Article 33 vs Article 34
Last reviewed: · By Victor Humenhuk (CIPP/E certified)
Article 33 requires a controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. Article 34 requires the controller to communicate the breach to the affected individuals themselves, but only where it is likely to result in a high risk, and without any fixed hour count beyond 'without undue delay'. The two provisions therefore differ on three axes: who is told, what risk threshold applies, and how fast. Processors do not notify the authority under Article 33(1); under Article 33(2) they notify their controller without undue delay.
Article 33 vs Article 34 side by side
| Feature | Article 33 | Article 34 |
|---|---|---|
| Who is told | The competent supervisory authority | The affected data subjects |
| Threshold | Unless unlikely to result in a risk to rights and freedoms | Only where likely to result in a high risk |
| Deadline | Without undue delay and where feasible within 72 hours of awareness | Without undue delay - no fixed hour count |
| Who does it | The controller; the processor notifies the controller (Art 33(2)) | The controller |
| Content | The four items in Art 33(3) | The nature of the breach in clear and plain language, plus Art 33(3)(b), (c) and (d) |
| Exemptions | None beyond the risk threshold; reasons required if later than 72 hours | The three grounds in Art 34(3) |
| Record-keeping | Article 33(5) - document every breach, whether or not notified | Same internal record |
When are you 'aware' and how do the 72 hours run?
A personal data breach is defined in Article 4(12) as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. It covers confidentiality, integrity and availability breaches alike - ransomware that only encrypts data, with no exfiltration, is still a breach.
The EDPB's breach notification guidelines treat a controller as aware once it has a reasonable degree of certainty that a security incident has occurred leading to personal data being compromised. A short initial investigation to establish that certainty is acceptable, and the clock starts at the end of it, not when a vague alert first appeared. Once it starts, it runs continuously: weekends and public holidays are included.
Two safety valves exist. Article 33(1) allows notification later than 72 hours provided it is accompanied by reasons for the delay, and Article 33(4) allows information to be provided in phases where it is not all available at once. Neither is a licence to wait until the investigation is complete.
What must each communication contain?
Article 33(3) fixes the content of the notification to the authority:
- The nature of the breach, including where possible the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned.
- The name and contact details of the data protection officer or other contact point where more information can be obtained.
- The likely consequences of the breach.
- The measures taken or proposed to address the breach, including where appropriate measures to mitigate its possible adverse effects.
Article 34(2) requires the last three of those items and adds a presentational requirement: the nature of the breach must be described to individuals in clear and plain language. In practice the communication to individuals should also tell them what to do - change a password, watch for phishing, contact their bank - because the purpose of Article 34 is to let people take protective action.
When can you avoid telling individuals?
Article 34(3) sets out three grounds, and the burden of showing one applies rests on the controller.
- Article 34(3)(a) - appropriate technical and organisational protection measures were applied to the affected data, in particular measures that render it unintelligible to anyone not authorised to access it. Strong, current encryption with an uncompromised key is the standard example.
- Article 34(3)(b) - subsequent measures ensure the high risk is no longer likely to materialise, for example the recipient of a misdirected file is identified and the data is verifiably deleted.
- Article 34(3)(c) - communication would involve disproportionate effort, in which case a public communication or similar equally effective measure must be used instead.
Two caveats. Article 34(4) lets the supervisory authority require communication after considering the likelihood of high risk, so the decision is never entirely yours. And encryption is not a universal answer: where the breach is a loss of availability, such as the destruction of the only encrypted copy, the data being unintelligible to an attacker does nothing for the individuals whose data has gone.
Whatever you decide, Article 33(5) requires every breach to be documented internally, with the facts, effects and remedial action, so the regulator can verify your reasoning after the event.
Related study notes
- Article 33 - notifying the supervisory authority
- Article 34 - communicating the breach to data subjects
- Article 33 vs Article 34 - side-by-side comparison
- Module 9 · Data breach notification (Articles 33 and 34)
- Risk reporting and the meaning of 'personal data breach'
Frequently asked questions
Does every breach have to be reported to the supervisory authority?
No. Notification is required unless the breach is unlikely to result in a risk to the rights and freedoms of individuals, so genuinely trivial incidents are not notified. Every breach must still be recorded internally under Article 33(5), including the reasoning for not notifying.
Do the 72 hours include weekends and holidays?
Yes. It is 72 clock hours from awareness, not three working days. If you cannot notify in time you may notify late, but the notification must then be accompanied by reasons for the delay.
Does a processor notify the supervisory authority?
No. Article 33(2) requires the processor to notify the controller without undue delay after becoming aware. The controller then decides whether Article 33 and Article 34 are triggered. Article 28(3) contracts commonly tighten the processor's deadline to a fixed number of hours.
Is encryption an automatic exemption from telling individuals?
No. It works under Article 34(3)(a) only where the encryption actually renders the data unintelligible to the unauthorised party - a current algorithm, properly implemented, with a key that was not itself compromised. It also does nothing for availability breaches where the encrypted data has been lost or destroyed.
Test yourself
Try the free CIPP/E practice questions, or read the full CIPP/E study guide - free.