{"id":3912,"date":"2026-06-25T09:40:00","date_gmt":"2026-06-25T07:40:00","guid":{"rendered":"https:\/\/www.lablogic.pl\/does-every-data-breach-need-to-be-reported\/"},"modified":"2026-10-03T00:36:45","modified_gmt":"2026-10-02T22:36:45","slug":"does-every-data-breach-need-to-be-reported","status":"publish","type":"post","link":"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/","title":{"rendered":"Does every data breach need to be reported?"},"content":{"rendered":"\n<p class=\"ll-art-meta wp-block-paragraph\"><a href=\"https:\/\/www.lablogic.pl\/en\/michal-rutkowski\/\"><strong>Micha\u0142 Rutkowski<\/strong><\/a> \u2022 for DPOs and process owners \u2022 published June 25, 2026 \u2022 updated October 3, 2026 \u2022 8 min read<\/p>\n\n\n\n<div class=\"wp-block-columns ll-art-shell is-layout-flex wp-container-core-columns-is-layout-7387b849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column ll-art-rail is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-railinner is-layout-constrained wp-block-group-is-layout-constrained\">\n\n\n\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column ll-art-main is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-answer is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 id=\"krotka-odpowiedz\" class=\"wp-block-heading\">Brief Answer<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Not every one. Reporting to the President of UODO is the rule \u2014 an organization can only deviate from it if its assessment indicates that the breach is unlikely to result in a risk to the rights or freedoms of natural persons. The report must be made without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach \u2014 not after its occurrence. The standard is \u201cwithout undue delay\u201d; 72 hours is a limit, not a period to be used up. Notifying the data subjects is a separate decision and only arises in cases of high risk. However, every breach, even those not reported by the organization, must be documented.    <\/p>\n<\/div>\n\n\n\n<h2 id=\"dlaczego\" class=\"wp-block-heading\">Why this question arises at all<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The doubt has two sources, both organizational, not legal.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">First, not every security incident is a personal data breach. A blocked login or a detected and repelled phishing attempt is not a breach where it did not compromise the confidentiality, integrity or availability of personal data. A server outage, by contrast, has to be assessed for any loss of availability of personal data, including a temporary one. A breach is an incident that led to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data. Until an organization resolves this qualification, discussion about reporting is premature.   <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Second, some organizations adopt the principle of \u201cwe report everything, just in case.\u201d This appears to be a cautious approach, but in practice, it weakens the controller&#8217;s position. A report is a statement about the outcome of a risk assessment \u2014 if an organization reports without this assessment, it shows the authority that it did not conduct one. The same mechanism works in reverse. A lack of reporting without documented analysis is equally difficult to defend.   <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Added to this is the mechanics of the deadline. Seventy-two hours are counted from the controller becoming aware of the breach, not from the moment the incident occurred. In large organizations, most of this time is usually consumed by the information flow. It runs from the employee, through the supervisor and IT department, to the data protection officer. The decision is made at the end of this path, and only then is it clear how much time realistically remains.   <\/p>\n\n\n\n<div class=\"wp-block-group ll-art-note is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\">It is also worth noting that the reporting threshold itself is subject to legislative work. The European Commission&#8217;s proposal from the Digital Omnibus package envisages raising the reporting threshold to high risk, extending the deadline to 96 hours, and establishing a common point for receiving reports. This is a project at the stage of work in the European Parliament and the Council \u2014 until the changes are adopted and enter into force, the existing rules apply, and current breaches should be assessed according to them.  <\/p>\n<\/div>\n\n\n\n<h2 id=\"co-ustalic\" class=\"wp-block-heading\">What needs to be determined before making a decision<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Whether the incident is a personal data breach<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Qualification covers three dimensions. These are confidentiality (data reached an unauthorized person), integrity (data was altered unlawfully or accidentally), and availability (data was lost or access to it is impossible). Loss of availability is sometimes overlooked, although it is a breach just like a leak \u2014 an organization that restored data from a backup after a ransomware attack still deals with a breach if it could not perform processing for some time. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This determination only answers the question of \u201cwhether GDPR is even applicable.\u201d It does not yet prejudge anything about reporting. