
Data Breach: What to Do Within 72 Hours According to GDPR?
Every company will eventually face a data breach. GDPR requires notification to the DPA within 72 hours. Here is a step-by-step incident response plan.
Author: Meiko Neuman
Founder and web strategist, Kodulehe Haldus
What is a data breach?
GDPR Article 4(12) defines it as: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Examples: - Hacking and database theft - An employee losing a laptop - An email sent to the wrong recipient - Ransomware encrypting data - Misconfiguration (public S3 bucket) - Plugin vulnerability (read our website security guide)
Statistics
IBM 2024 Cost of Data Breach Report: - Average cost: $4.88M - Mean time to identify: 194 days - Identification + containment: 277 days
In Estonia, the Data Protection Inspectorate (AKI) reported 312 breaches in 2024 (AKI Annual Report).
The 72-hour rule
GDPR Article 33: notify the relevant supervisory authority (in Estonia, AKI) within 72 hours after becoming aware of the breach.
Exceptions: - A risk to the rights and freedoms of individuals is unlikely (notification is not required) - However, when in doubt, always report – supervisory authorities prefer proactive disclosure
Action Plan
Hour 0-1: Identify - Who noticed? What exactly happened? - Which systems are affected? - Is the leak ongoing? **Stop it immediately.**
Hour 1-4: Containment - Shut down affected systems - Change passwords, API keys, and certificates - Isolate compromised servers from the network - Save a copy of logs (for forensics)
Hour 4-24: Assessment What data has been leaked? - Names, contact details? → low risk - Passwords (unencrypted)? → high risk - Bank cards, ID codes? → very high risk - Health data, sexual orientation, religion (special categories)? → critical
How many people are affected?
Hour 24-72: Notify the Supervisory Authority
Form: www.aki.ee → Data breach notification
You must provide: 1. Nature of the breach (what happened) 2. Categories and number of affected individuals 3. Likely consequences 4. Measures taken or proposed to be taken 5. DPO or point of contact
Day 1-3: Notify Users
GDPR Article 34: if the risk is high, notify the affected users directly.
Template:
`
Dear Customer,
On [Date], we identified a security breach in [which system]. Affected data: [list]. What we have done: [list, e.g., password resets]. What you should do: [specific steps].
We apologise and are continuing our investigation. Questions: [contact].
`
Day 3+: Deep Investigation - Hire a [DFIR](https://www.cisa.gov/) expert (digital forensics & incident response) - Full log analysis - Root cause analysis - Action plan to prevent recurrence
What can increase the fine?
- Delayed notification (over 72h without justification)
- Failure to notify users
- Repeated violations
- Missing basic security measures (HTTPS, backups, strong passwords)
Fines: up to €20M or 4% of global turnover.
What can mitigate the fine?
- Rapid and correct notification
- Cooperation with the supervisory authority
- Technical measures were in place
- Encrypted data (often notification is not even required if data is unreadable)
Preparation in Advance
What to do before a breach occurs:
- Data inventory – where is everything located?
- Roles and responsibilities – who does what?
- Contact list – DPA, lawyer, IT, PR
- Encryption at rest and in transit
- Backups and recovery drills
- Tabletop exercises – at least once a year
Further Reading
We can help with security audits and incident response planning – check out our website security services and get in touch.
Need help with your website?
Our team maintains, optimises and protects your website. Pricing is agreed based on scope.
Request a quoteAbout the author
Meiko Neuman — Founder and web strategist, Kodulehe Haldus. Meiko leads the Kodulehehaldus team and has spent over a decade helping companies maintain and optimise their websites for measurable business results. He writes about website management, SEO, AEO/GEO and the commercial side of the web.