Phased Notification
Phased notification is a way of reporting a personal data breach to a regulator in stages, rather than all at once. When an organisation does not yet have all the facts about a breach, it can send an initial notification and then provide the remaining details in further installments as its investigation continues. This helps organisations meet tight reporting deadlines even when the full picture is still emerging.
Phased notification refers to the practice, expressly contemplated by GDPR Article 33(4), of providing information about a personal data breach to the supervisory authority in phases where it is not possible to supply all required information at the same time. Under GDPR Article 33(1), a controller must still notify the competent supervisory authority of a notifiable breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it; phased notification does not displace this requirement but permits the controller to submit an initial notice within that timeframe and then supply further information as it becomes available, without further undue delay. In practice this typically means an initial notification (containing at least the information the controller can reasonably provide, such as the nature of the breach and preliminary assessment) followed by supplementary submissions detailing, for example, the categories and approximate numbers of data subjects and records affected, likely consequences, and measures taken or proposed. The mechanics and expectations around timing of subsequent phases can vary between national supervisory authorities and their guidance; readers should verify the current requirements against the applicable authority's guidance and the operative text of the GDPR (or UK GDPR, where the equivalent provisions apply). This entry concerns notification to supervisory authorities; communication to affected data subjects is governed separately and is out of scope here.
Why it matters
Personal data breaches rarely present a complete picture at the moment of discovery. An organisation may know that an incident has occurred long before it can establish the categories and approximate numbers of data subjects affected, the likely consequences, or the full remediation plan. Because GDPR Article 33(1) requires a controller to notify the competent supervisory authority of a notifiable breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it, controllers face pressure to report before their investigation has concluded. Phased notification, which is expressly contemplated by GDPR Article 33(4), resolves this tension by allowing the required information to be provided in stages where it is not possible to supply it all at the same time.
Who it's relevant to
Inside Phased Notification
Common questions
Answers to the questions practitioners most commonly ask about Phased Notification.