Skip to main content
Category: Security & Breach Notification

Notification Without Undue Delay

Also known as: Undue Delay Standard, Without Undue Delay
Simply put

"Notification without undue delay" is a timing standard in the GDPR requiring that certain data breach notifications be made promptly, without unnecessary hold-ups, once the relevant party becomes aware of the breach. It applies in several situations, such as a processor telling a controller about a breach, and an organisation telling affected individuals when a breach is likely to seriously affect them. What counts as "undue" delay depends on the circumstances rather than a single fixed deadline.

Formal definition

"Without undue delay" is a qualified promptness standard used across GDPR breach-notification obligations rather than a defined number of hours. Under Article 33 GDPR, a processor must notify the controller of a personal data breach without undue delay after becoming aware of it. Where a breach is likely to result in a high risk to affected individuals, the controller must communicate the breach to those data subjects without undue delay (this individual-notification obligation is generally associated with Article 34 GDPR, per the evidence). The standard is distinct from, but interacts with, the controller's obligation to notify the supervisory authority; guidance sources indicate that where notification to the authority is not made within 72 hours, it should be made without undue delay and accompanied by reasons for the delay, and phased notification may be used. What constitutes "undue" delay is assessed contextually, taking into account the nature and circumstances of the breach; readers should verify the precise article references, applicable timeframes, and any sector-specific or member state variations against the current official text, as some cited requirements (for example, specified 24-hour deadlines) may reflect particular regimes or guidance rather than the general GDPR standard.

Why it matters

The "without undue delay" standard shapes how quickly information about a breach flows between the parties involved and, ultimately, to the people whose data is affected. Because it is a qualified promptness standard rather than a single fixed countdown, it places a continuing burden on organisations to justify their timing. A processor that becomes aware of a personal data breach must notify the controller without undue delay under Article 33 GDPR, and that prompt hand-off is often what enables the controller to meet its own downstream obligations. Delay at one link in the chain can compromise the whole notification process.

The standard also governs communication to individuals. Where a breach is likely to result in a high risk to affected individuals, the controller must communicate it to them without undue delay, an obligation generally associated with Article 34 GDPR. This matters because timely notice can allow individuals to take protective steps. The flexibility of the standard cuts both ways: it accommodates genuinely complex investigations, but it does not license open-ended delay, and organisations are typically expected to document and, where relevant, explain any lag.

The standard interacts with, but is distinct from, the controller's obligation to notify the supervisory authority. Guidance indicates that where notification to the authority is not made within 72 hours, it should still be made without undue delay and accompanied by reasons for the delay, and that phased notification may be used where full details are not yet available. Readers should verify precise article references, timeframes, and any sector-specific or member state variations against the current official text, as some cited requirements may reflect particular regimes or guidance rather than the general GDPR standard.

Who it's relevant to

Data Processors
Processors carry a direct obligation to notify the controller without undue delay after becoming aware of a personal data breach, per Article 33 GDPR. Establishing clear internal detection and escalation procedures is generally important so that awareness translates promptly into notification, since delay by the processor can impede the controller's own downstream obligations.
Data Controllers
Controllers must, where a breach is likely to result in a high risk to affected individuals, communicate it to those individuals without undue delay, an obligation generally associated with Article 34 GDPR. Controllers also manage the interaction with supervisory-authority notification, including documenting reasons for any delay beyond 72 hours and using phased notification where appropriate.
Data Protection Officers and Compliance Leads
DPOs and compliance leads typically design and oversee the breach-response workflows that make timely notification achievable, including defining when awareness or detection occurs and how the contextual assessment of "undue" delay is documented. They should also track how requirements may differ across regimes, guidance, and member state implementations rather than assuming a single fixed deadline applies.
Legal and Contract Teams
Legal teams are generally responsible for reflecting the processor-to-controller notification standard in contractual arrangements and for advising on how the "without undue delay" obligations interact with authority notification timelines. Given that precise article references and timeframes can vary, they typically verify the applicable requirements against the current official text and relevant sector-specific rules.

Inside Notification Without Undue Delay

Trigger of the Obligation
The obligation to notify typically arises once the controller becomes aware of a personal data breach as defined under the GDPR. Awareness generally means having a reasonable degree of certainty that a security incident has occurred which compromised personal data. The precise moment of awareness can be subject to assessment based on the facts.
Notification to the Supervisory Authority
Under Article 33 GDPR, a controller must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, not later than a stated period after becoming aware of it. The Regulation frames this in terms of a maximum window rather than a target, and the reader should verify the specific time period against the current official text.
Delayed or Phased Notification
Where notification is not made within the applicable window, Article 33 generally requires that the notification be accompanied by reasons for the delay. Information may also be provided in phases where it is not possible to supply all details at once, provided this occurs without further undue delay.
Communication to Data Subjects
Under Article 34 GDPR, where a breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller must communicate the breach to affected data subjects without undue delay. This is a distinct obligation from notifying the supervisory authority and is subject to its own threshold and exceptions.
Processor's Role
A processor is generally required to notify the controller without undue delay after becoming aware of a personal data breach, as reflected in Article 33. The processor does not typically notify the supervisory authority directly on its own behalf; the notification obligation to the authority rests with the controller.
Risk-Based Assessment
Whether and how quickly to notify depends in part on an assessment of the likelihood and severity of risk to individuals. Notification to the supervisory authority is generally not required where the breach is unlikely to result in a risk to the rights and freedoms of natural persons, subject to assessment and documentation.
Documentation Duty
Controllers are generally expected to document breaches, including the facts, effects, and remedial action taken, regardless of whether the breach was notifiable. This record supports accountability and enables the supervisory authority to verify compliance.

