GDPR (security & breach)
GDPR — the cybersecurity you already had
The General Data Protection Regulation (EU) 2016/679 is a data-protection law, but it carries the EU’s most established security and breach-notification duties, and almost every organisation is subject to it. It is the piece most likely to overlap with a cyber incident.
The cybersecurity-relevant articles
Article 32 — security of processing
Controllers and processors must implement appropriate technical and organisational measures proportionate to risk — explicitly citing pseudonymisation and encryption; ongoing confidentiality, integrity, availability and resilience; the ability to restore availability after an incident; and a process to regularly test and evaluate the measures. This is the general-purpose “be secure” obligation that predates NIS2.
Article 33 — breach notification to the authority
A personal data breach must be notified to the competent Data Protection Authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals. Content: nature of the breach, categories/numbers affected, likely consequences, measures taken.
Article 34 — communication to individuals
Where a breach is likely to result in a high risk to individuals, they must be informed without undue delay (with defined exceptions, e.g. data was encrypted).
Penalties
Two tiers: up to €10M or 2% of worldwide turnover (e.g. Art. 32 security failures), and up to €20M or 4% (e.g. breaches of core principles/rights). The 4% tier is the highest in EU cyber-adjacent law.
Why it matters for cyber compliance
A single incident hitting personal data triggers both GDPR and (if you are a
regulated entity) NIS2 or DORA — different authorities, timelines and tests. Build the
runbook to fire both workflows from the moment of awareness. See
00-overview/04-how-laws-interact.md.
What’s changing
The Digital Omnibus (Nov 2025) proposes to route GDPR breach notification through the Single Entry Point, extend the deadline from 72h to 96h, and align the threshold to “high risk” — plus a clarified definition of personal data. These are proposals in trilogue. ⚠️ VERIFY final form.
Sources
- Text: https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB guidance on breach notification: https://www.edpb.europa.eu