Law firm guidesData protection

Your clients' data has leaked: the 72 hours and what follows

Last updated 2026-09-01 · Reviewed by Jaime Piñeira Pardo, registered with the ICAM bar, no. 138826

The short answer

The 72 hour clock starts when you become aware of the breach, not when it happened. You notify the AEPD unless the breach is unlikely to pose a risk, and you inform those affected where a high risk is likely. Everything written in those hours will be read later in the penalty file and in the civil claims.

On a Monday morning your platform provider warns you that a folder holding the last year's orders has been accessible without a password. Inside there are names, addresses, telephone numbers and the last four digits of the cards of nine thousand customers. Nobody yet knows whether anything was downloaded. Your team wants to wait for the provider's report before saying anything, sales wants to warn customers now, and you do not know when the seventy two hours start running.

The case, in five lines

What is brought
Legal handling of the security breach: a documented decision on whether to notify, notification to the supervisory authority, communication to the data subjects where required, and the later defence of the file and of any claims.
Before which court
The AEPD (the Spanish data protection authority) receives the notification and, where applicable, investigates and decides the case. Claims by those affected are heard by the Civil section of the Tribunal de Instancia (the first-instance court).
Deadline
Seventy two hours from becoming aware of the breach to notify the supervisory authority. To the data subjects, without undue delay where a high risk to their rights and freedoms is likely.
Who can bring it
The obligation falls on the controller. The processor must notify the breach to the controller without undue delay as soon as it becomes aware of it.
Financial risk
Breach of the obligations in Articles 25 to 39 falls in the tier of up to 10,000,000 euros or 2 per cent of total worldwide annual turnover. Individual claims from those affected come on top.

The 72 hours run from your awareness, not from the breach

Article 33 of the Regulation requires the breach to be notified to the competent supervisory authority without undue delay and, where feasible, not later than seventy two hours after becoming aware of it. The date that counts is not that of the technical failure or of the improper access: it is the one on which the controller learned it had happened.

That is why the first thing done is not to draft anything but to fix hour zero with a document: the provider's email, the system alert, the report from the employee who spotted it. That hour will later be defended before the authority and against anyone affected, and an hour zero improvised months afterwards does not survive comparison with the internal logs.

The same article contemplates arriving late without the world ending: if notification does not take place within seventy two hours, it must be accompanied by an explanation of the reasons for the delay. That is an orderly way out, not an automatic excuse, and it works far better where the reasons are verifiable and recorded in writing from day one.

You may decide not to notify, but you must document why

The duty to notify falls away unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. It is a genuine exception and sometimes the right call, but it rests on a judgement that must be defensible. Notifying by reflex is not free either: it puts the matter on the authority's desk with the classification you yourself gave it.

Paragraph 5 closes the door on deciding in silence. The controller shall document any breach, including the facts relating to it, its effects and the remedial action taken, and that documentation must enable the supervisory authority to verify compliance with the article. The decision not to notify is recorded, with its reasoning, or it does not exist.

Where notification is made, the minimum content is prescribed: the nature of the breach, with the categories and approximate number of data subjects and records concerned where possible; the name and contact details of the data protection officer or another contact point; the likely consequences; and the measures taken or proposed to address it, including any mitigation measures.

Customers are told only where the risk is high, and there are three exits

Article 34 sets a different and more demanding threshold than notification to the authority: the breach must be communicated to the data subject, without undue delay, where it is likely to result in a high risk to the rights and freedoms of natural persons. Not everything notified to the authority is communicated to customers, and confusing the two thresholds produces avoidable reputational harm or avoidable breaches.

The communication must describe in clear and plain language the nature of the breach and contain at least the contact point, the likely consequences and the measures taken or proposed, including mitigation. That clear and plain language is not a style tip: it is the standard against which it will later be judged whether you genuinely informed people or drafted a note designed not to.

There are three prescribed exits. That appropriate technical and organisational measures had been applied to the affected data rendering them unintelligible to anyone not authorised, such as encryption. That subsequent measures have been taken ensuring the high risk is no longer likely to materialise. Or that individual communication would involve disproportionate effort, in which case an equally effective public communication is used instead.

