Notification Without Undue Delay
"Notification without undue delay" is a timing standard in the GDPR requiring that certain data breach notifications be made promptly, without unnecessary hold-ups, once the relevant party becomes aware of the breach. It applies in several situations, such as a processor telling a controller about a breach, and an organisation telling affected individuals when a breach is likely to seriously affect them. What counts as "undue" delay depends on the circumstances rather than a single fixed deadline.
"Without undue delay" is a qualified promptness standard used across GDPR breach-notification obligations rather than a defined number of hours. Under Article 33 GDPR, a processor must notify the controller of a personal data breach without undue delay after becoming aware of it. Where a breach is likely to result in a high risk to affected individuals, the controller must communicate the breach to those data subjects without undue delay (this individual-notification obligation is generally associated with Article 34 GDPR, per the evidence). The standard is distinct from, but interacts with, the controller's obligation to notify the supervisory authority; guidance sources indicate that where notification to the authority is not made within 72 hours, it should be made without undue delay and accompanied by reasons for the delay, and phased notification may be used. What constitutes "undue" delay is assessed contextually, taking into account the nature and circumstances of the breach; readers should verify the precise article references, applicable timeframes, and any sector-specific or member state variations against the current official text, as some cited requirements (for example, specified 24-hour deadlines) may reflect particular regimes or guidance rather than the general GDPR standard.
Why it matters
The "without undue delay" standard shapes how quickly information about a breach flows between the parties involved and, ultimately, to the people whose data is affected. Because it is a qualified promptness standard rather than a single fixed countdown, it places a continuing burden on organisations to justify their timing. A processor that becomes aware of a personal data breach must notify the controller without undue delay under Article 33 GDPR, and that prompt hand-off is often what enables the controller to meet its own downstream obligations. Delay at one link in the chain can compromise the whole notification process.
The standard also governs communication to individuals. Where a breach is likely to result in a high risk to affected individuals, the controller must communicate it to them without undue delay, an obligation generally associated with Article 34 GDPR. This matters because timely notice can allow individuals to take protective steps. The flexibility of the standard cuts both ways: it accommodates genuinely complex investigations, but it does not license open-ended delay, and organisations are typically expected to document and, where relevant, explain any lag.
The standard interacts with, but is distinct from, the controller's obligation to notify the supervisory authority. Guidance indicates that where notification to the authority is not made within 72 hours, it should still be made without undue delay and accompanied by reasons for the delay, and that phased notification may be used where full details are not yet available. Readers should verify precise article references, timeframes, and any sector-specific or member state variations against the current official text, as some cited requirements may reflect particular regimes or guidance rather than the general GDPR standard.
Who it's relevant to
Inside Notification Without Undue Delay
Common questions
Answers to the questions practitioners most commonly ask about Notification Without Undue Delay.