Privacy
Glossary

Notification to the supervisory authority

Notification to the supervisory authority reports a personal data breach where it is likely to create a risk to the rights and freedoms of data subjects.

In brief

Notification to the supervisory authority is the controller’s communication of a personal data breach to the competent data protection supervisory authority. Under Article 33 GDPR, notification is generally required where the breach is likely to result in a risk to the rights and freedoms of natural persons. Where such a risk is unlikely, notification is not required. This notification is separate from the communication to affected data subjects under Article 34 GDPR.

The notification must be made without undue delay and, where feasible, within 72 hours after the controller becomes aware of the personal data breach. Where it is submitted later, the controller must give reasons for the delay. It should describe the nature and likely consequences of the breach, the affected categories and approximate numbers of data subjects and records, a contact point, and the measures taken or proposed to address the breach. If all information is not yet available, it may be provided in stages.

A processor must inform the controller without undue delay after becoming aware of a personal data breach. The controller must also document the breach and the reasoning behind its risk assessment, including where no notification to the supervisory authority is ultimately required. The data breaches and notification duties topic explains the process; the glossary provides further data protection terms.

General orientation, not individual advice.

Discuss your data protection matter

Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich