Practical guide · Updated 27 August 2026

Data breach: what matters in the first hours.

An incident first needs control, reliable facts and documented decisions—not rushed activity.

72 hControl the deadline early

The 72-hour period is not a general grace period. Once a possible personal data breach becomes known, facts, risk and ownership should be clarified without delay.

Immediate response plan

Six steps create control and a reliable evidence trail.

01

Contain without destroying evidence

Block affected access, isolate systems and stop further loss. Avoid premature deletion or reinstallation where this could remove important evidence.

02

Preserve the timeline and facts

Record discovery time, known events, affected systems, data categories, groups of people and initial actions with timestamps. Protect logs, screenshots and reports.

03

Bring accountable people together

Connect privacy, information security, management and relevant business owners through one clear decision path. Ask service providers for specific facts and containment actions.

04

Assess risk to individuals

Consider possible consequences such as identity misuse, financial loss, discrimination, reputational harm or loss of control. Record data type, scale, safeguards and likelihood.

05

Decide on notification duties

Where notification to the authority is required, it must generally be made without undue delay and, where feasible, within 72 hours of awareness. A high risk may also require communication to affected individuals.

06

Evidence the decision and effectiveness

A reasoned decision not to notify must also be documented. After containment, assign root-cause actions, owners, dates and an effectiveness test.

What belongs in the incident file

The decision path matters as much as the outcome.

Facts

What happened and when?

Source of the report, systems, data, affected groups, scale, timeline and containment measures already taken.

Decision

Why was this action taken?

Risk assessment, notification decision, approvals, open uncertainties, owners and the planned effectiveness review.

Official legal basis

GDPR Articles 33 and 34 govern notification and communication.

This guide provides general orientation and does not replace individual legal advice. Do not send sensitive incident data or documents through the general contact form.

Urgent data breach?

Establish a secure communication channel first.

Use only “Data breach” in the contact form and do not add sensitive details yet. Cleero will then agree the secure next step with you.

Book a consultation