NetOpsKit

Data Breach & Incident Notification Clock

Live countdown to the GDPR 72-hour and NIS2 24h / 72h / one-month deadlines, plus an indicative breach risk assessment and an Article 33(5) record.

Indicative GDPR risk assessment

Tick what applies. Factors follow the EDPB breach notification guidelines (type of breach, data, ease of identification, severity, vulnerable individuals, number of people).

Data involved
Circumstances

Article 33(5) breach record


How to use this tool

Enter the moment you became aware of the incident. The clock shows the GDPR deadline to notify the supervisory authority (72 hours) and the NIS2 early warning (24 hours), incident notification (72 hours) and final report (one month after the notification). Answer the risk questions to get an indicative view on whether to notify the authority and the individuals, then copy the generated record for your breach log. It is a decision aid, not a determination; contact your DPO or legal counsel for real incidents.

Worked example

Aware at 09:00 on a Monday: GDPR notification due by 09:00 Thursday; NIS2 early warning due 09:00 Tuesday and incident notification 09:00 Thursday. If the lost laptop was fully encrypted with the key safe, the indicative result is "risk unlikely: document it".

Frequently asked questions

When does the 72-hour GDPR clock start?

From the moment the controller becomes aware of the breach (Article 33(1)). The EDPB treats a controller as aware when it has a reasonable degree of certainty that a security incident has compromised personal data. Processors must notify the controller without undue delay.

When can I skip notifying the supervisory authority?

When the breach is unlikely to result in a risk to the rights and freedoms of individuals. You must still document every breach, including facts, effects and remedial action (Article 33(5)).

When must I tell the affected individuals?

Without undue delay when the breach is likely to result in a high risk to them (Article 34), unless an exception applies such as effective encryption.

What are the NIS2 reporting deadlines?

For a significant incident: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, an intermediate report on request, and a final report no later than one month after the incident notification (Article 23). Some entity types, such as trust service providers, have a shorter initial deadline.

Can one incident trigger both GDPR and NIS2 reporting?

Yes. The regimes are separate, with different authorities, thresholds and deadlines, so a single incident can require both.

Stuck on something this page doesn't cover?

Tell us the problem in your own words. We use these reports (anonymously) to decide which guides to write. No account, name or email needed. Do not include passwords or customer data.