EU institutions data protection regulation · Regulation (EU) 2018/1725
Article 34
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 1 part · 3 Council drafts · 6 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to EU institutions data protection regulationThe wording proposed by the Commission at the start of this legislative file.
Full article with Commission changes
Article with proposed changes
Official consolidated text dated 23 October 2018, with the Commission proposal change affecting this article applied.
Article 34
Notification of a personal data breach to the European Data Protection Supervisor
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
7296 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the European Data Protection Supervisor is not made within7296 hours, it shall be accompanied by reasons for the delay. - 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall inform the data protection officer about the personal data breach.
- 6.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the European Data Protection Supervisor to verify compliance with this Article.
No standalone Commission wording is mapped to this tracked part. A newly proposed provision may have no earlier text of its own.
Commission source wording and instructions
Article 34(1)
Commission proposal
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Article in June Presidency compromise · 10 June Council text
Comparison basis: Existing law (23 October 2018) compared with June Presidency compromise · 10 June (10 June 2026)
Article 34
Notification of a personal data breach to the European Data Protection Supervisor
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
7296 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the European Data Protection Supervisor is not made within7296 hours, it shall be accompanied by reasons for the delay. - 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall inform the data protection officer about the personal data breach.
- 6.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the European Data Protection Supervisor to verify compliance with this Article.
Article 34(1)
June Presidency compromise · 10 June
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay.
Article in June Presidency compromise · 18 June Council text
Comparison basis: Existing law (23 October 2018) compared with June Presidency compromise · 18 June (18 June 2026)
Article 34
Notification of a personal data breach to the European Data Protection Supervisor
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
7296 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the European Data Protection Supervisor is not made within7296 hours, it shall be accompanied by reasons for the delay. - 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall inform the data protection officer about the personal data breach.
- 6.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the European Data Protection Supervisor to verify compliance with this Article.
Article 34(1)
June Presidency compromise · 18 June
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay.
Article in September Presidency compromise Council text
Comparison basis: Existing law (23 October 2018) compared with September Presidency compromise (3 September 2026)
Article 34
Notification of a personal data breach to the European Data Protection Supervisor
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
7296 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the European Data Protection Supervisor is not made within7296 hours, it shall be accompanied by reasons for the delay. - 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall inform the data protection officer about the personal data breach.
- 6.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the European Data Protection Supervisor to verify compliance with this Article.
Article 34(1)
September Presidency compromise
Council wording reconstructed for this provision from the official operation
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay.
Official source passage and amending instruction
7. in Article 34, paragraph 1 is replaced by the following ‘1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay.
Article 34(1) 3 Council drafts
Article 34(1)
10 June 2026 · June Presidency compromise · 10 June
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay.
Article 34(1)
18 June 2026 · June Presidency compromise · 18 June
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay.
Article 34(1)
3 September 2026 · September Presidency compromise
Council wording reconstructed for this provision from the official operation
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay.
Official source passage and amending instruction
7. in Article 34, paragraph 1 is replaced by the following ‘1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Alternative wording Amendment 493 · Virginie Joron IMCO
against:
Article 34
Notification of a personal data breach to the European Data Protection Supervisor
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay. Processors shall continue to document personal data breaches that are not notified.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall inform the data protection officer about the personal data breach.
- 6.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the European Data Protection Supervisor to verify compliance with this Article.
Remove proposed wording Amendment 1671 · Pernando Barrena Arza ITRE · LIBE
against:
Article 34
Notification of a personal data breach to the European Data Protection Supervisor
- 1.
In the case of a personal data breach
that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than9672 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the European Data Protection Supervisor is not made within9672 hours, it shall be accompanied by reasons for the delay. - 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall inform the data protection officer about the personal data breach.
- 6.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the European Data Protection Supervisor to verify compliance with this Article.
Alternative wording Amendment 1672 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 34
Notification of a personal data breach to the European Data Protection Supervisor
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay. Controllers shall continue to document non-notified personal data breaches.
- 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall inform the data protection officer about the personal data breach.
- 6.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the European Data Protection Supervisor to verify compliance with this Article.
Alternative wording Amendment 1673 · Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba, Kristian Vigenin, Matjaž Nemec ITRE · LIBE
against:
Article 34
Notification of a personal data breach to the European Data Protection Supervisor
- 1.
In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than
9672 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within9672 hours, it shall be accompanied by reasons for the delay. - 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall inform the data protection officer about the personal data breach.
- 6.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the European Data Protection Supervisor to verify compliance with this Article.
Alternative wording Amendment 1674 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
against:
Article 34
Notification of a personal data breach to the European Data Protection Supervisor
- 1.
In the case of a personal data breach that is likely to result in a
highrisk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than9672 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within9672 hours, it shall be accompanied by reasons for the delay. - 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall inform the data protection officer about the personal data breach.
- 6.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the European Data Protection Supervisor to verify compliance with this Article.
Alternative wording Amendment 1675 · Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann ITRE · LIBE
against:
Article 34
Notification of a personal data breach to the European Data Protection Supervisor
- 1.
In the case of a personal data breach that is likely to result in a
highrisk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than9672 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within9672 hours, it shall be accompanied by reasons for the delay. - 2.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
- 3.
The notification referred to in paragraph 1 shall at least:
- (a)
describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (b)
communicate the name and contact details of the data protection officer;
- (c)
describe the likely consequences of the personal data breach;
- (d)
describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- (a)
- 4.
Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
- 5.
The controller shall inform the data protection officer about the personal data breach.
- 6.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the European Data Protection Supervisor to verify compliance with this Article.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Article 34(1)
European Commission proposal → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
European Commission proposal
Council Presidency text · ST 10426/26
Article 34(1)
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Article 34(1)
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
Council Presidency text · ST 12535/26
Article 34(1)
Wording reproduced in the amendment → Amendment 1671 · ITRE–LIBE amendments 1565–1740 to the draft report: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1671 · ITRE–LIBE amendments 1565–1740 to the draft report: removal
This wording is removed.
Article 34(1)
Wording reproduced in the amendment → Amendment 1672 · ITRE–LIBE amendments 1565–1740 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1672 · ITRE–LIBE amendments 1565–1740 to the draft report
Article 34(1)
Wording reproduced in the amendment → Amendment 1673 · ITRE–LIBE amendments 1565–1740 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1673 · ITRE–LIBE amendments 1565–1740 to the draft report
Article 34(1)
Wording reproduced in the amendment → Amendment 1674 · ITRE–LIBE amendments 1565–1740 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1674 · ITRE–LIBE amendments 1565–1740 to the draft report
Article 34(1)
Wording reproduced in the amendment → Amendment 1675 · ITRE–LIBE amendments 1565–1740 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1675 · ITRE–LIBE amendments 1565–1740 to the draft report
Article 34(1)
Wording reproduced in the amendment → Amendment 493 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded