# Communication to Data Subjects (Article 34 GDPR)

When a personal data breach has to be communicated to the data subjects, the content and form prescribed, the applicable period, and the conditions under which communication is not required under Article 34(3) GDPR.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/einzelthemen/datenschutzverletzung/1.3.15.4-benachrichtigung-der-betroffenen
> Sprache: en



Where a personal data breach is likely to result in a high risk, notification to the supervisory authority is not sufficient. In that case, the breach must in addition be communicated to the data subjects. A higher threshold applies to this communication than to the notification, but the same urgency applies. This page shows when, with what content and in what form communication has to be made, and when the obligation exceptionally does not apply.

<Callout type="info">
  **Key takeaways**

  * Communication is required only where the breach is likely to result in a **high** risk (Article 34(1) GDPR).
  * The communication is made without undue delay and in clear and plain language.
  * Content: the nature of the breach plus the information set out in Article 33(3)(b), (c) and (d) GDPR.
  * The aim is to enable data subjects to protect themselves; a direct message drawn up specifically for that purpose is therefore required.
  * The communication is not required where one of the three conditions in Article 34(3) GDPR is met (encryption, subsequent elimination of the risk, disproportionate effort).
</Callout>

## 1. When communication is required [#1-when-communication-is-required]

The obligation to communicate arises where the breach is likely to result in a high risk to the rights and freedoms of natural persons (Article 34(1) GDPR). The threshold is therefore higher than for the notification to the supervisory authority, which already applies where there is a simple risk. Data subjects are not to be overloaded with communications about every breach; they are to be warned only where they are able to take protective measures themselves. Whether a high risk exists follows from the [risk assessment](/docs/dsgvo-hub/einzelthemen/datenschutzverletzung/1.3.15.2-risikobewertung).

## 2. Content of the communication [#2-content-of-the-communication]

The communication describes in clear and plain language the nature of the breach and contains at least the information referred to in Article 33(3)(b), (c) and (d) GDPR (Article 34(2) GDPR):

* the **nature of the breach**;
* the **name and contact details** of the data protection officer or of another contact point;
* the **likely consequences** of the breach;
* the **measures taken or proposed** to address the breach and to mitigate its effects, where appropriate together with specific recommendations as to what data subjects can do themselves (such as changing passwords or having cards blocked).

The reference deliberately does not cover point (a), so that the categories and numbers of data subjects and of personal data records do not have to be communicated. A description of the nature of the breach itself nevertheless remains necessary.

## 3. Form and period [#3-form-and-period]

The communication is made without undue delay, that is, as quickly as possible. In so far as this is necessary in order to protect the data subjects, it may be made before or at the same time as the notification to the supervisory authority. As a matter of principle, it is addressed **directly** to the data subjects, by means of a message drawn up specifically for that purpose. It must not be embedded in other content, such as a newsletter or a standard message, because that impairs clarity and attention (EDPB, [Guidelines 9/2022](https://www.edpb.europa.eu/system/files/2024-10/edpb_guidelines_202209_personal_data_breach_notification_v2.0_de_0.pdf), para. 89). Suitable channels are direct contact by email, SMS or messenger service, a prominently placed notice on the website, or a message sent by post. A mere press release or blog post is not sufficient. Channels that could themselves be impaired by the breach are to be avoided. The message must be provided in a language and form that the data subjects understand.

## 4. Exceptions to the obligation to communicate [#4-exceptions-to-the-obligation-to-communicate]

Under Article 34(3) GDPR, communication is not required where one of the three conditions is met:

* **Precautionary protective measures (point (a)).** Before the breach, the controller had implemented appropriate technical and organizational measures and applied them to the personal data affected, rendering the data inaccessible to persons who are not authorized, for instance encryption corresponding to the state of the art. Where the key is compromised or the encryption becomes vulnerable, a fresh assessment has to be made.
* **Subsequent elimination of the risk (point (b)).** The controller has taken subsequent measures which ensure that the high risk is no longer likely to materialize, for instance by immediately blocking the unauthorized access before the data could be used. Where damage has already materialized, the obligation does not cease to apply.
* **Disproportionate effort (point (c)).** Where direct communication would involve disproportionate effort, for instance because the contact details of many data subjects are missing, it is replaced by a public communication or a similarly effective measure. Mere additional work or costs are not sufficient for that purpose; individual information best corresponds to the underlying idea of transparency.

Where the controller relies on an exception, it must be able to demonstrate that the conditions for that exception are met.

## 5. Order by the supervisory authority [#5-order-by-the-supervisory-authority]

Where the controller has not communicated the breach to the data subjects, the supervisory authority may require it to do so if it considers the risk to be high, or may conversely decide that one of the exceptions under paragraph 3 applies (Article 34(4) GDPR). This is a further reason to give careful reasons for a decision against communication and to document that decision. Where the supervisory authority considers the reasoning insufficient, it may make use of its powers and sanctions.


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.