Ir al contenido
Launch offerOnly until … — after that, prices go back to normal.See pricing

Blog

Security breaches: what to do in the first 72 hours

Author: Tranquilia by GRAC SA10 min read

General information about the law. It’s no substitute for a lawyer’s advice or a look at your specific case.

Direct answer: if personal data is lost, leaked or stolen in your business, you have 72 hours from the moment you find out —not from when it happened— to decide whether you have to notify the Agencia Española de Protección de Datos (AEPD, Spain's data protection authority), under article 33 of the Reglamento (UE) 2016/679 (RGPD, the EU data protection regulation). Many small breaches do not need to be notified to the AEPD, but all of them, notified or not, have to be written down in your internal incident record (art. 33.5 RGPD). This guide, reviewed on 16 July 2026, explains what to do in the first few hours, when to notify and when not to, with links to the official sources.

Contents

What exactly is a data security breach?

A security breach (the RGPD calls it a "personal data breach", art. 4.12) is any failure affecting personal data you hold: it is lost, destroyed, changed without permission, or reaches someone who was not supposed to see it.

You do not need a cyberattack for it to count. The following are security breaches, among others:

  • A work laptop or mobile phone lost or stolen, with client or employee data on it.
  • An email with a payslip, a client list or a contract sent to the wrong person.
  • A folder of paper documents left behind in a public place.
  • A cyberattack, a virus or ransomware getting into your systems.
  • Someone on your team accessing data they were not entitled to.

The law does not distinguish between a "big breach" and a "small breach" when it comes to requiring you to record it: the difference only matters when deciding whether you have to notify the AEPD, the people affected, both, or neither. That is exactly what we look at in the rest of the article.

What do I do in the first hour?

Before thinking about notifications, there are three things you can sort out in a few minutes:

  1. Stop the failure if it is still going on. Change the password, revoke the access, recover the device if you can. Do not delete anything that could help you understand what happened.
  2. Write down the exact time you found out. It is the most important piece of information of all: that is where the 72 hours start running from, not from when the failure actually happened.
  3. Gather what you already know, however little: what happened, what kind of data is involved (names, email addresses, health data, bank accounts…) and how many people, even if it is only a rough figure.

You do not need the full answer to get started. The AEPD accepts notifications with partial information, to be completed afterwards (we explain this in the section How do you notify the AEPD?).

When do I have to notify the AEPD and when not?

The rule in art. 33 RGPD is this: you have to notify unless the breach is unlikely to result in a risk to the rights and freedoms of the people affected. In practice, that comes down to two common scenarios:

You probably do not need to notify when, for example, the data was encrypted and the key has not been compromised, or when the data that leaked does not make anyone identifiable or cause them real harm (a file with only internal codes, no names and no contact details).

You probably do need to notify when the data affected is identifiable and its loss, leaking or misuse could cause real harm to people: identity theft, financial loss, discrimination, or when it involves special category data (health, ethnic origin, sexual orientation, trade union membership, among others).

Even if the conclusion is "there is no need to notify the AEPD", that does not release you from one obligation: you always have to document the failure in your internal record. We look at this in the section What do I have to document even if I notify nothing?

How exactly are the 72 hours counted?

The deadline starts when you become reasonably aware of the failure, not when it actually happened. If a failure happened on the Monday but you do not find out until the Saturday, the 72-hour clock starts on the Saturday, not the Monday.

The 72 hours are counted as running hours, not working days: if you find out on a Friday at 18:00, the deadline ends on the Monday at 18:00, public holidays and the weekend included. There is no pause for holidays or for the business being closed.

This is the detail that confuses people most: many count the deadline from the moment of the failure, and are late without having realised it. Writing down the exact date and time you found out, from the very first minute, is what lets you work out the deadline properly.

What if I miss the deadline?

If you go past the 72 hours, the instruction is not "there is no point notifying now": it is still better to notify late than not to notify. Art. 33 RGPD itself provides for this case: if the notification is not made within the deadline, it has to be accompanied by the reasons for the delay.

In practice, that means one honest sentence with no excuses: what happened that made the notice arrive after the 72 hours (for example, that more time was needed to understand the real extent of the failure). It is not a formality that disappears because the deadline was missed, it is a formality you carry out anyway, explaining the delay.

Do I have to tell the people affected as well?

Sometimes yes, on top of notifying the AEPD. Art. 34 RGPD requires you to communicate the breach directly to the people affected when it is likely to result in a high risk to their rights: for example, if bank details, passwords or health data that could be used against them have been leaked.

When you do have to tell them, the communication has to be made without undue delay and in clear, plain language —the same level of plainness that the rest of your communication with clients calls for— explaining what happened, which of their data is affected, what consequences it could have and what they can do to protect themselves.

