How This Works
Answer nine questions about the breach you are currently handling. The triage produces a verdict (notify the supervisory authority / borderline / document-only / internal-only), a deadline countdown from your awareness time, the Article 33(3) required contents tailored to your situation, the do-not-touch list, and a starter notification draft you can hand to counsel.
The questions are drawn from GDPR Articles 33 and 34, the European Data Protection Board (EDPB) Guidelines 9/2022 on personal-data-breach notification, and the EU Agency for Cybersecurity (ENISA) breach-notification framework. The substantive verdict on your specific breach is your DPO's and counsel's call; this triage organises the inputs.
Step 1 — What happened, and when did you become aware?
"Personal data" under GDPR Article 4(1) is any information relating to an identified or identifiable natural person.
"Awareness" under EDPB Guidelines 9/2022 is when you have a reasonable degree of certainty that an incident occurred and that personal data is affected. The 72-hour clock starts here. Provide a date and approximate hour — you can refine later.
Step 2 — Risk assessment
A higher count increases the severity but does not change whether the breach is notifiable. A single-subject breach can still be notifiable if the risk is high.
Special categories under Article 9 (health, biometric, racial / ethnic origin, sexual orientation, religious beliefs, trade-union membership, political opinions) and Article 10 (criminal-conviction data) push the risk assessment toward "high risk."
EDPB severity guidance: "high risk" means likely material consequences for affected individuals (financial loss, identity theft, discrimination, reputational damage, loss of confidentiality of professional secrets). "Risk" but not "high risk" means consequences are possible but limited. "Unlikely to result in a risk" means notification may not be required.
EDPB Guidelines 9/2022 and Article 34(3)(a): if affected data is rendered unintelligible to unauthorised parties (e.g., strong encryption at rest with keys not compromised), the breach may not require individual notification even if otherwise high-risk.
Step 3 — Jurisdiction & coordination
Single-state breaches go to that state's supervisory authority. Cross-border breaches trigger the EDPB one-stop-shop mechanism — you notify your lead supervisory authority, who coordinates with concerned supervisory authorities.
Article 33(2): processors must notify their controller "without undue delay" after becoming aware. The 72-hour clock to the supervisory authority is the controller's. The processor's own response work is upstream of that clock.
Article 39: the DPO must be involved in incidents involving personal data. Counsel typically reviews supervisory-authority submissions and any external communications before they go.
Your Triage Verdict
What Article 33(3) requires in the notification
Things to Avoid Right Now
Starter Notification Draft
A starter draft based on your answers. Your DPO and counsel will refine before submission to the supervisory authority. Replace bracketed fields with your specifics.
The Two-Page "GDPR 72-Hour" Battle-Card
A printable, laminate-on-the-wall checklist of the first-72-hour moves and the actions to avoid for a notifiable personal-data breach — Article 33 contents, Article 34 individual-notification thresholds, EDPB one-stop-shop coordination. Enter your email and we'll send it over.
Optional, and separate from your assessment — your assessment answers are never sent, only the email address you choose to enter here. Unsubscribe anytime.
The Free Triage Tells You the Verdict. The Paid Editions Get You Through the 72 Hours.
Each paid edition adds the runbook, the pre-filled supervisory-authority templates, multi-jurisdiction coordination guidance, and the toolkit appropriate to your situation — so your DPO has the documents in front of them, not just the verdict.