Data Breach Response: The First 72 Hours
For organisations: what the law requires between discovering a breach and the DPC's 72-hour deadline — and how to do it without panic.
A personal data breach is a security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. The misdirected email counts. The stolen laptop counts. The ransomware event counts. So does the employee looking at records they had no business opening.
The legal machinery that follows is short and unforgiving: assess the risk, notify the Data Protection Commission within 72 hours of becoming aware unless the breach is unlikely to result in a risk to individuals, tell the affected people without undue delay where the risk is high, and record everything. Organisations that have rehearsed this do it calmly; organisations that have not lose the first two days to confusion. Our free checklist tool walks the sequence interactively.
Hour zero: contain and preserve
Before any notification question, two operational priorities: stop the breach continuing (disable the account, recall the email where possible, isolate the system, change the credentials) and preserve the evidence (logs, the offending email, access records, timestamps). Containment limits the harm; preservation makes the risk assessment and any later regulatory engagement honest and answerable.
Identify a single owner for the incident immediately. The 72-hour clock does not pause for internal diary alignment.
The risk assessment that drives everything
Notification duties turn on risk to individuals, not embarrassment to the organisation. Assess: what data (contact details versus financial or health data), whose data and how many people, what exposure (sent to one trusted recipient who confirmed deletion, or exfiltrated by an attacker), and what could realistically follow (fraud, identity theft, distress, physical risk in sensitive contexts).
Document the assessment even when you conclude no notification is required — 'unlikely to result in a risk' is a judgment you may need to defend later, and the record of reasoning is your defence.
Notifying the DPC within 72 hours
Unless the breach is unlikely to result in a risk to individuals, the controller must notify the DPC without undue delay and where feasible within 72 hours of becoming aware — awareness meaning a reasonable degree of certainty a breach has occurred, not completed forensics. The notification covers the nature of the breach, categories and approximate numbers of people and records, likely consequences, and measures taken or proposed.
Two features stop the deadline being a trap: notification can be made in phases as facts emerge, and a late notification can be made with reasons for the delay. A prompt, candid, phased notification is always the better position than a perfect one delivered late.
Telling the people affected
Where the breach is likely to result in a high risk to individuals, they must be told without undue delay, in clear plain language: what happened, what data was involved, what the organisation is doing, and what they can do to protect themselves (password changes, fraud alerts, vigilance for phishing). Exceptions exist — for example where measures like strong encryption render the data unintelligible — but the default in high-risk cases is direct, useful communication.
The communication is also where legal exposure is shaped: an honest, protective notice serves affected people and reads well later; a minimising one does neither.
The breach register and the aftermath
Every breach — notified or not — must be documented internally: the facts, effects and remedial action. This register is what the DPC asks for first in any inspection, and a well-kept one demonstrates exactly the accountability the law requires.
After the incident: fix the root cause, retrain where the cause was human (misdirected email remains the perennial), review processor contracts if a vendor was involved (processors must notify controllers without undue delay), and expect correspondence — access requests and claims from affected individuals follow breaches, and the file you built in the first 72 hours is what answers them.
Frequently asked questions
Does every breach have to be reported to the DPC?
No — notification is required unless the breach is unlikely to result in a risk to individuals. But every breach must be internally documented, including the reasoning where you decide not to notify.
When does the 72-hour clock start?
When the controller becomes aware of the breach — a reasonable degree of certainty that an incident has occurred. You do not need completed forensics to notify; phased notification as facts emerge is expressly contemplated.
We missed the 72 hours. What now?
Notify anyway, with the reasons for the delay. A late, candid notification with good containment is a defensible position; discovered non-notification is not.
Do we have to tell the affected individuals?
Where the breach is likely to result in a high risk to them, yes — without undue delay, in plain language, with practical protective advice. Exceptions apply where measures such as encryption neutralise the risk.
Our IT provider caused the breach. Whose problem is it?
A processor must notify the controller without undue delay, but the controller owns the DPC notification and the communication to individuals. Your contract with the provider should govern cooperation and liability — and is worth reviewing after any incident.
Related pages
Talk to a GDPR solicitor
Mary Molloy Solicitors acts for individuals and organisations across Ireland on data protection matters — access requests, breaches, compensation claims, complaints and compliance. All enquiries are handled through our Dublin office.
Contact us — 01 5827148This page contains general information about Irish law and practice. It is not legal advice, it may not reflect your circumstances, and reading it does not create a solicitor–client relationship with Mary Molloy Solicitors. We do not advise on taxation; please speak to your accountant or Revenue. In contentious business, a solicitor may not calculate fees or other charges as a percentage or proportion of any award or settlement.