Skip to content
Data protection

Data Breach on Your Website: The 72-Hour Clock

When the 72-hour clock starts after a data breach, what belongs in the report to the supervisory authority, when the people affected have to be told, and what has to be documented beforehand.

14 min read DSGVODatenschutzBetriebsablauf

A contact form has been sending enquiries to a closed mailbox for three weeks. An editor account is taken over. A supplier reports that its systems were encrypted and that your customer list was inside. In all three cases, a deadline of no more than 72 hours starts the moment you know with reasonable certainty what happened (European Data Protection Board). This is not a large-corporate topic: the German federal data protection authority received 9,170 breach reports in the 2025 reporting year (BfDI), and Bavaria alone counted 3,603 breach notifications (BayLDA). This article sets out when the clock starts, what belongs in the report, when the people affected have to be told as well, and which part of the preparation sits on your own website.

Four steps, one clock: from awareness to notificationWhat gets recorded at each step - and when the 72 hours run outHour 0Awareness: the incident is confirmedOn the record: date, time, who reported it, how it surfacedHours 0 to 72Assessment: judge the risk to individualsOn the record: data categories, people affected, likely consequencesBy hour 72Notification to the supervisory authorityOn the record: nature of the breach, numbers affected, measures takenWithout undue delayInforming the people affectedOn the record: plain language, named contact, recommended steps9,170 data protection breach reports at the federal authority in 20253,603 breach reports in Bavaria, up 23 percent on the year (BayLDA)Deadlines under Articles 33 and 34 GDPR (European Data Protection Board, Guidelines 9/2022)

The clock starts at awareness, not at the end of the investigation

The rule sits in Article 33 of the General Data Protection Regulation and is shorter than its reputation. The controller notifies a personal data breach to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (European Data Protection Board). Two things follow. Reporting is the default and staying silent is the exception that needs a reason. And the deadline is a ceiling, not a working period: if you know after six hours what happened, you report after six hours.

The harder part is when the clock starts. The European Data Protection Board places it at the moment the controller has a reasonable degree of certainty that a security incident has occurred that has led to personal data being compromised (European Data Protection Board). That is neither the first vague suspicion nor the end of the investigation. Seeing an odd error message on Friday is not awareness. Reading the access logs on Monday and finding that an unknown device has been reading the mailbox for two weeks is. From that Monday the 72 hours run, even if the full list of affected messages only arrives later.

Missing the deadline does not void it; it makes it explainable. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay (European Data Protection Board). A late report with a sound reason therefore beats no report at all. It also means the explanation becomes part of the file and will be read if there is any doubt. Stating that the supplier only released the log data on Monday is a reason. Being on holiday is not.

The start of the deadline is a timestamp, not a feeling

Record the moment awareness occurs: date, time, who reported it, how it surfaced. Three lines in a file are enough. Without that timestamp you can neither show that the report was timely nor explain why it was not. If you keep your website provider contract and access rights in order, you will reach the logs that prove the timestamp much faster in that first hour.

How common a data breach actually is

Reporting has become routine. The German Federal Commissioner for Data Protection and Freedom of Information received 9,170 data protection breach reports in the 2025 reporting year (BfDI), of which 9,110 were made under Article 33 GDPR (BfDI). Its remit is narrow, covering federal bodies, postal services and telecommunications; businesses that run their own website report to a state authority instead. That the supervisory side does more than count is clear from a second figure in the same report: 129 supervisory measures such as warnings, orders or the imposition of penalty payments in the same year (BfDI).

At state level the numbers are larger and the direction is identical. The Bavarian Data Protection Authority received 3,603 breach notifications in 2025 (BayLDA), up 23 percent on the previous year (BayLDA). Baden-Wuerttemberg reports a rise in breach notifications of nearly 20 percent for the same year and almost a doubling of complaints from 4,034 to 7,673 (LfDI Baden-Württemberg). In North Rhine-Westphalia total submissions rose to 18,062 (LDI NRW), with data protection complaints inside that figure climbing from 7,539 by more than 67 percent to 12,592 (LDI NRW).

Scroll table sideways

Supervisory authorityFigure from the 2025 reporting yearWhat it means for a small business
Federal Commissioner for Data Protection9,110 reports under Article 33 GDPR (BfDI)Reporting is a routine process, not a scandal
Federal Commissioner for Data Protection129 supervisory measures (BfDI)The authority does not only count, it also acts
Bavarian Data Protection Authority3,603 breach notifications, up 23 percent (BayLDA)The state authority also handles thousands of reports a year
State Commissioner Baden-WuerttembergBreaches up nearly 20 percent (LfDI Baden-Württemberg)The rise is not a Bavarian peculiarity
State Commissioner North Rhine-Westphalia18,062 submissions, 12,592 of them complaints (LDI NRW)People affected complain sooner and more often
State Commissioner North Rhine-WestphaliaFines close to half a million euros (LDI NRW)A breach rarely stays without consequences

None of this calls for panic; it calls for a realistic expectation. An authority handling several thousand reports a year looks for patterns, not for culprits. It much prefers a short, sorted report with clear facts to a long explanation, and it sees the same businesses again when the cause is left in place. If you already answer GDPR subject access requests cleanly, you have built the records this process needs anyway.

The most common trigger is not an attack

Most people picture an external attack when they hear data breach. Supervisory authorities see something else. The state commissioner in Baden-Wuerttemberg records for 2025 that misdirected letters and their attachments formed a focal point of the breach notifications received under Article 33 GDPR (LfDI Baden-Württemberg). That is the group email to sixty addresses in an open field, the quote in the wrong envelope, the mail merge with a shifted address block. It costs neither an attacker nor malware, only two inattentive minutes, and it is reportable like any other breach as soon as there is a risk to the people affected.

Attacks are plentiful alongside. The Bavarian authority received 524 reports in 2025 in which controllers or their suppliers were hit by ransomware (BayLDA). Just under 400 reports concerned hijacked cloud platforms and email accounts (BayLDA). The second case is the underrated one: from a compromised mailbox, between 1,000 and 10,000 further accounts were written to in many cases, including those of other organisations (BayLDA). Your own breach then becomes your business partners' breach, and your company sits in the sender field. How to protect business correspondence is covered in business email deliverability.

Form pointing at the wrong address

After a provider change the contact form recipient leads nowhere or into a stranger's mailbox. It usually only becomes noticeable weeks later.

Directory without access control

A folder with quotes, applications or invoices sits on the web without a login and turns up in a search engine.

Hijacked account

An editor account without a second factor is taken over. The attacker reads along long before changing anything.

Injected script

A manipulated script in the page head skims form entries. The form keeps working, so nothing looks wrong at first.

Breach at a supplier

The host or the booking system reports an incident. Responsibility for notifying the authority still rests with your business.

Old data still sitting around

Applications from three years ago, a newsletter export on a laptop, a backup without a deletion date. What is deleted cannot leak.

The German Federal Office for Information Security measures the overall scale of data loss. In the reporting period from July 2024 to June 2025, 461 data leaks involving German institutions and consumers became known (BSI). Among the categories affected were dates of birth in 92 percent of cases, postal addresses in 72 percent and email addresses in 63 percent (BSI). The number of leak victims counted per quarter reached an all-time high of 78 in the first quarter of 2025 (BSI), while ransomware attacks reported to the federal police stayed largely unchanged at 950 (BSI). Across Europe, the EU cybersecurity agency analysed 4,875 incidents for the same period (ENISA); Germany is the most frequently named member state in them at 23.4 percent (ENISA).

Your form collects exactly the fields that show up in the leaks

Name, postal address, email address and occasionally a date of birth: that is the field list of an ordinary contact form and, at the same time, the list of data categories that appeared most often in the leaks that became known (BSI). The most effective precaution follows from that, and it is not technical. A field you do not collect cannot leak, cannot end up in a report and cannot trigger a notification. If you cut your contact form back to the fields you actually need in order to reply, you lower the odds of ever filing a report before any safeguard has to work.

Four steps: awareness, assessment, notification, informing people

The regulation does not name escalation levels, but the process has four. They interlock, and each step produces a fact that the next one needs. Once these four steps exist on a single sheet of paper, nobody loses time asking who decides what.

  • Awareness. An incident has been identified and classified with a reasonable degree of certainty as affecting personal data (European Data Protection Board). Record the date, the time, who reported it and how it surfaced. The deadline runs from here.
  • Assessment. Which data categories, which group of people, which possible consequences? That determines whether you report at all: breaches are reportable only where there is a risk to the rights and freedoms of the people affected (BayLDA).
  • Notification to the supervisory authority. Within no more than 72 hours (European Data Protection Board), usually through the online form of the competent state authority. A missing detail is filed later rather than waited for.
  • Informing the people affected. Only where a high risk is likely, and then without undue delay and in clear, plain language. This step is the visible one: it reaches customers, applicants and business partners directly.

The line between step two and step four carries most of the uncertainty. One question shortens it: what could happen to an individual with this data? For a lost appointment list holding first names, the answer is short. For an applicant list with a postal address, a date of birth and details of previous employment, it is not. How to take in applicant data with deadlines and deletion rules is covered in taking job applications online.

