Skip to main content
Category: Security & Breach Notification

Notification Not Required Exceptions

Also known as: Notification Exceptions, Breach Notification Exceptions
Simply put

In the context of data breach rules, these are specific situations where an organization does not have to notify regulators or affected individuals about a security incident, even though personal data was involved. For example, if the data was strongly encrypted or otherwise made unreadable to unauthorized parties, notification may not be required. Whether an exception applies depends on the specific facts and the applicable law, so each situation must be assessed individually.

Formal definition

Notification Not Required Exceptions refers to circumstances under which the obligation to report a personal data breach may be reduced or removed. Under the GDPR framework, breach notification obligations are generally triggered by an assessment of risk to the rights and freedoms of individuals; the available evidence describes exceptions such as encryption or redaction of the affected data, and, in certain jurisdictions, 'good faith' acquisition scenarios where an organization can demonstrate the data is unlikely to result in harm. The precise conditions vary substantially between the EU GDPR, the UK GDPR, and national or non-EU breach-notification laws, and the exact article references, thresholds, and 'good faith' concepts referenced in the evidence appear to derive from specific statutory regimes rather than a single uniform standard. Practitioners should verify the applicable notification thresholds, exemptions, and any documentation or accountability requirements against the current governing law and regulator guidance, as this remains context-dependent and subject to assessment on a case-by-case basis.

Why it matters

Breach notification obligations can impose significant operational, legal, and reputational burdens on an organization, so understanding when notification is not required is a meaningful part of incident response planning. Under the GDPR framework, the obligation to notify regulators or affected individuals is generally triggered by an assessment of the risk to the rights and freedoms of individuals, which means not every security incident involving personal data results in a mandatory notification. Correctly identifying whether a recognized exception applies helps organizations avoid both over-notification, which can dilute the significance of genuine high-risk breaches, and under-notification, which can expose them to enforcement and loss of trust.

The available evidence describes exceptions such as encryption or redaction of the affected data, and, in some jurisdictions, 'good faith' acquisition scenarios where an organization can demonstrate the data is unlikely to result in harm. However, these exceptions are not uniform: the precise conditions, thresholds, and concepts vary substantially between the EU GDPR, the UK GDPR, and national or non-EU breach-notification laws. An exception recognized under one statutory regime may not exist, or may be framed differently, under another, so treating a single formulation as settled law across jurisdictions is a common and consequential error.

Because whether an exception applies depends heavily on the specific facts and the governing law, each incident must be assessed individually and typically documented to support the organization's accountability position. Relying on an assumed exception without a defensible, contemporaneous assessment can leave an organization exposed if a regulator later disagrees with the analysis, particularly where the effectiveness of a protective measure such as encryption is in question.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads coordinate breach assessments and decide, in most cases with legal input, whether a notification exception applies. They typically need to ensure the reasoning behind any decision not to notify is documented to support the organization's accountability position, and to confirm which regime's exceptions govern a given incident.
Legal and Compliance Counsel
Counsel advise on whether a recognized exception, such as encryption, redaction, or, in certain jurisdictions, 'good faith' acquisition, removes or reduces the notification obligation under the specific applicable law. Because the conditions vary substantially between the EU GDPR, UK GDPR, and other regimes, they generally verify thresholds and exemptions against the current governing text and regulator guidance rather than assuming a uniform standard.
Security and Incident Response Engineers
Engineers implement and evaluate protective measures such as strong encryption or redaction, whose effectiveness can be decisive in whether an exception applies. They typically provide the technical facts, for example, whether affected data was rendered unreadable to unauthorized parties, that inform the risk assessment underlying any decision not to notify.
Organizations Operating Across Multiple Jurisdictions
Businesses subject to more than one breach-notification regime need to recognize that an exception available under one law may not exist, or may be framed differently, under another. Subject to assessment on a case-by-case basis, they should confirm the applicable exceptions and documentation requirements for each jurisdiction involved in an incident.

Inside Notification Not Required Exceptions

Effective technical and organisational protection measures
Where a controller has applied measures that render the affected personal data unintelligible to unauthorised persons, such as strong encryption, notification to affected data subjects may not be required. This exception generally turns on whether the measures were in place and applicable to the compromised data at the time of the breach, and is assessed case by case rather than assumed.
Subsequent measures eliminating high risk
If the controller takes steps after the breach that ensure the high risk to the rights and freedoms of data subjects is no longer likely to materialise, communication to individuals may not be required. Whether the risk has genuinely been contained is a matter for assessment and should be documented.
Disproportionate effort
Where individual notification would involve disproportionate effort, the controller may instead use a public communication or similar measure by which affected data subjects are informed in an equally effective manner. What qualifies as disproportionate is context dependent and should not be treated as a routine fallback.
Relationship to the risk threshold for individual notification
These exceptions operate against the baseline that communication to the data subject is generally required only where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons. Where no high risk arises, individual notification may not be triggered in the first place, separately from these specific exceptions.
Distinction from supervisory authority notification
These exceptions concern communication to affected individuals. Notification to the competent supervisory authority is a separate obligation with its own threshold and timing, and the exceptions to individual communication do not automatically remove any obligation to notify the authority or to document the breach internally.
Supervisory authority override
Even where a controller considers an exception applies, the supervisory authority may, having assessed the likelihood of high risk, require the controller to communicate the breach to the affected data subjects. The controller's reliance on an exception is therefore not necessarily final.

