Operational cyber readiness for SMEs

Under attack?

GDPR

GDPR 72 hours: how an SME should handle a possible breach notification

When the 72-hour clock really starts, which facts matter and how to avoid delays and improvised notifications during an incident.

Team PresidioSec

Incident response and cyber resilience for SMEs

2026-04-05

The clock does not start when someone notices in a chat

For an SME the real issue is not just knowing the number 72. The key is understanding when the organization has enough elements to reasonably believe a personal-data breach may have occurred.

That requires a minimum factual set: which systems are involved, which data may be affected, whether there are signs of exfiltration and who is validating the technical information.

A credible notification requires order, not just urgency

A good initial response separates three layers: technical assessment, business decision and notification drafting. If you mix them, you waste time and increase the risk of inconsistent versions.

That is why templates only help when triage has already clarified ownership, timelines and internal contacts. The document alone does not solve the incident.

Sources

Related reads

Next step

If you want to bring this method into your company, talk to us.

Go to contact