IP, Technology & Data Protection 7 min read

Security breach: the 72 hours that determine the fine

Leer en español

An open computer hard drive, with the platter exposed and a cable disconnected

A security breach is not something you can manage well by improvising. Article 33 of the General Data Protection Regulation requires notifying the supervisory authority without undue delay and, wherever feasible, within seventy-two hours at most. What gets decided in that window often weighs more heavily in the resulting case file than the incident itself.

What counts as a breach

The GDPR defines a personal data breach as any breach that results in the accidental or unlawful destruction, loss, or alteration of personal data, or unauthorised disclosure of or access to it.

The definition is broader than most people assume. Among others, the following count as breaches:

  • A ransomware attack that encrypts systems, even if no data was exfiltrated — availability has been lost.
  • An email sent to two hundred recipients in visible CC when they should have been BCC'd.
  • A laptop or USB drive lost without encryption.
  • One client's documents handed over to another by mistake.
  • A former employee who still has access to a shared folder.

In other words, no sophisticated attack is required. Most of the breaches that reach the Spanish Data Protection Agency (AEPD) are ordinary human error.

When the 72-hour clock starts

The clock starts running from the moment the controller becomes aware of the breach — not once it is fully understood, and not once the investigation is finished. This is where most case files run into trouble: three days get spent working out what happened, and by the time the decision to notify is made, the deadline has already passed.

Article 33 itself anticipates this: if notification does not take place within seventy-two hours, it must be accompanied by reasons for the delay. It also allows notification in phases — providing the information available at the time and completing it later.

Notifying with incomplete information within the deadline is always better than notifying in full after it has passed.

When you must notify — and when you don't

The duty to notify the supervisory authority falls away when it is unlikely that the breach poses a risk to the rights and freedoms of the people affected. That assessment has to be made — and documented — never simply assumed.

The analysis weighs the type of data compromised, its volume, whether it was encrypted with a key that was not itself compromised, how easily the individuals can be identified, the severity of the possible consequences, and the characteristics of those affected.

A list of corporate email addresses is not the same as a file containing health data, financial information, or data on minors. When special categories of data are involved, the risk is treated in practice as high.

When you must inform the people affected

Article 34 GDPR adds a second, separate obligation: when a breach is likely to result in a high risk to the rights and freedoms of individuals, they must be informed directly, without undue delay, and in clear, plain language.

That communication is not required if measures were already in place that render the data unintelligible — strong encryption, for example — if subsequent measures have been taken that rule out the high risk materialising, or if it would involve disproportionate effort, in which case it is replaced by an equally effective public communication.

The internal record: always mandatory

There is one obligation that admits no exception and is often overlooked: Article 33 itself requires every security breach to be documented, including its effects and the corrective measures taken, regardless of whether it needs to be notified at all.

That record is the first thing the AEPD asks for when it opens proceedings. Its absence counts against you on its own; its existence, by contrast, evidences due diligence and tends to noticeably reduce the scope of the case.

What to do in the first hour

  1. Contain it. Isolate the affected system, revoke access, change credentials. Stop the bleeding before you start investigating.
  2. Log the time. Record the exact time of detection, who detected it, and what is known at that point. That timestamp is what sets the clock running.
  3. Preserve evidence. Do not reinstall or reformat without a forensic copy first. Whatever is destroyed now cannot be recovered later.
  4. Assess the risk, combining legal and technical judgement, and put that assessment in writing — whether or not you end up notifying.
  5. Decide on notification within the deadline, even if it has to be done in phases.

What makes a breach costly is rarely the breach itself. It is being unable to show what was done, when, and why.

Who to notify from the Canary Islands

The Canary Islands has no regional data protection authority of its own, unlike Catalonia, the Basque Country, or Andalusia. The competent authority is always the Spanish Data Protection Agency (AEPD), based in Madrid, and notification is filed through its electronic headquarters.

In practice this simplifies the process — a single point of contact — but removes any local option: there is no office in the archipelago to go to, and the entire case is handled electronically. All the more reason to have a written response protocol ready before you need it, because the 72-hour clock does not pause while you work out who to call.

Need advice on IP, Technology & Data Protection? Our team is ready to help.


Notice: this article is for general information purposes and reflects the law in force on its publication date. It is not legal or tax advice for any specific case. Before making any decision, consult a professional.

Keep reading

Tax & Accounting

The Reinvestment Reserve for the Canary Islands (RIC): A Practical Guide

Up to 90% of undistributed profit can reduce the tax base — but only if the investment is made on time and in the right assets.

Inheritance & Succession

Inheritance Tax in Spain: A Guide for Non-Residents

Which rules apply when the heir doesn't live in Spain, and why the six-month deadline doesn't wait for the family to get organised.

Criminal Law

The Guard Court in Las Palmas: What Happens in the First Hours

What the guard court does, how long an arrest can last, what a fast-track trial is, and what family members can do in the meantime.

Commercial & Corporate Law

When a Director Answers with Personal Assets

A limited company doesn't always limit liability for its directors. There are two routes by which a director ends up answering with personal assets — and one of them is avoidable.

Inheritance & Succession

Accepting an Inheritance Without Knowing the Debts: The Benefit of Inventory

Accepting an inheritance outright means answering for the deceased's debts with your own assets too. There is a third option between accepting and renouncing.

Criminal Law

Road-Safety Offence: From the Alcohol Test to the Fast-Track Trial

Where the line falls between an administrative fine and a criminal offence, what penalties the Criminal Code sets out, and why pleading guilty on day one rarely pays off.

Criminal Law

You've Been Summoned to Testify as a Person Under Investigation: What Happens and What to Decide First

What that summons means, what rights you have from the moment you receive it, and why the decision to testify or not is made beforehand — never in the hallway.

Employment Law

You've Been Dismissed: The 20 Working Days That Decide Your Claim

The deadline to challenge a dismissal is a strict limitation period that starts running from day one. What to sign, what not to sign, and how your compensation is calculated.

Criminal Law

Preventing Corporate Crime: Compliance and White-Collar Criminal Law

An analysis of corporate criminal liability in Spain, and why a prevention model only works as a defense if it is genuine, not a template pulled off a shelf.

Tax & Accounting

Year-End Tax Closing: Keys to Optimizing Corporate Taxation

The decisions that lower a company's tax bill are made before 31 December, not in July when the Corporate Income Tax return is filed.

Community Management

Rehabilitation Grants: How Owners' Communities Can Apply

The majorities required, the correct order of procedures, and the mistakes that leave technically qualified owners' communities out of time.

¿Hablamos de su caso?

Analizamos su situación sin compromiso y le decimos con claridad qué vías tiene y cuál recomendamos.

Call WhatsApp