EU/GDPR Breach Response Checklist

A structured 72-hour checklist for GDPR-regulated organisations. Work through it on screen during an incident, or print it empty for your incident response binder. Based on GDPR Articles 33 and 34, EDPB Guidelines on breach notification, and operational best practice.

Last updated: April 2026 Jurisdiction: EU / EEA / GDPR See also: US Checklist
0 of 32 tasks completed 0%

First 4 Hours: Containment and Triage

Phase 1 Hour 0–4: Containment & Triage
Art. 33(5): “The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken.”

Hours 4–24: Scope and Assessment

Phase 2 Hour 4–24: Scope & Assessment

Hours 24–48: Art. 33 Notification Preparation

Phase 3 Hour 24–48: Notification Preparation

Hours 48–72: Execute DPA and Individual Notifications

Phase 4 Hour 48–72: Execute Notifications

Post-72 Hours: Remediation and Review

Phase 5 Post-72 Hours: Remediation & Review
Incident Notes

This checklist is for informational purposes only and does not constitute legal advice. Consult qualified legal counsel for your specific situation. Your checklist data is stored locally in your browser and is never transmitted to our servers.

US Breach Response Checklist →