Zweite Schicht DE, Deutsche Fassung Book a call

Use case

Updated

From the misdirected email to the supervisory authority: reporting a data breach within 72 hours, with a workflow that keeps counting at the weekend.

A staffing agency with 250 in-house employees. Thursday, 17:50: someone in payroll notices that the mail merge with one site's payslips did not go to the temporary workers but to the distribution list of contact persons at customers. Name, bank details and tax identification number, sent to around 140 outside recipients. From this moment, the clock of the General Data Protection Regulation (GDPR) is running: 72 hours, until Sunday at 17:50, weekend included. We supply the tool your data protection officer and management use to work through these three days; the legal assessment and the notification itself stay with you.

Sketch of a filing cabinet with four drawers, the second open with suspension files and a torn seal strip, an hourglass on top, next to it a tray of envelopes.

Duty

What the law requires

One incident, three duties: notify, inform, document. They apply to every company.

Duties in the event of a personal data breach under Articles 33 and 34 GDPR
Legal basisGeneral Data Protection Regulation (GDPR), Article 33 (notification to the supervisory authority and documentation) and Article 34 (communication to data subjects)
Who is affectedEvery controller that processes personal data. Processors, such as a payroll bureau, a data centre or a software provider, notify their controller of a breach without undue delay (Article 33(2)).
TriggerA personal data breach: data goes to the wrong recipients or is stolen, deleted, encrypted or viewed without authorisation
DeadlinesNotification to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk. A later notification must state the reasons for the delay.
Content of the notificationNature of the breach, categories and approximate number of data subjects and records, contact point, likely consequences, measures taken and planned
Data subjectsIf the risk is likely to be high, inform them without undue delay, in clear and plain language, with measures and recommendations. Where this would involve disproportionate effort, a public communication instead.
DocumentationEvery breach must be documented, including those that were not notified: facts, effects, remedial action (Article 33(5))
FineUp to €10 million or 2 percent of annual turnover (Article 83(4))
Legal position as ofOctober 2026. We build the workflow; the legal assessment of whether a case must be reported stays with your data protection officer, your legal department or law firm.

Clock

The workflow, hour by hour

The clock starts when you become aware, not on the next working day. The tool takes in the report, proposes a classification, keeps the deadline at the weekend too and prepares every notification for approval.

  1. Minute 0

    The report arrives, whatever the channel

    A form on the intranet, Teams or the telephone, plus reports from a processor, alerts from your own monitoring and tips from data subjects themselves. Every incoming report becomes a case with a timestamp. The workflow asks which data and how many people are affected and what has already been done.

  2. Minute 15

    Immediate measures and internal alert

    The data protection officer and management find out straight away, with a summary of the case. In parallel, the workflow puts forward the immediate measures: a request to the wrong recipients to delete the email and confirm they have done so, blocked access, changed passwords.

  3. Hour 2

    Classification in three levels, with reasons

    The workflow proposes one of three levels: no risk, in which case the breach is only documented; risk, in which case a notification goes to the supervisory authority; high risk, in which case the data subjects are informed as well. It gives reasons for its proposal based on the type and volume of data and the immediate measures. Bank details sent to 140 outsiders are not the same as a telephone list sent to a colleague. The decision rests with the data protection officer and management.

  4. by hour 72

    Notification to the supervisory authority

    The case produces the draft with all mandatory details: nature of the breach, categories and approximate number of data subjects and records, contact point, likely consequences, measures. The clock sends reminders after 24, 48 and 60 hours and escalates to management if nobody has approved it by then, on a Saturday just as on a Tuesday. Whatever is still open on Sunday is submitted later; if the notification does end up late, the reasons for the delay are attached straight away.

  5. without undue delay

    Informing data subjects if the risk is high

    Once high risk has been established, the communication is written in plain language: what has happened, what you have done and what data subjects can do themselves, such as checking bank statements or changing a password. After approval, it goes to each person individually, by email or letter.

  6. afterwards

    Follow-ups, register and trial run

    Questions from the authority and confirmations from the wrong recipients land in the same case. At the end, the case is entered in the register of all breaches. The lessons go into your rules, such as a block on attachments to external distribution lists.

Cascade

Who learns what has happened, and when

First those who have to decide, then those bound in by contract, then the authority, and if the risk is high, the people whose data it is. Each outgoing wave has a draft, a person who approves it and a point in time in the log; the internal alert goes out immediately.

The five waves of the cascade with recipient, channel, content and approval
WaveRecipientChannelContentApproval
1, immediatelyData protection officer and management, if needed the heads of IT and HREmail and Teams, a call according to the on-call list if no confirmation comesWhat is known, which data, how many people, immediate measures, status of the clocknone, internal alert according to a fixed list
2, on the first dayDepending on your role: your controller if you are a processor, or your processor if the error lies with them; plus your cyber or liability insurerEmail to the contacts named in the contract, claim notification to the insurerFacts, processing affected, request for cooperationData protection officer
3, by hour 72The competent supervisory authority, usually the one in the federal state where you have your registered officeThe authority's online form; each federal state has its ownMandatory details under Article 33, with anything still open submitted laterData protection officer and management
4, without undue delay if the risk is highEvery data subjectEmail or letter from the template, contact point for questionsWhat has happened, consequences, your measures, recommendations such as changing passwords and checking bank statementsData protection officer and management
5, if individual messages would be disproportionateThe publicNotice on your website, other channels if neededThe same information as in the individual message, without personal dataManagement

You set the order, the templates and the on-call list in the analysis. The workflow matches replies to the case and follows up when a deletion confirmation does not arrive.

