Skip to main content
Category: Breach and Risk Assessment

Notification to Supervisory Authority

Also known as: Breach Notification to Supervisory Authority, Personal Data Breach Notification
Simply put

Under the EU GDPR, when a personal data breach occurs, the organization responsible for deciding how and why data is processed generally must inform the relevant government privacy regulator, known as a supervisory authority. This notification is expected without undue delay and, where feasible, within 72 hours of becoming aware of the breach. If the notification is late, the organization must explain the reasons for the delay.

Formal definition

A procedural obligation under Article 33 of the EU GDPR requiring a data controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where notification is not made within 72 hours, it must be accompanied by reasons for the delay. The obligation to notify the supervisory authority rests with the controller; a processor's corresponding duty is to notify the controller (not the supervisory authority) without undue delay after becoming aware of a breach. This entry addresses the controller-facing notification duty to the supervisory authority under the EU GDPR only; it does not cover the separate obligation to communicate a breach to affected data subjects, the specific content requirements of the notification, risk-assessment thresholds, documentation of breaches, or breach-notification regimes under other instruments such as the UK GDPR, HIPAA, or U.S. state laws, which differ in triggers, timelines, and recipients. The 72-hour window is a maximum outer limit conditioned on feasibility and awareness, not a guarantee of compliance; adequacy depends on facts, risk assessment, and evidence of the controller's actions.

Why it matters

The notification obligation to a supervisory authority sits at the center of the EU GDPR's accountability model for breach management. It converts an internal security event into an external, time-bound regulatory duty: the controller must generally inform the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Because the clock starts on awareness rather than on the moment of the incident itself, organizations need detection, triage, and escalation processes that can establish and document when awareness occurred and support a defensible risk assessment.

The obligation also enforces a clear separation of accountability between roles. The duty to notify the supervisory authority rests with the controller. A processor's corresponding duty is different: it must notify the controller, not the supervisory authority, without undue delay after becoming aware of a breach. Conflating these roles is a common and consequential mistake, because a processor that assumes the controller will handle everything, or a controller that assumes its processor has already contacted the regulator, can produce a compliance gap that neither party notices until it is too late.

The 72-hour window is best understood as a maximum outer limit conditioned on feasibility and awareness, not a safe harbor or a guarantee of compliance. Where a notification is not made within that window, it must be accompanied by reasons for the delay. Adequacy still depends on the facts, the quality of the risk assessment, and the evidence a controller can produce of its actions. This entry addresses only the controller-facing notification duty to the supervisory authority under the EU GDPR; it does not cover communication to affected data subjects, the content requirements of the notification, breach documentation, or the differing regimes under the UK GDPR, HIPAA, or U.S. state laws.

Who it's relevant to

Data Controllers
Controllers bear the direct obligation to notify the competent supervisory authority under the EU GDPR. They must be able to determine when awareness occurred, assess whether the breach is likely to result in a risk to individuals, and act without undue delay within the 72-hour outer limit where feasible, or document reasons for any delay. Accountability here requires demonstrable evidence of the assessment and actions taken, not merely a stated intention to comply.
Data Processors
Processors do not notify the supervisory authority directly. Their corresponding duty under the EU GDPR is to notify the controller without undue delay after becoming aware of a breach, enabling the controller to meet its own timeline. Clear contractual and operational escalation paths between processor and controller are essential to avoid gaps where each party assumes the other is acting.
Data Protection Officers and Privacy Teams
DPOs and privacy teams typically coordinate the breach assessment and notification workflow, ensuring the risk evaluation is defensible and the timeline is tracked from the point of awareness. They should confirm that role responsibilities between controller and processor are correctly assigned and that reasons for any delayed notification are documented.
Incident Response and Security Teams
Security teams detect and investigate breaches and establish the facts, including when awareness occurred, that feed the controller's notification decision. While this obligation is a governance and legal duty rather than a security control, security detection and triage capabilities directly determine whether the notification timeline can be met.
Legal and Compliance Functions
Legal and compliance stakeholders advise on whether a breach meets the risk threshold that triggers notification, on how the 72-hour feasibility condition applies to the specific facts, and on documenting reasons for any delay. They should note that this EU GDPR duty differs in triggers, timelines, and recipients from regimes such as the UK GDPR, HIPAA, and U.S. state breach laws, which must be assessed separately.

Inside Notification to Supervisory Authority

Notification Trigger
Under the EU GDPR and UK GDPR, a data controller is generally required to notify the competent supervisory authority of a personal data breach unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The obligation to notify sits with the controller, not the processor; a processor's duty is generally to inform the controller.
Timing Expectation
Notification is expected without undue delay once the controller becomes aware of the breach, and the EU and UK GDPR frame a target of doing so promptly where feasible. Where notification is delayed beyond the expected window, reasons for the delay generally accompany the report. This entry does not specify a precise hour count as a guaranteed threshold across all regimes, since treatment differs by jurisdiction.
Content of the Notification
A notification typically describes the nature of the breach, including where possible the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed to address it, and contact details for the data protection officer or other point of contact where one exists.
Phased Reporting
Where all information is not available at once, information may generally be provided in phases without further undue delay, allowing an initial report to be supplemented as investigation progresses.
Documentation Obligation
The controller generally documents personal data breaches, including facts, effects, and remedial action, so that the supervisory authority can verify compliance. This reflects the accountability principle, which requires demonstrable evidence rather than stated intent.
Relationship to Data Subject Notification
Notification to the supervisory authority is distinct from any obligation to communicate a breach to affected data subjects. The two obligations have different triggers and thresholds and should not be treated as a single step.