Common questions

Answers to the questions practitioners most commonly ask about Notification Without Undue Delay.

Does 'without undue delay' mean I have exactly 72 hours to notify a personal data breach?
Not exactly. The 72-hour reference applies specifically to notifying the competent supervisory authority under Article 33, and it runs from when the controller becomes aware of the breach. 'Without undue delay' is a separate, broader standard that can require action sooner than 72 hours where feasible; the 72 hours functions as an outer limit for authority notification, not a licence to wait. Where notification to the authority occurs later than 72 hours, it must generally be accompanied by reasons for the delay. Communication to affected data subjects under Article 34 is governed by 'without undue delay' but is not tied to the same 72-hour figure. Assess the applicable obligation and timing against the current text and relevant guidance.
Do I have to notify individuals every time I notify the supervisory authority?
No. These are distinct obligations with different triggers. Notification to the supervisory authority under Article 33 is generally required unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. Communication to affected data subjects under Article 34 is generally required only where the breach is likely to result in a high risk to those rights and freedoms. There are also recognised exceptions to direct communication to individuals, such as where appropriate protective measures were applied to the affected data or where direct communication would involve disproportionate effort, in which case a public communication or similar measure may be used. Evaluate the risk level for each obligation separately.
When does the clock for 'awareness' actually start?
Awareness is generally understood to arise when the controller has a reasonable degree of certainty that a security incident has occurred that led to personal data being compromised, rather than at the moment of first suspicion. A short initial period of investigation to establish whether a breach has in fact occurred is typically accepted before awareness is treated as established. Controllers should document the timeline of detection, investigation, and the point of established awareness. Because interpretations can vary and are shaped by regulator guidance, verify the current position and any national nuances rather than relying on a fixed rule.
What should we do if we do not yet have all the details required for a complete notification?
The framework generally permits phased notification. Where it is not possible to provide all required information at once, the information may be provided in phases without further undue delay. This means an initial notification can be made within the applicable timeframe based on the facts then known, with further detail supplied as the investigation progresses. Controllers should still aim to give the authority a meaningful description of the breach, its likely consequences, and the measures taken or proposed. Record what was known at each stage and when subsequent information was supplied.
How should a processor handle its role in the notification timeline?
A processor that becomes aware of a personal data breach is generally required to notify the controller without undue delay. The processor does not typically notify the supervisory authority or data subjects directly on its own account for breaches affecting the controller's data; that responsibility generally rests with the controller. The practical mechanics, including the processor's notification timing and content, are usually specified in the data processing arrangement between the parties. Because the processor's prompt notification affects when the controller can establish awareness and meet its own deadlines, clear contractual escalation procedures are important.
What internal processes support meeting the 'without undue delay' standard in practice?
In most cases organisations rely on a documented breach response and escalation procedure, defined roles for detection triage and decision-making, and a maintained record of breaches. Maintaining internal documentation of all breaches, including those not notified and the reasoning, is generally expected and supports accountability. Pre-agreed criteria for assessing risk and high risk, clear lines to the relevant decision-makers, and tested workflows help reduce avoidable delay. Prepared notification templates and contact details for the competent authority can also assist. Tailor these processes to your risk profile and confirm requirements against the current text and applicable regulator guidance.

Common misconceptions

"Without undue delay" is a fixed deadline, and notifying anytime within the stated window is automatically compliant.
The stated window generally operates as a maximum outer limit rather than a target. The overarching standard is to act without undue delay, so a controller may be expected to notify sooner where feasible. Notifying at the last moment without justification is not necessarily compliant, and delay beyond the window generally requires reasons to be provided.
Every personal data breach must be reported to the supervisory authority and to affected individuals.
These are distinct, threshold-based obligations. Notification to the supervisory authority is generally not required where the breach is unlikely to result in a risk to individuals, and communication to data subjects is generally triggered only where there is likely to be a high risk. Both determinations are subject to assessment and should be documented.
A processor experiencing a breach must notify the supervisory authority itself.
A processor generally notifies the controller without undue delay after becoming aware of a breach. The obligation to notify the supervisory authority rests with the controller, though the applicable Article 28 arrangements and factual context determine the precise responsibilities.

Best practices

Establish a clear internal breach detection and escalation procedure so that the point of 'awareness' can be identified and documented, since the notification clock is generally tied to becoming aware of the breach.
Build and maintain a risk assessment methodology to determine whether a breach is unlikely to result in a risk (affecting supervisory authority notification) and whether it is likely to result in a high risk (affecting communication to data subjects).
Prepare notification templates in advance and plan for phased notification, capturing reasons for any delay where notification cannot be made within the applicable window.
Ensure Article 28 processor arrangements require processors to notify the controller without undue delay and specify the information and support the processor must provide.
Maintain a breach register documenting the facts, effects, and remedial action for all breaches, including those assessed as non-notifiable, to support accountability.
Verify the applicable time periods, thresholds, and any relevant supervisory authority guidance against the current official text, noting that positions can vary between EU member states and the UK GDPR.