{"id":5629,"date":"2026-09-19T23:29:55","date_gmt":"2026-09-19T21:29:55","guid":{"rendered":"https:\/\/www.lablogic.pl\/?p=5629"},"modified":"2026-09-19T23:42:50","modified_gmt":"2026-09-19T21:42:50","slug":"how-to-count-72-hours-for-breach-notification","status":"publish","type":"post","link":"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/","title":{"rendered":"How to count the 72 hours for notifying a personal data breach?"},"content":{"rendered":"\n<p class=\"ll-art-meta wp-block-paragraph\"><a href=\"https:\/\/www.lablogic.pl\/en\/michal-rutkowski\/\"><strong>Micha\u0142 Rutkowski<\/strong><\/a> \u2022 for DPOs and incident response teams \u2022 published September 19, 2026 \u2022 12 min read<\/p>\n\n\n\n<div class=\"wp-block-columns ll-art-shell is-layout-flex wp-container-core-columns-is-layout-7387b849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column ll-art-rail is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-railinner is-layout-constrained wp-block-group-is-layout-constrained\">\n\n\n\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column ll-art-main is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-answer is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 id=\"krotka-odpowiedz\" class=\"wp-block-heading\">Short answer<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The 72-hour deadline runs from the moment the controller becomes aware of the breach. It is not counted from the event itself and usually not from the first signal about it. According to the EDPB the controller becomes aware when it has a reasonable degree of certainty about the breach. What counts is certainty that a security incident has led to personal data being compromised. The hours also run on days off work, and the first requirement of the provision is notification without undue delay.<\/p>\n<\/div>\n\n\n\n<h2 id=\"dlaczego-pytanie\" class=\"wp-block-heading\">Why this question arises at all<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Article 33(1) GDPR links the deadline to the moment of becoming aware of the breach. The Regulation does not, however, define that notion. The definitions in Article 4 cover the personal data breach itself in point 12. They do not cover the moment of becoming aware of it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a medium-sized or large organisation this moment is rarely a single point. An employee notices an irregularity and passes it to the IT department. The security team verifies it and passes the result to the data protection officer. The officer assesses the effects for the data, and the board signs the notification. Each of these people learns about the event at a different hour. In my assessment the procedure should therefore settle whose knowledge starts the deadline.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second source of doubt is a second 72-hour deadline. An essential or important entity reports a significant incident without delay and no later than 72 hours from the moment it was detected. This is laid down in Article 11(1)(4a) of the Polish Act on the National Cybersecurity System (KSC). The Act provides for derogations from this rule. A trust service provider has 24 hours to report under Article 11(1a). Article 8i(1) excludes entities from the banking and financial market infrastructure sectors from the provisions on reporting significant incidents, with the exceptions listed in that provision.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Detecting an incident and becoming aware of a breach are two different moments, so for a single event the two deadlines may expire at different hours. The addressee of the report and the early warning submitted within 24 hours are described in <a href=\"https:\/\/www.lablogic.pl\/en\/what-does-a-significant-incident-report-to-a-csirt-contain\/\">What does a significant incident report to a CSIRT contain?<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The third source is organisational. Notification procedures usually follow the rhythm of office work, with document circulation and management approval. The deadline under Article 33(1) is meanwhile counted in hours.<\/p>\n\n\n\n<h2 id=\"co-ustalic\" class=\"wp-block-heading\">What has to be established before a decision<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">When the 72-hour deadline starts<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The starting point is becoming aware of the breach, not its occurrence. According to the EDPB the controller becomes aware at the moment it has a reasonable degree of certainty about two circumstances. A security incident has occurred and that incident has led to personal data being compromised.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The President of UODO describes becoming aware as the moment at which the controller obtains sufficient knowledge of an incident to consider it a personal data breach. The UODO guide links it to awareness of three circumstances. The event is a security incident and it concerns personal data being processed. It may also lead to the effects described in the definition of a breach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The two approaches are not identical. The EDPB speaks of an incident that has led to personal data being compromised. The UODO guide speaks of an event that may lead to this. In my assessment it is safer to follow the approach of the guide when documenting the deadline, because it is the President of UODO who will assess whether the notification arrived in time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The criterion concerns certainty about the breach itself. Where the fact of the breach is not in doubt but its scale is not yet known, the EDPB considers notification in phases a safe method. The same applies to uncertainty about the type of breach. The EDPB illustrates this with a lost USB key holding unencrypted data. The controller often cannot establish whether anyone gained access to the data. There is, however, a reasonable degree of certainty that an availability breach has occurred. Such a case has to be notified, and the controller becomes aware at the moment it realised the USB key had been lost.