Notify or document? A clear verdict, before the 72-hour clock runs out.
A free in-browser triage for the first 72 hours of a personal-data breach under the General Data Protection Regulation (GDPR). Answer nine questions. You get a clear verdict (notify or document) and your Article 33 deadline, counted from the time you became aware. You also get the required Article 33(3) contents, a do-not-touch list, and a starter notification draft you can hand to counsel.
The triage runs in your browser. Your answers never leave your device. That matters more when the question is "is this a breach we have to report?"
Two paths into the toolkit.
1. Take the free triage
Nine questions about the personal-data breach you're handling. The triage returns a notify-or-document verdict and the Article 33 72-hour deadline, counted from when you became aware. It also gives you the required Article 33(3) contents for your case and a starter draft you can hand to counsel. About five minutes. Runs in your browser, no email required, no data transmitted.
Start the free triage →2. Read the free Breach Battle-Card
A one-page printable reference that summarises the first 72 hours of a personal-data breach: the awareness-time anchor, the Article 33 vs. Article 34 distinction, the do-not-touch list, the four artefacts to capture before the clock starts. Keep one printed copy in the DPO's desk drawer.
Read the free guide →This is for a personal-data breach that's already happening.
It runs the live 72-hour clock (the notify-or-document decision and your Article 33 deadline), not the readiness work you do beforehand. To get ready before a breach, see the GDPR Checklist; if the incident isn't a personal-data breach, First 4 Hours covers general incident triage.
Three tiers: one for solo DPOs, one for cross-border SMBs, one for multi-DSA enterprises.
Each tier serves a different Data Protection Officer (DPO) situation. Buy the tier that matches the kind of breach you're handling, or the kind you might handle next.
- Expert annotations on the breach triage
- 72-hour clock countdown reference
- Article 33 notification starter template
- Do-not-touch list for the first hour
- First-hour triage and evidence-preservation card — contain without destroying evidence
- Processor breach notification pack — when the breach happens at your processor, or you are one
- Single supervisory-authority filing log
Enough if one person is handling a single-jurisdiction breach.
Buy Solo — $49- Everything in Solo
- Cross-border breach decision tree (one-stop-shop applicability)
- Lead Supervisory Authority identification worksheet
- Article 34 (data-subject notification) drafting checklist
- Multi-language notification guidance — what to translate for each Member State and how to brief a legal translator
- Record-of-breach register template (Article 33(5))
- Forensic readiness and evidence-preservation checklist
- Breach awareness and clock-start log — the dated evidence behind your 72-hour clock (PDF and editable Excel)
- Breach severity assessment worksheet — score the risk the way Article 33 asks you to (PDF and editable Excel)
- Breach tabletop exercise kit — rehearse the 72 hours before they happen for real
Choose this when a breach crosses more than one EU country.
Buy Team — $99- Everything in Team
- Multi-jurisdiction supervisory-authority filing matrix
- EDPB consistency-mechanism coordination playbook
- Sector overlays: healthcare, financial services, and telecommunications — the sector regimes that stack on GDPR Article 33, including NIS2 (EU Network and Information Security Directive) reporting
- Board-briefing pack (one-page incident summary + decision-log template)
- Regulator-communications template pack
- Post-breach review template
Step up here for multi-regulator filings and board-level coordination in a regulated sector.
Buy Enterprise — $299Every tier is a one-time purchase with a 30-day money-back guarantee, no questions asked, and free updates while the toolkit is in our catalogue.
How access works: the documents in every tier are downloads you keep, and the assessment app unlocks in your browser with the licence key from your purchase receipt — no account, no sign-in. The key activates on up to 3 devices on the solo tier, 7 on the middle tier, and 13 on the top tier.
The closest companion books: the GDPR Compliance pair.
The books teach the discipline; the toolkit does the work with you. There is no breach-only book; the GDPR Compliance pair is the closest companion, and its breach-notification chapters cover the same ground this toolkit operationalizes.
Build the readiness side, too
GDPR Breach Response is the tactical product. Once the notification deadline has passed and the dust has settled, build readiness with the matching strategic product so the next breach is less chaotic.
GDPR Compliance Assessment
The calm-day counterpart. 30-question self-assessment + the full toolkit for the documentation a regulator expects to see before a breach happens.
First 4 Hours Incident Response
The general-security sibling. If the breach started as an infrastructure incident (ransomware, vendor compromise, lost laptop), First 4 Hours handles the technical side while Breach Response handles the regulatory side.
The situations this toolkit is built for, written up.
The 72-hour clock — when does it actually start? — ~10 min read.
Telling your customers about a breach — ~8 min read.