What to Do After a Data Breach: A Practical Guide to the First 72 Hours Under the GDPR

For many businesses, the discovery of a data breach begins with panic, confusion and an urgent attempt to contain the technical problem. What organisations often do not realise, however, is that the first 72 hours after discovering a breach are legally critical under the GDPR. 

When a business discovers a data breach, the initial reaction is often to focus on the technical problems of identifying and stopping the leak, securing technical systems, and finding out what happened.

Those steps matter. However, from a legal and regulatory perspective, the most important fact is often overlooked: a potentially expensive clock has already started running.

Under the General Data Protection Regulation (GDPR), organisations have a maximum of 72 hours to determine whether a personal data breach must be notified to the Data Protection Commission (DPC), and to make that notification if necessary.

Having advised organisations on GDPR compliance since the Regulation came into force in 2018, and having acted for Irish, multinational, and international businesses in data protection matters, I have found that the first 72 hours after a breach often determines whether an incident remains minimal or develops into a much more serious regulatory and compliance problem. In a number of cases, I have also seen organisations have fines increased simply because the 72-hour reporting deadline was missed.

To avoid such GDPR consequences, organizations need to know the timeline they must act on and the actions they need to take when a data breach occurs.

Starting the 72-Hour Clock

One of the most common misconceptions I encounter is that the 72-hour deadline begins when the Data Protection Officer learns about the breach.

It does not.

In practical terms, the clock starts when the organisation becomes aware of the breach. If an employee discovers it, if a customer reports it, or if a supplier notifies you, the organisation’s awareness has begun.

This is why staff training is so important. Every employee should understand that a suspected data breach is not something to investigate quietly over several days before escalating. Information must be passed immediately to the person responsible for data protection compliance.

In larger organisations, that will usually be the Data Protection Officer. In smaller organisations, it may be a privacy officer, IT lead, or designated manager. What matters is that somebody has clear responsibility and receives the information quickly.

Every hour lost internally is an hour lost from the 72-hour reporting window.

Assess the Impact 

Before making any notification decision, you need to understand what has happened and to whom.

The first task is to gather reliable information, including:

  • What data was affected?
  • How many individuals were affected?
  • Is the data confidential, sensitive, or otherwise high-risk?
  • Was the information merely exposed, or was it actually accessed?
  • Has the breach been contained?
  • Is the exposure ongoing?

At this stage, businesses often focus exclusively on the technical details. While those are important, GDPR requires a different assessment.

The key legal question is not “What happened?”

The key question is: What is the likely risk to the rights and freedoms of the affected individuals?

Assess the Risk and Reporting Requirement

Not every data breach requires notification to the Data Protection Commission. The GDPR threshold is based on risk.

In broad terms, businesses should consider two factors:

1. Volume

How many individuals are affected?

A breach affecting tens of thousands of customers will naturally attract more regulatory concern than a breach affecting a handful of individuals.

2. Severity

What type of data was involved?

The accidental disclosure of email addresses is very different from the disclosure of medical records, financial information, or special category data.

As a rule of thumb:

VolumeRisk LevelLikely Outcome
Low VolumeLow RiskNotification may not be required
High VolumeLow RiskNotification often required
Low VolumeHigh RiskNotification often required
High VolumeHigh RiskNotification almost certainly required

In practice, organisations should be cautious. If there is any genuine uncertainty, the safer course is to notify.

Preparing Your DPO Notification

If the assessment indicates a risk to individuals’ rights and freedoms, the organisation should prepare its notification to the Data Protection Commission.

Many companies are surprised by how detailed this process can be.

It can take several hours to complete the DPC’s breach notification form online. The form requires substantial information about:

  • The nature of the breach
  • The categories of data involved
  • The number of affected individuals
  • Likely consequences
  • Mitigation measures already taken
  • Planned remedial actions

Crucially, you do not need to have every answer before making the initial notification.

The DPC recognises that investigations are often ongoing. Initial reports can be supplemented later as further information becomes available.

This is an important point, because organisations sometimes delay reporting while trying to achieve complete information about the breach.

That approach is an error. A late notification will create greater difficulties than an early notification followed by updates.

When a Data Breach Must Be Reported to the Data Protection Commission 

The regulatory notification requirement and the obligation to notify affected individuals are not the same thing.

A second risk assessment must be undertaken to assess the degree of risk to individuals.

Where the breach is likely to result in a high risk to individuals’ rights and freedoms, affected individuals may also need to be informed.

This could include circumstances involving:

  • Financial information
  • Health records
  • Identity documentation
  • Special category personal data
  • Information capable of facilitating fraud or identity theft

The notification method will depend on the circumstances.

For smaller volume incidents, direct communication may be appropriate through email, telephone, or letter.

For larger breaches affecting substantial numbers of individuals, public notices or broader communications may become necessary.

The objective is to give people enough information to understand the risk and protect themselves.

Most Breach Problems Start Before the Breach 

A data breach is never a pleasant experience for any organisation. However, from a GDPR perspective, the legal and procedural preparation is often just as important as the technical response.

In practice, one of the greatest risks to organisations is not necessarily the breach itself, but the failure to escalate information internally quickly enough once the breach becomes known.

Every employee should understand that the moment a potential breach is identified, time becomes legally significant. Internal procedures should be designed to move information quickly from frontline staff to whoever is responsible for GDPR compliance, whether that is a Data Protection Officer, privacy lead, IT security manager, or another designated decision-maker.

In my experience advising organisations on GDPR compliance and data breach management, businesses that act quickly, document their reasoning carefully, maintain clear procedures, and communicate promptly and openly with regulators generally achieve far better outcomes than those that allow delays, uncertainty, or poor internal processes to drive their response.


Simon McGarr
AUTHOR

Simon McGarr

Simon McGarr is a graduate of UCD and GMIT. He has been a lawyer with McGarr Solicitors since qualifying as a solicitor in 2008.

Simon is a CIPP/E Certified Information Privacy Professional/Europe specialising in GDPR compliance, data protection, and privacy rights law. He lectures for the Law Society of Ireland on its Diploma in Data Protection and Certificate in Data Protection programmes, and also serves as an external examiner.

Simon works with Irish and international organisations as an external DPO and on compliance, breach response, and data governance matters.

Privacy Overview

We use cookies to ensure our website functions securely and to provide you with a tailored browsing experience. Cookie information is stored in your browser and performs essential functions, such as saving your privacy preferences and helping us understand which sections of the website our visitors find most useful.