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Becoming aware does not take the form of a separate decision. According to the President of UODO the controller does not have to take any additional steps to establish the breach formally. It should, however, record precisely the time at which this happened.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How long the preliminary investigation may last<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Sometimes the controller becomes aware immediately. The EDPB gives the example of a third party that provides the controller with evidence of an unauthorised disclosure of data. In other cases a short preliminary investigation, which the controller may carry out, falls between the first signal and becoming aware. According to the EDPB the controller may not be regarded as aware during that investigation. It expects, however, that the investigation should begin as soon as possible. It is meant to establish with a reasonable degree of certainty whether a breach has taken place.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The length of this investigation also has a limit. According to the EDPB the preliminary actions should in most cases be completed soon after the initial alert. The initial alert is the moment when the controller or processor suspects a security incident that may involve personal data. It should take longer than this only in exceptional cases.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once the breach itself has been established, the EDPB allows a more detailed investigation. The preliminary investigation is therefore not an inquiry carried through to its end. Among the circumstances that do not justify a delay the President of UODO lists waiting for the completion of an internal investigation into the incident conducted to classify it. In my assessment the two positions can be reconciled. A brief check of the facts is acceptable, but waiting for the classification inquiry to end does not justify a delayed notification.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to recital 87 GDPR it should be ascertained whether all appropriate technological protection and organisational measures have been implemented to establish immediately whether a breach has taken place and to inform promptly the supervisory authority and the data subject. The EDPB links this to an obligation to maintain the ability to establish breaches in time. It also warns of the consequences of delay. Failing to act in a timely manner when it becomes apparent that a breach did occur could be considered a failure to notify.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In my assessment the time a signal spends circulating in the organisation without a person responsible for assessing it is therefore not neutral. It is a gap in the ability that the controller has to maintain.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">When the breach is established by the processor<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Article 33(2) GDPR requires the processor to notify the controller without undue delay after becoming aware of a breach. The EDPB points out that the Regulation does not set an explicit time limit for this notification. It therefore recommends prompt notification and the provision of further information in phases.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The processor does not need to assess the risk before notifying. According to the EDPB it only has to establish whether a breach has occurred and notify the controller. Assessing the risk is the controller&#8217;s task. The guidelines also take the view that in principle the controller becomes aware at the moment it receives this information from the processor.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The words in principle have a practical meaning. The EDPB notes that the processor may not know all the relevant facts. An example is the controller still holding a copy of personal data destroyed or lost by the processor. The controller may therefore carry out its own investigation, and its result may affect whether notification is required. The President of UODO stresses that the controller remains responsible for verifying the information and for the final analysis and classification of the incident.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The UODO guide treats a similar situation differently from the EDPB. In one of its examples a fire destroyed the servers holding backups at the processor. The processor established an availability breach and informed the controller. The controller held its own complete copy of those data and according to the guide rightly did not become aware of a breach. In a similar situation the EDPB speaks of the effect of the copy on the obligation to notify, while the guide speaks of no awareness at all.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Article 28(3)(f) GDPR requires the contract or other legal act to provide for the processor&#8217;s assistance in complying with the obligations under Articles 32 to 36. That assistance takes into account the nature of the processing and the information available to the processor. The EDPB states that the contract may include a requirement for early notification of breaches. Where the same incident affects several controllers, the processor notifies each of them. It may also notify the authority on behalf of the controller if the controller has given it an authorisation set out in the contract. According to the EDPB legal responsibility for the notification still remains with the controller. I recommend writing into the contract a deadline counted in hours and a channel through which the notification is to arrive outside working hours.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For joint controllers Article 26(1) GDPR requires their respective responsibilities to be set out in an arrangement between them, unless they are determined by Union or Member State law to which the controllers are subject. The EDPB recommends that the arrangement should name the controller responsible for notifying breaches.