Use case
From the misdirected email to the supervisory authority: reporting a data breach within 72 hours, with a workflow that keeps counting at the weekend.
A staffing agency with 250 in-house employees. Thursday, 17:50: someone in payroll notices that the mail merge with one site's payslips did not go to the temporary workers but to the distribution list of contact persons at customers. Name, bank details and tax identification number, sent to around 140 outside recipients. From this moment, the clock of the General Data Protection Regulation (GDPR) is running: 72 hours, until Sunday at 17:50, weekend included. We supply the tool your data protection officer and management use to work through these three days; the legal assessment and the notification itself stay with you.

Duty
What the law requires
One incident, three duties: notify, inform, document. They apply to every company.
| Legal basis | General Data Protection Regulation (GDPR), Article 33 (notification to the supervisory authority and documentation) and Article 34 (communication to data subjects) |
|---|---|
| Who is affected | Every controller that processes personal data. Processors, such as a payroll bureau, a data centre or a software provider, notify their controller of a breach without undue delay (Article 33(2)). |
| Trigger | A personal data breach: data goes to the wrong recipients or is stolen, deleted, encrypted or viewed without authorisation |
| Deadlines | Notification to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk. A later notification must state the reasons for the delay. |
| Content of the notification | Nature of the breach, categories and approximate number of data subjects and records, contact point, likely consequences, measures taken and planned |
| Data subjects | If the risk is likely to be high, inform them without undue delay, in clear and plain language, with measures and recommendations. Where this would involve disproportionate effort, a public communication instead. |
| Documentation | Every breach must be documented, including those that were not notified: facts, effects, remedial action (Article 33(5)) |
| Fine | Up to €10 million or 2 percent of annual turnover (Article 83(4)) |
| Legal position as of | October 2026. We build the workflow; the legal assessment of whether a case must be reported stays with your data protection officer, your legal department or law firm. |
Clock
The workflow, hour by hour
The clock starts when you become aware, not on the next working day. The tool takes in the report, proposes a classification, keeps the deadline at the weekend too and prepares every notification for approval.
- Minute 0
The report arrives, whatever the channel
A form on the intranet, Teams or the telephone, plus reports from a processor, alerts from your own monitoring and tips from data subjects themselves. Every incoming report becomes a case with a timestamp. The workflow asks which data and how many people are affected and what has already been done.
- Minute 15
Immediate measures and internal alert
The data protection officer and management find out straight away, with a summary of the case. In parallel, the workflow puts forward the immediate measures: a request to the wrong recipients to delete the email and confirm they have done so, blocked access, changed passwords.
- Hour 2
Classification in three levels, with reasons
The workflow proposes one of three levels: no risk, in which case the breach is only documented; risk, in which case a notification goes to the supervisory authority; high risk, in which case the data subjects are informed as well. It gives reasons for its proposal based on the type and volume of data and the immediate measures. Bank details sent to 140 outsiders are not the same as a telephone list sent to a colleague. The decision rests with the data protection officer and management.
- by hour 72
Notification to the supervisory authority
The case produces the draft with all mandatory details: nature of the breach, categories and approximate number of data subjects and records, contact point, likely consequences, measures. The clock sends reminders after 24, 48 and 60 hours and escalates to management if nobody has approved it by then, on a Saturday just as on a Tuesday. Whatever is still open on Sunday is submitted later; if the notification does end up late, the reasons for the delay are attached straight away.
- without undue delay
Informing data subjects if the risk is high
Once high risk has been established, the communication is written in plain language: what has happened, what you have done and what data subjects can do themselves, such as checking bank statements or changing a password. After approval, it goes to each person individually, by email or letter.
- afterwards
Follow-ups, register and trial run
Questions from the authority and confirmations from the wrong recipients land in the same case. At the end, the case is entered in the register of all breaches. The lessons go into your rules, such as a block on attachments to external distribution lists.
Cascade
Who learns what has happened, and when
First those who have to decide, then those bound in by contract, then the authority, and if the risk is high, the people whose data it is. Each outgoing wave has a draft, a person who approves it and a point in time in the log; the internal alert goes out immediately.
| Wave | Recipient | Channel | Content | Approval |
|---|---|---|---|---|
| 1, immediately | Data protection officer and management, if needed the heads of IT and HR | Email and Teams, a call according to the on-call list if no confirmation comes | What is known, which data, how many people, immediate measures, status of the clock | none, internal alert according to a fixed list |
| 2, on the first day | Depending on your role: your controller if you are a processor, or your processor if the error lies with them; plus your cyber or liability insurer | Email to the contacts named in the contract, claim notification to the insurer | Facts, processing affected, request for cooperation | Data protection officer |
| 3, by hour 72 | The competent supervisory authority, usually the one in the federal state where you have your registered office | The authority's online form; each federal state has its own | Mandatory details under Article 33, with anything still open submitted later | Data protection officer and management |
| 4, without undue delay if the risk is high | Every data subject | Email or letter from the template, contact point for questions | What has happened, consequences, your measures, recommendations such as changing passwords and checking bank statements | Data protection officer and management |
| 5, if individual messages would be disproportionate | The public | Notice on your website, other channels if needed | The same information as in the individual message, without personal data | Management |
You set the order, the templates and the on-call list in the analysis. The workflow matches replies to the case and follows up when a deletion confirmation does not arrive.
Approval
What stays with your people
- The classification. The workflow proposes one of the three levels and gives reasons. Whether there is a risk or a high risk is decided by the data protection officer and management.
