Data breach notification

The duty to report a personal data breach to the supervisory authority within 72 hours of becoming aware of it, and to the people affected when the risk to them is high (GDPR Articles 33 and 34).

A controller must notify without undue delay and, where feasible, within 72 hours, unless the breach is unlikely to result in a risk to people’s rights and freedoms. A processor must notify the controller without undue delay after becoming aware of a breach (Article 33(2)). Data processing agreements usually turn that into a specific deadline, such as 48 or 72 hours, and a change to it is worth catching.

Source: GDPR Arts. 33–34 ↗

ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.