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Does the 72-hour deadline run at weekends and on public holidays<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Yes. According to the President of UODO the 72-hour deadline runs regardless of days off work. A breach is notified as soon as possible and no later than 72 hours after becoming aware of it. The UODO guide adds that the GDPR does not provide for the deadline being suspended because of a weekend and the unavailability of key staff.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On the 72-hour deadline the EDPB refers in a footnote to Regulation No 1182\/71 determining the rules applicable to periods, dates and time limits. Under its Article 3(3) the periods include public holidays, Sundays and Saturdays. The exceptions are cases expressly excepted and periods expressed in working days. Article 3(4) moves the end of a period to the following working day where the last day falls on a public holiday, Sunday or Saturday. It concerns, however, periods expressed otherwise than in hours. Article 3(5) provides, in turn, that any period of two days or more includes at least two working days. The Regulation does not state expressly whether this rule extends a period counted in hours. Neither the guidelines nor the UODO guide discuss it, so in my assessment a procedure should not rely on it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Regulation also indicates from which moment the hours are counted. Where a period expressed in hours is calculated from the moment at which an event occurs, Article 3(1) does not count the hour during which the event occurred. Subject to paragraphs 1 and 4 such a period starts at the beginning of the first hour and ends with the expiry of the last hour of the period, under Article 3(2)(a). When a controller becomes aware of a breach on a Wednesday at 14.20, a period counted under these rules starts at 15.00 and ends on Saturday at 15.00.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Save as otherwise provided, Article 1 however limits the Regulation to acts of the Council or the Commission passed under the EEC Treaty or the Euratom Treaty. The GDPR was adopted by the European Parliament and the Council on the basis of Article 16 of the Treaty on the Functioning of the European Union. The guidelines do not explain how this reference should be understood. In my assessment it is safer to count the deadline from the minute of becoming aware, because the first requirement is in any case notification without undue delay.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In exceptional situations, for example when the electronic notification systems fail, the UODO guide allows a temporary notification by email to kancelaria@uodo.gov.pl. Such a notification has to be confirmed at the earliest possible date by one of the standard methods.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The UODO guide lists situations that should not justify a delay. The list is open, because it is introduced with the abbreviation \u201cinter alia\u201d.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The deadline fell on a weekend or another day off work, and key staff were unavailable.<\/li>\n\n\n\n<li>The person responsible for the notification was on leave or sick leave, and the controller had not arranged an appropriate substitute.<\/li>\n\n\n\n<li>Management had no time to approve the notification, although procedures should take account of the need to act without delay.<\/li>\n\n\n\n<li>The controller was waiting for the completion of an internal investigation into the incident conducted to classify it, or of the assessment of the risk associated with the breach.<\/li>\n\n\n\n<li>The controller needed additional time to gather all the required information.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For the last item the UODO guide points to a solution. It is an initial notification followed by a supplementary one.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What has to fit within 72 hours<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">According to the EDPB the controller should assess the likely risk to individuals within this period. Whether notification is required at all depends on that assessment. Article 33(1) waives it where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. According to the EDPB the controller should also determine within the same period the action needed to address the breach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The risk assessment does not have to wait for the full picture of the event. In Guidelines 01\/2021 the EDPB states that the controller should not wait for a detailed forensic examination or for early mitigation steps. A full risk assessment may take place in parallel with the notification.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Article 33(4) GDPR follows the same logic. Where and in so far as it is not possible to provide the information at the same time, it may be provided in phases without undue further delay. Information available at once therefore goes into the first notification. The President of UODO distinguishes three types of notification. They are initial, supplementary and complete notifications. The EDPB recommends informing the authority in the first notification that some information is missing and will be provided later.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Further investigation may show that no breach occurred. The controller may then pass this information to the authority. The EDPB states that there is no penalty for reporting an incident that ultimately turns out not to be a breach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The 72 hours are not a deadline to be used in full either. The provision puts notification without undue delay first and qualifies the 72-hour limit with the words where feasible. When discussing a ransomware attack in Guidelines 01\/2021 the EDPB refers to this deadline and states that exceeding it could be considered ill-advised in any case. Where the level of risk is high, even meeting it may be considered unsatisfactory.