GDPR
Security

Data Breach Notification Procedure Template

Procedures for detecting, assessing, and notifying personal data breaches per GDPR Articles 33 and 34.

What This Policy Covers

Purpose and Scope-Procedure objectives and breach definition.
Breach Detection and Assessment-Identifying and classifying breaches by risk level.
Supervisory Authority Notification-72-hour notification process and content requirements.
Data Subject Communication-When and how to notify affected individuals.
Breach Register-Documentation and record-keeping of all breaches.
Post-Breach Review-Lessons learned and preventive measures.

Required Sections

A compliant Data Breach Notification Procedure for GDPR must include the following6 sections. Each section addresses a specific control requirement that auditors will review.

1

Purpose and Scope

Procedure objectives and breach definition.

2

Breach Detection and Assessment

Identifying and classifying breaches by risk level.

3

Supervisory Authority Notification

72-hour notification process and content requirements.

4

Data Subject Communication

When and how to notify affected individuals.

5

Breach Register

Documentation and record-keeping of all breaches.

6

Post-Breach Review

Lessons learned and preventive measures.

Generate a Customized Version

This template shows the required structure. PoliWriter generates a fully customized Data Breach Notification Procedure that references your actual cloud providers, identity systems, tools, and team practices — ready for auditor review.