Personal data breach according to GDPR – 72 hours, risk assessment and IMY notification

Short answer: A personal data breach must always be documented. If the breach is likely to result in a risk to the rights and freedoms of natural persons, the controller must, as a general rule, notify the Swedish Authority for Privacy Protection (IMY) without undue delay and, if possible, within 72 hours of becoming aware of the breach. In the event of a likely high risk, the data subjects may also need to be informed.

What counts as a personal data breach?

It is not just about data intrusions. A breach can mean that personal data is destroyed, lost, altered, rendered inaccessible, or disclosed to unauthorized parties. Misdirected emails, incorrect access rights, stolen equipment, ransomware, and accidental deletion are common examples.

The first 72 hours – a practical workflow

  1. Stop and contain the breach. Ensure that the damage does not continue.
  2. Determine when you became aware. The timing dictates the 72-hour assessment.
  3. Map what happened. Which data, how many people, which systems, and which recipients are affected?
  4. Assess the risk. Look at the sensitivity of the data, volume, identifiability, and possible consequences.
  5. Decide on notification. If the risk threshold is met, notification should not be delayed while waiting for perfect facts. Information can be supplemented later.
  6. Assess informing data subjects. In the event of a likely high risk, prompt communication to those affected is required as a general rule.
  7. Document everything. Even breaches that are not notified must be documented, and the decision should be explainable.

What should a notification to IMY contain?

The GDPR states, among other things, that the nature of the breach must be described, as well as the categories and approximate numbers of data subjects and personal data records concerned, contact details for the data protection officer or other point of contact, likely consequences, and measures taken or planned. If some information is missing, it can in many cases be provided in stages.

When do data subjects need to be informed?

If the breach is likely to lead to a high risk for people's rights and freedoms, the affected parties must, as a general rule, be informed without undue delay. The information must be clear and help the person understand what has happened and what measures can mitigate the damage.

Common mistakes in incident management

  • starting the 72-hour clock too late
  • waiting for a full forensic investigation before notifying
  • lacking a documented risk assessment
  • confusing an information security incident with a personal data breach without assessing the GDPR component separately
  • the data processor not having clear internal escalation paths
  • not documenting breaches that are not notified

Incident register and follow-up

After the acute phase, the organization should record the root cause, lessons learned, corrective actions, and the person responsible for follow-up. Furthermore, incidents may provide reason to update the DPIA, record of processing activities, authorization procedures, training, and agreements with suppliers.

See the Mallbutiken template package for personal data breaches, IMY notification, and incident registers.

Related guides

If you are also working with broader cyber incidents, the guide on incident response plans may be relevant. For high-risk processing, also see our guide on DPIA.

FAQ

Must all breaches be notified to IMY?

No. All breaches must be documented, but notification is not required when it is unlikely that the breach will result in a risk to the rights and freedoms of natural persons.

What happens if 72 hours have passed?

Notification may still need to be made. The delay must then be justified. It is usually better to handle this openly than to refrain from a notification that should have been made.

Can a data processor notify directly?

The processor must notify the controller without undue delay. The division of responsibilities should be clearly regulated in the data processing agreement.

Official guidance: The Swedish Authority for Privacy Protection (IMY) has checklists and an e-service for personal data breaches at imy.se.

The article provides general information and does not replace legal advice.

Back to blog