ArbeitlyArbeitly

22. juni 2026

GDPR Data Breach Response for SMEs: What to Do in the First 72 Hours

A data breach triggers a 72-hour notification clock under GDPR. Here's exactly what small businesses and freelancers must do to respond correctly and avoid penalties.

gdpr
data-breach
compliance
eu-law
privacy
G

Understanding Your GDPR Breach Obligations

Under GDPR Article 33, any personal data breach that poses a risk to individuals' rights and freedoms must be reported to your supervisory authority within 72 hours of becoming aware of it. This isn't 72 hours from when the breach occurred — it's from when you become aware of it. The distinction matters: delayed discovery does not extend your compliance window.

For many freelancers and small businesses, a "data breach" sounds like a corporate catastrophe, but it includes relatively mundane incidents: sending an email containing client personal data to the wrong recipient, losing a laptop containing unencrypted client files, a cloud storage service becoming temporarily accessible due to misconfigured permissions, or a phishing attack that compromises your email account.

Immediate Response: The First Four Hours

When you discover or suspect a breach, act immediately on four fronts. First, contain the breach if possible: change compromised passwords, revoke unauthorized access, remove publicly accessible files, or isolate affected systems. Second, preserve evidence: don't delete logs or attempt to "clean up" the incident before documenting what happened. Screenshots, access logs, and email records are your evidence.

Third, assess the scope: what personal data was involved, whose data was it, how many individuals are affected, what is the likely impact on those individuals? Fourth, determine whether the breach triggers notification obligations: not all breaches require notification. A breach that is "unlikely to result in a risk to the rights and freedoms of natural persons" can be documented internally without supervisory authority notification.

The 72-Hour Notification to Your Supervisory Authority

If the breach poses a risk to individuals, notify your national supervisory authority (the DPA in your country — for example, BfDI in Germany, CNIL in France, ICO in the UK) within 72 hours. Most authorities have an online breach notification portal. Your notification must include: the nature of the breach, categories and approximate number of affected individuals, likely consequences, and measures taken or proposed to address the breach.

If you can't provide complete information within 72 hours, submit an initial notification with what you know and indicate that further information will follow. Regulators understand that investigations take time and value early notification over perfect notification.

Notifying Affected Individuals

If the breach is likely to result in high risk to individuals — identity theft risk, financial risk, significant reputational harm — you must also notify the affected individuals directly without undue delay. The notification must describe the nature of the breach in clear language, provide contact details for your data protection point of contact, describe the likely consequences, and explain measures taken to address the breach and mitigate its effects.

Keep records of all client data you hold using your business management tools so that in a breach scenario you can quickly identify who is affected without days of investigation.

Post-Breach: Learning and Improving

Every breach is an opportunity to improve your data security practices. Document the incident thoroughly, identify the root cause, implement technical and organizational measures to prevent recurrence, and review your data processing activities to identify any other vulnerabilities. GDPR requires you to maintain records of all breaches regardless of whether they trigger notification obligations.

Keep your client data secure and organized

Arbeitly stores your invoices and client data with security practices built for EU compliance. Start your free trial.

Del denne artikel