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">When the organization became aware of the breach<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The 72-hour deadline runs from becoming aware of the breach, that is from the moment the controller has a reasonable degree of certainty that an incident has led to personal data being compromised. How to count this deadline at weekends, during the preliminary investigation and when information comes from a processor is described in <a href=\"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/\">How to count the 72 hours for notifying a personal data breach?<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What risk arises for data subjects, not for the organization<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This is the point where perspectives most often diverge. The assessment concerns the consequences for data subjects \u2014 identity theft, financial fraud, disclosure of highly sensitive information, discrimination, financial loss, damage to reputation. The controller&#8217;s reputational risk is not part of this analysis.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The assessment combines two dimensions. These are the likelihood of the consequence occurring and the severity of its impact on the rights or freedoms of the individual. In its judgment of October 1, 2025 (III OSK 1830\/22), the Supreme Administrative Court indicated that determining that the probability is not low, combined with a high severity of potential impact, determines the possibility of high risk, and the obligation to notify does not require that the individual&#8217;s rights have already been actually violated. The Court also confirmed that the disclosure of a PESEL number along with a name and surname creates a high risk. For practical purposes, this means one thing. The argument \u201cnothing happened, no one used this data\u201d is not a premise for assessment.     <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The analysis is structured by EDPB guidelines containing eighteen example cases \u2014 ransomware, data exfiltration, internal risk, lost devices, incorrect correspondence dispatch, social engineering \u2014 along with an indication of when the obligation to report and notify arises in each of them. The guidelines are not a source of law but define supervisory practice and are a good reference point for building one&#8217;s own assessment criteria. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Is the risk high \u2014 i.e., the second, separate decision<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Reporting to the authority and notifying data subjects are two different obligations with different thresholds. Reporting to the UODO is only waived when the breach is unlikely to result in a risk to the rights or freedoms of natural persons. Notifying data subjects arises in the opposite scenario \u2014 only when the risk is high \u2014 and must occur without undue delay, without a rigid hourly deadline.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The GDPR provides for three situations where notifying data subjects is not required despite high risk. These are when the controller had implemented protection measures rendering the data unintelligible to unauthorized persons beforehand and applied them to the data affected by the breach, when the controller implemented measures after the breach to eliminate the likelihood of high risk, and when individual notification would require disproportionate effort \u2014 in which case a public communication is appropriate. Invoking the first of these exceptions requires demonstrating that the security measure was effective at the time of the breach; a declaration that \u201cthe data was encrypted\u201d without specifying the scope and method of key management does not close the case. The decision to rely on an exception is not the controller&#8217;s alone. The supervisory authority may require the data subjects to be notified or may decide that a condition waiving notification has been met (Article 34(4) GDPR). <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Which authority and what parallel obligations apply<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For cross-border processing, it is necessary to determine whether the President of UODO is the lead authority or if the authority of another country is competent. A controller without an organizational unit in the Union, but subject to the GDPR, does not benefit from the comprehensive cooperation mechanism \u2014 according to EDPB Guidelines 9\/2022, they must report the breach to the supervisory authorities of all countries where affected individuals reside. The appointment of an EU representative does not change this.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Regardless of the GDPR, the same incident may trigger other regimes. These are obligations towards CSIRT for entities covered by the National Cybersecurity System Act, sectoral obligations arising from DORA, the Polish Electronic Communications Law, or the eIDAS regulation. The deadlines and thresholds in these are different and do not replace each other. Organizations that are just setting up this area usually start by determining the scope of obligations within the framework of <a href=\"https:\/\/www.lablogic.pl\/en\/nis2-ksc\/\">preparation for NIS2 and KSC<\/a>, and only then combine the reporting paths into a single procedure.  <\/p>\n\n\n\n<h2 id=\"rozstrzygniecia\" class=\"wp-block-heading\">Four typical resolutions<\/h2>\n\n\n\n<figure class=\"wp-block-table ll-art-table\"><table><thead><tr><th>Situation<\/th><th>Report to UODO<\/th><th>Notify data subjects<\/th><th>What remains in the documentation<\/th><\/tr><\/thead><tbody><tr><td>Security incident with no impact on personal data<\/td><td>No<\/td><td>No<\/td><td>Register of security incidents; justification of qualification if the signal concerned data<\/td><\/tr><tr><td>Breach where a risk to data subjects is unlikely to arise<\/td><td>No<\/td><td>No<\/td><td>Entry in the breach register along with risk assessment and basis for the decision not to report<\/td><\/tr><tr><td>Breach with risk that is not high<\/td><td>Yes \u2014 without undue delay, no later than 72 hours from becoming aware<\/td><td>No<\/td><td>Entry in the register, report, correspondence with the authority, remedial actions<\/td><\/tr><tr><td>Breach with high risk<\/td><td>Yes \u2014 without undue delay, no later than 72 hours from becoming aware<\/td><td>Yes, without undue delay \u2014 unless one of the exceptions applies<\/td><td>Entry in the register, report, content and method of notification or justification for the exception<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The table organizes typical scenarios but does not replace an assessment. The same type of incident \u2014 for example, sending correspondence to the wrong recipient \u2014 falls into different rows depending on what data the attachment contained and who received it. <\/p>\n\n\n\n<h2 id=\"bledy\" class=\"wp-block-heading\">Most common mistakes<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n<li><strong>Counting the deadline from the incident instead of from becoming aware.<\/strong> Leads either to unnecessary haste or \u2014 more often \u2014 to the belief that the deadline has already passed, and to giving up on reporting.<\/li>\n\n\n\n<li><strong>Treating 72 hours as a deadline to resolve the matter.<\/strong> The GDPR allows for an initial report and subsequent supplementation of information, but the report must contain at least the nature of the breach together with the categories and approximate number of data subjects and personal data records concerned, the contact details of the data protection officer or another contact point, the likely consequences of the breach, and the measures taken or proposed to address it (Article 33(3) GDPR); reporting after the deadline requires an explanation for the delay. Waiting for complete findings is riskier than an incomplete report. <\/li>\n\n\n\n<li><strong>Risk assessment from the organization&#8217;s perspective.<\/strong> The question is what threatens individuals, not how the incident appears from the outside.<\/li>\n\n\n\n<li><strong>Overlooking availability breaches.<\/strong> Data loss and lack of access to it are breaches even if no unauthorized person saw the data.<\/li>\n\n\n\n<li><strong>Lack of documentation of unreported breaches.<\/strong> Article 33(5) GDPR does not require a \u201cregister\u201d as such, but documentation of every breach. This means its circumstances, its effects and the remedial action taken, in a form that enables the supervisory authority to verify compliance with that provision. During an inspection, it is this documentation that shows that the decision not to report was a decision, not an oversight. <\/li>\n\n\n\n<li><strong>Notification to data subjects written in legalistic language.<\/strong> The communication should allow the recipient to understand what happened and what they can do \u2014 if it doesn&#8217;t, the obligation has been fulfilled formally but not effectively.<\/li>\n<\/ul>\n\n\n\n<h2 id=\"wnioski\" class=\"wp-block-heading\">Conclusions and next steps<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The answer to the title question is resolved in two steps. First comes the qualification of the incident, then the risk assessment for data subjects.<\/p>\n\n\n\n<div class=\"wp-block-group ll-art-zdanie is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<p class=\"wp-block-paragraph\">Remember<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The reporting obligation is a rule from which an organization can only deviate based on a documented assessment \u2014 not the other way around.<\/p>\n\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">In practice, most problems stem not from the decision itself, but from what precedes it. Therefore, before the next breach, four things need to be decided. These are who in the organization has the right to determine that the controller has become aware of a breach; how the signal from the front line reaches the data protection officer and within what timeframe; according to what criteria the risk to data subjects is assessed, so that two different people reach a similar result; and where the assessment and the justification for the decision are recorded. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An organization that has these four elements makes a reporting decision within a few hours and can later demonstrate it. An organization that does not have them starts building the procedure during the breach \u2014 and this, usually, not the incident itself, determines the course of the matter. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Related materials<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/\">How to determine if an organization must appoint a DPO?<\/a><\/strong>  \u2014 a role that conducts risk assessment and maintains contact with the authority in the reporting decision process.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/\">Where should the board begin preparing for NIS2?<\/a><\/strong>  \u2014 the order of decisions determining whether a parallel obligation to CSIRT runs alongside reporting to the UODO.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/\">What should a personal data breach register contain?