GDPR and the DPC, for Irish businesses

GDPR

You have had a data breach. What the first 72 hours require

The 72 hours runs from when you became aware, not from when you finished investigating. That is the sentence most people get wrong on the day.

By Oscar CobbeCurrent as at 9 minute read4 sources

What counts as a breach

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. That definition is wider than an attack, and three of the four limbs have nothing to do with anybody malicious.

The Data Protection Commission received 6,521 valid breach notifications in 2025, a 16% decrease on 2024, and reported that almost half of them were caused by correspondence being sent to the wrong recipient.

That number is the useful one to hold. The typical Irish breach is not a hack. It is an email to the wrong address, a document attached in error, or a laptop left somewhere.

When the clock starts

Article 33(1) requires the controller to notify the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of the breach, unless it is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification is later than 72 hours it has to be accompanied by the reasons for the delay.

Awareness is the trigger, and it is a lower bar than certainty. Once you have a reasonable degree of certainty that a security incident occurred that compromised personal data, you are aware. Waiting until the investigation is complete is not an option the Article provides, which is why the DPC accepts an initial notification followed by further information.

The 72 hours is calendar hours. It runs across a weekend.

WhoWhat they oweBy when
Controller to the DPCNotification under Article 33(1)72 hours from awareness, unless no risk
Processor to the controllerNotification under Article 33(2)Without undue delay, no fixed hours
Controller to affected peopleCommunication under Article 34Without undue delay, where high risk
Everyone, internallyThe Article 33(5) recordEvery breach, notifiable or not

The processor has no 72 hours

This is the point that catches suppliers and the businesses that use them. Article 33(2) says the processor shall notify the controller without undue delay after becoming aware of a personal data breach. There is no 72 hour figure in it.

That is stricter rather than looser. The controller's clock is running from its own awareness, so a processor that takes three days to pass the news on has consumed the controller's entire window. Which is why the processor agreement should set a shorter, specific period, in hours, rather than repeating the Regulation's wording back at itself.

If you are the supplier, the same applies to you in reverse. If you host or run something for a client, work out now who you ring and how fast.

What to do in the first hour

In this order, and the order matters, because the two most common mistakes are notifying before you know anything and investigating before you stop the leak.

  1. 1Stop it. Take the exposed thing down, revoke the access, recall what can be recalled. Containment first, always.
  2. 2Write down the time you became aware and how. That timestamp is the start of the clock and it is the first thing anybody will ask.
  3. 3Establish the scope: what data, how many people, which categories, and whether any of it is special category data or children's data.
  4. 4Preserve the evidence before anybody tidies up. Logs, the email, the file, the versions. A well-meant cleanup destroys the ability to say how many people were affected.
  5. 5Decide on notification against the actual test, which is whether it is likely to result in a risk. If it is not, you do not notify, and you write down why.
  6. 6If you use a processor and the breach is theirs, get their account in writing rather than by phone.

Telling the people affected

Article 34 is the second question and it has a higher threshold: communication to the data subject is required where the breach is likely to result in a high risk to their rights and freedoms.

Article 34(3) provides three exceptions. Where you had applied appropriate technical and organisational protection measures to the data, in particular measures that render it unintelligible, such as encryption. Where you have taken subsequent measures that ensure the high risk is no longer likely to materialise. And where individual communication would involve disproportionate effort, in which case there has to be a public communication or similar measure instead.

The first of those is the practical argument for encrypting what you hold. A stolen encrypted laptop with a key nobody has is a very different conversation from a stolen laptop.

The record you keep even when you do not notify

Article 33(5) requires the controller to document any personal data breach, comprising the facts, its effects and the remedial action taken, and it says the documentation has to enable the supervisory authority to verify compliance with Article 33.

Any breach. Not any notified breach. A minor incident correctly assessed as not notifiable still has to be written down, and the record is what allows you to demonstrate that the assessment happened rather than that nobody noticed.

This is the duty most likely to be missing when a regulator eventually looks, and it is the cheapest of all of them to satisfy. A single log with the date, what happened, what data, how many people, the risk assessment and the decision is the whole artefact.

The incident is what starts the investigation. The paperwork is what the finding is about.

The clearest Irish illustration is the Data Protection Commission's inquiry into a small credit union, where a website plugin exposed member data. The security failure was one finding. The others were an incomplete record of processing and a processor arrangement that did not meet Article 28, neither of which had anything to do with the plugin.

How to notify

The DPC takes breach notifications through its own breach notification form rather than by email, and it says that all notifications must use it. An incomplete notification filed within the window and supplemented afterwards is the intended pattern.

What it asks for follows Article 33(3): the nature of the breach including the categories and approximate number of data subjects and records, the contact point for more information, the likely consequences, and the measures taken or proposed.

Approximate is the word to hold onto. An estimate given on time is worth more than a precise figure given late.

What to do before it happens

Everything above is faster if three things exist already, and none of them takes a week to produce.

A named person who makes the notification decision, with a deputy, because breaches are discovered on Fridays. The list of what personal data you hold and where it lives, which is the Article 30 record and is the thing that makes scoping a breach a twenty minute job rather than a two day one. And a processor agreement with a notification period in hours rather than a repetition of the Regulation.

There is a fourth, and it is the one people skip: read the plan once before you need it. We publish our own breach response plan, including what happens in the first hour and when the 72 hours starts, because a plan nobody outside the company can read is a plan nobody has audited.

Sources

  1. 1.Breach notification, and the notification form · Data Protection Commission
  2. 2.DPC publishes 2025 Annual Report · Data Protection Commission
  3. 3.Regulation (EU) 2016/679, Articles 33 and 34 · EUR-Lex, Publications Office of the European Union
  4. 4.Inquiry into Slane Credit Union, IN-19-7-5 · Data Protection Commission

Free, and the answers stay in your browser

The assessment that should have happened first

A lot of breaches happen in processing that was never assessed. The free check runs the Irish list against what you do and says whether an assessment was mandatory before you started.

Run the free check

If you are in one right now

Ring us. If you are not, the compliance retainer is the version of this that exists before it is needed: the record of what you hold, the processor agreements with real notification periods, and a plan with names in it.

Compliance retainer

Who wrote this

Oscar Cobbe · Founder, FourWinds Digital

Writes and maintains the legal explainers on this site, and does the compliance work behind them. Every date and article number here is checked against the instrument itself before it is published, and corrected in place when the law moves.

More about how we work →

Read next

More on GDPR and the DPC, for Irish businesses

Written on 31 August 2026 and accurate as at that date. This is general information about how the rules work, not legal advice on your situation. We are not solicitors and we say so when you need one.