Skip to main content
GDPRRegulation (EU) 2016/679

Article 33: Notification of a personal data breach to the supervisory authority

GDPR Art. 33, Chapter IV, Section 2

1. In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to

276 words in the official text.

Across the acts

  • NIS2cites this provision

    Where the competent authorities become aware in the course of supervision or enforcement that the infringement by an essential or important entity of the obligations laid down in Articles 21 and 23 of this Directive can entail a personal data breach, as defined in Article 4, point (12), of Regulation (EU) 2016/679 which is to be notified pursuant to Article 33 of that Regulation, they shall, without undue delay, inform the supervisory authorities as referred to in Article 55 or 56 of that Regulation.

Sits inside (2)

Cites (1)

Recitals matched by wording (2)

These recitals name no article. The dataset matched them to this one by text similarity, and they are marked so nobody reads a match as a citation.

Source texts: the Official Journal, through the Publications Office. Dataset built 2026-07-29. Study aid, not legal advice.

GDPR 32016R0679

Every connection on this page is drawn from the official text of Regulation (EU) 2016/679. Study aid, not legal advice.

See how GDPR sits beside the other three acts on the crossover map, or find what your role must do in the obligations checklist.