Common questions

Answers to the questions practitioners most commonly ask about Notification to Supervisory Authority.

Does every personal data breach have to be notified to a supervisory authority?
No. Under the EU GDPR and UK GDPR, notification is generally required only where a personal data breach is likely to result in a risk to the rights and freedoms of individuals. Breaches unlikely to result in such a risk typically do not need to be reported to the authority, though the controller should still document them internally. This is a risk-based assessment, not an automatic obligation for all incidents, and the outcome depends on the facts of each case. Other regimes, such as the CCPA and CPRA framework or HIPAA in the United States, apply different triggers and thresholds and should not be assumed to mirror the GDPR standard. This answer does not address which specific incidents cross the risk threshold in your context.
Is notifying the supervisory authority the same as notifying the affected individuals?
No, these are distinct obligations with different triggers. Under the EU GDPR and UK GDPR, notification to the supervisory authority is generally required when a breach is likely to result in a risk to individuals, while communication directly to affected data subjects is generally required only when the breach is likely to result in a high risk to them. It is therefore possible to owe a notification to the authority without owing communication to individuals, and the assessments should be made separately. This entry does not cover the content requirements or timing specifics of individual communications, which are treated elsewhere.
Which party is responsible for making the notification, the controller or the processor?
Under the EU GDPR and UK GDPR, the obligation to notify the supervisory authority generally rests with the controller. A processor that becomes aware of a personal data breach is typically obligated to notify the controller, but does not itself notify the supervisory authority in that capacity. Contractual arrangements between controller and processor commonly specify timelines and information the processor must provide to support the controller's assessment. This division of accountability should be documented; stating an intent to cooperate is not sufficient without demonstrable arrangements. This answer does not address scenarios involving joint controllers or cross-jurisdictional allocation of responsibility.
What information should a notification to the supervisory authority typically contain?
Under the EU GDPR and UK GDPR, a notification generally describes the nature of the breach including, where possible, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it and mitigate adverse effects. The name and contact details of the data protection officer or other contact point are typically included. Where full information is not available at once, it may generally be provided in phases without undue further delay. This entry does not cover the specific form or portal each authority requires, which varies by jurisdiction.
What should we do if we cannot complete our investigation within the expected notification timeframe?
The EU GDPR and UK GDPR generally contemplate that full details may not be available at the point of initial notification. In such cases information may typically be provided in phases as the investigation progresses, without undue further delay, rather than delaying the initial notification until everything is known. Documenting the reasons for any delay and the steps being taken to gather information supports the accountability principle, which requires demonstrable evidence rather than stated intent alone. This answer does not specify the exact deadlines, which are set by the applicable instrument and may be interpreted differently by individual authorities.
Do we need to keep records even for breaches we decide not to notify?
Yes, as a general matter of accountability. Under the EU GDPR and UK GDPR, controllers are typically expected to document personal data breaches, including the facts relating to the breach, its effects, and the remedial action taken, regardless of whether the breach met the threshold for notifying the supervisory authority. This internal record enables the authority to verify compliance if requested and demonstrates that a reasoned risk assessment was performed. Maintaining this documentation is part of demonstrable accountability, not merely an internal formality. This entry does not address retention periods for such records or how they interact with broader records of processing obligations.

Common misconceptions

Every personal data breach must be reported to the supervisory authority.
Under the EU and UK GDPR, notification is generally not required where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. A risk assessment, documented for accountability purposes, informs whether notification is warranted. Treatment differs across other regimes.
The data processor is responsible for notifying the supervisory authority.
The notification obligation to the supervisory authority generally rests with the controller. A processor's typical duty is to inform the controller without undue delay after becoming aware of a breach, enabling the controller to meet its own obligation.
Notifying the supervisory authority and notifying affected individuals are the same requirement.
These are separate obligations with different thresholds. Communication to data subjects generally applies where a breach is likely to result in a high risk to their rights and freedoms, which is a different test from the supervisory authority trigger.

Best practices

Establish a documented breach assessment process that evaluates risk to the rights and freedoms of data subjects, since this assessment generally determines whether supervisory authority notification is required and provides the evidence accountability frameworks expect.
Define contractual and operational channels requiring processors to inform the controller of breaches without undue delay, so the controller can meet its own notification timing expectations.
Maintain an internal breach register recording facts, effects, and remedial actions for all breaches, including those not notified, to demonstrate compliance if the supervisory authority requests verification.
Prepare notification templates capturing the nature of the breach, affected categories and approximate numbers, likely consequences, measures taken, and the relevant point of contact, to support timely and complete reporting.
Enable phased reporting workflows so an initial notification can be submitted promptly and supplemented as facts are confirmed, with reasons documented where notification is delayed.
Confirm the applicable regime and competent supervisory authority for each processing context, since obligations under the EU GDPR, UK GDPR, and other frameworks differ and should not be assumed interchangeable.