advice on your case. Independent educational site, with no ties to the institutions of the European Union. The redress links in this file point only to official bodies.

Sources checked on July 29, 2026. · https://depleindroit.odersa.org/en/fiches/la-fuite-de-donnees · Content licensed under CC BY 4.0.

What the law owes you

Every right with its amount or its deadline, the extract of the official text it rests on, and its address.

A breach is not just a hack

A personal data breach covers destruction, loss, alteration, unauthorised disclosure or unauthorised access, whether accidental or unlawful. An internal mistake or a lost laptop fits the definition just as much as an attack.

The official text · Article 4(12)

“‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;”

Official Journal of the European Union · EUR-Lex · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

Informed directly when the risk is high

When the breach is likely to result in a high risk to your rights and freedoms, the controller communicates it to you, personally, without undue delay. The warning email is an obligation, not a commercial gesture.

The official text · Article 34(1)

“1. When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.”

Official Journal of the European Union · EUR-Lex · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

Minimum content, in clear and plain language

The warning describes the nature of the breach and contains at least a contact point where more information can be obtained, the likely consequences, and the measures taken or proposed. What is missing can be claimed.

The official text · Article 34(2)

“2. The communication to the data subject referred to in paragraph 1 of this Article shall describe in clear and plain language the nature of the personal data breach and contain at least the information and measures referred to in points (b), (c) and (d) of Article 33(3).”

Official Journal of the European Union · EUR-Lex · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

72 hours: the clock runs towards the authority

72 h

The notification to the supervisory authority is due without undue delay and, where feasible, not later than 72 hours after becoming aware; beyond that, it must carry the reasons for the delay. Your own communication has no number: it is due without undue delay once the risk is high.

The official text · Article 33(1)

“1. In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.”

Official Journal of the European Union · EUR-Lex · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

The authority can order them to warn you

If the company did not write to you, the supervisory authority can consider whether the breach carries a high risk, then require the individual communication or find that a written exception applies. The last word does not belong to the press statement.

The official text · Article 34(4)

“4. If the controller has not already communicated the personal data breach to the data subject, the supervisory authority, having considered the likelihood of the personal data breach resulting in a high risk, may require it to do so or may decide that any of the conditions referred to in paragraph 3 are met.”

Official Journal of the European Union · EUR-Lex · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

A complaint to lodge where you live

With a supervisory authority, in particular that of the Member State of your habitual residence, your place of work or the place of the infringement. The authority then informs you of the progress and the outcome, including the possibility of a judicial remedy.

The official text · Article 77(1) and (2)

“1. Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes this Regulation. 2. The supervisory authority with which the complaint has been lodged shall inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Article 78.”

Official Journal of the European Union · EUR-Lex · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

This site is educational and independent: it is not an official European Union website, and this verdict is not legal advice on your case. The deadlines and wordings quoted are copied from the official text or the official page, linked under each right.