Scroll table sideways

StepDeadlineRecipientIf the deadline slips
Record awarenessimmediatelyyour own fileThe start of the deadline cannot be evidenced later
Assess the riskwithin the 72 hoursyour own fileThe report goes out without an assessment
Notification under Article 33 GDPRno more than 72 hours (European Data Protection Board)competent supervisory authorityThe notification has to be accompanied by reasons for the delay (European Data Protection Board)
Informing people under Article 34 GDPRwithout undue delaythe people affectedThe authority can order the communication
Early warning under the German BSI Act24 hours after becoming aware (BSI)Federal Office for Information SecurityApplies to regulated entities only
Final report under the German BSI Actone month after the report at the latest (BSI)Federal Office for Information SecurityApplies to regulated entities only

What belongs in the report

The authorities' reporting forms follow the structure of Article 33(3) GDPR. They ask for four blocks, and none of them requires technical vocabulary. If you noted the facts during the assessment phase, filling in the form takes twenty minutes.

  • Nature of the breach. What happened, in one sentence, plus the categories and the approximate number of people and records concerned.
  • Contact point. Name and contact details of the place where more information can be obtained. In a small business that is the management, not the supplier.
  • Likely consequences. What the incident may mean for the people affected: unwanted advertising, identity misuse, inferences about sensitive data.
  • Measures taken. What you did to address the breach and mitigate its effects. Account locked, address corrected, recipient asked to delete.
  • If delayed: the reason. Why the report took longer than 72 hours (European Data Protection Board).
  • The timestamp of awareness. Without it the authority cannot judge whether the report was timely, and it will ask.

Speed before completeness

The German Federal Office for Information Security sums up its reporting principle for significant security incidents in three words: Schnelligkeit vor Vollständigkeit - speed before completeness (BSI). The data protection report follows the same logic: where information is still missing, it may be supplied in stages. A report with three open points and a date for the follow-up serves the people affected better than a polished report five days later. Anyone who already keeps an eye on downtime and availability notices an incident earlier and wins exactly the hours that make this deadline tight.

You also document what you do not report

The quietest duty in the regulation is the one an inspection catches first. The controller documents breaches of the protection of personal data, comprising the facts relating to the breach, its effects and the remedial action taken, and that documentation has to enable the supervisory authority to verify compliance (European Data Protection Board). This applies to every breach, including the ones you deliberately do not report after your risk assessment. If you document nothing, you cannot show that not reporting was a reasoned decision rather than an omission.

incident-2026-03-14.txt
Incident          2026-03-14  contact form pointed at a closed mailbox
Awareness         2026-03-14  09:20, reported by the accounts team
How it surfaced   customer asked again, no reply had arrived
Period            2026-02-21 to 2026-03-14
Data              name, email, postal address, free-text message
Affected          approx. 40 people, 41 records
Recipient         mailbox at the previous provider, switched off
Risk              low: no retrieval evidenced, mailbox inactive
Decision          no Article 33 report, documented under para. 5
Remedy            address corrected, test submission checked
Sign-off          management, 2026-03-14 11:05

Breaching the reporting and documentation duties falls into the lower fine bracket of the regulation. Infringements of Articles 25 to 39 are subject to administrative fines of up to 10 million euros or up to 2 percent of total worldwide annual turnover, whichever is higher (Article 83(4) GDPR). For a trade or retail business the percentage is the more relevant figure, and authorities as a rule do not exhaust the bracket with cooperative businesses. The number still belongs here, because it explains why a three-line note on the day of the incident is a sound investment.

When the people affected have to be told

The second communication does not go to an authority but to people. It becomes due when the breach is likely to result in a high risk to personal rights and freedoms. The yardstick is the same as for the report to the authority, set one level higher. The Bavarian authority states the lower bound plainly: breaches are reportable only where there is a risk to the rights and freedoms of the people affected by the incident (BayLDA). No risk, no report; no high risk, no communication.

In practice this is the part that decides reputation. The communication reaches customers, applicants and suppliers, and it gets passed on. A text that names the incident, puts the consequences in proportion and gives one concrete recommendation reads as seriousness; one that plays things down gets quoted back at you. That text is better written beforehand than on the night after, and it belongs on the same page as your imprint and privacy policy.

  • What happened, in plain language. One sentence without jargon, plus the period and the data categories.
  • What it means for the individual. Concrete rather than abstract: what to expect and what not to expect.
  • What you have done. Account locked, address corrected, supplier replaced.
  • What the person should do. Change a password, watch for unusual post, check bank statements.
  • Who is reachable. Name, phone number and address for questions, for a few days outside office hours too.
  • Where to read the current status. A plain page on your own website carries further than a mass email with an attachment.

