GDPR (security & breach)

← All instruments
in forceadjacent
Type
regulation
Layer
adjacent
Status
in force
In force
2018-05-25
Last verified
2026-07-16

GDPR — the cybersecurity you already had

The General Data Protection Regulation (EU) 2016/679 is a data-protection law, but it carries the EU’s most established security and breach-notification duties, and almost every organisation is subject to it. It is the piece most likely to overlap with a cyber incident.

The cybersecurity-relevant articles

Article 32 — security of processing

Controllers and processors must implement appropriate technical and organisational measures proportionate to risk — explicitly citing pseudonymisation and encryption; ongoing confidentiality, integrity, availability and resilience; the ability to restore availability after an incident; and a process to regularly test and evaluate the measures. This is the general-purpose “be secure” obligation that predates NIS2.

Article 33 — breach notification to the authority

A personal data breach must be notified to the competent Data Protection Authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals. Content: nature of the breach, categories/numbers affected, likely consequences, measures taken.

Article 34 — communication to individuals

Where a breach is likely to result in a high risk to individuals, they must be informed without undue delay (with defined exceptions, e.g. data was encrypted).

Penalties

Two tiers: up to €10M or 2% of worldwide turnover (e.g. Art. 32 security failures), and up to €20M or 4% (e.g. breaches of core principles/rights). The 4% tier is the highest in EU cyber-adjacent law.

Why it matters for cyber compliance

A single incident hitting personal data triggers both GDPR and (if you are a regulated entity) NIS2 or DORA — different authorities, timelines and tests. Build the runbook to fire both workflows from the moment of awareness. See 00-overview/04-how-laws-interact.md.

What’s changing

The Digital Omnibus (Nov 2025) proposes to route GDPR breach notification through the Single Entry Point, extend the deadline from 72h to 96h, and align the threshold to “high risk” — plus a clarified definition of personal data. These are proposals in trilogue. ⚠️ VERIFY final form.

Sources