GDPR Data Breach Notification Ireland — The 72-Hour Rule Explained
A lost laptop, an email sent to the wrong recipient, a ransomware attack — all three are personal data breaches under GDPR, and all three can start a legal clock ticking. Irish businesses that process personal data must notify the Data Protection Commission (DPC) within 72 hours of becoming aware of a breach that poses a risk to individuals' rights and freedoms. Miss that window, or handle the assessment wrong, and a breach that could have been a minor incident becomes a DPC enforcement matter.
What counts as a personal data breach
Article 4(12) GDPR defines a personal data breach as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This is broader than most people assume — it is not limited to hacking.
- A device containing personal data (laptop, phone, USB drive) is lost or stolen
- An email, letter, or attachment containing personal data is sent to the wrong recipient
- A ransomware or malware attack encrypts or destroys data you hold
- A staff member accesses or discloses personal data without authorisation
- A website or database misconfiguration exposes personal data publicly
- A supplier or processor you use suffers a breach affecting data you gave them
The 72-hour notification rule
Under Article 33 GDPR, once you become aware of a breach, you must notify the DPC within 72 hours unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. The clock starts when you (or your data processor) first become aware that a breach has occurred — not when you finish investigating it.
You notify via the DPC's breach notification form at dataprotection.ie. If you cannot provide full details within 72 hours, GDPR allows you to notify in phases — submit what you know within the deadline and provide the remaining information without undue further delay, explaining the reason for the delay in your submission.
What the DPC notification must include
- The nature of the breach, including the categories and approximate number of data subjects and records affected
- The name and contact details of your Data Protection Officer or another contact point
- The likely consequences of the breach
- The measures taken or proposed to address the breach and mitigate its effects
When you must also tell the affected individuals
Article 34 GDPR sets a higher threshold for direct notification to individuals: it is required only where the breach is likely to result in a high risk to their rights and freedoms — for example, exposed financial details, health information, or credentials that could enable identity theft. The communication must describe the breach in clear, plain language and cover the same points as the DPC notification.
You do not need to notify individuals if the exposed data was already unintelligible to anyone without authorised access (for example, strongly encrypted), if you have since taken measures that remove the high risk, or if direct notification would involve disproportionate effort — in which case a public communication (such as a website notice) can be used instead.
Keep a breach register — even for breaches you don't report
Article 33(5) requires every controller to document all breaches internally, including the facts, effects, and remedial action taken — regardless of whether the breach met the threshold for DPC notification. This is one of the most commonly missed GDPR obligations: businesses correctly decide a minor breach doesn't need reporting, then fail to log it anywhere. If the DPC later asks to see your breach history, an empty register when you know incidents occurred is itself a compliance gap.
A practical breach response checklist
- Contain the breach immediately — revoke access, isolate affected systems, recover lost devices where possible
- Record the date and time you became aware — this is your 72-hour deadline anchor
- Assess the risk to individuals: what data, how sensitive, how many people, how likely is misuse
- Log the incident in your breach register regardless of the outcome of the risk assessment
- If notifiable, submit the DPC breach notification form within 72 hours, even with incomplete details
- If high risk, notify affected individuals in clear language without undue delay
- Review and fix the underlying cause to prevent repeat incidents
Penalties for getting breach notification wrong
Failing to notify the DPC within 72 hours where required, or failing to notify affected individuals where the high-risk threshold is met, is itself a separate GDPR infringement — distinct from any penalty for the breach itself. These failures fall into the lower administrative fine tier of up to €10 million or 2% of global annual turnover, whichever is higher, and can compound the reputational damage of the breach if it later emerges that notification was late, incomplete, or skipped altogether.
Need to generate this document now?
ComplianceDesk generates Irish-compliant documents in minutes — no accountant required.
Generate a DSAR or GDPR response document →