What to Do When You Discover a Data Breach

Date: 07/10/2026

What to Do When You Discover a Data Breach — Cerberus DPS

The clock starts the moment you know

A laptop with a customer list gets stolen. An email with attachments goes to the wrong person. A vendor tells you their system — which held your data — was hacked. However it happens, the GDPR gives you a strict window to act: you must notify the supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach — unless it is unlikely to result in a risk to people’s rights and freedoms (Article 33(1)). Knowing what to do before it happens is the difference between a controlled 72 hours and a panicked one.

If the breach happened at a vendor that processes data on your behalf, they are obliged to tell you without undue delay once they become aware of it (Article 33(2)). Your contract with them should spell out exactly how and how fast that happens.

Step 1: Contain it

Before anything else, stop the bleeding. Revoke access, change passwords, isolate the affected system, retrieve what can be retrieved. Document what you did and when — this record becomes part of your breach file.

Step 2: Work out what actually happened

You need enough facts to make the notification decision, not a full forensic report:

  • What data was involved (names, emails, payment details, health data)?
  • How many people are affected?
  • Was it lost, stolen, or just exposed to the wrong person?
  • Is there a realistic risk of harm — identity theft, financial loss, discrimination, distress?

Step 3: Decide whether it’s notifiable

Not every incident is a reportable breach. A password briefly emailed to the wrong internal colleague, caught and deleted in minutes, is different from a customer database exposed publicly online. Under Article 33, you must notify unless the breach is “unlikely to result in a risk to the rights and freedoms of natural persons”. When you are genuinely unsure, our advice is to notify — under-reporting carries more risk than over-reporting.

Step 4: Notify the Commissioner within 72 hours

In Cyprus, this means notifying the Office of the Commissioner for Personal Data Protection, which provides an online breach notification form (in Greek, or in English where the breach concerns cross-border processing). The notification doesn’t need to be a finished investigation — the GDPR explicitly allows the information to be provided in phases, without undue further delay (Article 33(4)). Report what you know now and add to it as the investigation continues. If you do miss the 72-hour mark, the notification must explain the reasons for the delay.

Step 5: Work out if you also need to tell the affected individuals

This is a separate, higher threshold: Article 34 requires you to inform the affected individuals without undue delay when the breach is likely to result in a high risk to them — not just any risk. If someone’s financial data or login credentials were exposed, that threshold is often met. If a minor internal mix-up posed negligible risk, it may not be.

There are exceptions (Article 34(3)): for example, where the data was protected in a way that makes it unintelligible to anyone not authorised to see it, such as strong encryption, or where you have taken steps that mean the high risk is no longer likely to materialise.

Step 6: Document everything, regardless of the outcome

Every breach must be documented internally — including the ones you decide not to report — covering the facts, its effects and the remedial action taken (Article 33(5)). If the Commissioner ever asks, this record is what demonstrates you made a reasoned decision rather than ignoring the incident.

Why your prior compliance work matters here

If you’ve already done the groundwork — data minimisation, access controls built in from the start, and a clear lawful basis for each dataset — a breach is smaller and easier to scope by definition. There’s simply less exposed, and you already know what you’re looking at.

Quick checklist for the first 24 hours

  1. Contain the incident — stop ongoing exposure.
  2. Establish the facts: what data, how many people, what risk.
  3. Decide whether it meets the Article 33 notification threshold.
  4. If yes, notify the Cyprus Commissioner within 72 hours of becoming aware.
  5. Separately assess the Article 34 high-risk threshold for notifying individuals.
  6. Document the decision either way.
  7. Get help early — a breach under time pressure is not the moment to figure out the rules from scratch.

Facing a breach, or want a plan in place before one happens? Let’s Talk GDPR.

Related reading


References

  1. Regulation (EU) 2016/679 (GDPR) — Article 33 (notification of a personal data breach to the supervisory authority) and Article 34 (communication of a personal data breach to the data subject).
  2. EDPB Guidelines 9/2022 on personal data breach notification under GDPR.
  3. EDPB — Notify a data breach — national authority contact points, including the Cyprus Office of the Commissioner for Personal Data Protection.
  4. Office of the Commissioner for Personal Data Protection (Cyprus) — personal data breach notification.
Latest Articles & Insides