Common questions

Answers to the questions practitioners most commonly ask about Notification Not Required Exceptions.

If a personal data breach occurs, must it always be notified to the supervisory authority?
No. Notification to the supervisory authority is generally required, but the GDPR recognises an exception where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. This is a risk-based assessment rather than an automatic obligation, so the controller must document its reasoning even where it concludes notification is not required. You should verify the precise wording and article references against the current official text.
Does qualifying for a notification exception mean the breach does not need to be recorded or acted upon at all?
No. An exception from notifying the supervisory authority or affected individuals does not remove the controller's general obligation to document all personal data breaches internally, including the facts, effects, and remedial action taken. The exceptions concern outward notification, not the internal accountability and record-keeping expectations. The threshold for notifying the supervisory authority and the (typically higher) threshold for notifying affected individuals are also distinct and should be assessed separately.
How should a controller assess whether a breach is unlikely to result in a risk?
Assessment is context-dependent and typically considers factors such as the type and sensitivity of the data, the number of individuals affected, the ease of identifying individuals, the severity of potential consequences, and whether protective measures were in place. Because this is a case-by-case evaluation, controllers generally document the assessment and its outcome so the decision not to notify can be justified. Regulatory guidance on these factors exists and may evolve, so consult current guidance from the relevant supervisory authority.
Can technical measures such as encryption support reliance on a notification exception?
In many cases, effective technical and organisational measures that render the data unintelligible to unauthorised persons can be relevant to whether a breach is likely to result in a risk, particularly regarding notification to affected individuals. Whether such measures are sufficient depends on the specifics, including the strength of the measure and whether the protection could be compromised. This should be assessed at the time of the breach rather than assumed in advance, and you should verify the applicable conditions against the current official text and guidance.
What should be documented when a controller decides an exception applies?
Controllers should generally record the facts relating to the breach, the categories and approximate numbers of individuals and records concerned, the assessment of likelihood and severity of risk, the reasoning for concluding notification was not required, and any remedial or mitigating actions taken. Maintaining this documentation supports the accountability principle and enables the controller to demonstrate the basis for its decision if later reviewed by a supervisory authority.
Does relying on an exception vary between the EU GDPR and the UK GDPR or across member states?
The core structure of the notification regime is broadly similar under the EU GDPR and the UK GDPR, but the relevant supervisory authority and its guidance differ, and interpretive expectations can vary between regulators. Member state or national implementing law and sector-specific rules may also affect timing, procedure, or additional obligations. Controllers operating across jurisdictions should check the position with each applicable authority rather than assuming a single approach applies everywhere.

Common misconceptions

Encryption always removes any obligation to notify a breach.
Encryption or similar measures may support an exception to communicating with data subjects only where they actually render the affected data unintelligible to unauthorised parties and applied to the data in question. The strength, implementation, and whether keys were also compromised all matter, and the assessment is case specific. A separate obligation to notify the supervisory authority and to document the breach may still apply.
If an exception to notifying individuals applies, no obligations remain.
Communication to affected data subjects and notification to the supervisory authority are distinct obligations with different thresholds. An exception to individual communication does not, by itself, relieve the controller of the internal documentation obligation or any applicable duty to notify the authority.
Once a controller decides an exception applies, that decision is final.
A supervisory authority can assess the likelihood of high risk and require the controller to communicate the breach to affected individuals despite the controller's view that an exception applied. The controller's determination should be documented and defensible, not treated as conclusive.

Best practices

Document the reasoning for relying on any exception at the time the decision is made, including the risk assessment and the specific facts supporting the exception, so the position can be defended if the supervisory authority queries it.
Assess the individual communication threshold and the supervisory authority notification obligation separately, and do not assume that an exception to one removes the other.
Verify that any technical measures relied on, such as encryption, actually applied to the compromised data and rendered it unintelligible, including confirming that decryption keys were not also affected.
Treat disproportionate effort as a narrow, evidence-based justification, and where used, plan an equally effective public or alternative communication rather than omitting notice.
Maintain the internal breach record regardless of whether individuals are notified, so the facts, effects, and remedial action are available for accountability purposes.
Keep the analysis under review as the situation develops and be prepared to notify affected individuals if the supervisory authority requires it or if new information changes the risk assessment.