EU/GDPR Breach Response Checklist
A structured 72-hour checklist for GDPR-regulated organisations. Work through it on screen during an incident, or print it empty for your incident response binder. Based on GDPR Articles 33 and 34, EDPB Guidelines on breach notification, and operational best practice.
First 4 Hours: Containment and Triage
Phase 1
Hour 0–4: Containment & Triage
Art. 33(5): “The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken.”
Hours 4–24: Scope and Assessment
Phase 2
Hour 4–24: Scope & Assessment
Hours 24–48: Art. 33 Notification Preparation
Phase 3
Hour 24–48: Notification Preparation
Hours 48–72: Execute DPA and Individual Notifications
Phase 4
Hour 48–72: Execute Notifications
Post-72 Hours: Remediation and Review
Phase 5
Post-72 Hours: Remediation & Review
Incident Notes
Key Legal References
Key Legal References
- GDPR Article 33 — Notification of a personal data breach to the supervisory authority (72-hour deadline)
- GDPR Article 34 — Communication of a personal data breach to the data subject (high-risk threshold)
- EDPB Guidelines 9/2022 — Personal data breach notification under Regulation 2016/679
- AP (Netherlands) — Data breach notification portal
- Article source — Corporate Breach Response Checklist: The First 72 Hours
This checklist is for informational purposes only and does not constitute legal advice. Consult qualified legal counsel for your specific situation. Your checklist data is stored locally in your browser and is never transmitted to our servers.
US Breach Response Checklist →