Privacy
Focus topic

Data breaches and notification duties

Assess a data breach, preserve the facts and organise the next steps.

BRANDAUER Rechtsanwälte
Contact person

Mag. Bernhard Brandauer, Rechtsanwalt

BRANDAUER Rechtsanwälte

Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.

A personal data breach can result from a misdirected email, a lost laptop, a compromised account or an error by a service provider. It is not limited to data being published online. Loss, destruction, alteration, unauthorised disclosure or unauthorised access to personal data may all require assessment.

A business should not begin by looking for a completed form. It should first establish what happened: which data may be affected, how many people may be involved, who could access the data and when the incident became known. Only then can the business assess whether the Austrian supervisory authority or the affected individuals must be notified.

Article 33 GDPR generally sets a 72-hour period from becoming aware of a breach for notifying the supervisory authority where notification is required. This does not mean that every technical cause must be solved within 72 hours. It does mean that the initial assessment, interim findings and decision must be organised without undue delay.

Mag. Bernhard Brandauer, Rechtsanwalt

Initial orientation

How should the breach be assessed first?

Answer the questions based on the facts currently available. The result is an initial orientation and not a final assessment of the specific incident.

01 Question 1

Is it known which personal data may be affected?

Record incomplete information with its time and source.

Result

Your orientation

01

Notification to the supervisory authority should be assessed without undue delay.

Preserve the known facts and assess notification under Article 33 GDPR. At the same time consider whether the high-risk threshold for communication under Article 34 GDPR may be met.

Use the data breach initial check →
02

A breach that is not reported still needs a documented assessment.

Not every breach requires notification. Record the facts, the risk assessment and the reasons for the decision so compliance with Article 33(5) GDPR can later be demonstrated.

Use the data breach checklist →
03

Incomplete information requires a reliable interim assessment.

Uncertainty is not a reason to leave the incident unattended. Separate confirmed facts from assumptions, preserve evidence and update the assessment. The period may already be running while the technical investigation continues.

Document the breach step by step →
The central distinction

Authority notification, communication and documentation

These duties are triggered by different levels of risk. Each duty therefore needs its own assessment.

Authority notification, communication and documentation
Question Typical consequence
Is a risk for rights and freedoms likely? Assess notification to the supervisory authority under Article 33 GDPR
Is a high risk likely? In principle communicate with affected individuals under Article 34 GDPR without undue delay
Is notification not required? Document the breach and the reasons for the decision under Article 33(5) GDPR

The assessment depends on the incident. Encryption, access controls and rapid containment may affect the result.

What is a personal data breach?

Article 4(12) GDPR defines a personal data breach as a breach of security leading to accidental or unlawful destruction, loss or alteration of personal data. Unauthorised disclosure or access is also covered.

A message sent to the wrong recipient therefore requires assessment just as a cyberattack does. A file may have been exposed only briefly and a cloud account may have been open only for a short period. Whether a notification duty exists is a separate question.

The process is not limited to digital systems. A lost paper file, an exposed printout or a letter sent to the wrong address can trigger the same assessment. The relevant point is the concrete risk to the people described by the data.

  • Loss or theft of a device containing personal data
  • A message sent to the wrong recipient or an open distribution list
  • Unauthorised access after phishing, credential compromise or a configuration error
  • Accidental deletion or alteration without reliable recovery

The first hours after the breach becomes known

The time of awareness is a central reference point. Record when a person in the business first learned facts that made a breach likely. A vague suspicion without concrete indications must be distinguished from that point. Once the relevant information exists the assessment process should begin.

Immediate measures should limit further harm. They may include disabling an account, recalling a message, isolating a system or preserving logs. Technical actions should be linked to a legal timeline so a later review can show what was known and why each step was taken.

A responsible person should coordinate the response. If a processor is involved it must inform the controller without undue delay. The roles and workflows for service providers should therefore be clear in the agreement and the incident process.

  • Record the time of awareness and the escalation route
  • Stop further disclosure or access
  • Preserve logs, messages and affected files unchanged
  • Assign responsibility for the legal assessment and communication

Risk assessment under Article 33 GDPR

A rule that every breach must be reported is incorrect. Article 33 GDPR links authority notification to the likelihood of a risk for the rights and freedoms of individuals. The number of records is not the only factor. Sensitive content can be significant even when only a few people are affected. A large dataset protected by effective encryption may be assessed differently.