<\/a><\/strong> \u2014 how to record the outcome of the risk assessment and the reasons for not notifying.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/\">How to count the 72 hours for notifying a personal data breach?<\/a><\/strong> \u2014 the moment of becoming aware of a breach and counting the notification deadline.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/how-to-notify-data-subjects-of-a-breach\/\">How do you notify data subjects of a breach and what must the communication contain?<\/a><\/strong> \u2014 the content, channel and exceptions for communicating a breach to data subjects at high risk.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Sources<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-sources\">\n<li>Regulation (EU) 2016\/679 of the European Parliament and of the Council (GDPR), Art. 4(12), Art. 33 and Art. 34, consolidated text \u2014 EUR-Lex: <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj\/eng\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a>   <\/li>\n\n\n\n<li>Proposal for a Regulation amending, inter alia, Regulation (EU) 2016\/679 (Digital Omnibus), COM(2025) 837 \u2014 EUR-Lex: <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=celex:52025PC0837\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a> <\/li>\n\n\n\n<li>Which breaches must be reported to the President of UODO, and which do not require reporting? \u2014 Office for Personal Data Protection: <a href=\"https:\/\/uodo.gov.pl\/pl\/525\/2581\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a> (in Polish)<\/li>\n\n\n\n<li>Within what period should a breach be reported to the President of UODO? \u2014 Office for Personal Data Protection: <a href=\"https:\/\/uodo.gov.pl\/pl\/525\/2584\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a> (in Polish)<\/li>\n\n\n\n<li>Other obligations and regulations related to breaches \u2014 Office for Personal Data Protection: <a href=\"https:\/\/uodo.gov.pl\/pl\/542\/2586\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a> (in Polish)<\/li>\n\n\n\n<li>When, in the event of a breach, should data subjects be notified? Important judgment of the Supreme Administrative Court (announcement of October 24, 2025 on the judgment of October 1, 2025, III OSK 1830\/22) \u2014 Office for Personal Data Protection: <a href=\"https:\/\/uodo.gov.pl\/pl\/138\/3932\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a> (in Polish)<\/li>\n\n\n\n<li>Guidelines 01\/2021 on examples regarding personal data breach notification, version 2.0, adopted December 14, 2021 \u2014 European Data Protection Board: <a href=\"https:\/\/www.edpb.europa.eu\/our-work-tools\/our-documents\/guidelines\/guidelines-012021-examples-regarding-personal-data-breach_en\" target=\"_blank\" rel=\"noreferrer noopener\">edpb.europa.eu<\/a> <\/li>\n\n\n\n<li>Guidelines 9\/2022 on personal data breach notification under GDPR, version 2.0, adopted March 28, 2023 \u2014 European Data Protection Board: <a href=\"https:\/\/www.edpb.europa.eu\/system\/files\/2023-04\/edpb_guidelines_202209_personal_data_breach_notification_v2.0_en.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">edpb.europa.eu<\/a> <\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-group ll-art-cta is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading ll-nietoc\">Organize your reporting decision before it&#8217;s needed<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If, in your organization, the qualification of incidents and risk assessment for data subjects currently rely on the experience of individuals, it is worth establishing criteria and a decision-making path calmly. Incident and breach support includes situation assessment, reporting decisions, and organizing the response process. <\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/www.lablogic.pl\/en\/incident-response\/\">Incident and breach support<\/a><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Not every one. Reporting to the UODO is the rule, from which one can only deviate based on a documented risk assessment for data subjects. The 72-hour deadline runs from becoming aware of the breach, and notifying data subjects is a separate decision.  <\/p>\n","protected":false},"author":2,"featured_media":5575,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ll_stan_prawny":"August 2026","footnotes":""},"categories":[71],"tags":[81],"class_list":["post-3912","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-incidents","tag-featured"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Not every personal data breach must be reported. How to assess the risk to individuals, when the 72-hour clock starts and when you must notify the people.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Micha\u0142 Rutkowski\"\/>\n\t<meta name=\"keywords\" content=\"featured\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Not every breach goes to the regulator\" \/>\n\t\t<meta property=\"og:description\" content=\"Reporting turns on the risk to individuals; 72 hours runs from awareness.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-does-every-data-breach-need-to-be-reported-en-1.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-does-every-data-breach-need-to-be-reported-en-1.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t\t<meta property=\"article:section\" content=\"Incidents and Breaches\" \/>\n\t\t<meta property=\"article:tag\" content=\"gdpr\" \/>\n\t\t<meta property=\"article:tag\" content=\"breaches\" \/>\n\t\t<meta property=\"article:tag\" content=\"reporting\" \/>\n\t\t<meta property=\"article:tag\" content=\"compliance\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-06-25T07:40:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-10-02T22:36:45+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Not every breach goes to the regulator\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Reporting turns on the risk to individuals; 72 hours runs from awareness.