Out-Law / Your Daily Need-To-Know

OUT-LAW NEWS 3 min. read

GDPR data breach notification template criticisms ‘legitimate’, says expert

Abstract binary code

AerialPerspective Works/iStock.


The European Data Protection Board (EDPB) should reduce some of the requirements it seeks to impose on businesses when they go to initially notify personal data breaches under the General Data Protection Regulation (GDPR), an expert has said.

Amsterdam-based Wouter Seinen of Pinsent Masons said Insurance Europe, an umbrella body for trade associations in the insurance industry, has raised some fair criticisms of the EDPB’s draft template for data breach notifications in a response it had published to the proposals.

Under Article 33 of the GDPR, organisations are obliged to disclose certain personal data breaches to data protection authorities and affected individuals. Organisations must notify local data protection authorities of personal data breaches they have experienced "without undue delay and, where feasible, not later than 72 hours after having become aware of it ... unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons".

In addition, Article 34 requires that where there is a high risk of damage arising to the data subject then the data subjects must be informed directly without undue delay.

There is currently inconsistency across the EU in terms of the information data protection authorities seek from organisations notifying data breaches. The EDPB has developed a draft template with a view to achieving greater standardisation. In June, it opened a consultation on its proposals. At the time, experts at Pinsent Masons highlighted that while the questions broadly align with what the GDPR specifies about the information that must be reported in respect of personal data breaches, some go further by requiring additional explanation and detail. The draft template poses 125 questions in total.

In its response to the EDPB’s consultation, which closed on 5 August, Insurance Europe has called for the proposals to be refined. It said that “the current template appears excessively lengthy and granular in several areas” and called on the EDPB to strip back the information requirements to those “strictly necessary for the purposes of Article 33 GDPR”, adding that “sections that do not materially contribute to the assessment of the incident” should be simplified.

EU data protection authorities enable organisations to provide them with details of personal data breaches in phases – while an initial notification must be made not later than 72 hours after they become aware of the breach, the staged approach allows organisations to follow up with more details later, as and when they uncover more information about the incident and its impact. Insurance Europe said, however, that the EDPB’s draft template is not clear on how this “staged notification” operates.

Insurance Europe said: “The template should also make it clearer that controllers may submit an initial notification within the 72-hour period based on the information reasonably available at that stage and subsequently provide additional details through follow-up notifications. It should recognise that many breaches – especially cybersecurity incidents and incidents involving processors or third-party service providers – require extensive technical investigation before reliable information becomes available.”

“Further clarification would be beneficial regarding the practical operation of incomplete and follow-up notifications, including whether information already submitted will be pre-populated in subsequent submissions and how controllers should indicate where information remains under investigation,” it added.

Seinen agreed, advocating for the EDPB to update the template before it puts a finalised version into the public domain.

Seinen said: “The EDPB initiative is directionally positive: a common EU template should improve consistency across data protection authorities, reduce divergent national forms and help supervisors triage breach notifications. However, Insurance Europe has a legitimate point that the draft risks becoming too granular for the early incident-response window. Article 33 GDPR permits phased notification precisely because facts are often uncertain within 72 hours, particularly in cyber incidents involving processors, third-party providers or forensic investigation.”

“The key refinements which the EDPB should consider are: preservation of staged reporting, making ‘unknown / under investigation’ options prominent, and retention of meaningful free-text fields. On the more ‘technical end’ I think the EDPB could do more to avoid multiple duplicative contact sections, consider bulk handling for substantially similar incidents, and map each field clearly to the Article 33(3) information requirements or a supervisory purpose,” he added.

Seinen said the EDPB template should also be designed to integrate with single-entry-point and cross-regulatory reporting initiatives, rather than becoming another standalone portal. He highlighted how the same significant incident can be reportable under a raft of EU legislation, citing the crossover between the GDPR’s notification requirements and those under NIS2, DORA, the e-Privacy regime and Digital Services Act, as examples.

Last year, the European Commission set out proposals for a new Digital Omnibus Regulation under which obligations around the reporting of security and data breaches that arise across a suite of often overlapping EU regulations would be streamlined. Those proposals remain subject to amendment and approval by the European Parliament and Council of Ministers.

We are processing your request. \n Thank you for your patience. An error occurred. This could be due to inactivity on the page - please try again.