GDPR Data Breach Notification: 72-Hour Rule Explained (2026)

Independently fact-checked against primary sources (last audited September 11, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 11, 2026. · 19 primary sources cited on this page. How we verify our legal content

GDPR Data Breach Notification: 72-Hour Rule Explained (2026)

Updates

Corrected the processor's deadline (the EDPB recommends prompt notification to the controller and sets no 72-hour processor target), added the rule that a non-EU controller with only an Article 27 representative must notify every supervisory authority where affected individuals reside, corrected Australia's OAIC deadline to as soon as practicable, corrected the Booking.com and Bank of Ireland enforcement details to the regulators' own decisions, noted the pending EU proposal that would move the deadline to 96 hours, and replaced four dead source links.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Expanded to evergreen explainer: added EDPB Guidelines 9/2022 detail, processor duty section, NIS2 overlap, breach register deep-dive, common pitfalls, recent enforcement (Meta EUR 251M Dec 2024, Bank of Ireland EUR 463K Mar 2022, PTSB EUR 277.5K May 2026), global comparison table, and updated statistics (443 breach notifications per day in Europe as of early 2026).

Reviewed and approved by an editor

Sources and References

  1. GDPR Full Text — Regulation (EU) 2016/679(eur-lex.europa.eu).gov
  2. EDPB Guidelines 9/2022 on Personal Data Breach Notification, v2.0 (adopted 28 March 2023)(edpb.europa.eu).gov
  3. EDPB Guidelines 01/2021 on Examples Regarding Personal Data Breach Notification(edpb.europa.eu).gov
  4. EDPB One-Stop-Shop Case Digest: Security of Processing and Data Breach Notification (2024)(edpb.europa.eu).gov
  5. Regulation (EU) 2016/679, Article 33 (EUR-Lex, Official Journal text)(eur-lex.europa.eu).gov
  6. EDPB: Data Breaches (SME Data Protection Guide)(edpb.europa.eu).gov
  7. EDPB: How to Notify a Data Breach to Your DPA(edpb.europa.eu).gov
  8. ICO — Personal Data Breaches: A Guide(ico.org.uk).gov
  9. EDPS — Personal Data Breach Notification Guidelines(edps.europa.eu).gov
  10. Irish DPC — Meta EUR 251 Million Fine (December 2024)(dataprotection.ie).gov
  11. Irish DPC — Permanent TSB EUR 277,500 Fine (May 2026)(dataprotection.ie).gov
  12. Irish DPC: Decision in Inquiry IN-19-9-5 (Bank of Ireland Group plc, 14 March 2022)(dataprotection.ie).gov
  13. DLA Piper — Personal Data Breaches in Europe Reach 443 Per Day (February 2026)(dlapiper.com)
  14. NIS2 Directive — Directive (EU) 2022/2555(eur-lex.europa.eu).gov
  15. EDPB — Summary of Guidelines 9/2022 and 01/2021 on Data Breach Notification (2025)(edpb.europa.eu).gov
  16. Irish DPC: Final Decision in Inquiry IN-19-9-5, Bank of Ireland Group plc (14 March 2022, PDF)(dataprotection.ie).gov
  17. Autoriteit Persoonsgegevens: Booking.com Fined for Delay in Reporting Data Breach (31 March 2021)(autoriteitpersoonsgegevens.nl).gov
  18. European Commission: Digital Omnibus Proposal, COM(2025) 837 final (19 November 2025)(eur-lex.europa.eu).gov
  19. OAIC: Part 4: Notifiable Data Breaches (NDB) Scheme(oaic.gov.au).gov
  20. eCFR: 45 CFR 164.408, HIPAA Breach Notification to the Secretary(ecfr.gov).gov
Share: