Incidents and Breaches

How to recognise an incident, assess the risk to individuals and decide whether to report it, with the deadlines that apply.

Legal status: August 2026

Support during an incident

See also: DPO and GDPR NIS2 and KSC Training and workshops AI Act

A structured response to incidents and breachesThe first hours decide what you are able to demonstrate later. If you want the sequence of steps agreed before anything happens, let us talk about your processes. Explore the service

What should a breach register contain? — LabLogic article graphic by Michał Rutkowski
Incidents and Breaches

What should a personal data breach register contain?

Article 33(5) GDPR requires documentation, not a register in a prescribed form. The documentation has to let the supervisory authority verify compliance with the whole article, which is why the entries that call for the most content are those on breaches the controller did not notify.

What to do after detecting an incident? — LabLogic article graphic by Michał Rutkowski
Incidents and Breaches

What to do after detecting an incident?

First confirm the event and secure the evidence, then limit the effects, and only then qualify the matter legally. Detection starts several independent clocks counted from different moments, which is why the order of actions matters more than speed.

Must every data breach be reported? — LabLogic article graphic by Michał Rutkowski
Incidents and Breaches

Does every data breach need to be reported?

Not every one. Reporting to the UODO is the rule, from which one can only deviate based on a documented risk assessment for data subjects. The 72-hour deadline runs from becoming aware of the breach, and notifying data subjects is a separate decision.

Scroll to Top