# Notification to the Supervisory Authority (Article 33 GDPR)

When a personal data breach has to be notified to the supervisory authority, the 72-hour period and how it is calculated, the competent authority, the minimum content of the notification, phased and bundled notification, and the documentation obligation under Article 33(5) GDPR.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/einzelthemen/datenschutzverletzung/1.3.15.3-meldung-an-die-aufsichtsbehoerde
> Sprache: en



Where the risk assessment results in at least a risk to the rights and freedoms of natural persons, the personal data breach has to be notified to the supervisory authority. This page answers the four practical questions: when, to whom, with what content and within what period. In addition, there is the documentation obligation, which applies independently of the notification.

<Callout type="info">
  **Key takeaways**

  * Every breach has to be notified unless it is unlikely to result in a risk (Article 33(1) GDPR).
  * Period: without undue delay, where feasible within 72 hours of awareness. Where the period is exceeded, reasons must be given.
  * The addressee is the competent supervisory authority; in the case of cross-border processing, the lead authority (one-stop-shop).
  * The minimum content is set out in Article 33(3) GDPR; missing information may be provided subsequently in phases (paragraph 4).
  * Every breach has to be documented, including one that is not notified (Article 33(5) GDPR).
</Callout>

## 1. When notification is required [#1-when-notification-is-required]

The obligation to notify is the rule, non-notification the exception. It is dispensed with only where the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Article 33(1) GDPR). The classification is provided by the [risk assessment](/docs/dsgvo-hub/einzelthemen/datenschutzverletzung/1.3.15.2-risikobewertung). Where the controller refrains from notifying, it must be able to demonstrate that no risk existed; this follows from the scheme of the provision and from the accountability principle.

## 2. Period: without undue delay, where feasible within 72 hours [#2-period-without-undue-delay-where-feasible-within-72-hours]

### 2.1 Start of the period and the significance of the 72 hours [#21-start-of-the-period-and-the-significance-of-the-72-hours]

The notification is made without undue delay, that is, without culpable hesitation, and where feasible within 72 hours after the controller has become aware of the breach (Article 33(1) GDPR). What is decisive for the start of the period is awareness, that is, the point in time of sufficient certainty that personal data are affected (see [First steps and internal procedure](/docs/dsgvo-hub/einzelthemen/datenschutzverletzung/1.3.15.1-erste-schritte-und-interner-ablauf)). The 72 hours are an outer limit and not a buffer: anyone able to notify earlier must notify earlier.

### 2.2 Calculation of the period [#22-calculation-of-the-period]

The period is calculated in accordance with the rules on periods under Union law, not under the German Civil Code (BGB). It is a period expressed in hours. It does not begin immediately upon awareness, but at the beginning of the next full hour, and it ends upon expiry of the 72nd hour. It continues to run on public holidays, Sundays and Saturdays and is not extended to the next working day where it ends on such a day (the Bavarian Data Protection Commissioner (BayLfD), [guidance on the obligation to notify and the obligation to communicate](https://www.datenschutz-bayern.de/datenschutzreform2018/OH_Meldepflichten.pdf), paras. 76 et seq.). Where the period extends over a weekend or public holidays, appropriate provision must therefore be made.

<Mermaid
  chart="flowchart LR
  A[&#x22;Thu 14:30<br/>incident&#x22;] --> B[&#x22;Fri 08:00<br/>noticed internally&#x22;]
  B --> C[&#x22;Fri 18:50<br/>sufficient awareness&#x22;]
  C --> D[&#x22;Fri 19:00<br/>period begins&#x22;]
  D --> E[&#x22;Mon 19:00<br/>period ends&#x22;]"
/>

In the example, the period does not begin until sufficient awareness is obtained on Friday at 18:50, counted from the next full hour, that is, from 19:00, and it ends on Monday at 19:00. The weekend counts towards it.

### 2.3 Late notification [#23-late-notification]

Where the notification is not made within 72 hours, it must be accompanied by reasons for the delay (Article 33(1), second sentence, GDPR). Those reasons must set out comprehensibly why notification was not made earlier; mere keywords are not sufficient. A late notification may result in measures by the supervisory authority and in an administrative fine.

## 3. Which supervisory authority [#3-which-supervisory-authority]

The addressee is the supervisory authority competent under Article 55 GDPR. In the case of cross-border processing, the controller notifies the lead supervisory authority, which serves as the single point of contact (one-stop-shop). The lead authority is not necessarily located where the data subjects reside or where the incident occurred; when preparing its response plan, the controller should clarify which authority that is. Where it is unclear which authority is the lead authority, notification should at least be made to the local supervisory authority of the place where the incident occurred. A controller not established in the EU that falls within the territorial scope of the GDPR informs every supervisory authority in whose Member State data subjects are resident (EDPB, [Guidelines 9/2022](https://www.edpb.europa.eu/system/files/2024-10/edpb_guidelines_202209_personal_data_breach_notification_v2.0_de_0.pdf), para. 73).

## 4. Content of the notification [#4-content-of-the-notification]

The notification must contain at least the information listed in Article 33(3) GDPR. The supervisory authorities regularly provide online forms for this purpose.

* **The nature of the breach**, where possible including the categories and approximate number of data subjects concerned as well as the categories and approximate number of personal data records concerned (point (a)).
* **The name and contact details** of the data protection officer or of another contact point where more information can be obtained (point (b)).
* **A description of the likely consequences** of the breach (point (c)).
* **A description of the measures taken or proposed** to address the breach and, where appropriate, to mitigate its possible adverse effects (point (d)).

The absence of precise figures must not hold up the notification; approximate details and estimates are sufficient at first. Where necessary, further information may be added, for instance a reference to a processor involved.

## 5. Phased and bundled notification [#5-phased-and-bundled-notification]

Where not all the information is available in time, the controller may first submit an initial notification and provide the missing information subsequently in phases without undue further delay (Article 33(4) GDPR). It is advisable to point out to the supervisory authority in the initial notification that further information will follow. Where several very similar breaches occur within a short period, they may be bundled into a single meaningful notification, provided that the same types of data are affected in the same way. Where it turns out after an initial notification that no breach existed after all, the notification may be corrected; there is no penalty for notifying an incident that does not turn out to be a breach.

## 6. Documentation obligation under Article 33(5) [#6-documentation-obligation-under-article-335]

Irrespective of whether notification is made, the controller documents every personal data breach, including all the facts relating to it, its effects and the remedial action taken (Article 33(5) GDPR). The documentation must enable the supervisory authority to verify compliance with the obligation to notify. It is an expression of [accountability](/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.9-rechenschaftspflicht) (Article 5(2) GDPR). What must be recorded is, in particular, the cause and the course of events, the data concerned, the effects and the measures, as well as, where a decision is taken not to notify, the reasons why no risk was assumed. The GDPR does not specify a retention period of its own; the documentation must be kept in such a way that the supervisory authority is able to examine it on request. An internal register of personal data breaches is the appropriate tool for this.

## 7. Protection against self-incrimination [#7-protection-against-self-incrimination]

A concern widespread in practice is that one's own notification will trigger investigations against the company or against the individuals involved. The law takes account of this: information provided by the person subject to the notification obligation on the basis of that obligation may be used in criminal proceedings against him or against certain relatives only with his consent (§ 42(4) of the German Federal Data Protection Act, BDSG); the same applies to proceedings under the German Act on Regulatory Offenses (§ 43(4) BDSG). This does not remove the obligation to notify as such, and a fear of sanctions does not justify concealing a breach that is subject to the obligation to notify.


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.