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-does-every-data-breach-need-to-be-reported-en-1.jpg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/does-every-data-breach-need-to-be-reported\\\/#article\",\"name\":\"Reporting a personal data breach \\u2014 the rule and exceptions\",\"headline\":\"Does every data breach need to be reported?\",\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-does-every-data-breach-need-to-be-reported-en-1.jpg\",\"width\":1200,\"height\":630,\"caption\":\"Must every data breach be reported? \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"datePublished\":\"2026-06-25T09:40:00+02:00\",\"dateModified\":\"2026-10-03T00:36:45+02:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/does-every-data-breach-need-to-be-reported\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/does-every-data-breach-need-to-be-reported\\\/#webpage\"},\"articleSection\":\"Incidents and Breaches\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/does-every-data-breach-need-to-be-reported\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"position\":1,\"name\":\"LabLogic\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/#listItem\",\"name\":\"Incidents and Breaches\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/#listItem\",\"position\":2,\"name\":\"Incidents and Breaches\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/does-every-data-breach-need-to-be-reported\\\/#listItem\",\"name\":\"Does every data breach need to be reported?\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"name\":\"LabLogic\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/does-every-data-breach-need-to-be-reported\\\/#listItem\",\"position\":3,\"name\":\"Does every data breach need to be reported?\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/#listItem\",\"name\":\"Incidents and Breaches\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\",\"name\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"email\":\"m.rutkowski@lablogic.pl\",\"telephone\":\"+48586231777\",\"foundingDate\":\"2004\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/cropped-lablogic-site-icon-512.png\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/does-every-data-breach-need-to-be-reported\\\/#organizationLogo\",\"width\":512,\"height\":512},\"image\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/does-every-data-breach-need-to-be-reported\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"additionalType\":\"https:\\\/\\\/schema.org\\\/ProfessionalService\",\"legalName\":\"LabLogic Consulting Micha\\u0142 Rutkowski\",\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"ul. Wolno\\u015bci 15\",\"postalCode\":\"81-327\",\"addressLocality\":\"Gdynia\",\"addressRegion\":\"pomorskie\",\"addressCountry\":\"PL\"},\"vatID\":\"PL9580972114\",\"taxID\":\"9580972114\",\"areaServed\":{\"@type\":\"Country\",\"name\":\"Poland\"},\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"founder\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"hasOfferCatalog\":{\"@type\":\"OfferCatalog\",\"name\":\"Services\",\"itemListElement\":[{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"External Data Protection Officer (DPO)\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/external-dpo\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"NIS2 and KSC implementation support\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-ksc\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"Incident and data breach response\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/incident-response\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"GDPR and NIS2 training\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/training\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"AI Act: roles, obligations and preparation\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/ai-act\\\/\"}}]}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/michal-rutkowski\\\/\",\"name\":\"Micha\\u0142 Rutkowski\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski-portret\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/michal-rutkowski-iod-dpo-rodo-nis2-lablogic.webp\",\"width\":864,\"height\":1080,\"caption\":\"Micha\\u0142 Rutkowski\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"jobTitle\":\"Data Protection Officer (DPO), NIS2\\\/KSC and cybersecurity advisor\",\"description\":\"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.\",\"email\":\"m.rutkowski@lablogic.pl\",\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"worksFor\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/does-every-data-breach-need-to-be-reported\\\/#webpage\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/does-every-data-breach-need-to-be-reported\\\/\",\"name\":\"Reporting a personal data breach \\u2014 the rule and exceptions\",\"description\":\"Not every personal data breach must be reported. How to assess the risk to individuals, when the 72-hour clock starts and when you must notify the people.