
What is a data breach, and what you must be able to show within 72 hours
The law around it takes ten minutes to read and the supervisory authority explains it well. What is not there is the hard part: the report form asks questions only your logs can answer, and whether those logs exist was decided months earlier.
A breach is rarely a hack. Most cases are a mail to the wrong recipient, a lost device or a folder of paper, and data you can no longer reach yourself counts too.
The 72-hour clock starts when you discover it, not when it happened. What makes those hours expensive is not the report but the four questions under it: which data, how many people, since when, and how you found out.
You answer those from logs or you do not answer them. Filing “unknown” three times is allowed, and it is exactly what shows that nobody was watching.
What counts as a breach, and what does not
A personal data breach is a security incident that leads to personal data being destroyed, lost, altered, or seen by someone who should not have seen it. That is the whole definition, and it says remarkably little about hackers.
Most cases are not attacks. An attachment to the wrong recipient. A phone left on a train. A folder of HR files in the paper bin. An account that stayed open after someone left, and that someone could still get into.
And there is a category almost everyone misses: data you can no longer reach yourself. Files sitting encrypted on your own server after a ransomware attack have not been made public, but they are gone, and loss is right there in the definition. That is why an attack where nothing left the building can still be reportable.
What does not count: a leak with no personal data in it. A price list in the street is annoying and is not a breach. A security hole you find and close before anyone used it is not one either; that is a vulnerability, and it only becomes a breach once data is actually involved.
When you must report, and to whom
The main rule: within 72 hours to the supervisory authority (in the Netherlands the Autoriteit Persoonsgegevens) unless the breach is unlikely to result in a risk to the people it concerns. That exception is narrower than it sounds, because it is about their risk, not about the damage to your organisation.
The 72 hours run from the moment you become aware of the breach, not from the moment it happened. A breach that ran for six months and was found yesterday starts its clock yesterday. That is kinder than it sounds, and it is also why you need to be able to show when you knew; that date later becomes the start of the sum.
If the risk is high, you tell the people themselves as well, in a way they can act on: what leaked, what they can expect and what they should do now. A letter in officialese meets the letter of the rule and not its point.
A breach you do not report still gets written down. Every breach goes in your own register, including the one you conclude posed no risk, especially that one, because the reasoning has to be traceable afterwards.
The form asks questions about your logs
Anyone opening the report form for the first time expects a question about what happened. It is there, and it is the easy part. The hours go into the questions underneath.
Which categories of personal data. How many people. When it started and when it stopped. How you found out. Those are not legal questions; they are questions for your logs.
If you do not have them the answer is “unknown”, and that is allowed: a report with an estimate and a follow-up beats no report. But three “unknown” answers are information too, and they are the information a supervisor reads as nobody having been watching.
What makes the difference here was decided before the breach existed. Which events get recorded: sign-ins, failed sign-ins, file access, changes to permissions. How long they are kept. And whether an administrator can read them but not quietly clean them up. A thirty-day retention sounds generous until you find a breach in September that started in March.
What we do here, and what we do not
What we do. The part made of technology: making sure the logs exist, that they survive long enough and that nobody can quietly trim them, so that within those 72 hours we can say which accounts, which devices and which period. Beforehand we lower the odds: multi-factor authentication, permissions that match the job rather than the history, and encrypted storage: for us that is Apricorn, with the encryption inside the device and a keypad on the housing, so the PIN never passes through the computer. A lost stick nobody can open is a different conversation from a lost stick.
What we do not do. We do not file the report. That belongs to the organisation that decides why and how the data is processed, and that is you, even when we run the systems. Our role is usually that of processor, and a processor reports to its client and not to the supervisory authority; quickly, so your clock does not start with our turnaround time. We are also not a law firm and not a data protection officer: whether something is reportable, whether the risk is high enough to tell the people involved, and what that message says, is a legal judgement and we leave it to someone qualified to make it.
Questions we get about this
The four that come back most often.
Does every breach have to be reported?
No. You do not have to report if the breach is unlikely to result in a risk to the people whose data it is. That exception is narrower than it looks, because it turns on their risk and not on the damage to your organisation. Recording it is always required: the breach you do not report still belongs in your own register, together with the reasoning behind that decision. That judgement is a legal one; we supply the facts under it and do not make it.
When exactly do the 72 hours start?
On discovery, not on the incident. The moment someone in your organisation could reasonably have known there was a breach starts the clock, a breach that ran for six months and was found this morning has its deadline from this morning. That is why it pays to record when a report came in and who did what with it: that moment later becomes the start of the sum.
Does a lost laptop count if it was encrypted?
Yes, but it ends differently. The breach happened, so it goes in your register and you weigh whether it needs reporting. If the data was encrypted with a method that is still current and whoever found it does not have the key, the risk to the people involved is low and they usually do not need to be told separately. That is exactly why encrypted drives and sticks buy you more than peace of mind: they change the outcome, not only the odds.
Do you file the report for us?
No. The report belongs to the organisation that decides why the data is processed, and that is you, even when we run the systems. We are usually the processor, and that role reports to its client rather than to the supervisory authority. What we do is reach you fast enough and hand over the facts the report rests on: which accounts, which devices, which period. We are not a law firm and not a data protection officer.
Further reading
What comes before it, and where this lands in a standard.
Shall we see whether you could answer those questions?
Tell us what is being recorded today and how long it stays. We will say which questions on the report form you could answer right now and which you could not, and what it takes to fix the second list.
Practical IT knowledge in your inbox
New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.