Back to blog
    Header image for the article "Data Breach: What to Do Within 72 Hours According to GDPR?"
    WCAG & GDPR compliance06/06/20268 min

    Data Breach: What to Do Within 72 Hours According to GDPR?

    Every company will eventually face a data breach. GDPR requires notification to the DPA within 72 hours. Here is a step-by-step incident response plan.

    Author: Meiko Neuman

    Founder and web strategist, Kodulehe Haldus

    What is a data breach?

    GDPR Article 4(12) defines it as: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

    Examples: - Hacking and database theft - An employee losing a laptop - An email sent to the wrong recipient - Ransomware encrypting data - Misconfiguration (public S3 bucket) - Plugin vulnerability (read our website security guide)

    Statistics

    IBM 2024 Cost of Data Breach Report: - Average cost: $4.88M - Mean time to identify: 194 days - Identification + containment: 277 days

    In Estonia, the Data Protection Inspectorate (AKI) reported 312 breaches in 2024 (AKI Annual Report).

    The 72-hour rule

    GDPR Article 33: notify the relevant supervisory authority (in Estonia, AKI) within 72 hours after becoming aware of the breach.

    Exceptions: - A risk to the rights and freedoms of individuals is unlikely (notification is not required) - However, when in doubt, always report – supervisory authorities prefer proactive disclosure

    Action Plan

    Hour 0-1: Identify - Who noticed? What exactly happened? - Which systems are affected? - Is the leak ongoing? **Stop it immediately.**

    Hour 1-4: Containment - Shut down affected systems - Change passwords, API keys, and certificates - Isolate compromised servers from the network - Save a copy of logs (for forensics)

    Hour 4-24: Assessment What data has been leaked? - Names, contact details? → low risk - Passwords (unencrypted)? → high risk - Bank cards, ID codes? → very high risk - Health data, sexual orientation, religion (special categories)? → critical

    How many people are affected?

    Hour 24-72: Notify the Supervisory Authority

    Form: www.aki.ee → Data breach notification

    You must provide: 1. Nature of the breach (what happened) 2. Categories and number of affected individuals 3. Likely consequences 4. Measures taken or proposed to be taken 5. DPO or point of contact

    Day 1-3: Notify Users

    GDPR Article 34: if the risk is high, notify the affected users directly.

    Template: ` Dear Customer,

    On [Date], we identified a security breach in [which system]. Affected data: [list]. What we have done: [list, e.g., password resets]. What you should do: [specific steps].

    We apologise and are continuing our investigation. Questions: [contact]. `

    Day 3+: Deep Investigation - Hire a [DFIR](https://www.cisa.gov/) expert (digital forensics & incident response) - Full log analysis - Root cause analysis - Action plan to prevent recurrence

    What can increase the fine?

    • Delayed notification (over 72h without justification)
    • Failure to notify users
    • Repeated violations
    • Missing basic security measures (HTTPS, backups, strong passwords)

    Fines: up to €20M or 4% of global turnover.

    What can mitigate the fine?

    • Rapid and correct notification
    • Cooperation with the supervisory authority
    • Technical measures were in place
    • Encrypted data (often notification is not even required if data is unreadable)

    Preparation in Advance

    What to do before a breach occurs:

    1. Data inventory – where is everything located?
    2. Roles and responsibilities – who does what?
    3. Contact list – DPA, lawyer, IT, PR
    4. Encryption at rest and in transit
    5. Backups and recovery drills
    6. Tabletop exercises – at least once a year

    Further Reading

    We can help with security audits and incident response planning – check out our website security services and get in touch.

    Need help with your website?

    Our team maintains, optimises and protects your website. Pricing is agreed based on scope.

    Request a quote

    About the author

    Meiko Neuman Founder and web strategist, Kodulehe Haldus. Meiko leads the Kodulehehaldus team and has spent over a decade helping companies maintain and optimise their websites for measurable business results. He writes about website management, SEO, AEO/GEO and the commercial side of the web.

    Related articles