When the Direction générale des Finances publiques notified the CNIL of unauthorized access to fiscal and cadastral data in August 2026, they triggered Article 33 and Article 34 obligations that many public-sector controllers still struggle to operationalize. Your breach response can't start when you discover unauthorized access; it needs to be a tested procedure before that moment arrives.
This template provides a breach notification framework designed for public-sector controllers handling sensitive administrative data. It covers both supervisory authority notification (Article 33) and data subject communication (Article 34), with guidance for customizing it to different breach scenarios.
Purpose of the Template
This template is a two-part notification system: an internal breach assessment form that feeds into external notifications, and pre-drafted communication templates for both the supervisory authority and affected individuals. Use it when you've identified unauthorized access, accidental disclosure, or loss of personal data that poses a risk to individuals' rights and freedoms.
The template assumes you're a controller, not a processor notifying a controller. If you're a processor, you need a different workflow under Article 33(2).
Prerequisites
Before you customize this template, ensure:
- Incident containment: The breach must be contained or actively contained. Don't wait for perfect information, but don't notify while attackers still have active access.
- Preliminary scope: You should know what categories of data were affected, even if you don't yet have exact record counts.
- Legal review access: Someone with authority to approve external communications should review your draft notifications before transmission.
- Contact registry: Current contact details for your supervisory authority and (for Article 34 notifications) affected individuals or their representatives.
You don't need to complete a full forensic investigation. Article 33 requires notification within 72 hours of becoming aware of the breach; waiting for certainty means missing the deadline.
The Template
Part 1: Internal Breach Assessment Form
PERSONAL DATA BREACH ASSESSMENT
Incident ID: [Unique reference]
Date/time of discovery: [When your team became aware]
Discovered by: [Role, not name]
BREACH DESCRIPTION
What happened: [Unauthorized access / accidental disclosure / loss /
destruction / alteration]
Data categories affected:
□ Identification data (names, ID numbers, contact details)
□ Financial data (tax information, bank details, income data)
□ Location data (addresses, cadastral information)
□ Professional data (SIREN, business registration)
□ Authentication credentials (passwords, tokens)
□ Special category data under Article 9
□ Criminal conviction data under Article 10
□ Other: [specify]
Estimated number of individuals affected: [Range if exact count unknown]
RISK ASSESSMENT
Likelihood of adverse impact:
□ Low: Data encrypted/pseudonymized, limited sensitivity
□ Medium: Readable data, moderate sensitivity, no known misuse
□ High: Sensitive data, evidence of extraction or misuse
Potential consequences for individuals:
□ Identity theft or fraud risk
□ Financial loss
□ Discrimination or reputational damage
□ Loss of confidentiality (professional secrecy, tax data)
□ Physical safety concerns
□ Other: [specify]
ARTICLE 33 DETERMINATION
Must notify supervisory authority within 72 hours?
□ YES (likely risk to rights and freedoms exists)
□ NO (document why risk is unlikely)
□ UNCERTAIN (escalate to DPO immediately)
ARTICLE 34 DETERMINATION
Must notify affected individuals directly?
□ YES (high risk to rights and freedoms)
□ NO, because: [select one or more]
□ Appropriate technical protections in place (encryption)
□ Subsequent measures eliminate high risk
□ Disproportionate effort required (public communication instead)
□ Risk is not high
CONTAINMENT STATUS
Breach contained: □ Yes □ Partially □ No
Immediate actions taken: [List steps]
Responsible party: [Internal team/external processor/unknown]
Part 2: Supervisory Authority Notification (Article 33)
SUBJECT: Personal Data Breach Notification, [Your Organization]
, Ref: [Incident ID]
To: [Your supervisory authority's breach notification contact]
Dear [Supervisory Authority],
[Your organization name], acting as controller, notifies you of a
personal data breach under Article 33 GDPR.
1. NATURE OF THE BREACH
On [date], we discovered [unauthorized access to / accidental disclosure
of / loss of] personal data in [affected system/database]. The breach
involved [brief description: e.g., "unauthorized access to our tax
information system allowing extraction of fiscal data"].
2. CATEGORIES AND APPROXIMATE NUMBER OF DATA SUBJECTS
Affected individuals: Approximately [number or range]
Categories: [Taxpayers / service users / employees / other]
3. CATEGORIES AND APPROXIMATE NUMBER OF RECORDS
Records affected: Approximately [number or range]
Data categories: [List, e.g., "fiscal information including income
reference, household quotient, withholding tax rate; cadastral data
including property addresses and surface areas"]
Authentication credentials affected: [Yes/No, if yes, specify type]
4. LIKELY CONSEQUENCES
[Describe risk: e.g., "The exposed fiscal data could enable targeted
phishing or identity fraud. Cadastral information combined with names
creates risk of physical security concerns or property-related fraud."]