Consider the type and scope of the data, the number and group of affected people and the possible consequences. Ask whether contact data could support fraud, whether health information or financial details are involved and whether a recipient could actually read the data. The duration of access and the safeguards in place also matter.

The decision should include a reasoned explanation. The business does not have to prove every possible consequence. It should be able to show which facts were considered and why a risk was accepted or rejected. The data breach initial check helps structure these questions.

The 72-hour period and authority notification

Where a risk is likely the controller must notify the competent supervisory authority without undue delay. Where feasible the notification should be made no later than 72 hours after awareness. If the period is exceeded the delay must be explained. The period is therefore not a reason to wait for the forensic investigation to finish.

An initial notification can be based on the secured interim position. Missing information can be supplied later. Article 33(3) GDPR refers to the nature of the breach, the categories and approximate number of affected people and records, likely consequences and measures taken or proposed. A contact point must also be provided.

Whether the Austrian authority is competent depends on the establishment, the processing and the applicable allocation of responsibilities. Use the procedure provided by the competent authority. An internal note saying “reported” is not a sufficient record. Keep the submitted version and later supplements together.

  • Describe the nature and cause of the breach
  • Define data categories and groups of affected people
  • Explain possible consequences and containment measures
  • Record the contact point and the transmission time

When affected individuals must be informed

Communication under Article 34 GDPR is distinct from authority notification. It generally applies where the breach is likely to result in a high risk to the rights and freedoms of individuals. In that case affected people must be informed without undue delay in clear and plain language.

Communication may not be required where effective technical and organisational measures have made the high risk unlikely. Subsequent measures may also matter if they mean that the high risk is no longer likely. The reasons belong in the incident record.

The message should explain the incident, the contact point, likely consequences and measures already taken. If direct communication would involve disproportionate effort a public communication may be required. The appropriate form depends on the incident and the people affected.

Documentation and internal responsibility

Article 33(5) GDPR requires the controller to document every personal data breach. This applies even when the risk assessment concludes that authority notification is not required. The record should contain the facts, effects and remedial measures and allow the authority to verify compliance.

A consistent incident file can contain the timeline, affected systems, data categories, recipients, safeguards, assessment and approvals. Update it when new information arrives. An incident register is not a substitute for an individual assessment. It should make decisions traceable and expose recurring weaknesses.

The privacy governance framework should assign responsibility for containment, legal approval and communication with processors and individuals. The data breach checklist supports the first internal record.

Common mistakes after a data breach

Problems often arise from unclear responsibility and an incomplete timeline rather than from a lack of technical knowledge. The incident process should address these points explicitly.

  • Counting 72 hours only after the investigation is complete: The assessment must begin with the secured interim facts.
  • Reporting every breach automatically: Article 33 GDPR requires a risk assessment. A decision not to report still needs documentation.
  • Looking only at the technical cause: Data type, affected people, recipients and consequences are also relevant.
  • Leaving the processor out: A processor must inform the controller without undue delay.
  • Communicating too early or too vaguely: Individuals need clear information about effects and safeguards.
  • Skipping a review: The first assessment may change when logs or responses reveal new facts.

Documents businesses should prepare

A business can reduce response time when essential information is easy to find during normal operations. Useful materials include current contact routes, role descriptions, processor lists and a process for preserving technical logs. Preparation should match the size and risk of the processing.

For a specific breach record the affected systems, data fields, recipients, access period, safeguards and communication steps. Also preserve the decision explaining why a notification was or was not required. This turns a rushed response into a reviewable process.

A breach may reveal a structural weakness. After the urgent response review access rights, training, retention concepts and processor agreements. The data breach checklist supports a shared internal vocabulary.

Frequently asked questions

Questions businesses often ask about data breaches

Must every personal data breach be reported within 72 hours? +
No. The 72-hour period concerns notification to the supervisory authority where the breach is likely to create a risk to the rights and freedoms of individuals. Every breach still needs to be assessed and documented.
What if not all information is available after 72 hours? +
Where notification is required an initial notification should use the secured interim facts. Missing information can be added later. The delay and its reasons should be recorded.
Must affected individuals always be informed? +
No. Article 34 GDPR applies to a likely high risk. Whether an exception applies depends on encryption and other effective safeguards among other factors.

Sources

BRANDaktuelle Legal News

Subscribe to legal news

Receive new articles and legal updates from the firm with BRANDaktuelle Rechtsnews.

Subscribe to legal news

Assess a data breach with legal support

If a breach has occurred or a service provider has reported an incident we can help assess risk, documentation and communication.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich