GDPR Article 33 & 34 Compliance Tool

Data breach?
You have 72 hours.

BreachNotify assesses your obligations, drafts your supervisory authority notification, and generates an individual notice — before the clock runs out.

Share this
Time remaining to notify DPA
--hours
:
--min
:
--sec
Enter discovery date/time below
Important: BreachNotify generates draft notifications to assist your compliance process. Always have drafts reviewed by a qualified Data Protection Officer or legal counsel before submission. This tool does not constitute legal advice.
🏢 Your Organisation
🔴 The Breach
The 72-hour clock starts from this moment (Art. 33 GDPR)
🗃 Data Categories Affected

Select all categories of personal data that were compromised.

⚠️ You have selected special category data (Art. 9/10 GDPR). This significantly increases the likelihood that individual notification (Art. 34) will be required and that the DPA will treat this as high priority.
⚠️ Likely Consequences
⚠️

Assessing your breach…

BreachNotify is evaluating obligations and drafting notifications.

🔴

✅ Immediate Action Checklist
📨 Article 33 — DPA Notification

Notification to Supervisory Authority

To be submitted to your Data Protection Authority

Art. 33 GDPR
✏️ Click to edit before submitting · This is a draft — review carefully
📢 Article 34 — Individual Notification

Need expert breach support right now?

GDPRGard experts provide emergency breach support — submission to your DPA, legal review, and individual notification management.

Prefer to listen? Click play for AI narration
Why It Matters

The 72-hour clock starts the moment you find out

Under Article 33 GDPR, a personal-data breach that poses a risk to individuals must be reported to your supervisory authority within 72 hours of becoming aware of it — not 72 hours from when it happened. If the risk is high, Article 34 also requires notifying the affected individuals directly. Most businesses don't learn the deadline exists until they're already inside it.

BreachNotify assesses what actually happened, tells you whether it's reportable, and drafts both the supervisory-authority notification and any individual notices — so you can move fast instead of researching the rules mid-crisis.

1

Describe what happened

What data was involved, how it was exposed, and roughly how many people are affected.

2

Get your obligation assessed

Whether this meets the reporting threshold, and whether individuals need to be notified directly.

3

Get draft notifications

A supervisory-authority notification and, if needed, individual notices — ready to review and file.

Common Questions

If you're dealing with a breach right now

Does this file the notification for me?
No — you still submit it yourself through your supervisory authority's own channel (e.g. their online portal). BreachNotify gives you a ready-to-file draft so that step doesn't cost you hours you don't have.
What counts as a reportable breach?
Any breach of personal data — accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access — that's likely to result in a risk to people's rights and freedoms. Low-risk incidents (e.g. encrypted data with no key exposure) may not need reporting.
What's the difference between Article 33 and Article 34?
Article 33 is the notification to your supervisory authority, required for most reportable breaches. Article 34 is direct notification to the affected individuals, required only when the breach is likely to result in a high risk to them.
Should I still involve a lawyer or DPO?
For anything beyond a minor, low-risk incident, yes — especially if the breach is large, sensitive, or ambiguous. Use BreachNotify to get moving immediately and produce a first draft; get it reviewed before you file if the stakes are high.
Is the breach information I enter stored?
No. The details you provide are sent to our AI provider to generate the assessment and drafts, then discarded — nothing is retained on our servers. See the note below for the full legal basis.
What if I'm not sure whether it needs reporting at all?
That's exactly what the assessment step is for — describe the incident and it will tell you whether it meets the reporting threshold, so you're not guessing under time pressure.