Article 32 is judged backwards: what you had in place beforehand

Once the breach is notified, the investigation looks not only at how you reacted but at what existed the day before. Article 32 requires appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing.

The article itself lists what that level may include: pseudonymisation and encryption, the ability to ensure the ongoing confidentiality, integrity, availability and resilience of systems, the ability to restore access to the data promptly after a physical or technical incident, and a process for regularly testing, assessing and evaluating the effectiveness of those measures.

Two paragraphs often decide the outcome. Adherence to an approved code of conduct or to a certification mechanism may serve as an element to demonstrate compliance. And the controller and processor must take steps to ensure that anyone acting under their authority with access to the data processes them only on their instructions, unless required to do otherwise by law.

Notifying properly is written into Article 83 as mitigation

Article 83 requires due regard, when deciding on a fine and its amount, to the manner in which the supervisory authority became aware of the infringement, in particular whether the controller or processor notified it and to what extent. Also weighed are the measures taken to mitigate the damage suffered by data subjects and the degree of cooperation with the authority.

That is the practical reason why the notification is drafted with legal judgement and not as a technical report. The same event, told as a controlled incident with measures already applied, or told as an accidental discovery with no plan, produces two different gradings on exactly the same leaked data.

And behind the file come those affected. Article 82 gives anyone who has suffered material or non material damage the right to compensation from the controller or the processor, with exemption only on proof of not being in any way responsible for the damaging event. Where several take part in the same operation, each answers for the whole loss towards the person affected.

How we run the case, step by step

  1. 1

    Fix hour zero and freeze the evidence

    We record precisely when and by whom awareness arose, and preserve logs, emails and system copies before anyone touches them. The seventy two hours run from that hour, not from the technical failure.

  2. 2

    Assess the risk in writing

    We analyse the categories of data, the approximate number of people affected, the likely consequences and whether encryption or pseudonymisation was in place. From that analysis comes the decision whether to notify, and the document supporting it if anyone challenges it later.

  3. 3

    Notify the AEPD with the minimum content

    The notification describes the nature of the breach, the categories and approximate number of data subjects and records, the contact point, the likely consequences and the measures taken. Where information is missing, it is provided in phases without undue delay.

  4. 4

    Decide on communicating with those affected

    If a high risk is likely, we communicate without undue delay in clear and plain language. If one of the three Article 34 exceptions applies, we document which and why, since the authority may afterwards require the communication anyway.

  5. 5

    Close the documentary record of the breach

    We record the facts, the effects and the remedial measures taken, in a form that lets the authority verify compliance. That file is what gets handed over if a request for information arrives tomorrow.

  6. 6

    Defend the file and the claims

    If proceedings are opened, we make submissions on the grading criteria using your own notification as mitigation. In parallel we organise the response to individual compensation claims from those affected.

The evidence that decides the case

  • The internal record showing the exact hour awareness arose and who had it.
  • The access logs and the technical report on scope, data categories and number of people affected.
  • The written risk assessment that grounded the decision to notify or not to notify.
  • Documentation of the Article 32 measures in force before the incident, in particular encryption or pseudonymisation.
  • The contract with the processor and the date on which it notified the breach to the controller.
  • The communications sent to those affected, with their text and the delivery and receipt trail.

What closes the door

  • Counting the seventy two hours from the incident. The period runs from becoming aware, and confusing the two leads to notifying late for no reason or panicking needlessly.
  • Waiting for the provider's full report. Information may be provided in phases without undue delay, and silence burns the whole period.
  • Deciding not to notify without recording it. The controller must document any breach, its effects and the measures taken, and a decision with no trail reads as an omission.
  • Sending customers a note that explains nothing. The law demands clear and plain language, and an evasive text aggravates rather than protects.
  • Drafting the notification as a technical report. It is the document the authority will use to grade the fine, and cooperation and mitigation measures weigh there.

