The glossary to understand and take action

Notification of a personal data breach

A data breach may affect the confidentiality, integrity or availability of data. The controller must assess the incident and the notification obligations provided for by the GDPR.

Understand the scope

What is this process for?

The CNPD states that notification must be made within 72 hours of becoming aware of the breach where it is likely to result in a risk to rights and freedoms. Informing data subjects is subject to its own conditions.

In your file

How to prepare the process

Quickly identify the data, individuals and systems concerned, the possible consequences and the measures taken. Document the analysis even when notification is not required. The service provider must report the information in accordance with its obligations to enable this assessment. Waiting to know every detail may compromise compliance with the timetable: follow the official notification instructions.

A scenario to help you understand

Educational example

A company discovers that customer data has been sent to the wrong recipient. It contains the incident, assesses the risk and documents the notification decision.

Fictitious situation, presented to illustrate the concept.

Prepare for what comes next

Points to check

  • Établir les faits et la chronologie
  • Évaluer le risque pour les personnes
  • Suivre notification et mesures correctrices

Connecting concepts

Terms to know as well

Continue with the concepts, contacts and procedures related to this topic.

Put it into practice

Explore further with our guides

Sources and verification

References consulted on 20 September 2026. Official procedures specify the applicable conditions and exceptions.

This guide explains a general process. The applicable rules depend on your situation; it does not constitute personalised advice. Report a correction.

A definition gives you a reference point. To examine your situation, clarify your question with a professional.