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What to do when the 72-hour deadline has passed<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Article 33(1) GDPR provides for a notification made after 72 hours. It has to be accompanied by the reasons for the delay. The expiry of the deadline therefore does not remove the obligation to notify but adds a justification to it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The EDPB allows delayed notification in some cases and gives an example. Within a short time a controller faces a series of similar confidentiality breaches that affect many people in the same way. It becomes aware of the first of them and detects further breaches with different causes before notifying. Instead of notifying each one separately it may prepare a single bundled notification. The guidelines set three conditions for this. The breaches must concern the same type of personal data breached in the same way over a relatively short period. Where different types of data are breached in different ways, each breach is notified separately.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to the EDPB delayed notifications should not be seen as something that regularly takes place. It adds that a bundled notification may also be made within 72 hours. The President of UODO states in turn that delays should result only from exceptional situations.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How to document the moment of awareness<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Article 33(5) GDPR requires all breaches to be documented. The documentation comprises in particular the facts relating to the breach, its effects and the remedial action taken. It has to enable the supervisory authority to verify compliance with Article 33. The President of UODO states that the time of becoming aware of the breach is part of this mandatory documentation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I recommend recording four timestamps with the time and the name of the person who recorded them.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>The first signal and its source.<\/li>\n\n\n\n<li>The start of the preliminary investigation.<\/li>\n\n\n\n<li>Becoming aware of the breach together with the findings that decided it.<\/li>\n\n\n\n<li>Sending the notification and each supplement to it.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">A record of becoming aware with its reasons makes it possible to show the authority why the deadline was counted from a given hour. The other elements of the entry are described in <a href=\"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/\">What should a personal data breach register contain?<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Timeline of a single breach<\/h3>\n\n\n\n<figure class=\"wp-block-table ll-art-table\"><table><thead><tr><th>Moment<\/th><th>What it means for the deadline<\/th><th>Basis<\/th><th>Exceptions and limitations<\/th><th>Applies from<\/th><\/tr><\/thead><tbody><tr><td>Occurrence of the event<\/td><td>the deadline does not run<\/td><td>Article 33(1) GDPR<\/td><td>an event without effect on personal data is not a breach within the meaning of Article 4(12)<\/td><td>25 May 2018<\/td><\/tr><tr><td>First signal<\/td><td>the deadline usually does not run yet, and the controller may carry out a short preliminary investigation<\/td><td>EDPB Guidelines 9\/2022, paragraphs 33, 34 and 36<\/td><td>with clear evidence of a breach the controller becomes aware immediately, and the investigation should in most cases be completed soon<\/td><td>Guidelines version 2.0 from 28 March 2023<\/td><\/tr><tr><td>Controller becomes aware<\/td><td>the deadline starts to run<\/td><td>Article 33(1) GDPR, EDPB Guidelines 9\/2022, paragraph 31<\/td><td>no obligation to notify where a risk to individuals is unlikely<\/td><td>provision from 25 May 2018, Guidelines version 2.0 from 28 March 2023<\/td><\/tr><tr><td>Information from the processor<\/td><td>in principle the moment the controller becomes aware<\/td><td>Article 33(2) GDPR, EDPB Guidelines 9\/2022, paragraph 44, UODO guide, section 5.2<\/td><td>according to the EDPB the controller&#8217;s own findings, for example about a copy of the data, may affect whether notification is required, and according to the UODO guide they may rule out awareness of a breach<\/td><td>provision from 25 May 2018, Guidelines version 2.0 from 28 March 2023, UODO guide version of 20 February 2025<\/td><\/tr><tr><td>Expiry of 72 hours<\/td><td>notification still required, with reasons for the delay<\/td><td>Article 33(1), second sentence, GDPR, EDPB Guidelines 9\/2022, paragraphs 62 to 65<\/td><td>delay acceptable in some cases, for example with a bundled notification of a series of similar breaches<\/td><td>provision from 25 May 2018, Guidelines version 2.0 from 28 March 2023<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 id=\"najczestsze-bledy\" class=\"wp-block-heading\">Common mistakes<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n<li><strong>Counting the deadline from board approval.<\/strong> The deadline runs from becoming aware of the breach. The UODO guide lists management&#8217;s lack of time among the circumstances that do not justify a delay.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n<li><strong>Waiting for the forensic report.<\/strong> According to the EDPB the risk assessment should not wait for a detailed examination. Information can be provided in phases.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n<li><strong>Moving the deadline to the next working day.<\/strong> According to the President of UODO the notification is made regardless of days off work.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n<li><strong>Treating information from the processor as a preliminary rumour.<\/strong> According to the EDPB the controller has in principle become aware of the breach from that moment. According to the EDPB the controller&#8217;s own findings, for example about a copy of the data, may affect whether notification is required. According to the UODO guide they may rule out awareness itself.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n<li><strong>Applying the 72 hours to communication to data subjects.<\/strong> Article 34(1) GDPR requires communication to data subjects without undue delay where the breach is likely to result in a high risk. This provision gives no number of hours.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n<li><strong>A single date in the procedure for the GDPR and the KSC Act.