Mahope tools: EUComply Clean Copy DeskUptime Transmute BugBottle All tools
FREE TOOL

GDPR Breach Report Generator

Article 33 requires you to notify the supervisory authority within 72 hours of becoming aware of a personal data breach. Fill in what you know — get a structured notification and a data-subject communication.

1. The controller
2. Timeline
The 72-hour deadline is calculated when you fill in this field — counted from the moment the controller became aware of the breach.
3. The breach
4. Receiving authority

Submit through your national authority's portal. In Denmark: datatilsynet.dk. The generator only produces the document — submission happens on the official portal.

The two obligations

  • Article 33 — notify the authority, within 72 hours. The controller must notify the supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it — unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If notification is not made within 72 hours, it must be accompanied by reasons for the delay.
  • Article 34 — tell the affected people, when the risk is high. When a breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller must communicate the breach to the affected data subjects without undue delay. Communication is not required if the data was rendered unintelligible (e.g. encrypted), if subsequent measures ensure the high risk is no longer likely, or if it would involve disproportionate effort (a public communication may be used instead).

Honest limitation: National supervisory authorities vary in portal, format and extra fields. This generator follows Articles 33 and 34 of Regulation (EU) 2016/679; always check your national authority's own guidance before submitting.

Related: free privacy notice generator · DPA generator · RoPA generator · GDPR fines in 2026 · paid EU compliance templates