Skip to main content →
Search Client access
Free tool · Compliance

Data breach: do I have to notify the AEPD within 72 hours?

If you have just discovered a breach, the clock is already ticking: the 72 hours of Article 33 GDPR run from the moment you become aware of it, not from when it happened. This simulator guides you in 2 minutes through the three duties: always document, notify the AEPD — the Spanish Data Protection Authority — unless the risk is unlikely, and inform those affected only if the risk is high.

Free, no sign-up Instant result Your answers never leave your browser
Quick answer

The three duties after a breach, in one table.

ObligationWhen?DeadlineLegal basis
Document internallyAlways — every breach, notified or notImmediate internal record: facts, effects and remedial measuresArt. 33(5) GDPR
Notify the AEPDUnless risk unlikely — unless the breach is unlikely to result in a risk to individuals≤ 72 hours from becoming aware (if late, together with the reasons for the delay)Art. 33 GDPR
Inform those affectedHigh risk only — with 3 exceptions: unintelligible data (encryption), subsequent measures removing the high risk, or disproportionate effort (Art. 34(3))Without undue delay, in clear and plain languageArt. 34 GDPR

The penalty: breaching Articles 33 and 34 can be fined with up to 10 million euros or 2% of total worldwide annual turnover, whichever is higher (Art. 83(4) GDPR). Verified real case: the AEPD fined Air Europa €100,000 for notifying a breach 41 days after becoming aware of it (decision PS/00179/2020).

The AEPD itself offers two free official tools: Asesora Brecha (should I notify the AEPD?) and Comunica-Brecha RGPD (should I inform those affected?). Sources: GDPR, Arts. 33-34 (EUR-Lex) and the AEPD guide on data breach notification (June 2021, Spanish).

Last verified: 24 July 2026

How it works

Seven questions, no data sent.

01

You answer 7 questions

What happened, whether personal data are involved, whether they were encrypted, which categories and what volume, your role (controller or processor) and your risk assessment. Everything happens in your browser: nothing is sent or stored.

02

We apply the Arts. 33-34 decision tree

The same criteria as the AEPD's guide: always document, notify unless the risk is unlikely, inform those affected only if a high risk is likely and no Art. 34(3) exception applies.

03

You get cumulative verdicts

One verdict per duty, with an unambiguous badge, the 72-hour clock explained and, if you must notify, the checklist of the minimum content under Art. 33(3). Printable for your internal record.

Question 1 1 / 7

What exactly has happened?

The AEPD's guide classifies breaches into three types: confidentiality, integrity and availability. Ransomware or lost documentation also count (availability).

Are personal data affected?

If the incident does not affect personal data, it is not a personal data breach and Articles 33 and 34 GDPR do not apply (although the ENS or the NIS regime may).

Were the data unintelligible to third parties?

Robust encryption with the keys safe is the typical exception under Article 34(3)(a): it makes communication to those affected unnecessary and reduces the risk.

What is the most sensitive category of data affected?

Special categories under Article 9 (health, ideology, sexual orientation, biometrics…), criminal convictions and vulnerable groups raise the risk according to the AEPD's guide.

Approximately how many people are affected?

Volume (number of individuals and records affected) is one of the risk criteria in the AEPD's guide. If you don't know, estimate upwards.

Do you act as controller or as processor?

The controller decides the purposes and means; the processor processes the data on the controller's behalf (an accounting firm handling the data of its client's customers, a SaaS provider…).

All things considered: what risk does it pose to those affected?

The risk level, according to the AEPD's guide, combines the severity of the consequences and the likelihood that they materialise: breach type, categories, volume, vulnerable groups and ease of identification.

Indicative result

This is what you need to do, duty by duty

Legal notice: this result is indicative and generated automatically from your answers; it is not legal advice and does not replace the risk assessment that falls to the controller. If you have a real breach on your hands, act now: document it, use the AEPD's official tools and don't let the 72-hour clock run out. For any question with legal implications, check the official source or book a session with me.
Got a breach right now? Urgent free session →
The rules, made clear

Three duties and one 72-hour clock.

