Notification to Supervisory Authority
Under the EU GDPR, when a personal data breach occurs, the organization responsible for deciding how and why data is processed generally must inform the relevant government privacy regulator, known as a supervisory authority. This notification is expected without undue delay and, where feasible, within 72 hours of becoming aware of the breach. If the notification is late, the organization must explain the reasons for the delay.
A procedural obligation under Article 33 of the EU GDPR requiring a data controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where notification is not made within 72 hours, it must be accompanied by reasons for the delay. The obligation to notify the supervisory authority rests with the controller; a processor's corresponding duty is to notify the controller (not the supervisory authority) without undue delay after becoming aware of a breach. This entry addresses the controller-facing notification duty to the supervisory authority under the EU GDPR only; it does not cover the separate obligation to communicate a breach to affected data subjects, the specific content requirements of the notification, risk-assessment thresholds, documentation of breaches, or breach-notification regimes under other instruments such as the UK GDPR, HIPAA, or U.S. state laws, which differ in triggers, timelines, and recipients. The 72-hour window is a maximum outer limit conditioned on feasibility and awareness, not a guarantee of compliance; adequacy depends on facts, risk assessment, and evidence of the controller's actions.
Why it matters
The notification obligation to a supervisory authority sits at the center of the EU GDPR's accountability model for breach management. It converts an internal security event into an external, time-bound regulatory duty: the controller must generally inform the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Because the clock starts on awareness rather than on the moment of the incident itself, organizations need detection, triage, and escalation processes that can establish and document when awareness occurred and support a defensible risk assessment.
The obligation also enforces a clear separation of accountability between roles. The duty to notify the supervisory authority rests with the controller. A processor's corresponding duty is different: it must notify the controller, not the supervisory authority, without undue delay after becoming aware of a breach. Conflating these roles is a common and consequential mistake, because a processor that assumes the controller will handle everything, or a controller that assumes its processor has already contacted the regulator, can produce a compliance gap that neither party notices until it is too late.
The 72-hour window is best understood as a maximum outer limit conditioned on feasibility and awareness, not a safe harbor or a guarantee of compliance. Where a notification is not made within that window, it must be accompanied by reasons for the delay. Adequacy still depends on the facts, the quality of the risk assessment, and the evidence a controller can produce of its actions. This entry addresses only the controller-facing notification duty to the supervisory authority under the EU GDPR; it does not cover communication to affected data subjects, the content requirements of the notification, breach documentation, or the differing regimes under the UK GDPR, HIPAA, or U.S. state laws.
Who it's relevant to
Inside Notification to Supervisory Authority
Common questions
Answers to the questions practitioners most commonly ask about Notification to Supervisory Authority.