Are You Able to "Implement" the GDPR 72-Hour Rule? — Designing a Timeline for Responding to Personal Data Breaches

    September 4, 2026

    Author of this article

    Privacy Expert

    Kohei Kurihara

    [Disclaimer] This article is based on the author’s personal views, and the author is not a licensed attorney. Please note that this article is not intended to provide legal advice.

    Introduction

    The GDPR (General Data Protection Regulation) imposes very strict reporting requirements, commonly referred to as the “72-hour rule.” Given the recent increase in data breaches, it is essential for companies not only to report accurately to the authorities but also to identify potential risk factors in advance.

    *In Europe, discussions regarding revisions to the GDPR are taking place as part of the European Digital Omnibus Act, which aims to overhaul complex digital regulations. In a joint opinion issued on February 11, 2026, by the European Data Protection Supervisor (EDPS) and the European Data Protection Board (EDPB), a statement was made supporting the extension of the 72-hour deadline to 96 hours; therefore, there is a possibility that practical reporting obligations may also be subject to change in the future.

    Furthermore, in order to prepare reports within a limited timeframe, it is necessary to identify potential risks in advance—rather than considering risk responses after the fact—and conduct an assessment that includes whether the company is capable of addressing those risks on its own.

    What exactly is the 72-hour rule required by the GDPR?

    Article 33 of the GDPR stipulates that companies are required to report data breaches to the relevant data protection authority within 72 hours of becoming aware of them. Because this reporting obligation arises within such a short period—72 hours—it has come to be known as the “72-hour rule.”

    Until the GDPR was enacted as law in May 2016, companies were encouraged to report data breaches under the European Data Protection Directive, which was enacted in October 1995.

    However, under the laws governing telecommunications carriers, there are cases where reporting obligations are imposed on specific companies, and in some countries—such as Ireland—Codes of Practice are required; consequently, even within the European Union, reporting obligations for data breaches had not been standardized as a uniform corporate responsibility.

    Since the GDPR came into effect, in the event of a data breach, it has become necessary not only to report the incident to regulatory authorities but also to notify the affected individuals if their rights may have been infringed. In the event of a high-risk data breach, not only the company but also the individuals whose information was compromised may face secondary or even tertiary harm, such as fraudulent phone calls.

    For this reason, companies must not limit their reporting to regulatory authorities alone; they must also report directly to the individuals concerned so that they can take steps to mitigate the risk themselves.

    The reason for setting this short 72-hour reporting deadline is that, in particular, the individual in question must be provided with the necessary information at the time of reporting so that they can understand the risks through the company’s report and, in some cases, avoid or minimize those risks.

    So far, we have explained the “72-Hour Rule” along with the background behind the establishment of the reporting obligation. While preventive measures taken before a data breach occurs are extremely important for companies to ensure accountability, they are now also subject to strict requirements regarding how they respond once a breach has occurred.

    Required Response Procedures in the Event of a Data Breach

    So, assuming a data breach has occurred, how should a company respond?

    In April 2023, the European Data Protection Board (EDPB) published guidelines and a summary document outlining the procedures for reporting data breaches. The summary document provides a clear explanation of the data breach reporting procedures that companies should follow.

    The figure below, based on a publication by the European Data Protection Board, illustrates the flow of the internal verification process as created by the author.

    Procedures to Follow in the Event of a Data Breach: Phase 1

    Record information regarding data breaches in the document (Data Breach Registration)

    • First, it is necessary to acknowledge that an information leak has occurred within the company. To that end, we will document the nature of the information leaks that have occurred within the company, the measures the company has taken to address them, and the potential risks involved.

    Assess whether there is a risk that a data breach could infringe on an individual’s rights

    • In guidelines adopted in October 2017 by the European Article 29 Working Party—the predecessor to the European Data Protection Board (now the EDPB)—data breaches are classified into three types. The risks arising from a breach are organized according to the classifications in the guidelines and then assessed.

    Procedures to Follow in the Event of a Data Breach: Phase 2 (When the Leaked Information Poses a High Risk)

    Even if you do not have all the information available at the outset, you are still required to report to the relevant regulatory authorities.

    • If it is determined that the leaked information poses a high risk, you must report it to the relevant regulatory authority. The European Data Protection Board has compiled a list of reporting channels for regulatory authorities in various countries on its website, so you should submit your report using the appropriate contact information or form.

      *While many countries within the European Union have adopted electronic forms for reporting data breaches, the content of such reports may vary by country depending on the future policies of each nation’s regulatory authorities. Therefore, at this time, we recommend that you organize the information in accordance with the formats and templates published by the European Data Protection Board (discussed below) and establish internal procedures for reporting.

    Assess whether there is a very high risk that a data breach could infringe on individual rights

    • At the same time, it is necessary to assess not only whether a data breach has occurred, but also whether the leaked information poses a risk of infringing on an individual’s rights. The guidelines on data breach notifications establish “a high risk of infringing on an individual’s freedoms or rights” as the criterion for notification.

    Procedures to Follow in the Event of a Data Breach: Phase 3 (When the Risk to Individuals Is High)

    Individuals must be notified promptly

    • As a result of the risk assessment, in cases where there is a “high risk of infringing on an individual’s freedoms or rights,” the organization is required to notify the individual using appropriate means, such as SMS or direct messages, so that the individual can understand the risks they may face due to the data breach.

    So far, we have outlined the steps companies should take when a data breach occurs.

    What penalties might apply if a data breach is reported late?

    From the perspective of those involved in day-to-day business operations, while you may now understand the procedures to follow in the event of a data breach, you’re probably wondering what penalties would be imposed if a breach report is delayed or if other obligations are not met.

    In this article, we will present a case involving penalties imposed on the U.S.-based company Argon Medical Devices in Norway as a reference example.

    In this case, the company was required to report the data breach within 72 hours of its discovery, but failed to do so for 67 days, ultimately resulting in a fine of 2.5 million kronor (approximately 42.6 million yen).

    The incident began when a cyberattack between May 21 and June 14, 2021, resulted in the leakage of employee data within Europe, including Norway. The attack allowed unauthorized third parties to access employee data; however, when the breach was discovered on June 14, the company conducted an investigation assuming that only its U.S. headquarters had been affected.

    Subsequently, during the investigation, it was discovered on July 19 that a data breach had also occurred within the European Union. After conducting an assessment of the breach in accordance with the GDPR, the final report was not completed until September 24.

    In this case, although the Norwegian regulatory authority had requested additional information even after July 19, the company ultimately submitted its report on September 24, significantly exceeding the 72-hour deadline; this became the key point of contention regarding whether a fine should be imposed.

    From a practical standpoint, the following points can be learned from this case.

    1. Design appropriate procedures for identifying information leaks and reporting them

      - Although the company in question had designed procedures for reporting data breaches after fully assessing the circumstances of each incident, its internal systems were not structured in compliance with regulations, even though it was required to file the necessary reports within the limited timeframe of 72 hours.

    2. We will continue to report data breaches while implementing countermeasures.

      - By submitting reports within 72 hours, companies can obtain the necessary information from regulatory authorities, allowing both parties to understand the current situation.

    3. Even companies outside Europe should understand that a data breach involving the personal information of individuals in Europe could pose a risk to those individuals.

      - Since complying solely with U.S. and Japanese laws could result in delays in reporting data breaches, countermeasures should be implemented in accordance with procedures tailored to local regulations.

    Although we presented this as a case of a U.S. company violating the GDPR, it is important to exercise extreme caution, especially when a company’s headquarters or offices are located outside Europe and the headquarters is responsible for decision-making regarding European operations, as this can lead to delays in reporting and responding to data breaches.

    Let's take a look at the reporting templates published by European governments.

    So far, we have outlined the procedures for responding to data breaches and discussed actual cases where fines were imposed. From a practitioner’s perspective, I believe the biggest challenge when a data breach occurs is determining exactly what information to report.

    The European Data Protection Board is soliciting public comments on the template for reporting to national regulatory authorities within the European Union for the period from June 10 to August 5 of this year (this template has not yet been officially adopted; updates are expected following a review of feedback from national regulatory authorities).

    This template (as of the public comment period: published on June 10, 2026) consists of 126 items and 7 sections, and outlines the rationale for the reporting requirements for each item.

    The following table summarizes the information that should be included in each of the seven sections.

    Section

    Details of the Implementation

    1. Information That Must Be Reported in the Event of a Data Breach

    When submitting a leak report, indicate whether it is an initial report, a follow-up report, or a final report. In addition, include the report ID, which the regulatory authority needs to cross-reference with previous reports.

    2. Information on the Data Manager and Reporter

    This section provides information about the company submitting the report, as well as the industry and business operations to which it belongs. It also includes information about the person responsible for the report.

    3. Initial Information Required for Reporting a Data Breach

    Provide detailed information regarding the date and time of the data breach, the nature of the information involved, and the circumstances of the breach. Additionally, if the cause of the data breach is known at the time of the initial report, include information regarding the circumstances surrounding the breach, the extent of the damage caused, and the affected individuals.

    4. Additional Information Required for Data Breach Reports

    This section outlines the results of a risk assessment regarding the potential impact of a data breach on the affected individuals. In addition, it describes the measures that will be implemented in the event of a future breach.

    5. Communication with Individuals Whose Information Has Been Compromised

    Describe the measures you have in place regarding how you communicate with the individual in question when there is a possibility that the individual’s rights may be infringed.

    6. Other Issues

    If reports have been filed with entities other than data protection regulators, describe those circumstances as well. Additionally, if a data breach has occurred across national borders, describe the circumstances of the cross-border breach.

    7. Reference Attachments

    I am attaching documentation proving that a data breach occurred, as well as email correspondence with the individual in question.

    A review of the items in the reporting template reveals that while they are divided into initial and ongoing responses, the template also requires a description of the measures taken regarding the individual in question. From a practical standpoint, companies need to establish a system that allows them to assess the impact of a data breach as early as possible and report it to all relevant parties.

    Furthermore, when reporting additional information, it is essential to ensure that no required items are overlooked. To this end, it is necessary to establish a system in advance—during normal operations—that allows for a quick assessment of the situation in the event of a data breach, based on a clear understanding of the required reporting items.

    So far, we have discussed the “72-hour rule” required under the GDPR and practical measures for compliance. Even for Japanese companies, if the affected individuals are located in Europe, they must comply with the requirements of local regulations; therefore, we recommend that you first review the template and assess the extent to which your company’s data breach reporting system is currently in place.

    Reference Materials


    Author of this article

    Privacy Expert

    Kohei Kurihara

    While in college, he worked at a politician’s office and joined Rakuten after graduation. After two years in sales, he started his own business. He supports the expansion of foreign digital services into Japan and the global expansion of Japanese services. Since 2017, he has served as the Japan representative for the U.S.-based nonprofit Government Blockchain Association.

    Since then, while involved in founding startups, he has spoken at international conferences—including those organized by UNESCO—on blockchain-related topics. In 2020, he established the general incorporated association Privacy by Design Lab, where he focuses on advocacy for privacy and works to create international platforms for dialogue. His areas of expertise include data protection (personal information protection), digital marketing, and blockchain. He runs “Privacy Talk,” an interview-based media platform that features direct conversations with leaders in the privacy industry both in Japan and abroad.

    Share this article

    Facebook Share ButtonX Share Button
    Backspace key

    List of Helpful Articles