GDPR Breach Response

The 72-hour clock — without inventing the notification in real time.

A free in-browser triage for the first 72 hours of a personal-data breach under the GDPR. Answer nine questions. You get a clear verdict — notify or document — and your Article 33 deadline, counted from the time you became aware. You also get the required Article 33(3) contents, a do-not-touch list, and a starter notification draft you can hand to counsel.

The triage runs in your browser. Your answers never leave your device. That matters more when the question is "is this a breach we have to report?"

Pick a tier

Three tiers — one for solo DPOs, one for cross-border SMBs, one for multi-DSA enterprises.

Each tier serves a different Data Protection Officer (DPO) situation. Buy the tier that matches the kind of breach you're handling — or the kind you might handle next.

Solo
$49one-time
For one person handling the breach: a solo or fractional Data Protection Officer, a privacy lead, a founder, or counsel standing in as DPO.
  • Nine-question breach triage with expert annotations
  • 72-hour clock countdown reference
  • Article 33 notification starter template
  • Do-not-touch list for the first hour
  • Single-jurisdiction Supervisory Authority directory entry
Buy Solo — $49
Enterprise
$199one-time
For enterprise DPO teams and counsel in regulated sectors — healthcare, finance, telecoms — who file with several regulators at once.
  • Everything in SMB
  • Multi-jurisdiction Data Supervisory Authority (DSA) filing matrix
  • EDPB consistency-mechanism coordination playbook
  • Sector overlays: HIPAA breach pairing, PCI DSS §12.10, and NIS2 reporting
  • Board-briefing pack (one-page incident summary + decision-log template)
  • Legal-counsel handoff package
  • Cross-border subject-notification translation matrix
Buy Enterprise — $199
How it works

Two paths into the toolkit.

1. Take the free triage

Nine questions about the personal-data breach you're handling. The triage returns a notifiable-or-document verdict, the Article 33 72-hour deadline calculated from your awareness time, the required Article 33(3) contents tailored to your situation, and a starter notification draft you can hand to counsel. About five minutes. Runs in your browser — no email required, no data transmitted.

Start the free triage →

2. Download the free Breach Battle-Card

A one-page printable reference that summarises the first 72 hours of a personal-data breach: the awareness-time anchor, the Article 33 vs. Article 34 distinction, the do-not-touch list, the four artefacts to capture before the clock starts. Keep one printed copy in the DPO's desk drawer.

Get the free Battle-Card →

The privacy-first promise matters most when you're handling a breach.

The free GDPR Breach Response triage scores you locally in your browser. We do not collect your answers, the categories of personal data involved, the data subjects affected, the date of awareness, or any other detail of the breach. We collect your email address only if you choose to enter it for the Battle-Card download. Nothing else.

Our website uses Cloudflare's server-side traffic analytics for aggregate page counts — no JavaScript injection, no cookies, no identifiable data.