Skip to main content
Category: Security & Breach Notification

Article 34

Simply put

The evidence provided does not contain any source describing Article 34 in the context of the GDPR or data privacy law. Instead, the sources refer to entirely unrelated 'Article 34' provisions in other legal instruments, such as the Geneva Convention (IV) on the prohibition of hostage-taking, the Constitution of India, the California state constitution, and the Charter of the United Nations. Because none of the supplied evidence relates to data protection, no privacy-focused definition can be generated from it.

Formal definition

The evidence packet contains no material addressing Article 34 of the GDPR (which, in the Regulation text, concerns communication of a personal data breach to the affected data subject) or any related privacy instrument. The available sources reference distinct and unrelated legal provisions bearing the same numbering: Article 34 of the Geneva Convention (IV), 1949 (prohibition of hostage-taking); Article 34 of the Constitution of India (restriction on rights while martial law is in force); Article 34 of the California Constitution (voter approval for publicly-funded low-rent housing projects); and Article 34 of the Charter of the United Nations (Security Council investigation of disputes). A precise, sourced privacy definition cannot be produced without evidence relevant to data protection law; the reader should supply GDPR-specific source material and verify any article reference against the current official Regulation text.

Why it matters

The reference "Article 34" is ambiguous, and the evidence supplied for this entry does not relate to data protection law at all. The sources instead describe unrelated provisions that happen to share the same numbering: Article 34 of the Geneva Convention (IV) (prohibition of hostage-taking), Article 34 of the Constitution of India (restriction on rights while martial law is in force), Article 34 of the California Constitution (voter approval for publicly-funded low-rent housing projects), and Article 34 of the Charter of the United Nations (Security Council investigation of disputes). None of these bears on personal data, controllers, processors, or any privacy obligation.

For a privacy and GDPR audience, this matters because citing an article number without confirming its instrument is a common source of error, and an incorrect cross-reference can undermine a compliance program. In the GDPR itself, Article 34 concerns communication of a personal data breach to the affected data subject; however, that characterisation is not supported by the evidence digest provided here and should be verified against the current official Regulation text before use.

Because the supplied evidence contains no data protection material, no privacy-focused definition can be generated from it. Readers should treat this entry as a disambiguation flag rather than a substantive definition, and should supply GDPR-specific source material to obtain an accurate, citable privacy definition.

Who it's relevant to

Data protection officers and compliance leads
Anyone relying on this entry for a GDPR obligation should not do so on the current evidence, which contains no data protection sources. Confirm the intended instrument and verify any article reference against the current official Regulation text before incorporating it into a compliance program.
Privacy lawyers and legal researchers
The ambiguity here illustrates why an article number must be paired with its instrument. The sources cited describe Geneva Convention (IV), Indian constitutional, Californian constitutional, and UN Charter provisions rather than any privacy law, so this reference requires disambiguation before it can support a legal citation.
Editors and knowledge-base maintainers
This entry should be flagged for re-sourcing. To produce a privacy definition of GDPR Article 34, supply source material drawn from the GDPR text or official regulatory guidance rather than the unrelated instruments currently in the evidence digest.

Inside Article 34

Communication to the data subject
Article 34 GDPR concerns the obligation of a controller to communicate a personal data breach to the affected data subjects, as distinct from the notification to the supervisory authority addressed in Article 33.
High risk trigger threshold
The duty to communicate to individuals is generally triggered where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons. This is a higher threshold than the risk standard that governs notification to the supervisory authority.
Undue delay standard
Where the threshold is met, communication should be made to the data subject without undue delay. Article 34 does not attach the specific time indication associated with authority notification, so the reader should verify the exact wording against the current official text.
Content of the communication
The communication is generally expected to describe, in clear and plain language, the nature of the breach and to include information broadly corresponding to certain elements of the Article 33 notification, such as the likely consequences and the measures taken or proposed to address the breach and mitigate its effects.
Exceptions to the obligation
Article 34 sets out circumstances in which direct communication to data subjects may not be required, generally including where appropriate protective measures such as encryption rendering data unintelligible were applied, where subsequent measures ensure the high risk is no longer likely to materialise, or where individual communication would involve disproportionate effort, in which case a public communication or similar measure may be used instead. Practitioners should confirm the precise conditions in the current text.
Role of the supervisory authority
The supervisory authority may, having considered the likelihood of high risk, require the controller to communicate the breach to data subjects or may confirm that one of the exception conditions applies.

Common questions

Answers to the questions practitioners most commonly ask about Article 34.