Articles, penalties and decisions last verified: 24 July 2026 (official sources at the end).

A personal data breach is any security incident that compromises the data of natural persons. The AEPD's guide (June 2021 version) classifies them into three types: confidentiality (someone unauthorised accesses the data: a hack, an email sent to the wrong recipient), integrity (the data are altered) and availability (the data become inaccessible: ransomware or lost documentation count as a breach, even if nothing was taken). If your company processes personal data — that is, practically always, as the cybersecurity and GDPR vertical guide explains —, the GDPR imposes three distinct duties on you after a breach, each with a different threshold.

Duty 1 · Document. Always (Art. 33(5))

Every breach is documented internally, whether notified or not: the facts, its effects and the remedial measures taken, in a way that allows the supervisory authority to verify compliance. It is the duty most often forgotten and the cheapest to fulfil. Failing to document is, in itself, a minor infringement under Article 74.n of the LOPDGDD, the Spanish data protection act.

Duty 2 · Notify the AEPD within 72 hours (Art. 33)

The general rule is to notify the supervisory authority "without undue delay and, where feasible, not later than 72 hours after" becoming aware of the breach. Two nuances that change real cases: the clock runs from awareness, not from when the breach occurred; and the only exemption is that the breach is unlikely to result in a risk to the rights and freedoms of natural persons — an assessment you must be able to justify. If you notify after 72 hours, the notification must be accompanied by the reasons for the delay.

What if you don't have all the information within 72 hours? Article 33(4) allows notification in phases: the information is provided gradually, without undue further delay. The minimum content is set by Article 33(3): the nature of the breach, with the categories and approximate number of data subjects and records concerned, the contact details of the data protection officer, the likely consequences, and the measures taken or proposed. The notification is submitted electronically, with a recognised electronic certificate, through the breach form of the AEPD's electronic office, which accepts supplementary notifications.

Duty 3 · Inform those affected, only if the risk is high (Art. 34)

Communication to data subjects is only mandatory where the breach is likely to result in a high risk to their rights and freedoms — and then it must be done without undue delay and in clear and plain language, with the DPO's contact details, the likely consequences and the measures taken. Article 34(3) contains three exceptions: (a) the data were unintelligible to third parties, such as encrypted data with the keys safe; (b) the controller has taken subsequent measures ensuring the high risk can no longer materialise; and (c) individual communication would involve a disproportionate effort, in which case it is replaced by an equally effective public communication. Beware: the AEPD can require the communication if it does not accept the exception (Art. 34(4)).

What the AEPD penalises: two real cases

Breaches of Articles 33 or 34 fall under Article 83(4) GDPR: fines of up to 10 million euros or 2% of total worldwide annual turnover, whichever is higher. The fine is neither automatic nor always the maximum — it is graduated under Article 83(2), as the GDPR fine calculator shows —, but the real range is wide: in decision PS/00179/2020, the AEPD fined Air Europa €100,000 under Article 33 (it notified the breach 41 days after becoming aware of it) plus €500,000 for the security measures under Article 32(1). At the other end, PS/00152/2020 ended with a reprimand for Fundación Síndrome 5P– for not notifying within 72 hours: same article, very different penalty.

The Spanish specifics: the LOPDGDD

Organic Law 3/2018 (LOPDGDD) lands the sanctioning regime in Spain: it is a serious infringement (Art. 73) for the processor not to notify the controller of breaches it becomes aware of (73.q), to breach the duty to notify the authority (73.r) or not to inform the data subject when the authority has required it (73.s). Minor infringements (Art. 74) include incomplete, late or defective notification (74.m), failing to document breaches (74.n) and failing to inform the data subject of a high-risk breach where no requirement was issued (74.ñ). And Article 77 marks the big difference for the public sector: public administrations are not fined — the authority issues a decision declaring the infringement, with measures, a possible reprimand, disciplinary proceedings and publicity.