Approval

What stays with your people

  • The classification. The workflow proposes one of the three levels and gives reasons. Whether there is a risk or a high risk is decided by the data protection officer and management.
  • The notification to the authority. No draft goes into the form without approval. Escalation makes sure that a person approves in time, at the weekend too.
  • Informing the data subjects. Wording, group of recipients and channel are confirmed before sending. A person answers questions from data subjects; the workflow puts the case in front of them.
  • The conversation with the supervisory authority. Your data protection officer answers its questions, with the log in front of them.

Integration

Which systems the workflow sits in

The workflow itself processes personal data, often particularly sensitive data such as salaries, health or job applications. That is why it runs on your server or in a German data centre, reads from the systems you have and writes back to them.

System integration in detail

  • IncomingReporting form on the intranet, Teams, telephone with call note, data protection inbox, alerts from the firewall and email system
  • CaseA ticketing system such as Jira or ServiceNow, or a separate case store that only data protection and management can access
  • DatasetHR software and payroll, applicant management, record of processing activities, list of processors
  • CommunicationEmail sending with templates, mail merge letters, Teams for escalation, on-call list
  • AuthorityOnline forms of the federal states' supervisory authorities. They rarely have an interface: the workflow pre-fills the notification, a person enters it, and the timestamp goes into the log.

Evidence

The log is the evidence

With a data breach, documentation is a duty in its own right: every breach belongs in the register, including those for which no notification was needed after checking. In the workflow, the entry is produced along the way, from the case: facts, classification with reasons and the names of those who decided, measures, outcome.

When the supervisory authority asks when you became aware and when you reported, the answer is an export for the authority, the insurer and the auditor.

Twice a year, a trial run with a made-up case checks whether the on-call list and templates are right and whether those who approve respond on a Saturday too.

Experience

What we bring

The building blocks of this reporting chain have been running at our customers for years. Reading incoming items at scale, matching them to the right case and routing them on is something we know from a technology distributor with twelve sites, where enquiries from twelve sites across Europe reach the right team according to rules. Applying a set of rules and classifying every finding with reasons is something we built across ten domains for a fuel cell manufacturer. Cases with log, approval and email sending run every night in our own operations.

We put the reporting channel to the supervisory authority into operation together with your data protection officer. It is accepted with a made-up breach on a Friday afternoon: this shows whether the workflow pulls the right list of data subjects from your HR software and whether someone approves on Saturday. We show you what the log of such a trial run looks like in the first call.

Read the case studies

Price

Price and scope

The order of magnitude first: the workflow analysis costs €4,900 at a fixed price and takes three days. Based on our projects, a custom tool typically costs between €25,000 and €60,000, as a fixed price that becomes binding after the analysis; the first version is ready in about six weeks, longer with several duties and languages. Ongoing operation after that starts at €2,900 a month and can be cancelled monthly. A narrower range in advance would be guesswork: one site and a group with several companies and supervisory authorities do not need the same tool. What determines the price:

  • number of incoming channels and whether alerts from monitoring are part of it
  • number of systems from which data subjects and data categories are determined
  • number of companies, supervisory authorities and processors
  • whether the workflow covers only the GDPR or also NIS2 and the Cyber Resilience Act, when the same incident starts several clocks

Data flow: incident data stays on your server or in a German data centre. Reading, the classification proposal and drafts run on open models on your own servers; no incident goes to a model that trains on it. Data flow per service.

Related

Related use cases

Further reading: AI data protection in companies: three ways and Introducing AI with the works council, because a workflow that handles personnel data is almost always subject to co-determination.

Questions

Questions about the reporting chain for data breaches

What data protection officers and management want to know before the first real case goes through the workflow. More answers under Questions and answers.

Does the AI decide whether we report a data breach?

No. It proposes one of three levels, no risk, risk or high risk, and gives reasons for its proposal based on the type and volume of data and the measures taken. The decision is made by your data protection officer and management. The clock still counts from the moment you became aware, so that the decision does not eat into the 72 hours.

We act as a processor for our customers. What changes?

In that case you do not notify the authority of a breach, but your customer as the controller, without undue delay, and the customer then has its own 72 hours. The workflow knows the contact at the customer from your contracts and prepares the notification with the details the customer needs for its own.

Who is there at night and at the weekend, and who is liable for what?

At the weekend the workflow runs without people beside it: it opens the case, counts down the deadline and calls the people on your on-call list until someone confirms. As part of ongoing operation we monitor that the workflow is running, with response times on working days; round-the-clock standby is agreed separately. If it fails, the on-call list, templates and list of data subjects are ready as an export, and your data protection officer carries on by hand. Your company remains responsible for the deadline as the controller; we are liable for the tool under our terms and conditions.

An incident can also fall under NIS2 or the Cyber Resilience Act. Do we then need three workflows?

No. The same incident becomes one case with several clocks, each duty with its own deadline, recipient and template. Shared details are recorded once. Which duties apply to you is something you clarify with your legal advisers in the analysis.

Handover

The first step is a 30-minute call.

You tell us about the workflow that costs you the most time. We tell you honestly whether AI pays off there and what the next step would be. Whether a workflow analysis follows is up to you.

Book a callApproach and prices