GDPR
Chapter IV - Controller and Processor

GDPR GDPR-Art.33: Notification of a personal data breach to the supervisory authority

On becoming aware of a personal data breach, notify it to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; a notification made later than 72 hours must be accompanied by the reasons for the delay. A processor must notify its controller without undue delay after becoming aware of a breach. The notification must at least describe the nature of the breach including, where possible, the categories and approximate number of data subjects and of personal data records concerned, give the name and contact details of the data protection officer or other contact point, describe the likely consequences, and describe the measures taken or proposed including any measures to mitigate adverse effects. Information may be provided in phases where it cannot all be given at once. Document every personal data breach, including the facts, its effects and the remedial action taken, so the supervisory authority can verify compliance with this Article.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 89 controls across 49 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

C5 (Germany) · 4 controls

  • C5-OPS-21 Involvement of Cloud Customers in the Event of Incidents
  • C5-SIM-01 Policy for security incident management
  • C5-SIM-02 Processing of security incidents
  • C5-SIM-03 Documentation and reporting of security incidents

FedRAMP High · 4 controls

  • IR-4 Incident Handling
  • IR-5 Incident Monitoring
  • IR-6 Incident Reporting
  • IR-8 Incident Response Plan

FedRAMP Moderate · 4 controls

  • IR-4 Incident Handling
  • IR-5 Incident Monitoring
  • IR-6 Incident Reporting
  • IR-8 Incident Response Plan

ISO 27001:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.5 Contact with authorities

ISO 27002:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.5 Contact with authorities

NIS2 Directive · 4 controls

  • Art.21.2.b Incident handling
  • Art.23.1 Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients
  • Art.23.4.b Submit an incident notification within 72 hours, with an initial assessment and indicators of compromise
  • Art.23.4.d Submit a final report within one month, and a progress report where the incident is still running
  • NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident
  • NIST-CSF-RS.AN-06 Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents

SOC 2 · 4 controls

  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches
  • SOC2-P6.5 P6.5 Vendor commitments to report unauthorised disclosures
  • SOC2-P6.6 P6.6 Notifying breaches and incidents
  • TRINIDAD-1 Scope, Definitions, Commission
  • TRINIDAD-4 Security, Accuracy
  • TRINIDAD-5 Enforcement and Sanctions

Canadian PIPEDA · 2 controls

DORA · 2 controls

ISO 27701:2019 · 2 controls

  • 6.13.1 Management of information security incidents and improvements
  • 8.2.1 Customer agreement

NIST SP 800-53 Rev 5 · 2 controls

  • SWE-11 Integritetsskyddsmyndigheten (IMY)
  • SWE-12 Investigatory Powers
  • PMF-M.4 Privacy Incident Management
  • CBPR-PR-32 Detection, prevention and response measures

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person

Bahrain PDPL · 1 control

  • SD134-17 Incident Notification
  • CAYDPA-s16 Personal Data Breach Notification (s.16)
  • CSL-Art42 Personal Information Protection and Breach Handling - Art. 42
  • PIPL-Art57 Breach Remediation and Notification
  • IS.D.OR.225 External Reporting of Information Security Events

EU AI Act · 1 control

  • EGY-PDPL-Art.7 Personal data infringement (breach) notification
  • UAE-PDPL-Art.9 Data breach notification (UAE PDPL Article 9)
  • s65 s 65 Notify the Federal Commissioner of breaches within 72 hours and document all breaches
  • Art. 2-quaterdecies.1 Art. 2-quaterdecies.1 Microenterprises: notify breaches through the Garante's simplified procedure
  • NDB Notifiable Data Breaches scheme
  • OCCHS-1 Scope, Applicability, and Definitions of Heightened Standards

Privacy Act 2020 · 1 control

  • NZPRV-7 Notifiable Privacy Breach Scheme
  • RO-LAW190-014 Personal Data Breach Notification
  • CIA-BRC-09 Breach notification to data subjects and FSC
  • TANZANIA-1 Scope, Registration, Lawful Basis
  • UKGDPRREG-3 Controller and Processor (Articles 24-43)
  • UZB-DPL-16 Incident Notification
  • ZDPA-08 Personal Information Breach Notification

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter IV - Controller and Processor

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.33 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 89 it maps to, and the evidence behind each claim, over MCP and REST.