<\/strong> The deadline under Article 33(1) GDPR runs from becoming aware of the breach, and the deadline under Article 11(1)(4a) of the KSC Act from detecting the significant incident.<\/li>\n<\/ul>\n\n\n\n<h2 id=\"wnioski\" class=\"wp-block-heading\">Conclusions and next steps<\/h2>\n\n\n\n<div class=\"wp-block-group ll-art-zdanie is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<p class=\"wp-block-paragraph\">Remember<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The 72-hour deadline is usually decided before the event, in the procedure.<\/p>\n\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">On the day of the breach the organisation carries out what it has settled beforehand. In my assessment most time is lost between the first signal and becoming aware, because the provision does not measure that stretch in hours.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I recommend five steps that put the counting of the deadline in order. None of them is a requirement written expressly in the legislation.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Name a person who receives incident signals around the clock and a deputy.<\/li>\n\n\n\n<li>Establish who becomes aware of breaches on behalf of the controller and on the basis of what findings.<\/li>\n\n\n\n<li>Record in the procedure that the short preliminary investigation begins immediately after the signal.<\/li>\n\n\n\n<li>Prepare a template initial notification and name the person authorised to send it on days off work, also through the emergency channel.<\/li>\n\n\n\n<li>Review data processing agreements for the deadline and channel for processors to notify breaches.<\/li>\n<\/ol>\n\n\n\n<h2 id=\"materialy-powiazane\" class=\"wp-block-heading\">Related materials<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/\"><strong>Does every data breach need to be reported?<\/strong><\/a> \u2014 the notification threshold and the assessment of risk to individuals, which decides whether the deadline has to be counted at all.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.lablogic.pl\/en\/what-should-a-personal-data-breach-register-contain\/\"><strong>What should a personal data breach register contain?<\/strong><\/a> \u2014 where to record the moment of awareness and its reasons.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.lablogic.pl\/en\/what-to-do-after-detecting-an-incident\/\"><strong>What to do after detecting an incident?<\/strong><\/a> \u2014 the order of actions in the first day, when several deadlines run at once.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.lablogic.pl\/en\/what-does-a-significant-incident-report-to-a-csirt-contain\/\"><strong>What does a significant incident report to a CSIRT contain?<\/strong><\/a> \u2014 the second 72-hour deadline, counted from detection.<\/li>\n<\/ul>\n\n\n\n<h2 id=\"zrodla\" class=\"wp-block-heading\">Sources<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-sources\">\n<li>Regulation (EU) 2016\/679 of the European Parliament and of the Council (GDPR), consolidated version \u2014 Article 4(12), Article 26(1), Article 28(3)(f), Article 33, Article 34(1) and Article 99(2) \u2014 <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A02016R0679-20160504\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a> (accessed September 19, 2026).<\/li>\n\n\n\n<li>Regulation (EU) 2016\/679 (GDPR), version as published in OJ EU L 119 of 4 May 2016 \u2014 recital 87 \u2014 <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A32016R0679\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a> (accessed September 19, 2026).<\/li>\n\n\n\n<li>Act of 5 July 2018 on the National Cybersecurity System, consolidated text as at 7 July 2026 \u2014 Article 8i(1) and Article 11(1)(4) and (4a) and (1a) (in Polish) \u2014 <a href=\"https:\/\/isap.sejm.gov.pl\/isap.nsf\/DocDetails.xsp?id=WDU20180001560\" target=\"_blank\" rel=\"noreferrer noopener\">isap.sejm.gov.pl<\/a> (accessed September 19, 2026).<\/li>\n\n\n\n<li>Regulation (EEC, Euratom) No 1182\/71 of the Council of 3 June 1971 determining the rules applicable to periods, dates and time limits \u2014 Article 1 and Article 3(1) to (5) \u2014 <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:31971R1182\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a> (accessed September 19, 2026).<\/li>\n\n\n\n<li>Personal Data Protection Office (UODO), Guide on personal data breaches, version of 20 February 2025 \u2014 sections 5.2 and 9.2 (in Polish) \u2014 <a href=\"https:\/\/uodo.gov.pl\/pl\/598\/3563\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a> (accessed September 19, 2026).<\/li>\n\n\n\n<li>European Data Protection Board, Guidelines 9\/2022 on personal data breach notification under GDPR, version 2.0 adopted 28 March 2023 \u2014 paragraphs 31 to 48, 53 and 56 to 65 \u2014 <a href=\"https:\/\/www.edpb.europa.eu\/system\/files\/documents\/2023-04\/edpb_guidelines_202209_personal_data_breach_notification_v2.0_en.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">edpb.europa.eu<\/a> (accessed September 19, 2026).<\/li>\n\n\n\n<li>European Data Protection Board, Guidelines 01\/2021 on Examples regarding Personal Data Breach Notification, version 2.0 adopted 14 December 2021 \u2014 paragraphs 8, 9 and 24 \u2014 <a href=\"https:\/\/www.edpb.europa.eu\/system\/files\/documents\/2022-01\/edpb_guidelines_012021_pdbnotification_adopted_en.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">edpb.europa.eu<\/a> (accessed September 19, 2026).<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-group ll-art-cta is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading ll-nietoc\">Let us establish the hour from which you count the deadline<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A dispute about the notification deadline is usually decided by the record made in the first hours after the signal. <a href=\"https:\/\/www.lablogic.pl\/en\/incident-response\/\">Support with incidents and breaches<\/a> covers a review of the procedure for the moment of awareness, substitutes and agreements with processors.