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/does-every-data-breach-need-to-be-reported\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-does-every-data-breach-need-to-be-reported-en-1.jpg\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/does-every-data-breach-need-to-be-reported\\\/#mainImage\",\"width\":1200,\"height\":630,\"caption\":\"Must every data breach be reported? \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/does-every-data-breach-need-to-be-reported\\\/#mainImage\"},\"datePublished\":\"2026-06-25T09:40:00+02:00\",\"dateModified\":\"2026-10-03T00:36:45+02:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"name\":\"Micha\\u0142 Rutkowski - LabLogic\",\"alternateName\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Reporting a personal data breach \u2014 the rule and exceptions","description":"Not every personal data breach must be reported. How to assess the risk to individuals, when the 72-hour clock starts and when you must notify the people.","canonical_url":"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/","robots":"max-image-preview:large","keywords":"featured","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/#article","name":"Reporting a personal data breach \u2014 the rule and exceptions","headline":"Does every data breach need to be reported?","author":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"publisher":{"@id":"https:\/\/www.lablogic.pl\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-does-every-data-breach-need-to-be-reported-en-1.jpg","width":1200,"height":630,"caption":"Must every data breach be reported? \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"datePublished":"2026-06-25T09:40:00+02:00","dateModified":"2026-10-03T00:36:45+02:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/#webpage"},"isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/#webpage"},"articleSection":"Incidents and Breaches"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","position":1,"name":"LabLogic","item":"https:\/\/www.lablogic.pl\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/#listItem","name":"Incidents and Breaches"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/#listItem","position":2,"name":"Incidents and Breaches","item":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/#listItem","name":"Does every data breach need to be reported?"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","name":"LabLogic"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/#listItem","position":3,"name":"Does every data breach need to be reported?","previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/#listItem","name":"Incidents and Breaches"}}]},{"@type":"Organization","@id":"https:\/\/www.lablogic.pl\/#organization","name":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","url":"https:\/\/www.lablogic.pl\/en\/","email":"m.rutkowski@lablogic.pl","telephone":"+48586231777","foundingDate":"2004","logo":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/cropped-lablogic-site-icon-512.png","@id":"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/#organizationLogo","width":512,"height":512},"image":{"@id":"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/#organizationLogo"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"additionalType":"https:\/\/schema.org\/ProfessionalService","legalName":"LabLogic Consulting Micha\u0142 Rutkowski","address":{"@type":"PostalAddress","streetAddress":"ul. Wolno\u015bci 15","postalCode":"81-327","addressLocality":"Gdynia","addressRegion":"pomorskie","addressCountry":"PL"},"vatID":"PL9580972114","taxID":"9580972114","areaServed":{"@type":"Country","name":"Poland"},"knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"founder":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"hasOfferCatalog":{"@type":"OfferCatalog","name":"Services","itemListElement":[{"@type":"Offer","itemOffered":{"@type":"Service","name":"External Data Protection Officer (DPO)","url":"https:\/\/www.lablogic.pl\/en\/external-dpo\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"NIS2 and KSC implementation support","url":"https:\/\/www.lablogic.pl\/en\/nis2-ksc\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"Incident and data breach response","url":"https:\/\/www.lablogic.pl\/en\/incident-response\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"GDPR and NIS2 training","url":"https:\/\/www.lablogic.pl\/en\/training\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"AI Act: roles, obligations and preparation","url":"https:\/\/www.lablogic.pl\/en\/ai-act\/"}}]}},{"@type":"Person","@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski","url":"https:\/\/www.lablogic.pl\/michal-rutkowski\/","name":"Micha\u0142 Rutkowski","image":{"@type":"ImageObject","@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski-portret","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/michal-rutkowski-iod-dpo-rodo-nis2-lablogic.webp","width":864,"height":1080,"caption":"Micha\u0142 Rutkowski"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"jobTitle":"Data Protection Officer (DPO), NIS2\/KSC and cybersecurity advisor","description":"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.","email":"m.rutkowski@lablogic.pl","knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"worksFor":{"@id":"https:\/\/www.lablogic.pl\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/#webpage","url":"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/","name":"Reporting a personal data breach \u2014 the rule and exceptions","description":"Not every personal data breach must be reported. How to assess the risk to individuals, when the 72-hour clock starts and when you must notify the people.