Skip to main content
Category: Security & Breach Notification

Phased Notification

Also known as: Phased Reporting, Phased Breach Notification
Simply put

Phased notification is a way of reporting a personal data breach to a regulator in stages, rather than all at once. When an organisation does not yet have all the facts about a breach, it can send an initial notification and then provide the remaining details in further installments as its investigation continues. This helps organisations meet tight reporting deadlines even when the full picture is still emerging.

Formal definition

Phased notification refers to the practice, expressly contemplated by GDPR Article 33(4), of providing information about a personal data breach to the supervisory authority in phases where it is not possible to supply all required information at the same time. Under GDPR Article 33(1), a controller must still notify the competent supervisory authority of a notifiable breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it; phased notification does not displace this requirement but permits the controller to submit an initial notice within that timeframe and then supply further information as it becomes available, without further undue delay. In practice this typically means an initial notification (containing at least the information the controller can reasonably provide, such as the nature of the breach and preliminary assessment) followed by supplementary submissions detailing, for example, the categories and approximate numbers of data subjects and records affected, likely consequences, and measures taken or proposed. The mechanics and expectations around timing of subsequent phases can vary between national supervisory authorities and their guidance; readers should verify the current requirements against the applicable authority's guidance and the operative text of the GDPR (or UK GDPR, where the equivalent provisions apply). This entry concerns notification to supervisory authorities; communication to affected data subjects is governed separately and is out of scope here.

Why it matters

Personal data breaches rarely present a complete picture at the moment of discovery. An organisation may know that an incident has occurred long before it can establish the categories and approximate numbers of data subjects affected, the likely consequences, or the full remediation plan. Because GDPR Article 33(1) requires a controller to notify the competent supervisory authority of a notifiable breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it, controllers face pressure to report before their investigation has concluded. Phased notification, which is expressly contemplated by GDPR Article 33(4), resolves this tension by allowing the required information to be provided in stages where it is not possible to supply it all at the same time.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads coordinating a breach response can use phased notification to meet the initial Article 33(1) deadline even where the investigation is incomplete, then manage a structured sequence of supplementary submissions. They should confirm the specific expectations of the relevant supervisory authority, as timing and format guidance can differ between member states and under the UK GDPR.
Incident Response and Security Teams
Teams investigating an incident often continue to establish facts, such as the scope and number of affected records, after the initial notice is due. Phased notification allows their findings to feed into later installments to the supervisory authority without further undue delay, so response and reporting workflows should be designed to capture and hand off information as it emerges.
In-House and External Legal Counsel
Counsel advising controllers on breach obligations should recognise that Article 33(4) permits phased reporting but does not relax the underlying obligation to make the initial notification without undue delay and, where feasible, within 72 hours under Article 33(1). Counsel should verify applicable national and UK GDPR guidance and note that member state derogations and regulator expectations can vary.
Controllers Operating Across Multiple Jurisdictions
Organisations subject to more than one supervisory authority should be aware that the mechanics and timing expectations around subsequent phases can diverge between authorities. They should confirm the current requirements against each relevant authority's guidance rather than assuming a single approach applies uniformly.

Inside Phased Notification

Statutory basis (Article 33(4))
GDPR Article 33(4) expressly permits a controller to provide breach information to the supervisory authority in phases where it is not possible to provide all information at the same time, allowing further details to be supplied without undue further delay.
Initial notification timing
Under Article 33(1), a controller must notify the competent supervisory authority of a personal data breach (unless it is unlikely to result in a risk to individuals) without undue delay and, where feasible, not later than 72 hours after becoming aware of it. Phased notification does not extend or replace this initial deadline; it addresses situations where complete information is not yet available at the point of that first notice.
Content of the notification (Article 33(3))
The information a notification should contain, such as the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed, may be provided progressively where it cannot all be assembled at once.
Reasoned justification for delay
Where notification is not made within 72 hours, Article 33(1) requires that the notification be accompanied by reasons for the delay. Phasing the later details should be documented so the controller can explain why full information could not be provided initially.
Documentation obligation
Article 33(5) requires the controller to document any personal data breach, including its facts, effects, and remedial action. Records of each phase support this obligation and enable the supervisory authority to verify compliance.
Relationship to data subject communication
Phased notification under Article 33(4) concerns notice to the supervisory authority. Communication to affected data subjects is a distinct requirement under Article 34, triggered where the breach is likely to result in a high risk to their rights and freedoms, and should not be conflated with the phased authority notice.