This second notice is not always needed: many breaches that are notified to the AEPD do not reach the high risk level that triggers art. 34. The decision depends on the specific case, not on an automatic rule.

How do you notify the AEPD in practice?

On its security breaches page, the AEPD explains that notifications are made electronically, through its Sede Electrónica (its official online administrative portal). On that same page, the AEPD provides controllers and processors with support tools: one for assessing whether a specific incident requires notification (Asesora Brecha) and another for preparing and sending the notice (Comunica-Brecha RGPD).

The minimum content of the notice, under art. 33.3 RGPD, includes: what happened, roughly how many people and how much data are affected, a contact point where they can ask for more information, what likely consequences it could have, and what measures you have taken or are going to take. If you still do not have all the information by the time the 72 hours are up, you can notify with what you know and complete it afterwards in phases: the RGPD expressly allows this.

What do I have to document even if I notify nothing?

This is the obligation that gets overlooked most. Art. 33.5 RGPD requires you to document all security breaches, whether or not they are notified to the AEPD: the facts relating to the breach, its effects and the remedial action taken.

That record has to include, as a minimum:

  • The date the failure happened and the date you found out.
  • What happened.
  • What kind of data, and roughly how many people, have been affected.
  • What consequences it could have for those people.
  • What measures you have taken, or are going to take, to fix it and to stop it happening again.

If no failure has ever happened in your business, your record can be empty: that is not a problem, it is the normal situation, and that blank sheet already complies with the law. What would be a problem is not having the record ready for the day you need it.

What happens if I don't comply with this?

The AEPD is the body that monitors this in Spain. It can ask for explanations, order changes, issue a warning or impose a fine. The RGPD sets the possible maximums at two levels: up to 10 million euros or 2% of annual worldwide turnover, and up to 20 million or 4%, depending on the infringement (art. 83 RGPD); whichever of the two figures is higher applies.

In practice, those figures are the legal ceiling, not the norm: the penalty is graded according to the seriousness, the size of the business and whether you have cooperated. A small business that records its incidents and notifies when it should is not in that scenario. That is why it is worth setting the procedure up calmly, before you need to use it, rather than improvising it on the day a real failure happens.

Checklist for the first 72 hours

A summary to keep to hand for the day you need it, not a list to memorise today:

  1. Contain the failure. Change passwords, revoke access, recover what you can.
  2. Write down the exact time you found out. That is where the 72 hours are counted from.
  3. Gather what you know: what happened, what data and how many people, roughly.
  4. Assess the risk to the people affected: could they suffer real harm?
  5. If there is a risk, notify the AEPD through the Sede Electrónica, within the 72 hours or explaining the reason for the delay.
  6. If the risk to those people is high, tell them as well, without delay and in clear language.
  7. Document the incident in your internal record, whether notification was needed or not.
  8. Review which measure stops it happening again, and note it in the record itself.

Frequently asked questions

Do the 72 hours count from when the failure happened or from when I find out? From when you find out. If the failure happened earlier but you do not discover it until later, the deadline starts at the moment of discovery, not at the moment of the failure.

Does losing a work mobile phone count as a security breach? Yes, if that phone has access to personal data: contacts, emails, apps with client or employee data. It counts just like a cyberattack for the purposes of recording it and, if necessary, of notifying it.

Do I have to notify even if I am not sure whether there is a risk? The rule is to notify unless a risk is unlikely. If you have reasonable doubts, the more prudent option is to notify; in any case, always document the incident, whether you notify or not.

What happens if my incident record is empty? Nothing: it means that, for now, no security failure has happened in your business. An empty record already complies with the obligation in art. 33.5 RGPD; what matters is having it ready for the day you need to use it.

Can I notify the AEPD with incomplete information? Yes. Art. 33.4 RGPD allows the information to be provided in phases if it is not all available at the start, as long as you do not delay it without reason.

Official sources


Where to go from here

Spotting a security failure is daunting, above all if you do not know where to start. With Tranquilia you have a guided 6-question questionnaire that tells you whether you have to notify the AEPD and, if you do, leaves you with the draft notice and the internal incident record ready to go over with your gestoría (the firm that handles your business's administrative paperwork).

👉 Start the security breach questionnaire — free for up to 2 companies, no card and no time limit.


Content report produced with Tranquilia — it does not constitute an official certification or a legal opinion. If you have doubts about a specific case, check with your gestoría or with a legal professional.

Review: Translation of the Spanish original, which prevails in case of divergence.

Get your clients GDPR-compliant in 15 minutes.

Set up my free instance

No card, no sales calls. Two companies free, for as long as you like.

Blog