The second clock: for regulated entities

A shorter deadline runs alongside the data protection one, and it does not apply to everyone. For entities covered by the German BSI Act in its version implementing the European network and information security directive, the early warning for a significant security incident is due within 24 hours of becoming aware of it (BSI). The chain does not end there: a final report is due at the latest one month after the notification (BSI).

For a typical trade, retail or service business with a website this second clock as a rule does not apply. The distinction still matters, because it shows up in contracts. Anyone working as a subcontractor for an energy utility, a hospital or a logistics operator increasingly finds 24-hour reporting deadlines in framework agreements that bind contractually, regardless of their own classification. If you bid for public sector contracts, read those clauses before you submit, because they take effect with the award.

What the website can do beforehand

The most effective precaution is collecting less, and it costs nothing. A form with four fields produces a smaller incident than one with fourteen. An application process with a clear deletion date produces none at all after two years. And a site that works without a cookie banner because it is built data-minimal has fewer data paths to document when something goes wrong.

Technically the picture on the web is mixed. Transport is largely solved: 97.3 percent of home pages requested on mobile run over HTTPS (Web Almanac). The rest is not. Only 21.9 percent of pages set a Content Security Policy at all (Web Almanac), the rule that would stop an injected script from skimming form entries. Of the pages that do set one, 92 percent still allow unsafe-inline and largely undo the protection (Web Almanac). And only 36 percent of pages requested on mobile send an HSTS header (Web Almanac), which keeps the very first request off an unprotected detour.

  • The contact form collects only the fields needed to reply; every additional field has a named purpose.
  • The recipient address of the form is documented and checked with a test submission after every provider change.
  • Editor accounts are personal, carry a second factor and are withdrawn when someone leaves; the roles and permissions are written down.
  • Every supplier with data access has a data processing agreement in place, including a reporting route and a response time for incidents.
  • Embedded third-party content is known and justified; how to do that without silent data flows is covered in maps, videos and fonts.
  • The attack surface of the site is deliberately kept small: little foreign code, few accounts, few data stores.
  • An incident sheet exists as a file, with the fields from the example above and a named responsible person.
  • The link to the reporting form of the competent supervisory authority is stored, so nobody has to search for it inside the deadline.

These eight points take a morning and last for years. The difference between a business that files a report in two hours and one that needs three days lies almost entirely in this preparation. A look at the services overview shows which part of it belongs to building a site and which part to running it.

When it matters, what counts is not how good your technology was, but how quickly you can say what happened.

The first hours in five steps

When it happens, a short sequence helps more than a manual. The following five steps can be worked through by one person who is not an information security specialist.

  • Stop it and write it down. Lock the account, switch off the form, correct the address. In the same move, note the date, the time and how it surfaced, because the 72 hours run from that timestamp (European Data Protection Board).
  • Estimate the scope, do not investigate it. Which data categories, how many people, what period? A reasoned estimate is enough for the report; the exact number is filed later.
  • Assess the risk and decide. If there is a risk to the people affected, you report (BayLDA). If a high risk is likely, informing those people comes on top.
  • Report, gaps and all. Fill in the online form of the competent state authority and mark open points as open. The principle is speed before completeness (BSI).
  • Fix the cause and document it. The remedy belongs in the same file as the awareness entry, because the documentation has to enable the authority to verify compliance (European Data Protection Board). If you want support building the site and its data paths, the way in is the contact page.

Sources and studies

This article draws on Guidelines 9/2022 of the European Data Protection Board on personal data breach notification, which reproduce the wording of Article 33 GDPR, and on Article 83(4) GDPR. The reporting figures come from the 34th activity report of the German Federal Commissioner for Data Protection and Freedom of Information, the 15th activity report of the Bavarian Data Protection Authority, the 41st activity report of the State Commissioner for Data Protection in Baden-Wuerttemberg and the 31st activity report of the State Commissioner for Data Protection and Freedom of Information in North Rhine-Westphalia, each covering the 2025 reporting year. Figures on data leaks, ransomware and the reporting deadlines under the German BSI Act come from the 2025 report on the state of IT security in Germany and the information packages of the Federal Office for Information Security; the Europe-wide incident counts come from the ENISA Threat Landscape 2025. The adoption figures for HTTPS, Content Security Policy and HSTS come from the security chapter of the Web Almanac 2025. None of this replaces legal advice on an individual case.