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/www.lablogic.pl\/en\/incident-response\/\">Support with incidents and breaches<\/a><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The 72-hour deadline runs from the moment the controller becomes aware of the breach, not from the event itself. Awareness means a reasonable degree of certainty about the breach. The hours also run at weekends and on public holidays, and the first requirement is notification without undue delay.<\/p>\n","protected":false},"author":2,"featured_media":5632,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ll_stan_prawny":"","footnotes":""},"categories":[71],"tags":[],"class_list":["post-5629","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-incidents"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"The 72-hour deadline for notifying a personal data breach runs from becoming aware of it, not from the event. See what counts and how to record that moment.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Micha\u0142 Rutkowski\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"The 72 hours run from becoming aware of the breach\" \/>\n\t\t<meta property=\"og:description\" content=\"The deadline also runs at weekends. The EDPB and the President of UODO describe the moment of awareness differently, and the difference matters with processors.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-count-72-hours-for-breach-notification-en.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-count-72-hours-for-breach-notification-en.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t\t<meta property=\"article:section\" content=\"Incidents and Breaches\" \/>\n\t\t<meta property=\"article:tag\" content=\"gdpr\" \/>\n\t\t<meta property=\"article:tag\" content=\"breaches\" \/>\n\t\t<meta property=\"article:tag\" content=\"uodo\" \/>\n\t\t<meta property=\"article:tag\" content=\"dpo\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-09-19T21:29:55+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-19T21:42:50+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"The 72 hours run from becoming aware of the breach\" \/>\n\t\t<meta name=\"twitter:description\" content=\"The deadline also runs at weekends. The EDPB and the President of UODO describe the moment of awareness differently, and the difference matters with processors.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-count-72-hours-for-breach-notification-en.jpg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-count-72-hours-for-breach-notification\\\/#article\",\"name\":\"72-hour deadline for breach notification \\u2014 how to count it\",\"headline\":\"How to count the 72 hours for notifying a personal data breach?\",\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-how-to-count-72-hours-for-breach-notification-en.jpg\",\"width\":1200,\"height\":630,\"caption\":\"The 72 hours run from awareness \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"datePublished\":\"2026-09-19T23:29:55+02:00\",\"dateModified\":\"2026-09-19T23:42:50+02:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-count-72-hours-for-breach-notification\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-count-72-hours-for-breach-notification\\\/#webpage\"},\"articleSection\":\"Incidents and Breaches\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-count-72-hours-for-breach-notification\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"position\":1,\"name\":\"LabLogic\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/#listItem\",\"name\":\"Incidents and Breaches\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/#listItem\",\"position\":2,\"name\":\"Incidents and Breaches\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-count-72-hours-for-breach-notification\\\/#listItem\",\"name\":\"How to count the 72 hours for notifying a personal data breach?\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"name\":\"LabLogic\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-count-72-hours-for-breach-notification\\\/#listItem\",\"position\":3,\"name\":\"How to count the 72 hours for notifying a personal data breach?\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/incidents\\\/#listItem\",\"name\":\"Incidents and Breaches\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\",\"name\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"email\":\"m.rutkowski@lablogic.pl\",\"telephone\":\"+48586231777\",\"foundingDate\":\"2004\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/cropped-lablogic-site-icon-512.png\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-count-72-hours-for-breach-notification\\\/#organizationLogo\",\"width\":512,\"height\":512},\"image\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-count-72-hours-for-breach-notification\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"additionalType\":\"https:\\\/\\\/schema.org\\\/ProfessionalService\",\"legalName\":\"LabLogic Consulting Micha\\u0142 Rutkowski\",\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"ul. Wolno\\u015bci 15\",\"postalCode\":\"81-327\",\"addressLocality\":\"Gdynia\",\"addressRegion\":\"pomorskie\",\"addressCountry\":\"PL\"},\"vatID\":\"PL9580972114\",\"taxID\":\"9580972114\",\"areaServed\":{\"@type\":\"Country\",\"name\":\"Poland\"},\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"founder\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\"},\"hasOfferCatalog\":{\"@type\":\"OfferCatalog\",\"name\":\"Services\",\"itemListElement\":[{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"External Data Protection Officer (DPO)\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/external-dpo\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"NIS2 and KSC implementation support\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/nis2-ksc\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"Incident and data breach response\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/incident-response\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"GDPR and NIS2 training\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/training\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"AI Act: roles, obligations and preparation\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/ai-act\\\/\"}}]}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/\",\"name\":\"Micha\\u0142 Rutkowski\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-count-72-hours-for-breach-notification\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Micha\\u0142 Rutkowski\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"jobTitle\":\"Data Protection Officer (DPO), NIS2\\\/KSC and cybersecurity advisor\",\"description\":\"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.