The EACB welcomes the European Data Protection Board (EDPB)’s objective of promoting greater harmonisation, consistency and legal certainty across the European Economic Area in relation to personal data breach notifications under Articles 33 and 34 GDPR. At the same time, the EACB stresses the importance of ensuring that the draft template remains proportionate, practical and closely aligned with the GDPR framework.
In its response, the EACB highlights that, in its current form, the template risks introducing additional administrative burdens for organisations, particularly given the strict 72-hour notification timeframe. The EACB calls for a clearer distinction between information strictly required at the initial notification stage under Articles 33 and 34 GDPR and supplementary information that could be provided at a later stage or upon request. It also underlines the importance of maintaining a flexible and risk-based approach that reflects the evolving nature of breach investigations and avoids transforming the notification process into a detailed justification exercise.
The EACB further emphasises the need to ensure interoperability between GDPR breach notifications and other reporting frameworks, including those related to cybersecurity and operational resilience, in order to reduce duplication and improve efficiency. The EACB encourages the EDPB to ensure that the final template supports effective supervision while preserving proportionality, operational feasibility and the distinction between internal incident management processes and external regulatory notification.
30 July 2026
EACB response to the EDPB public consultation on the draft template for personal data breach notifications
EACB