Purpose of the Template
Under Article 33 GDPR, you must notify your supervisory authority of personal data breaches within 72 hours. The challenge is that each EU Member State has different requirements. Some prefer web forms; others accept email. The fields and definitions vary.
The EDPB's proposed common template aims to standardize this process. It's a structured format that supervisory authorities will implement through IT tools, with predefined values for incident types, breach classifications, and affected data categories. The template is under public consultation until 5 August 2026, giving you time to prepare your internal processes before its widespread adoption.
This guide helps you complete the template efficiently, map your existing breach response data to the EDPB's structure, and build a workflow for phased reporting when you don't have complete information within the 72-hour window.
Prerequisites
Before using this template script, ensure you have:
An active breach response protocol that captures the minimum Article 33(3) GDPR requirements: nature of the breach, categories and approximate numbers of data subjects and records affected, likely consequences, and measures taken or proposed.
A classification system that categorizes your personal data holdings. The EDPB template uses predefined data types: basic data (name, surname, date of birth), contact information, biometric data, employment-related health data, location data. Ensure your data inventory aligns with these categories to complete the template accurately under time pressure.
Documentation of your technical and organizational measures in place when the breach occurred. The template includes a predefined list: pseudonymization, encryption, incident logging, access controls, periodic audits. Know which of these were active and functioning at the time of the incident.
A cross-border breach protocol if you operate in multiple jurisdictions. The template requires identifying your lead supervisory authority and impacted Member States. You should already know this based on your Article 56 analysis, but the template makes it a mandatory field.
The Template Script
This script translates the EDPB's structure into a completion workflow. It goes beyond Article 33(3) GDPR's minimum requirements, meaning you need to gather more information than you might be used to.
Section 1: Breach Identification and Classification
Field: Notification status (complete / incomplete / withdrawn)
Your entry: Mark "incomplete" if you're reporting within 72 hours but lack full details. Article 33(4) GDPR permits phased reporting.
Field: Incident type (predefined options)
Your entry: Select from ransomware, hacking, malware, phishing, data exfiltration, incorrect access permissions, or other predefined categories.
Note: If your incident involves multiple vectors, select the primary attack method first.
Field: Breach classification
Your entry: Indicate whether the breach affected confidentiality, integrity, or availability. Many breaches affect more than one.
Section 2: Affected Data and Subjects
Field: Types of breached data (predefined list)
Your entry: Select all applicable categories. If you hold special category data under Article 9 GDPR, specify which types were affected.
Field: Categories of data subjects
Your entry: Describe the groups affected: employees, customers, minors, etc.
Field: Approximate numbers
Your entry: Provide your best estimate of affected data subjects and records. If you're reporting at the incomplete stage, state that numbers are provisional and will be updated.
Section 3: Consequences and Measures
Field: Assessment of consequences
Your entry: Describe the likely impact on data subjects. Be specific about the harm scenarios: unauthorized access to health records, exposure of financial data, reputational damage, risk of phishing attacks using exposed contact details.
Field: Measures in place when breach occurred
Your entry: Select from the predefined list which technical and organizational measures were active. If encryption was in place but the breach still occurred, explain why in the narrative section.
Field: Measures taken to address the breach
Your entry: Select from predefined options covering containment, investigation, and prevention. Include measures to mitigate adverse effects on data subjects.
Section 4: Cross-Border Elements
Field: Lead supervisory authority
Your entry: Identify your lead authority if you're processing data across multiple Member States under Article 56 GDPR.
Field: Impacted jurisdictions
Your entry: List all Member States where affected data subjects are located or where your processing activities take place.
Section 5: Attachments
Upload supporting documents: copies of communications sent to data subjects, internal risk assessments, ransomware notes, phishing messages, or other evidence relevant to the breach.
Customizing the Template
The template is standardized, but your completion process shouldn't be. Here's how to adapt it to your organization's reality:
Build a data mapping bridge. Create a translation table that maps your internal data classifications to the EDPB's predefined categories. If you classify data as "PII Level 2," document which EDPB categories that includes. This prevents confusion during an active incident.
Prepare incomplete notification triggers. Define what information you can reliably provide within 72 hours and what will require phased reporting. For most organizations, incident type, affected data categories, and initial impact assessment are available quickly. Precise numbers, root cause analysis, and comprehensive mitigation measures take longer.
Standardize your consequence assessment language. Draft example assessments for common breach scenarios: unauthorized access to employee records, exposure of customer contact details, loss of encrypted devices. Your breach response team can adapt these under pressure rather than writing from scratch.
Align your technical measures documentation. The template's predefined list of measures should match your information security documentation. If you're selecting "encryption" and "access controls," you should be able to attach evidence showing these were active and properly configured.
Coordinate with your Digital Omnibus planning. The EDPB template exists alongside proposed EU-wide breach reporting reforms that would introduce a single portal and common template across GDPR, NIS2, DORA, and other frameworks. Don't build a workflow so specific to this template that you can't adapt when the Digital Omnibus proposals materialize.
Validation Steps
Before submitting your first notification using this template:
Run a tabletop exercise. Use a realistic breach scenario and complete the template under simulated time pressure. Identify which fields your team struggles with and which information isn't readily available.
Check your phased reporting process. Submit a test incomplete notification (if your supervisory authority's IT tool permits testing) and verify you can update it with additional information. Confirm that your internal workflow tracks which fields remain outstanding.
Verify your attachments are accessible. During an incident, you won't have time to search file systems for risk assessments or communication templates. Create a breach response folder with pre-approved document templates and examples you can attach quickly.
Confirm your cross-border analysis is current. If you've changed your processing activities or expanded to new Member States, your lead supervisory authority identification may have changed. The template requires this information, and getting it wrong has Article 56 implications.
Review against Article 33(3) GDPR directly. The template requests more information than the regulation requires. Ensure you're not delaying notification because you're trying to complete every optional field. Submit an incomplete notification on time rather than a complete notification late.
The template is under consultation until 5 August 2026. If specific fields create operational problems for your organization, submit feedback to the EDPB during the consultation period. This is your opportunity to influence the final design before widespread supervisory authority adoption.



