Skip to main content
Category: Security & Breach Notification

Article 33

Simply put

"Article 33" is a generic article label that appears in many different legal instruments, and the evidence provided here refers only to non-privacy sources: the New York controlled substances law, the Constitution of India, a labor contract savings clause, the UN Refugee Convention, and the UN Charter. None of the supplied evidence addresses a data protection or GDPR provision, so a Privacy Track glossary definition cannot be reliably generated from this evidence packet. Readers seeking the GDPR breach-notification provision should note that no supporting GDPR text was provided here and should consult the official Regulation.

Formal definition

The evidence packet supplied for this entry contains no data protection or privacy-law material. It documents five unrelated "Article 33" provisions: Article 33 of the New York Public Health Law (controlled substances); Article 33 of the Constitution of India (Parliament's power to modify fundamental rights for the armed forces); Article 33 of a labor agreement (savings clause); Article 33 of the 1951 UN Refugee Convention (the principle of non-refoulement); and Article 33 of the UN Charter (pacific settlement of disputes). Because none of these sources establishes a privacy or GDPR meaning, no authoritative privacy-track definition can be substantiated from the evidence provided. Practitioners should be aware that a separate provision, Article 33 of the EU General Data Protection Regulation (and its UK GDPR counterpart), governs notification of a personal data breach to the supervisory authority; however, that provision is not represented in this evidence packet, and its text and requirements must be verified against the current official EU and UK sources rather than inferred from the materials cited here.

Why it matters

"Article 33" is a label that recurs across many legal instruments, and the evidence packet supplied for this entry references only non-privacy sources: the New York Public Health Law on controlled substances, the Constitution of India, a labor-agreement savings clause, the 1951 UN Refugee Convention, and the UN Charter. For a Privacy Track audience, the practical significance of this entry is primarily one of disambiguation: a bare citation to "Article 33" is ambiguous and can point to entirely unrelated bodies of law, so practitioners should confirm which instrument is intended before relying on any provision.

The disambiguation matters because a citation error can have compliance consequences. A compliance program that references "Article 33" without naming the source instrument risks confusion between, for example, the non-refoulement principle in the Refugee Convention and a data protection obligation. When the intended reference is the EU General Data Protection Regulation, that provision is generally understood to concern notification of a personal data breach to the supervisory authority; however, the evidence packet supplied here does not contain the text of that GDPR provision, and none of the cited sources substantiate its content.

Because the supporting regulatory text is not present in this evidence packet, readers should not treat any description of the GDPR provision as verified here. Practitioners seeking the breach-notification requirements should consult the current official EU Regulation text, and separately the UK GDPR as retained and amended in UK law, since the two regimes can diverge and are administered by different supervisory authorities.

Who it's relevant to

Data protection officers and compliance leads
DPOs and compliance leads may encounter "Article 33" as shorthand for a breach-notification obligation, but this evidence packet does not supply that regulatory text. They should verify any breach-notification requirement against the current official EU GDPR, and separately the UK GDPR, before relying on it, since the two regimes are administered by different supervisory authorities and can diverge.
Privacy and technology lawyers
Lawyers reviewing cross-referenced documents should treat a bare "Article 33" citation as ambiguous and confirm the governing instrument, because the same label appears in national public-health law, constitutional law, labor agreements, and international conventions such as the Refugee Convention and the UN Charter.
Editors and knowledge-base maintainers
Those maintaining glossaries or citation systems should flag "Article 33" as a disambiguation term and ensure that any privacy-specific entry is grounded in verified GDPR or UK GDPR source text, which is not present in this evidence packet.

Inside Article 33

Controller notification duty to the supervisory authority
Article 33 GDPR requires a controller to notify the competent supervisory authority of a personal data breach. The obligation is generally triggered unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons, meaning a risk-based threshold governs whether notification is required.
Timing expectation (the 72-hour reference)
Notification to the supervisory authority is expected without undue delay and, where feasible, not later than 72 hours after the controller becomes aware of the breach. Where notification is not made within that period, it must generally be accompanied by reasons for the delay. Practitioners should verify the exact wording against the current official text.
Processor-to-controller notification
Where a processor becomes aware of a personal data breach, Article 33 requires it to notify the controller without undue delay. The processor's role here is distinct from the controller's own notification duty to the supervisory authority; the processor generally does not notify the authority directly under this provision.
Minimum content of the notification
The notification should generally describe the nature of the breach (including, where possible, categories and approximate numbers of data subjects and records concerned), provide contact details (typically the DPO or another contact point), describe the likely consequences, and set out measures taken or proposed to address and mitigate the breach.
Phased / staged notification
Where all information is not available at once, Article 33 generally permits information to be provided in phases without undue further delay, allowing an initial notification followed by supplementary detail as the investigation progresses.
Internal record-keeping of breaches
Controllers are generally required to document personal data breaches, including the facts, effects, and remedial action taken, so that the supervisory authority can verify compliance. This documentation obligation applies to breaches whether or not they are notifiable.
Relationship to Article 34
Article 33 concerns notification to the supervisory authority, which is distinct from Article 34's separate duty to communicate a breach to affected data subjects where there is a high risk. The two thresholds and audiences should not be conflated.
EU GDPR and UK GDPR scope
The provision exists in both the EU GDPR and, in materially similar form, the UK GDPR, where the Information Commissioner's Office is the relevant supervisory authority. Member state or UK-specific procedural detail and guidance can vary, so the applicable regime and current guidance should be confirmed.

