/ Articles /
Legal
/

Data Breach Notification Under GDPR

Apr 8, 2026
12
Min Read
Who should read this?

Irish companies, startups, and SMEs handling personal data under GDPR, especially those reporting to the DPC.

They'll learn precise notification timelines, what to report, response processes, documentation, and proactive steps to avoid enforcement like fines and reputational damage.

Key Takeaways

  • Notify DPC within 72 hours of awareness if breach risks individuals; 2024 saw 7,781 notifications, 50% misdirected correspondence.
  • Breaches include non-cyber incidents like wrong emails or lost devices; no malicious intent required.
  • Maintain breach register for all incidents, documenting facts, effects, actions.
  • Build response plan with team roles, containment, assessment; train and test regularly.
  • Late notifications risk fines/reprimands, e.g., €40k university, €251M Meta for Article 33 failures.

Frequently Asked Questions

What counts as a personal data breach under GDPR?

A personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access to personal data. It includes confidentiality breaches (e.g., wrong email), integrity (data alteration), and availability (ransomware), even non-cyber like lost devices.

When must you notify the DPC?

You must notify the DPC within 72 hours of becoming aware if the breach is likely to result in a risk to individuals' rights. Most breaches meet this low threshold; notify promptly even if info is incomplete, supplementing later.

What must a DPC notification include?

It requires the breach nature (affected people/records), contact details (DPO), likely consequences, and measures taken or proposed. Use the DPC's online form for guidance.

When must affected individuals be notified?

Directly communicate if high risk (e.g., identity theft, financial loss). Include clear description, contacts, consequences, measures. Exceptions for encryption or disproportionate effort with public notice.

What does a breach response procedure involve?

Assemble team (incident lead, IT, legal), contain immediately, assess scope/risk, document everything, maintain breach register. Train staff and test via exercises.

Explore our other topics