22. júní 2026
GDPR Data Breach Response for SMEs: What to Do in the First 72 Hours
A data breach triggers a 72-hour notification clock under GDPR. Here's exactly what small businesses and freelancers must do to respond correctly and avoid penalties.
Understanding Your GDPR Breach Obligations
Under GDPR Article 33, any personal data breach that poses a risk to individuals' rights and freedoms must be reported to your supervisory authority within 72 hours of becoming aware of it. This isn't 72 hours from when the breach occurred — it's from when you become aware of it. The distinction matters: delayed discovery does not extend your compliance window.
For many freelancers and small businesses, a "data breach" sounds like a corporate catastrophe, but it includes relatively mundane incidents: sending an email containing client personal data to the wrong recipient, losing a laptop containing unencrypted client files, a cloud storage service becoming temporarily accessible due to misconfigured permissions, or a phishing attack that compromises your email account.
Immediate Response: The First Four Hours
When you discover or suspect a breach, act immediately on four fronts. First, contain the breach if possible: change compromised passwords, revoke unauthorized access, remove publicly accessible files, or isolate affected systems. Second, preserve evidence: don't delete logs or attempt to "clean up" the incident before documenting what happened. Screenshots, access logs, and email records are your evidence.
Third, assess the scope: what personal data was involved, whose data was it, how many individuals are affected, what is the likely impact on those individuals? Fourth, determine whether the breach triggers notification obligations: not all breaches require notification. A breach that is "unlikely to result in a risk to the rights and freedoms of natural persons" can be documented internally without supervisory authority notification.
The 72-Hour Notification to Your Supervisory Authority
If the breach poses a risk to individuals, notify your national supervisory authority (the DPA in your country — for example, BfDI in Germany, CNIL in France, ICO in the UK) within 72 hours. Most authorities have an online breach notification portal. Your notification must include: the nature of the breach, categories and approximate number of affected individuals, likely consequences, and measures taken or proposed to address the breach.
If you can't provide complete information within 72 hours, submit an initial notification with what you know and indicate that further information will follow. Regulators understand that investigations take time and value early notification over perfect notification.
Notifying Affected Individuals
If the breach is likely to result in high risk to individuals — identity theft risk, financial risk, significant reputational harm — you must also notify the affected individuals directly without undue delay. The notification must describe the nature of the breach in clear language, provide contact details for your data protection point of contact, describe the likely consequences, and explain measures taken to address the breach and mitigate its effects.
Keep records of all client data you hold using your business management tools so that in a breach scenario you can quickly identify who is affected without days of investigation.
Post-Breach: Learning and Improving
Every breach is an opportunity to improve your data security practices. Document the incident thoroughly, identify the root cause, implement technical and organizational measures to prevent recurrence, and review your data processing activities to identify any other vulnerabilities. GDPR requires you to maintain records of all breaches regardless of whether they trigger notification obligations.
Keep your client data secure and organized
Arbeitly stores your invoices and client data with security practices built for EU compliance. Start your free trial.
Tengdar greinar
Digital Nomad Visa and Tax Guide for EU Freelancers
Navigating visas and taxes as a digital nomad within and beyond the EU requires careful planning. Here's a comprehensive guide for location-independent freelancers.
Work From Anywhere: EU Legal Compliance Checklist
Working remotely from different EU countries creates legal obligations that many freelancers overlook. Here's your compliance checklist for location-independent work.
Subcontracting vs Partnering: EU Legal Differences
Subcontracting and partnering look similar from the outside but have very different legal implications in the EU. Understanding the difference protects your business.
Deila þessari grein