If you are a public entity or your system falls within the scope of the ENS (Spanish National Security Framework), two independent notifications also coexist: the personal data one to the AEPD (Art. 33 GDPR) and the security incident one to CCN-CERT when it has a significant impact (Royal Decree 311/2022, Art. 33.2). You can check your ENS situation with the ENS self-assessment. In the regional public sector, the data protection authority may be the regional one: APDCAT in Catalonia, AVPD in the Basque Country and the Council for Transparency and Data Protection in Andalusia.

The AEPD's official tools

Before deciding blind, use the AEPD's own two free tools, renewed on 10 October 2023: Asesora Brecha, which guides you on whether to notify the authority (Art. 33), and Comunica-Brecha RGPD, which guides you on whether to inform those affected (Art. 34). Both generate a downloadable report with your answers — useful as evidence for the internal documentation required by Article 33(5) — and the AEPD does not store the data you enter. This simulator applies the same criteria in a single pass; for your specific case, those tools and the official guide are the reference.

Frequently asked questions

The doubts of the first 72 hours.

Do all data breaches have to be notified to the AEPD?+

No. Article 33(1) GDPR requires notification unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. What is mandatory in every case is documenting the breach internally (Article 33(5)), whether you notify or not: the AEPD can request that record to verify compliance.

When does the 72-hour clock start?+

From the moment the controller becomes aware of the breach, not from when it happened. If the notification is made after 72 hours, it must still be submitted together with the reasons for the delay (Article 33(1)). Notifying late is punishable: the AEPD fined Air Europa 100,000 euros for notifying a breach 41 days after becoming aware of it (PS/00179/2020).

What if I still don't have all the information after 72 hours?+

The GDPR provides for this: the notification may be made in phases (Article 33(4)), providing the information gradually without undue further delay. The AEPD's notification form accepts an initial notification and subsequent supplementary notifications. Don't wait until you have everything: notify what you know within the deadline and complete it later.

When do I have to inform the affected individuals?+

Only when the breach is likely to result in a high risk to their rights and freedoms (Article 34(1)), without undue delay and in clear and plain language. There are three exceptions (Article 34(3)): the data were unintelligible to third parties — for example, encrypted with the keys safe —, you have taken subsequent measures ensuring the high risk can no longer materialise, or individual communication would involve a disproportionate effort, in which case it is replaced by an equally effective public communication.

What happens if I don't notify a breach?+

Breaching Articles 33 and 34 can be fined with up to 10 million euros or 2% of total worldwide annual turnover, whichever is higher (Article 83(4) GDPR). The fine is neither automatic nor always the maximum: it is graduated under Article 83(2). Outcomes range from reprimands (Fundación Síndrome 5P–, PS/00152/2020) to fines of 100,000 euros for notifying 41 days late (Air Europa, PS/00179/2020).

Does the processor notify the AEPD?+

No, unless mandated by the controller. Article 33(2) GDPR requires the processor to notify the controller without undue delay after becoming aware of a breach; the notification to the AEPD is submitted by the controller. For the processor, failing to inform the controller is a serious infringement under Article 73.q of the LOPDGDD, the Spanish data protection act.

Does ransomware without data theft count as a breach?+

Yes. The AEPD's guide classifies breaches into three types — confidentiality, integrity and availability — and includes ransomware and the loss of documentation as availability breaches. The absence of exfiltration does not exempt you from assessing the risk: unless it is unlikely to affect people's rights, you must notify the AEPD within 72 hours. And document it, always (Article 33(5)).

Got a breach right now?

Don't lose hours deciding blind.

Book a free 30-minute session. We go through your case, what needs notifying and to whom, and how to document it — and if the 72-hour clock is pressing, we prioritise what's urgent.

Book a free session →