No evidence of data misuse has been identified as of this notification.
5. [MEASURES TAKEN OR PROPOSED](/glossary/measures-taken-or-proposed)
Immediate containment: [Actions taken]
Individual notification: [We are/are not notifying individuals directly
because...]
Additional safeguards: [Planned measures]
6. CONTACT POINT
DPO: [Name, email, phone]
Incident lead: [Role, email, phone]
We will provide updates as our investigation progresses.
[Your name]
[Your role]
[Organization]
[Date and time of notification]
Part 3: Data Subject Communication (Article 34)
SUBJECT: Important Security Notice Regarding Your [Tax/Service] Data
Dear [Title/Name],
We're writing to inform you that [your organization] experienced a
security incident that may have affected your personal information.
WHAT HAPPENED
On [date], we discovered that an unauthorized party accessed our
[system name], which stores [type of data]. The accessed information
included [specific categories: fiscal information, cadastral data, etc.].
WHAT INFORMATION WAS INVOLVED
Your [income reference data / property addresses / business registration
details / other] may have been accessed.
Your login credentials and passwords were NOT affected by this incident.
WHAT WE'RE DOING
We have [contained the breach / implemented additional security measures /
notified relevant authorities including the CNIL]. We are conducting a
full investigation.
WHAT YOU SHOULD DO
1. Monitor your accounts for unusual activity, particularly [relevant
accounts or services].
2. Be alert for phishing attempts. We will never ask you to verify
sensitive information by email or phone. If you receive unexpected
contact requesting [tax details / financial information], do not respond
and report it to [contact].
3. If you notice suspicious activity related to your [tax filings /
property records / other], contact us immediately at [secure contact
method].
QUESTIONS
Our dedicated support line is available at [phone] [hours]. You can also
contact our Data Protection Officer at [email].
We take the security of your information seriously and apologize for
this incident.
[Signature]
[Title]
[Organization]
[Date]
How to Customize It
For the assessment form: Adjust data categories to match what you actually process. A healthcare authority needs "health data" checkboxes; a land registry needs "property ownership" categories. The form should reflect your data inventory.
For supervisory authority notification: Your authority may have a specific portal or form. Use their format if required, but ensure these Article 33 elements appear: nature of breach, categories and numbers, likely consequences, measures taken, and a contact point. The CNIL, for instance, uses an online notification system; adapt the content above to their fields.
For data subject communication: Tone matters here. The DGFiP incident notification told individuals that passwords weren't affected; lead with what's safe, then explain what's at risk. If you're notifying elderly taxpayers, avoid technical jargon. If you're notifying businesses about SIREN exposure, you can be more direct about commercial risk.
Remove sections that don't apply. If no special category data was involved, delete that checkbox rather than leaving it blank; it reduces cognitive load during an actual incident.
Timing customization: If you operate across multiple EU jurisdictions, note that the 72-hour clock starts when you become aware, not when you finish investigating. "Aware" means when you have reasonable certainty a breach occurred, not when you have complete details.
Validation Steps
Before you file this template away, test it:
Run a tabletop exercise: Give your team a scenario (unauthorized access to your citizen database, accidental email to wrong recipients) and time how long it takes to complete the assessment form. If it takes more than 30 minutes, your form is too complex.
Verify supervisory authority contact details: Check your authority's website for current breach notification procedures. The CNIL's process may differ from the ICO's. Confirm email addresses, portal URLs, and phone numbers annually.
Test Article 34 delivery channels: If you plan to notify 40,000 individuals by email, do you have verified email addresses? If not, you may need public communication instead; confirm that path exists.
Legal sign-off: Have your legal team or DPO review the templates now, while there's no time pressure. They'll suggest language changes that prevent you from admitting liability or making commitments you can't keep.
Check encryption status: The assessment form asks about technical protections. Verify whether your sensitive databases are actually encrypted at rest. If they're not, that's a finding that changes your breach response and your immediate security roadmap.
When the CNIL conducts on-site investigations to verify your security measures meet current standards, they'll look at your breach response capability. A tested template proves you've operationalized Article 33 and Article 34, not just documented them.