Common questions

Answers to the questions practitioners most commonly ask about Article 33.

Does Article 33 require notifying the supervisory authority about every personal data breach?
No. Article 33(1) requires notification to the competent supervisory authority only where the breach is likely to result in a risk to the rights and freedoms of natural persons. Where a breach is unlikely to result in such a risk, notification to the authority is generally not required, though the controller must still document the breach internally under Article 33(5). This risk assessment is context dependent and should be documented, so the distinction between a notifiable and non-notifiable breach turns on the outcome of that assessment rather than the mere occurrence of a breach.
Is the 72-hour deadline an absolute cut-off after which notification is pointless?
No. The 72-hour period runs from when the controller becomes aware of the breach, and it is a target for notification, not a bar. Article 33(1) expressly contemplates late notification: where notification is not made within 72 hours, it must be accompanied by reasons for the delay. Notification can also be provided in phases under Article 33(4) where all information is not available at once. So a controller that misses the 72-hour window should still notify and explain the delay rather than treat the obligation as extinguished.
When does the 72-hour clock start under Article 33?
The period runs from the point at which the controller becomes 'aware' of a personal data breach. Regulatory guidance has generally treated awareness as arising when the controller has a reasonable degree of certainty that a security incident has occurred that led to personal data being compromised, which may follow a short initial investigation period. The precise moment can be fact-specific, and readers should assess it case by case and consult current supervisory authority guidance, as interpretation may vary between the EU and UK contexts and among individual regulators.
What information must an Article 33 notification to the supervisory authority contain?
Article 33(3) sets out the minimum content, which generally includes a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects and of personal data records concerned), the name and contact details of the data protection officer or other contact point, the likely consequences of the breach, and the measures taken or proposed to address it and mitigate possible adverse effects. Where the full picture is not yet available, this information may be provided in phases under Article 33(4).
What is the processor's role when a breach occurs under Article 33?
Under Article 33(2), a processor must notify the controller without undue delay after becoming aware of a personal data breach. The processor's obligation is to alert the controller; the controller retains responsibility for assessing risk and, where the threshold is met, notifying the supervisory authority. This allocation is typically reinforced by the terms of the Article 28 data processing agreement, which often specifies timelines and cooperation arrangements. Processors are not themselves obliged to notify the supervisory authority under Article 33.
What documentation should a controller keep to demonstrate Article 33 compliance?
Article 33(5) requires the controller to document all personal data breaches, including the facts relating to the breach, its effects, and the remedial action taken. This documentation duty applies regardless of whether the breach was notifiable, and it enables the supervisory authority to verify compliance. Maintaining an internal breach register capturing the assessment and the reasoning behind any decision not to notify is a common practice to evidence accountability, though the specific format is not prescribed by the Regulation.

Common misconceptions

Every personal data breach must be reported to the supervisory authority.
Notification under Article 33 is subject to a risk threshold. A breach that is unlikely to result in a risk to the rights and freedoms of natural persons generally does not require notification to the authority, although the controller should still document it and record the reasoning for not notifying.
The 72-hour period is an absolute, unbreachable deadline that starts at the moment of the incident.
The clock generally runs from when the controller becomes aware of the breach, not from the incident itself, and the standard is without undue delay and where feasible within 72 hours. Late notification is contemplated provided reasons for the delay are given; the reader should verify the precise wording in the current text.
A processor must notify the supervisory authority when it suffers a breach.
Under Article 33, a processor's duty is generally to notify the controller without undue delay. Responsibility for notifying the supervisory authority typically rests with the controller, and any allocation of practical steps should be reflected in the Article 28 data processing agreement.

Best practices

Establish a documented breach-response procedure that defines when the controller is deemed aware, so the without-undue-delay and where-feasible-72-hour expectation can be met and evidenced.
Maintain an internal breach register recording the facts, effects, and remedial action for all breaches, including those assessed as not notifiable, together with the risk assessment supporting each decision.
Apply a structured risk assessment to determine whether the risk threshold for notifying the supervisory authority is met, and separately assess the high-risk threshold relevant to notifying data subjects.
Use the Article 28 data processing agreement to set clear processor-to-controller breach notification timelines and cooperation obligations, so the controller can meet its own duties.
Prepare a notification template capturing the minimum content elements and enable phased notification where full information is not initially available.
Confirm the applicable regime (EU GDPR or UK GDPR), identify the competent supervisory authority, and check current regulator guidance and the official text, as procedural detail and interpretation can vary between authorities.