Digital Omnibus tracker

EU institutions data protection regulation · Regulation (EU) 2018/1725

Article 34

Compare the available Commission, Council and Parliament texts and amendments affecting this article.

Article total: 1 part · 3 Council drafts · 6 Parliament amendments

Removed wording is struck through; added or replacement wording is highlighted.

Institutional text

The wording proposed by the Commission at the start of this legislative file.

Full article with Commission changes

Article with proposed changes

Official consolidated text dated 23 October 2018, with the Commission proposal change affecting this article applied.

Article 34

Notification of a personal data breach to the European Data Protection Supervisor

  1. 1.

    In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 7296 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the European Data Protection Supervisor is not made within 7296 hours, it shall be accompanied by reasons for the delay.

  2. 2.

    The processor shall notify the controller without undue delay after becoming aware of a personal data breach.

  3. 3.

    The notification referred to in paragraph 1 shall at least:

    1. (a)

      describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;

    2. (b)

      communicate the name and contact details of the data protection officer;

    3. (c)

      describe the likely consequences of the personal data breach;

    4. (d)

      describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.

  4. 4.

    Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.

  5. 5.

    The controller shall inform the data protection officer about the personal data breach.

  6. 6.

    The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the European Data Protection Supervisor to verify compliance with this Article.

Commission source wording and instructions

Article 34(1)

Commission proposal

1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay.

Institutional text

Council Presidency texts

Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.

Article 34(1)

June Presidency compromise · 10 June

1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay.

Competing proposals

European Parliament amendments

These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.

More filters

Alternative wording Amendment 493 · Virginie Joron IMCO
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay. Processors shall continue to document personal data breaches that are not notified.
Preview
against:
Source identification

Header printed in the source: Article 4 – paragraph 1 – point 7 / Regulation (EU) 2018/1725 / Article 34 – paragraph 1

Remove proposed wording Amendment 1671 · Pernando Barrena Arza ITRE · LIBE
7. in Article 34, paragraph 1 is replaced by the following 1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay.’
Preview
against:
Source identification

Header printed in the source: Article 4 – paragraph 1 – point 7 / Regulation (EU) 2018/1725 / Article 34 – paragraph 1

Deletion marker printed in the source: deleted

Alternative wording Amendment 1672 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 96 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 96 hours, it shall be accompanied by reasons for the delay. Controllers shall continue to document non-notified personal data breaches.
Preview
against:
Source identification

Header printed in the source: Article 4 – paragraph 1 – point 7 / Regulation (EU) 2018/1725 / Article 34 – paragraph 1

Alternative wording Amendment 1673 · Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Lina Gálvez, Francisco Assis, Alex Agius Saliba, Kristian Vigenin, Matjaž Nemec ITRE · LIBE
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 9672 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 9672 hours, it shall be accompanied by reasons for the delay.
Preview
against:
Source identification

Header printed in the source: Article 4 – paragraph 1 – point 7 / Regulation (EU) 2016/679 / Article 34 – paragraph 1

Alternative wording Amendment 1674 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 9672 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 9672 hours, it shall be accompanied by reasons for the delay.
Preview
against:
Source identification

Header printed in the source: Article 4 – paragraph 1 – point 7 / Regulation (EU) 2018/1725 / Article 34 – paragraph 1

Alternative wording Amendment 1675 · Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann ITRE · LIBE
1. In the case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall without undue delay and, where feasible, not later than 9672 hours after having become aware of it, notify the personal data breach to the European Data Protection Supervisor. Where the notification to the European Data Protection Supervisor is not made within 9672 hours, it shall be accompanied by reasons for the delay.
Preview
against:
Source identification

Header printed in the source: Article 4 – paragraph 1 – point 7 / Regulation (EU) 2018/1725 / Article 34 – paragraph 1