Ready-to-run compliance workflow

GDPR Article 33 breach notification

A controller must notify the supervisory authority of a personal-data breach without undue delay and within 72 hours of becoming aware, unless the breach is unlikely to risk individuals' rights. The notification must state the nature, categories and rough number affected, likely consequences, and measures taken; a late filing must carry reasons for the delay.

Add to my workspace

Testing is free and does not create a Record. Unfinished live attempts are not charged.

What it does

From facts to a reviewable result.

This workflow uses the published release shown above. Later updates cannot silently change the reasoning attached to a completed Record.

01

Information it collects

  • Approx. number of personal-data records affected
  • Supervisory authority notified
  • Authority-notification date, time, and zone
  • Data protection officer or other contact point
  • Notified within 72 hours
  • A personal-data breach under GDPR has been confirmed
  • Categories of affected data subjects
  • Available notification information is being supplied in phases

Plus 12 further items when relevant.

02

What completion creates

A structured, version-bound Record containing the submitted facts, release identity, timestamp, and validation result.

Choose the experience

Use the same rules in the format the work needs.

01

Form

Collect the complete set of relevant facts in one responsive document.

02

Guided assessment

Guide someone one relevant question at a time through the published logic.

03

Compliance checklist

Review the required controls and retain evidence of the completed check.

Use this release

Test the workflow now.
Put it to work when it fits.

Create a Flow