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/#website"},"breadcrumb":{"@id":"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/#breadcrumblist"},"author":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"creator":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-does-every-data-breach-need-to-be-reported-en-1.jpg","@id":"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/#mainImage","width":1200,"height":630,"caption":"Must every data breach be reported? \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"primaryImageOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/#mainImage"},"datePublished":"2026-06-25T09:40:00+02:00","dateModified":"2026-10-03T00:36:45+02:00"},{"@type":"WebSite","@id":"https:\/\/www.lablogic.pl\/en\/#website","url":"https:\/\/www.lablogic.pl\/en\/","name":"Micha\u0142 Rutkowski - LabLogic","alternateName":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.lablogic.pl\/#organization"}}]},"og:locale":"en_US","og:site_name":"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice","og:type":"article","og:title":"Not every breach goes to the regulator","og:description":"Reporting turns on the risk to individuals; 72 hours runs from awareness.","og:url":"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/","og:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-does-every-data-breach-need-to-be-reported-en-1.jpg","og:image:secure_url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-does-every-data-breach-need-to-be-reported-en-1.jpg","og:image:width":1200,"og:image:height":630,"article:section":"Incidents and Breaches","article:tag":["gdpr","breaches","reporting","compliance"],"article:published_time":"2026-06-25T07:40:00+00:00","article:modified_time":"2026-10-02T22:36:45+00:00","twitter:card":"summary_large_image","twitter:title":"Not every breach goes to the regulator","twitter:description":"Reporting turns on the risk to individuals; 72 hours runs from awareness.","twitter:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-does-every-data-breach-need-to-be-reported-en-1.jpg"},"aioseo_meta_data":{"post_id":"3912","title":"Reporting a personal data breach \u2014 the rule and exceptions","description":"Not every personal data breach must be reported. How to assess the risk to individuals, when the 72-hour clock starts and when you must notify the people.","keywords":null,"keyphrases":{"focus":{"keyphrase":"reporting a personal data breach","score":0},"additional":[{"keyphrase":"72 hour breach notification","score":0},{"keyphrase":"when to notify the supervisory authority","score":0},{"keyphrase":"breach risk assessment","score":0},{"keyphrase":"notifying data subjects","score":0}]},"primary_term":null,"canonical_url":null,"og_title":"Not every breach goes to the regulator","og_description":"Reporting turns on the risk to individuals; 72 hours runs from awareness.","og_object_type":"article","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"Incidents and Breaches","og_article_tags":[{"label":"GDPR","value":"GDPR"},{"label":"breaches","value":"breaches"},{"label":"reporting","value":"reporting"},{"label":"compliance","value":"compliance"}],"twitter_use_og":true,"twitter_card":"summary_large_image","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":0,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-08-18 09:54:44","updated":"2026-10-02 22:36:53","seo_analyzer_scan_date":null,"focus_keyword":"reporting a personal data breach","additional_keywords":[{"word":"72 hour breach notification","score":0},{"word":"when to notify the supervisory authority","score":0},{"word":"breach risk assessment","score":0},{"word":"notifying data subjects","score":0}],"truseo_locale":null},"spectra_blocks_featured_image_url":{"thumbnail":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-does-every-data-breach-need-to-be-reported-en-1-150x150.jpg","width":150,"height":150},"medium":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-does-every-data-breach-need-to-be-reported-en-1-300x158.jpg","width":300,"height":158},"medium_large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-does-every-data-breach-need-to-be-reported-en-1-768x403.jpg","width":768,"height":403},"large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-does-every-data-breach-need-to-be-reported-en-1-1024x538.jpg","width":1024,"height":538},"full":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-does-every-data-breach-need-to-be-reported-en-1.jpg","width":1200,"height":630}},"spectra_blocks_author_info":{"display_name":"Micha\u0142 Rutkowski","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","author_link":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/","description":"Micha\u0142 Rutkowski \u2014 praktyk ochrony danych i cyberbezpiecze\u0144stwa, w\u0142a\u015bciciel LabLogic. Od 2004 roku pracuje na styku technologii, ochrony danych i zarz\u0105dzania ryzykiem. Pe\u0142ni funkcj\u0119 zewn\u0119trznego IOD\/DPO, prowadzi audyty RODO, kwalifikacj\u0119 i wdro\u017cenia NIS2 oraz ustawy o KSC, wspiera organizacje przy incydentach i naruszeniach ochrony danych, szkoli zarz\u0105dy, kadr\u0119 kierownicz\u0105 oraz zespo\u0142y IT i compliance. Pracuje ze \u015brednimi i du\u017cymi organizacjami, w tym z sektora finansowego i bran\u017c regulowanych."},"_links":{"self":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/3912","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/comments?post=3912"}],"version-history":[{"count":5,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/3912\/revisions"}],"predecessor-version":[{"id":5760,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/3912\/revisions\/5760"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media\/5575"}],"wp:attachment":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media?parent=3912"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/categories?post=3912"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/tags?post=3912"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}