\",\"email\":\"m.rutkowski@lablogic.pl\",\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"worksFor\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-count-72-hours-for-breach-notification\\\/#webpage\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-count-72-hours-for-breach-notification\\\/\",\"name\":\"72-hour deadline for breach notification \\u2014 how to count it\",\"description\":\"The 72-hour deadline for notifying a personal data breach runs from becoming aware of it, not from the event. See what counts and how to record that moment.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-count-72-hours-for-breach-notification\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-how-to-count-72-hours-for-breach-notification-en.jpg\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-count-72-hours-for-breach-notification\\\/#mainImage\",\"width\":1200,\"height\":630,\"caption\":\"The 72 hours run from awareness \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-count-72-hours-for-breach-notification\\\/#mainImage\"},\"datePublished\":\"2026-09-19T23:29:55+02:00\",\"dateModified\":\"2026-09-19T23:42:50+02:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"name\":\"Micha\\u0142 Rutkowski - LabLogic\",\"alternateName\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"72-hour deadline for breach notification \u2014 how to count it","description":"The 72-hour deadline for notifying a personal data breach runs from becoming aware of it, not from the event. See what counts and how to record that moment.","canonical_url":"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/#article","name":"72-hour deadline for breach notification \u2014 how to count it","headline":"How to count the 72 hours for notifying a personal data breach?","author":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author"},"publisher":{"@id":"https:\/\/www.lablogic.pl\/en\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-count-72-hours-for-breach-notification-en.jpg","width":1200,"height":630,"caption":"The 72 hours run from awareness \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"datePublished":"2026-09-19T23:29:55+02:00","dateModified":"2026-09-19T23:42:50+02:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/#webpage"},"isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/#webpage"},"articleSection":"Incidents and Breaches"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","position":1,"name":"LabLogic","item":"https:\/\/www.lablogic.pl\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/#listItem","name":"Incidents and Breaches"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/#listItem","position":2,"name":"Incidents and Breaches","item":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/#listItem","name":"How to count the 72 hours for notifying a personal data breach?"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","name":"LabLogic"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/#listItem","position":3,"name":"How to count the 72 hours for notifying a personal data breach?","previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/incidents\/#listItem","name":"Incidents and Breaches"}}]},{"@type":"Organization","@id":"https:\/\/www.lablogic.pl\/en\/#organization","name":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","url":"https:\/\/www.lablogic.pl\/en\/","email":"m.rutkowski@lablogic.pl","telephone":"+48586231777","foundingDate":"2004","logo":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/cropped-lablogic-site-icon-512.png","@id":"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/#organizationLogo","width":512,"height":512},"image":{"@id":"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/#organizationLogo"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"additionalType":"https:\/\/schema.org\/ProfessionalService","legalName":"LabLogic Consulting Micha\u0142 Rutkowski","address":{"@type":"PostalAddress","streetAddress":"ul. Wolno\u015bci 15","postalCode":"81-327","addressLocality":"Gdynia","addressRegion":"pomorskie","addressCountry":"PL"},"vatID":"PL9580972114","taxID":"9580972114","areaServed":{"@type":"Country","name":"Poland"},"knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"founder":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author"},"hasOfferCatalog":{"@type":"OfferCatalog","name":"Services","itemListElement":[{"@type":"Offer","itemOffered":{"@type":"Service","name":"External Data Protection Officer (DPO)","url":"https:\/\/www.lablogic.pl\/en\/en\/external-dpo\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"NIS2 and KSC implementation support","url":"https:\/\/www.lablogic.pl\/en\/en\/nis2-ksc\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"Incident and data breach response","url":"https:\/\/www.lablogic.pl\/en\/en\/incident-response\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"GDPR and NIS2 training","url":"https:\/\/www.lablogic.pl\/en\/en\/training\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"AI Act: roles, obligations and preparation","url":"https:\/\/www.lablogic.pl\/en\/en\/ai-act\/"}}]}},{"@type":"Person","@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author","url":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/","name":"Micha\u0142 Rutkowski","image":{"@type":"ImageObject","@id":"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","width":96,"height":96,"caption":"Micha\u0142 Rutkowski"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"jobTitle":"Data Protection Officer (DPO), NIS2\/KSC and cybersecurity advisor","description":"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.","email":"m.rutkowski@lablogic.pl","knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"worksFor":{"@id":"https:\/\/www.lablogic.pl\/en\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/#webpage","url":"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/","name":"72-hour deadline for breach notification \u2014 how to count it","description":"The 72-hour deadline for notifying a personal data breach runs from becoming aware of it, not from the event. See what counts and how to record that moment.