← All posts

GDPR Data Breach Response: What to Do in the First 72 Hours

When a personal data breach occurs, GDPR starts a 72-hour clock. Article 33 requires you to notify the Data Protection Commission within that window — unless the breach is unlikely to result in a risk to individuals.

Most Irish SMEs have no structured process for responding to a data breach. This guide explains what counts as a notifiable breach, what your notification to the DPC must contain, when you also need to notify affected individuals, and how to manage the first three days.

What Is a Personal Data Breach?

A personal data breach is any security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

This is broader than most people assume. It includes: - Ransomware encrypting systems that hold personal data (even if no data was exfiltrated) - An email sent to the wrong recipient containing personal data - A lost or stolen device that held unencrypted personal data - An employee accessing records they had no legitimate reason to access - A third-party supplier experiencing a breach that affects data you shared with them - Accidental deletion of personal data without available backup

Not every breach requires notification to the DPC. The trigger is whether the breach is likely to result in a risk to the rights and freedoms of individuals. If it isn't — you still must document it internally, but do not need to notify the DPC.

Assessing Whether to Notify the DPC

The risk assessment considers: - The nature, sensitivity, and volume of the data affected - How many individuals are affected - The likely consequences — financial harm, identity theft, discrimination, reputational damage, physical risk - Whether the data was encrypted or otherwise inaccessible to the unauthorised party

When in doubt, notify. A failure to notify a breach that should have been reported is a breach of Article 33 in its own right. The DPC's position is generally that over-reporting is preferable to under-reporting.

What Your DPC Notification Must Contain

Article 33(3) specifies the required content:

1. Nature of the breach What type of breach occurred, which categories of personal data are affected, how many individuals are affected (approximately), and which categories of data subjects are affected.

2. Contact details Name and contact details of the Data Protection Officer or other contact point who can provide further information.

3. Likely consequences A description of the likely consequences of the breach for affected individuals.

4. Measures taken or proposed Steps already taken or planned to address the breach and mitigate its effects, including where appropriate measures to mitigate any possible adverse effects.

Where all required information is not available within 72 hours, the notification may be made in phases — the initial notification covers what you know, with supplementary information provided as the investigation progresses. Document the reason for any delay.

When Must You Also Notify Affected Individuals?

Article 34 requires direct notification to affected individuals where the breach is likely to result in a high risk — a higher threshold than the DPC notification trigger.

High risk indicators include: financial data (account numbers, payment card information), identity documents, health or biometric data, data enabling identity theft, or situations where the volume and sensitivity of data makes significant harm likely.

Notification to individuals must: - Be in clear, plain language - Describe the nature of the breach - Include the DPO or contact point details - Describe likely consequences - Describe measures taken or proposed, including steps individuals can take to protect themselves

The DPC may direct you to notify individuals even where you have assessed this as unnecessary. Comply promptly with any such direction.

Managing the First 72 Hours: A Practical Structure

Hour 0–4: Contain and assess Stop the ongoing breach where possible. Preserve evidence. Identify what data was affected, how many individuals, and how. Convene your incident response team.

Hour 4–24: Assess notification obligation Work through the risk assessment above. Make the decision on whether to notify the DPC. If in doubt, notify.

Hour 24–48: Prepare the notification Complete the DPC notification using the online reporting portal (dataprotection.ie). If the investigation is incomplete, submit what you know and note that supplementary information will follow.

Hour 48–72: Notify the DPC (if not already done) Submit the notification before the 72-hour deadline expires. If the deadline will not be met for legitimate reasons, document why and provide that context in the notification.

Post-notification: Manage consequences Assess whether individual notification is required. Engage affected individuals if so. Continue investigating root cause. Document the full incident and response for your breach register (Article 33(5) requires all breaches to be recorded internally regardless of whether they are notified).

How ShieldIQ Supports Breach Response

ShieldIQ's incident management module includes GDPR-specific breach response workflows with the 72-hour timeline automatically tracked from the moment an incident is logged. The AI drafts the DPC notification based on your incident record. All breach documentation is stored in a tamper-evident log that satisfies the Article 33(5) internal record-keeping requirement.

Run a free GDPR assessment to see your breach response posture →