All tools › Breach 72-Hour Deadline Calculator

Breach 72-Hour Deadline Calculator

For EU GDPR and UK GDPR personal data breaches. Includes a live countdown.

The breach
Are you the controller or a processor?

How the 72-hour rule works

Under Article 33 of the GDPR, a controller must notify the supervisory authority of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it — unless the breach is unlikely to result in a risk to people. The 72 hours are calendar hours: weekends and holidays count.

If the risk to individuals is high, Article 34 also requires telling the affected people without undue delay. Processors must tell their controller without undue delay.

Frequently asked questions

Do weekends count in the 72 hours?

Yes. The deadline is 72 consecutive hours.

What if I don't have all the details yet?

Notify within 72 hours with what you know and provide the rest in phases (Article 33(4)).

Do I have to notify every breach?

No — only those likely to result in a risk to people. But you must record every breach internally.

Last reviewed 2026-10-09. Sources: official legal texts on EUR-Lex, legislation.gov.uk and the California Privacy Protection Agency.