Insights · Privacy & GDPR

Data breach: what to do in 72 hours

by 8 min read updated on

In common perception, a personal-data breach means a cyber-attack launched by an outsider. The reality is broader and, often, closer to home: an email sent to the wrong recipient, a lost device, the improper access of someone inside the organisation are equally a data breach. When the event occurs, a very narrow window opens for the controller — namely, seventy-two hours — within which decisions governed in detail by Regulation (EU) 2016/679 (GDPR) must be taken. It is therefore worth clarifying what counts as a breach, when and how to notify it to the Garante, in which cases to inform the data subjects, and what consequences follow from inaction.

What a personal-data breach is

Article 4(12) of the Regulation defines a personal-data breach as a breach of security leading — accidentally or unlawfully — to the destruction, loss, alteration, unauthorised disclosure of, or access to, personal data processed. Three aspects, then, may be affected: confidentiality (improper disclosure or unauthorised access), integrity (alteration of the data) and availability (loss or destruction, even temporary).

It follows that the notion covers a wide range of heterogeneous events: the ransomware attack that encrypts the archives and bars access; the loss of an unencrypted laptop; sending a message to a list of recipients left in the clear; credential theft; even the conduct of an employee who consults company databases for purposes unrelated to their duties. It does not matter whether the event is intentional or merely negligent: what matters is the effect produced on the data.

Notifying the Garante: the 72-hour deadline

Once a breach has occurred, Article 33 requires the controller to notify it to the supervisory authority — in Italy, the Garante for the protection of personal data — «without undue delay and, where feasible, not later than 72 hours after having become aware of it». The deadline runs not from the event itself, but from the moment the controller acquires a reasonable degree of certainty that it has occurred.

The obligation has a single exception: notification is not required where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. This is, however, an assessment to be carried out rigorously and of which a record must be kept: the exemption presupposes a reasoned, prognostic judgment, not a convenient self-absolution.

The notification must carry a minimum content (Article 33(3)):

  • the description of the nature of the breach;
  • the categories and approximate number of data subjects and of records concerned;
  • the contact details of the reference point (the DPO or another point of contact);
  • the likely consequences of the breach;
  • the measures taken or proposed to remedy it and mitigate its effects.

Where this information is not immediately available, notification in successive phases is permitted. Finally, where notification is made beyond seventy-two hours, it must be accompanied by the reasons for the delay: exceeding the deadline does not exempt, but must at least be justified.

As to how, the notification is submitted exclusively through the online procedure made available on the Garante’s services portal (decision no. 209 of 27 May 2021; servizi.gpdp.it/databreach).

It should be added that, if the breach occurs at a processor — for example an IT service provider — the latter must inform the controller without undue delay, the burden of notifying the Garante then falling on the controller.

When the data subject must also be informed

Distinct from notification to the Garante is communication to the person to whom the data relate. Article 34 requires it when the breach is likely to result in a high risk to the rights and freedoms of the data subject: in that case the controller must inform them without undue delay, in clear and plain language, so that they can take the appropriate precautions — change their credentials, monitor their account, and the like.

Communication is not required in three exhaustive cases (Article 34(3)):

  • where the controller had put in place measures rendering the data unintelligible to third parties — notably encryption;
  • where it has taken, after the fact, measures ensuring that the high risk is no longer likely to materialise;
  • where individual communication would involve a disproportionate effort, in which case a public communication of equivalent effectiveness is used.

Even in these cases, however, the Garante retains the power to order communication nonetheless, where it finds the conditions are met.

The duty to document every breach

There is one obligation too often neglected: under Article 33(5), the controller must document any personal-data breach — including those that, following the risk assessment, it has decided not to notify. The documentation must set out the circumstances, the effects and the measures adopted, so as to enable the Authority to verify compliance with the rule.

It is, in essence, an internal breach register, complementary to the record of processing activities and likewise an expression of the accountability principle. The decision not to notify a breach, in particular, must not be left to word of mouth: it must be set down in a document explaining the reasons. Failing that, in an inspection the controller will be unable to demonstrate that the assessment was made correctly.

What to do in the first hours: a procedure

The tightness of the deadline counsels against improvisation. The organisation should equip itself, in advance, with an incident-management procedure that sets out a few essential steps:

  • Contain. Halt the spread of the event and limit its effects: revoke an access, isolate a system, recall a communication.
  • Assess. Estimate the nature of the data involved, the number of data subjects and the level of risk, in order to decide whether the breach must be notified to the Garante and whether it must be communicated to the data subjects.
  • Document. Record the event promptly in the breach register, together with the decisions taken.
  • Notify and communicate. Where due, send the notification to the Garante within seventy-two hours and, where there is a high risk, inform the data subjects.
  • Remediate. Adopt the corrective measures needed to prevent a recurrence.

Timeliness is no formality: every hour that passes widens the circle of affected data subjects and aggravates the controller’s position.

What the case law says

In terms of penalties, failure to comply with the notification and communication obligations falls within the band of Article 83(4)(a) of the Regulation: up to 10 million euros or, for undertakings, up to 2% of total worldwide annual turnover, whichever is higher. That such rigour is no abstraction is confirmed by a decision of particular significance.

By decision of 26 March 2026 (doc. web no. 10234984) the Garante imposed on Intesa Sanpaolo S.p.A. a fine of 31.8 million euros. The case arose from a breach — notified by the bank in July 2024 — consisting in the unauthorised access, by an employee, to the banking data of 3,573 customers, with more than 6,600 consultations, lasting from February 2022 to April 2024: that is, for over two years before it was detected.

The Garante censured, first, the overall inadequacy of the security measures (Article 32): the operating model allowed staff to query the entire customer base without controls capable of preventing and detecting unjustified access. But — what matters most here — the Authority also condemned the handling of the breach: the notification proved «incomplete and late», and communication to the data subjects came only after an earlier order of the Garante of 2 November 2024. The case plainly illustrates a twofold lesson: that breaches often come from within, and not only from outside; and that lateness and incompleteness of the information obligations are not mere formal irregularities, but materially aggravate the controller’s liability.

The discipline of the data breach rewards those who prepare in time. Setting up a response procedure, training staff and carefully keeping the breach register make it possible to face the incident with composure, precisely in the hours when every decision must be taken quickly. It is the same approach that governs the other privacy obligations — from the website privacy policy to the record of processing activities — and which lies at the heart of GDPR compliance for businesses and professionals.

Frequently asked questions

Are the 72 hours business days? No: they are calendar hours and include Saturdays, Sundays and public holidays. Hence the value of a response procedure active outside office hours too.

Is an email sent to the wrong recipient a data breach? Yes: it amounts to an unauthorised disclosure. The risk must be assessed and, if high, the breach must also be communicated to the data subjects.

Must the data subject always be informed of a breach? No: communication to the data subject (Article 34) is required only where the breach presents a high risk; otherwise, notification to the Garante, where due, is sufficient.

This article is for informational purposes and reflects the rules in force as at the date of publication; it does not replace an assessment of the specific case.

This article is for general information only and is not legal advice on any specific case. Content reviewed by Giuseppe Foti, legal consultant — last checked on July 15, 2026.

← All insights

Contact

Your case isn’t a textbook case?

The articles frame problems in general terms: your situation needs an opinion tailored to it.

First reply within one business day. The first contact is free and carries no obligation.