Does Article 34 require notifying data subjects about every personal data breach?
No. Article 34 applies only where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons. This is a higher threshold than the notification duty to the supervisory authority under Article 33, which is triggered by risk (unless the breach is unlikely to result in a risk). Many breaches that must be reported to a supervisory authority under Article 33 will not require communication to affected individuals under Article 34, because they do not meet the high-risk threshold. The assessment is context-dependent and should be documented.
Is communication to data subjects under Article 34 the same obligation as notifying the supervisory authority?
No, these are distinct obligations directed at different recipients and triggered by different thresholds. Notification to the competent supervisory authority is governed by Article 33 and generally arises where a breach poses a risk to data subjects. Communication to affected data subjects is governed by Article 34 and generally arises only where the breach is likely to result in a high risk. A controller may need to satisfy one, both, or neither obligation depending on the circumstances, and the timing and content requirements differ. The two provisions should be assessed separately.
How should a controller assess whether a breach meets the 'high risk' threshold for Article 34?
The assessment is fact-specific and generally considers factors such as the type and sensitivity of the personal data involved, the ease of identifying affected individuals, the severity of potential consequences, the volume of data and number of individuals affected, and any special category data under Article 9. Regulatory guidance from the European Data Protection Board and national supervisory authorities offers frameworks for this evaluation. Because interpretations can vary between regulators and depend on the circumstances, controllers should document their reasoning and verify the current guidance applicable in their jurisdiction.
Are there circumstances where communication to data subjects is not required even for a high-risk breach?
Article 34 sets out conditions under which communication to data subjects may not be required, subject to assessment. These generally include situations where the controller has implemented appropriate technical and organisational protection measures applied to the affected data (such as measures that render the data unintelligible to unauthorised persons), where subsequent measures have been taken to ensure the high risk is no longer likely to materialise, or where individual communication would involve disproportionate effort. In the latter case, a public communication or similar measure may be used instead. A supervisory authority can also require communication where it disagrees with the controller's assessment. Controllers should verify the precise conditions against the current official text.
What information should a communication to data subjects contain?
The communication should generally describe, in clear and plain language, the nature of the personal data breach and typically include information such as the name and contact details of the data protection officer or other contact point, the likely consequences of the breach, and the measures taken or proposed to address it, including measures to mitigate possible adverse effects. Clarity and accessibility for the affected individuals are central to the provision. Controllers should confirm the specific required elements against the current text and any applicable regulatory guidance.
How quickly must data subjects be informed under Article 34?
Article 34 generally requires that communication to affected data subjects be made without undue delay once the high-risk threshold is met. This is a distinct timing standard from the supervisory authority notification framework under Article 33. What constitutes undue delay is context-dependent and may be influenced by the need to first contain the breach or coordinate with the supervisory authority. Controllers should document the timeline and rationale for the timing of any communication, and verify the applicable standard against the current official text.

Common misconceptions

Every personal data breach must be communicated to affected individuals.
Communication under Article 34 is generally required only where the breach is likely to result in a high risk to the rights and freedoms of natural persons. Many breaches meet the lower threshold for authority notification under Article 33 without triggering the Article 34 duty, and the assessment is context and risk dependent.
Article 33 and Article 34 impose the same obligation.
They are distinct. Article 33 concerns notification to the supervisory authority at a risk threshold, while Article 34 concerns communication to data subjects at the higher high risk threshold. The addressee, trigger, timing language, and available exceptions differ.
Encryption or other measures automatically remove the duty to inform individuals.
The exceptions in Article 34 may apply, for example where measures such as encryption render the data unintelligible, but this is subject to assessment of whether the high risk remains likely to materialise. Reliance on an exception should be documented, and a supervisory authority may still require communication.

Best practices

Assess breaches against both the Article 33 risk threshold and the higher Article 34 high risk threshold separately, and document the reasoning for whichever conclusion is reached.
Prepare template communications in clear and plain language that address the nature of the breach, the likely consequences, and the measures taken or proposed, so they can be issued without undue delay when the high risk threshold is met.
Where reliance on an exception is claimed, such as prior encryption or subsequent risk-mitigating measures, record the factual and technical basis and be prepared to justify it to the supervisory authority.
Coordinate the Article 34 assessment with the incident response and Article 33 workflow so that authority notification and individual communication decisions are consistent and evidenced.
Consider the disproportionate effort scenario in advance, planning for a public communication or equivalent measure as an alternative to individual contact where appropriate.
Verify current timing, content, and exception requirements against the official GDPR text and applicable regulator guidance, and check for any divergence under the UK GDPR or national implementing law before finalising a breach communication procedure.