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/#website"},"breadcrumb":{"@id":"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/#breadcrumblist"},"author":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author"},"creator":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-count-72-hours-for-breach-notification-en.jpg","@id":"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/#mainImage","width":1200,"height":630,"caption":"The 72 hours run from awareness \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"primaryImageOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/#mainImage"},"datePublished":"2026-09-19T23:29:55+02:00","dateModified":"2026-09-19T23:42:50+02:00"},{"@type":"WebSite","@id":"https:\/\/www.lablogic.pl\/en\/#website","url":"https:\/\/www.lablogic.pl\/en\/","name":"Micha\u0142 Rutkowski - LabLogic","alternateName":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.lablogic.pl\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice","og:type":"article","og:title":"The 72 hours run from becoming aware of the breach","og:description":"The deadline also runs at weekends. The EDPB and the President of UODO describe the moment of awareness differently, and the difference matters with processors.","og:url":"https:\/\/www.lablogic.pl\/en\/how-to-count-72-hours-for-breach-notification\/","og:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-count-72-hours-for-breach-notification-en.jpg","og:image:secure_url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-count-72-hours-for-breach-notification-en.jpg","og:image:width":1200,"og:image:height":630,"article:section":"Incidents and Breaches","article:tag":["gdpr","breaches","uodo","dpo"],"article:published_time":"2026-09-19T21:29:55+00:00","article:modified_time":"2026-09-19T21:42:50+00:00","twitter:card":"summary_large_image","twitter:title":"The 72 hours run from becoming aware of the breach","twitter:description":"The deadline also runs at weekends. The EDPB and the President of UODO describe the moment of awareness differently, and the difference matters with processors.","twitter:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-count-72-hours-for-breach-notification-en.jpg"},"aioseo_meta_data":{"post_id":"5629","title":"72-hour deadline for breach notification \u2014 how to count it","description":"The 72-hour deadline for notifying a personal data breach runs from becoming aware of it, not from the event. See what counts and how to record that moment.","keywords":null,"keyphrases":{"focus":{"keyphrase":"72-hour deadline","score":0,"analysis":[]},"additional":[{"keyphrase":"becoming aware of a personal data breach","score":0,"analysis":[]},{"keyphrase":"72 hours to notify a data breach","score":0,"analysis":[]},{"keyphrase":"data breach notification at the weekend","score":0,"analysis":[]},{"keyphrase":"processor breach notification","score":0,"analysis":[]}]},"primary_term":null,"canonical_url":null,"og_title":"The 72 hours run from becoming aware of the breach","og_description":"The deadline also runs at weekends. The EDPB and the President of UODO describe the moment of awareness differently, and the difference matters with processors.","og_object_type":"article","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"Incidents and Breaches","og_article_tags":[{"label":"GDPR","value":"GDPR"},{"label":"breaches","value":"breaches"},{"label":"UODO","value":"UODO"},{"label":"DPO","value":"DPO"}],"twitter_use_og":true,"twitter_card":"summary_large_image","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-09-19 21:37:50","updated":"2026-09-19 21:42:54","seo_analyzer_scan_date":null,"focus_keyword":"72-hour deadline","additional_keywords":[{"word":"becoming aware of a personal data breach","score":0},{"word":"72 hours to notify a data breach","score":0},{"word":"data breach notification at the weekend","score":0},{"word":"processor breach notification","score":0}],"truseo_locale":null},"spectra_blocks_featured_image_url":{"thumbnail":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-count-72-hours-for-breach-notification-en-150x150.jpg","width":150,"height":150},"medium":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-count-72-hours-for-breach-notification-en-300x158.jpg","width":300,"height":158},"medium_large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-count-72-hours-for-breach-notification-en-768x403.jpg","width":768,"height":403},"large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-count-72-hours-for-breach-notification-en-1024x538.jpg","width":1024,"height":538},"full":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-count-72-hours-for-breach-notification-en.jpg","width":1200,"height":630}},"spectra_blocks_author_info":{"display_name":"Micha\u0142 Rutkowski","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","author_link":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/","description":"Micha\u0142 Rutkowski \u2014 praktyk ochrony danych i cyberbezpiecze\u0144stwa, w\u0142a\u015bciciel LabLogic. Od 2004 roku pracuje na styku technologii, ochrony danych i zarz\u0105dzania ryzykiem. Pe\u0142ni funkcj\u0119 zewn\u0119trznego IOD\/DPO, prowadzi audyty RODO, kwalifikacj\u0119 i wdro\u017cenia NIS2 oraz ustawy o KSC, wspiera organizacje przy incydentach i naruszeniach ochrony danych, szkoli zarz\u0105dy, kadr\u0119 kierownicz\u0105 oraz zespo\u0142y IT i compliance. Pracuje ze \u015brednimi i du\u017cymi organizacjami, w tym z sektora finansowego i bran\u017c regulowanych."},"_links":{"self":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/5629","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/comments?post=5629"}],"version-history":[{"count":2,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/5629\/revisions"}],"predecessor-version":[{"id":5631,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/5629\/revisions\/5631"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media\/5632"}],"wp:attachment":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media?parent=5629"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/categories?post=5629"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/tags?post=5629"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}