Data breach?
The 72-hour clock is ticking. We help immediately.
Whether it’s an email to the wrong distribution list, a lost laptop, or a ransomware attack—mistakes happen everywhere people work. The key is that you deal with it properly now. Our emergency team first assesses the incident and then, if necessary, reports it to the regulatory authority and notifies the affected individuals.
Emergency hotline · Mon–Fri 9:00–17:00 · experienced data protection officers and lawyers
Stop the incident
Blocking access, disconnecting devices, recalling faulty shipments – curbing damage, but not deleting anything.
Note the time
When did the problem occur and when did you find out about it?
Contact us
We assess the risk with you.
Emergency hotline for data breaches or by email sofortdatenschutz@mip-consult.de





What is a data breach within the meaning of the GDPR?
A data breach, described GDPR as a „breach of the protection of personal data“, occurs when personal data is unintentionally or unlawfully destroyed, altered, disclosed or made accessible, or lost (Article 4, GDPR No. 12). A hacker attack is just one of many cases. Most data breaches occur in the workplace.
Email sent to the wrong recipient
A wrong recipient address, an open distribution list with CC instead of BCC, or an attachment with extraneous data. This is the most common case in practice.
Lost or stolen devices
Laptops forgotten on trains, work phones stolen, USB sticks gone missing, especially critical without encryption.
Ransomware and hacker attacks
Encrypted systems, leaked customer data, extortion. Here, every hour counts for reporting and communication.
Documents sent to the wrong recipient
Mail to the wrong address, files in old paper, documents in the waiting room. Analogous incidents can also be data protection violations, but are not automatically subject to reporting. Whether a report to the supervisory authority is required also depends here GDPR on the risk assessment pursuant to Art. 33.
Unauthorized access
Disqualified employees retain access, or employee rights are granted too widely.
Misconfiguration and data leak
Open cloud storage, incorrectly set permissions, forms with publicly viewable entries, often unnoticed for months.
The first 72 hours:
What happens now in what order
Hour 0
Detect and contain
Block access, isolate systems, recall faulty shipments. Document the moment of knowledge, and from now on, the deadline counts.
After that
Document and remediate
Any data breach is documented (Article 33(5) GDPR). We evaluate the incident and close the gap so that it does not happen again.
Hour 0–24
Inform affected persons
In cases of expected high risk, those affected must be notified in accordance with Article 34 of the GDPR. We formulate the notification clearly, correctly, and without panic.
Until hour 72
Assess the risk
What data, how many people affected, what consequences? We are examining whether there is a risk to the affected individuals and therefore whether a report must be submitted.
Missed the deadline? Still report it – with justification.
If a required notification is not made within 72 hours, the delay must be explained. The obligation to report immediately remains in effect. Failing to report immediately is the most costly mistake. Therefore, please call us even if the 72-hour deadline has already passed.
In an emergency and even before that at your side
Emergency team for data breaches
Immediately
Reactive support with expertise and operational experience in non-standard situations. From the first call to the final documentation.
Prevention: Escalation process and simulation
We develop defined escalation processes for data breaches with you and simulate incidents so that every action is taken in the event of an emergency.
Deadline for reporting to the supervisory authority – upon becoming aware of the data breach (Art. 33 GDPR).
or 2 % of the worldwide annual turnover: fine for violations of the reporting and notification obligation (Art. 83(4) GDPR).
that's enough.
Frequently asked questions about data breaches
Does every data breach have to be reported to the supervisory authority?
No. The notification under Article 33 GDPR is not required if the breach is not likely to result in a risk to the rights and freedoms of the data subjects, for example in the case of a lost, securely encrypted laptop. However, every data breach, even the non-reportable ones, must be documented. Assessing whether there is a risk is the crucial step, and it is here that we can help you.
When does the 72-hour deadline start?
From the moment the responsible person becomes aware of the data breach, that is, as soon as it is reasonably certain that a security incident involves personal data. The deadline also applies on weekends and public holidays. If there is still no information, the notification can be made in stages: first the essential information, and details will be provided later.
When must those affected be informed?
If the data breach is expected to pose a high risk to those affected, for example in the case of compromised access data, health data or bank details, the affected individuals must be informed immediately in accordance with Article 34 GDPR. The notification must explain in clear and simple language what has happened and what the affected individuals can do.
What happens if we don't report it or report it too late?
Violations of the reporting and notification obligation can be punished with fines of up to 10 million euros or 2 % % of the worldwide annual turnover (Art. 83, para. 4). GDPR Furthermore, affected parties may be entitled to compensation for damages and reputational damage. Compensation claims do not automatically arise from a failure to report or a late report; they are subject to GDPR the requirements of Art. 82. A reputational damage also does not necessarily occur.
Our service provider had the breach – who has to report it?
The processor must report the incident to you as the controller immediately (Article 33(2) GDPR). The reporting to the supervisory authority and informing the data subjects remain your responsibility. Therefore, check whether your processor agreements include clear reporting procedures and deadlines for service providers.
What must be included in the report to the supervisory authority?
At least the nature of the breach with categories and approximate number of affected individuals and data sets, the contact details of the data protection officer, the likely consequences, and the measures taken or proposed (Article 33(3) GDPR).

Data breach?
Call us.
Non-binding · 15 minutes · Free








