Law note · Germany

GDPR Articles 33-34, Breach Notification in Germany

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2018-05-25 reviewed 2026-08-24

A controller must notify the competent Landesdatenschutzbehorde, or the BfDI for the federal public sector and telecommunications and postal providers, without undue delay and within 72 hours where feasible, after becoming aware of a personal data breach, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No BDSG derogation from this timeline was identified.

What it asks of an app

  • Notify the competent German data protection authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Germany, unless the breach is unlikely to risk their rights and freedoms.
  • Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

When LexLint raises it

Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics

Primary source: Official Journal text, EUR-Lex, Regulation (EU) 2016/679

← Back to the example  ·  Lint your app →