The law that applies

  • Art. 33 RGPD. It requires the controller to notify the breach to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless it is unlikely to result in a risk to rights and freedoms; late notification must state the reasons for the delay. The processor must alert the controller without undue delay. The notification must at least describe the nature of the breach with the categories and approximate number of data subjects and records, the contact point, the likely consequences and the measures taken, and may be completed in phases. Every breach must be documented so the authority can verify compliance. 32016R0679
  • Art. 34 RGPD. It requires communication of the breach to the data subject without undue delay where it is likely to result in a high risk to their rights and freedoms, describing in clear and plain language the nature of the breach and including the contact point, the likely consequences and the measures taken. It is not required where measures rendering the data unintelligible to unauthorised persons, such as encryption, had been applied, where subsequent measures remove the likelihood of the high risk, or where it would involve disproportionate effort, in which case an equally effective public communication is used. The authority may require the communication if it has not yet been made. 32016R0679
  • Art. 32 RGPD. It requires the controller and processor to implement appropriate technical and organisational measures for a level of security appropriate to the risk, having regard to the state of the art, costs and the nature, scope, context and purposes of processing, including where appropriate pseudonymisation and encryption, ongoing confidentiality, integrity, availability and resilience, the ability to restore access promptly and regular testing of effectiveness. In assessing the appropriate level, regard is had to risks of unauthorised destruction, loss, alteration or access. Adherence to codes of conduct or certification may serve to demonstrate compliance. 32016R0679
  • Art. 83 RGPD. It requires fines to be effective, proportionate and dissuasive and lists the circumstances to be weighed, among them measures taken to mitigate damage, the degree of responsibility given the measures under Articles 25 and 32, cooperation with the authority and the manner in which it became aware of the infringement, in particular whether the controller itself notified it. Breaches of the obligations in Articles 25 to 39 fall in the tier of up to 10,000,000 euros or 2 per cent of total worldwide annual turnover, whichever is higher. 32016R0679
  • Art. 82 RGPD. It gives anyone who has suffered material or non material damage from an infringement of the Regulation the right to compensation from the controller or the processor. The processor is liable only where it failed to meet obligations specifically directed at processors or acted outside or contrary to the controller's lawful instructions. Exemption requires proof of not being in any way responsible for the damaging event, and where several take part in the same operation each answers for the whole loss towards the person affected, with a right of recourse against the others. 32016R0679

Each article checked against the consolidated text published in the BOE (the Spanish official gazette).

Frequently asked questions

When exactly do the 72 hours start?

From the moment the controller becomes aware of the breach, not from when it occurred or from when its full scope is known. That is why the moment and the channel through which it was learned should be documented precisely. If notification is nonetheless later, it must be accompanied by the reasons for the delay, and those reasons will have to be verifiable.

Do I always have to tell my customers?

No. The threshold is different: the data subject is told where the breach is likely to result in a high risk to rights and freedoms. And there are three exceptions: that the data were unintelligible thanks to measures such as encryption, that subsequent measures remove the likelihood of that high risk, or that individual communication would take disproportionate effort, replaced then by an equally effective public communication.

The failure was my provider's. Am I the one who answers?

The duty to notify the authority falls on the controller, and the processor must alert it without undue delay once it learns of the breach. As for compensation, the processor is liable only where it failed to meet obligations specifically directed at processors or acted outside or contrary to the controller's lawful instructions. Towards the person affected, each participant may answer for the whole loss.

Is notifying an admission of the infringement?

It is not, and in fact the Regulation treats it as a favourable element. In setting the fine, due regard is had to how the authority became aware of the infringement, in particular whether the controller notified it and to what extent, together with measures taken to mitigate the damage and the degree of cooperation. What aggravates is not notifying: it is the authority finding out some other way.

What if I still do not know how many customers are affected?

The notification asks for the categories and approximate number of data subjects and records concerned where possible, and expressly provides that if the information cannot all be given at once it may be provided in phases without undue delay. Waiting for the exact figure is not the cautious option: it is the most common route to a late notification.

This guide explains how the action works in general. It does not replace the study of your own case: deadlines depend on when things happened and on what you have done since.

Tell us about your case.

A lawyer studies it and tells you whether there is a claim, how long you have left and what can be sought. Your matter is quoted afterwards, because every case is different.

Other cases in this area