GDPR Breach Response

Notify or document? A clear verdict, before the 72-hour clock runs out.

A free in-browser triage for the first 72 hours of a personal-data breach under the General Data Protection Regulation (GDPR). Answer nine questions. You get a clear verdict (notify or document) and your Article 33 deadline, counted from the time you became aware. You also get the required Article 33(3) contents, a do-not-touch list, and a starter notification draft you can hand to counsel.

The triage runs in your browser. Your answers never leave your device. That matters more when the question is "is this a breach we have to report?"

Free first

Two paths into the toolkit.

1. Take the free triage

Nine questions about the personal-data breach you're handling. The triage returns a notify-or-document verdict and the Article 33 72-hour deadline, counted from when you became aware. It also gives you the required Article 33(3) contents for your case and a starter draft you can hand to counsel. About five minutes. Runs in your browser, no email required, no data transmitted.

Start the free triage →

2. Read the free Breach Battle-Card

A one-page printable reference that summarises the first 72 hours of a personal-data breach: the awareness-time anchor, the Article 33 vs. Article 34 distinction, the do-not-touch list, the four artefacts to capture before the clock starts. Keep one printed copy in the DPO's desk drawer.

Read the free guide →
Who this is for

This is for a personal-data breach that's already happening.

It runs the live 72-hour clock (the notify-or-document decision and your Article 33 deadline), not the readiness work you do beforehand. To get ready before a breach, see the GDPR Checklist; if the incident isn't a personal-data breach, First 4 Hours covers general incident triage.

Pick a tier

Three tiers: one for solo DPOs, one for cross-border SMBs, one for multi-DSA enterprises.

Each tier serves a different Data Protection Officer (DPO) situation. Buy the tier that matches the kind of breach you're handling, or the kind you might handle next.

Solo
$49one-time
For one person handling the breach: a solo or fractional Data Protection Officer, a privacy lead, a founder, or counsel standing in as DPO.
  • Expert annotations on the breach triage
  • 72-hour clock countdown reference
  • Article 33 notification starter template
  • Do-not-touch list for the first hour
  • First-hour triage and evidence-preservation card — contain without destroying evidence
  • Processor breach notification pack — when the breach happens at your processor, or you are one
  • Single supervisory-authority filing log

Enough if one person is handling a single-jurisdiction breach.

Buy Solo — $49
Enterprise
$299one-time
For enterprise DPO teams and counsel in regulated sectors (healthcare, finance, telecoms) who file with several regulators at once.
  • Everything in Team
  • Multi-jurisdiction supervisory-authority filing matrix
  • EDPB consistency-mechanism coordination playbook
  • Sector overlays: healthcare, financial services, and telecommunications — the sector regimes that stack on GDPR Article 33, including NIS2 (EU Network and Information Security Directive) reporting
  • Board-briefing pack (one-page incident summary + decision-log template)
  • Regulator-communications template pack
  • Post-breach review template

Step up here for multi-regulator filings and board-level coordination in a regulated sector.

Buy Enterprise — $299

Every tier is a one-time purchase with a 30-day money-back guarantee, no questions asked, and free updates while the toolkit is in our catalogue.

How access works: the documents in every tier are downloads you keep, and the assessment app unlocks in your browser with the licence key from your purchase receipt — no account, no sign-in. The key activates on up to 3 devices on the solo tier, 7 on the middle tier, and 13 on the top tier.

From Sylvan Press

The closest companion books: the GDPR Compliance pair.

The books teach the discipline; the toolkit does the work with you. There is no breach-only book; the GDPR Compliance pair is the closest companion, and its breach-notification chapters cover the same ground this toolkit operationalizes.

The privacy-first promise matters most when you're handling a breach.

The free GDPR Breach Response triage scores you locally in your browser. We do not collect your answers, the categories of personal data involved, the data subjects affected, the date of awareness, or any other detail of the breach. We collect your email address only if you choose to enter it for the Battle-Card download. Nothing else.

Our website uses Cloudflare's server-side traffic analytics for aggregate page counts — no JavaScript injection, no cookies, no identifiable data.

From the blog

The situations this toolkit is built for, written up.

The 72-hour clock — when does it actually start? — ~10 min read.

Telling your customers about a breach — ~8 min read.