Common questions

Answers to the questions practitioners most commonly ask about Phased Notification.

Is phased notification a workaround that lets us delay reporting a breach beyond the 72-hour window?
No. Phased notification is not a mechanism for postponing the initial notification. Under GDPR Article 33(1), where a breach is notifiable, the controller must still notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it. Article 33(4) then permits that, where and insofar as it is not possible to provide the required information at the same time, the information may be provided in phases without further undue delay. The phasing relates to completing the details after the initial notice, not to delaying that initial notice.
Is it actually permitted to notify the supervisory authority in stages, or is that legally uncertain?
Phasing is expressly permitted. GDPR Article 33(4) provides that where the required information cannot be provided at the same time, it may be provided in phases without further undue delay. So the permissibility of phased notification is grounded in the Regulation's text rather than being an open question. What can vary in practice is how individual supervisory authorities expect phased submissions to be structured and how they assess 'undue delay', so controllers should check the relevant authority's guidance for procedural expectations.
What should the initial notification contain if we do not yet have all the details?
The initial notification should still meet the requirements of Article 33(1) and be made without undue delay and, where feasible, within 72 hours. It should include the information available at that point, generally covering the categories set out in Article 33(3), such as the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the contact point, the likely consequences, and the measures taken or proposed. Where specific elements are not yet known, the controller can indicate this and supply the outstanding information in later phases without further undue delay under Article 33(4).
How quickly do the later phases of information need to be submitted?
Article 33(4) requires that the remaining information be provided 'without further undue delay' once it becomes available. The Regulation does not set a fixed second deadline for the follow-up phases, so timing is assessed against what is reasonable given the ongoing investigation. Controllers should generally document why particular information was not available initially and provide updates as the facts are established. Specific expectations may differ between supervisory authorities, so it is advisable to confirm any procedural preferences with the relevant authority.
How should we document a phased notification internally?
It is generally advisable to maintain a record that shows when the controller became aware of the breach, what was included in the initial notification, why certain information could not be provided at that time, and when each subsequent phase was submitted. This supports the accountability principle and the internal breach-recording obligation under Article 33(5), which requires controllers to document breaches, their effects, and the remedial action taken. Clear records also help demonstrate that both the initial notice and the later phases were made without undue delay.
Does using phased notification to the authority change our obligations to notify affected data subjects?
Phasing under Article 33(4) concerns notification to the supervisory authority and does not by itself alter the separate obligation to communicate a breach to affected data subjects. Communication to data subjects is governed by Article 34 and is generally required, without undue delay, where the breach is likely to result in a high risk to their rights and freedoms, subject to the exceptions set out there. Controllers should assess the data-subject notification duty independently, even where their submission to the authority is being provided in phases.

Common misconceptions

Phased notification lets a controller wait beyond 72 hours before contacting the supervisory authority.
The initial notification is still governed by Article 33(1), which requires notice without undue delay and, where feasible, not later than 72 hours after awareness. Article 33(4) permits only the later completion of information that was genuinely unavailable at the time of that initial notice; it does not postpone the first notification itself.
Whether phased notification is permitted at all is legally unsettled.
Article 33(4) expressly allows phased provision of information to the supervisory authority where it is not possible to supply everything at the same time. The permissibility is clear on the face of the Regulation; what remains context-dependent is the assessment of when phasing is genuinely justified and how supervisory authorities expect it to be handled in practice.
Phased notification to the authority also satisfies the duty to inform affected individuals.
Notification to the supervisory authority under Article 33 and communication to data subjects under Article 34 are separate obligations with different triggers and timing. Providing phased information to the regulator does not, in itself, discharge any Article 34 duty to inform individuals.

Best practices

Make the initial supervisory-authority notification without undue delay and, where feasible, within the 72-hour window under Article 33(1), even if some details are still outstanding.
Clearly flag in the initial notice that it is a phased submission under Article 33(4), identifying which information is provided and which will follow.
Include the reasons for any delay, and document why the outstanding information could not reasonably be assembled in time.
Maintain internal records of each phase in line with the Article 33(5) documentation duty, capturing facts, effects, and remedial measures.
Assess separately whether the breach triggers Article 34 communication to affected individuals, and treat that as a distinct obligation from the phased authority notice.
Verify the specific expectations and any procedural guidance of the competent supervisory authority, as practice on phasing can vary between regulators.