- The notification to the authority. No draft goes into the form without approval. Escalation makes sure that a person approves in time, at the weekend too.
- Informing the data subjects. Wording, group of recipients and channel are confirmed before sending. A person answers questions from data subjects; the workflow puts the case in front of them.
- The conversation with the supervisory authority. Your data protection officer answers its questions, with the log in front of them.
Integration
Which systems the workflow sits in
The workflow itself processes personal data, often particularly sensitive data such as salaries, health or job applications. That is why it runs on your server or in a German data centre, reads from the systems you have and writes back to them.
- IncomingReporting form on the intranet, Teams, telephone with call note, data protection inbox, alerts from the firewall and email system
- CaseA ticketing system such as Jira or ServiceNow, or a separate case store that only data protection and management can access
- DatasetHR software and payroll, applicant management, record of processing activities, list of processors
- CommunicationEmail sending with templates, mail merge letters, Teams for escalation, on-call list
- AuthorityOnline forms of the federal states' supervisory authorities. They rarely have an interface: the workflow pre-fills the notification, a person enters it, and the timestamp goes into the log.
Evidence
The log is the evidence
With a data breach, documentation is a duty in its own right: every breach belongs in the register, including those for which no notification was needed after checking. In the workflow, the entry is produced along the way, from the case: facts, classification with reasons and the names of those who decided, measures, outcome.
When the supervisory authority asks when you became aware and when you reported, the answer is an export for the authority, the insurer and the auditor.
Twice a year, a trial run with a made-up case checks whether the on-call list and templates are right and whether those who approve respond on a Saturday too.
Experience
What we bring
The building blocks of this reporting chain have been running at our customers for years. Reading incoming items at scale, matching them to the right case and routing them on is something we know from a technology distributor with twelve sites, where enquiries from twelve sites across Europe reach the right team according to rules. Applying a set of rules and classifying every finding with reasons is something we built across ten domains for a fuel cell manufacturer. Cases with log, approval and email sending run every night in our own operations.
We put the reporting channel to the supervisory authority into operation together with your data protection officer. It is accepted with a made-up breach on a Friday afternoon: this shows whether the workflow pulls the right list of data subjects from your HR software and whether someone approves on Saturday. We show you what the log of such a trial run looks like in the first call.
Price
Price and scope
The order of magnitude first: the workflow analysis costs €4,900 at a fixed price and takes three days. Based on our projects, a custom tool typically costs between €25,000 and €60,000, as a fixed price that becomes binding after the analysis; the first version is ready in about six weeks, longer with several duties and languages. Ongoing operation after that starts at €2,900 a month and can be cancelled monthly. A narrower range in advance would be guesswork: one site and a group with several companies and supervisory authorities do not need the same tool. What determines the price:
- number of incoming channels and whether alerts from monitoring are part of it
- number of systems from which data subjects and data categories are determined
- number of companies, supervisory authorities and processors
- whether the workflow covers only the GDPR or also NIS2 and the Cyber Resilience Act, when the same incident starts several clocks
Data flow: incident data stays on your server or in a German data centre. Reading, the classification proposal and drafts run on open models on your own servers; no incident goes to a model that trains on it. Data flow per service.
Related
Related use cases
- NIS2: reporting a security incident in your own operations. An attack in which data leaks starts two clocks: 24 hours to the Federal Office for Information Security, 72 to the data protection supervisory authority.
- Whistleblower protection: the internal reporting channel. The same incoming channel, the same confidentiality, different deadlines.
- Cyber Resilience Act: reporting a vulnerability in your product. If customer data leaks through a flaw in the product, the GDPR clock is running too.
- All use cases: reporting duties with deadlines, with the table of deadlines across all duties.
Further reading: AI data protection in companies: three ways and Introducing AI with the works council, because a workflow that handles personnel data is almost always subject to co-determination.
Questions
Questions about the reporting chain for data breaches
What data protection officers and management want to know before the first real case goes through the workflow. More answers under Questions and answers.
Does the AI decide whether we report a data breach?
No. It proposes one of three levels, no risk, risk or high risk, and gives reasons for its proposal based on the type and volume of data and the measures taken. The decision is made by your data protection officer and management. The clock still counts from the moment you became aware, so that the decision does not eat into the 72 hours.
We act as a processor for our customers. What changes?
In that case you do not notify the authority of a breach, but your customer as the controller, without undue delay, and the customer then has its own 72 hours. The workflow knows the contact at the customer from your contracts and prepares the notification with the details the customer needs for its own.
Who is there at night and at the weekend, and who is liable for what?
At the weekend the workflow runs without people beside it: it opens the case, counts down the deadline and calls the people on your on-call list until someone confirms. As part of ongoing operation we monitor that the workflow is running, with response times on working days; round-the-clock standby is agreed separately. If it fails, the on-call list, templates and list of data subjects are ready as an export, and your data protection officer carries on by hand. Your company remains responsible for the deadline as the controller; we are liable for the tool under our terms and conditions.
An incident can also fall under NIS2 or the Cyber Resilience Act. Do we then need three workflows?
No. The same incident becomes one case with several clocks, each duty with its own deadline, recipient and template. Shared details are recorded once. Which duties apply to you is something you clarify with your legal advisers in the analysis.
Handover
The first step is a 30-minute call.
You tell us about the workflow that costs you the most time. We tell you honestly whether AI pays off there and what the next step would be. Whether a workflow analysis follows is up to you.