
In brief. A data breach is any security breach that destroys, loses, alters or exposes personal data. Once detected, the GDPR imposes two time-bound obligations: notify the Spanish Data Protection Agency (AEPD) without undue delay and no later than 72 hours (art. 33) and, where there is high risk, communicate it to the data subjects (art. 34). Non-compliance is penalised under Article 83 of the GDPR, with fines of up to €20M or 4% of total annual worldwide turnover. Cyber insurance funds much of the response —forensics, legal advice, communication and third-party liability— subject to the terms of each policy.
What is a personal data breach?
Article 4.12 of the GDPR defines it precisely: a personal data breach is any breach of security leading to the accidental or unlawful destruction, loss or alteration of personal data, or the unauthorised disclosure of, or access to, such data. The definition is deliberately broad and covers three dimensions: confidentiality (improper access), integrity (alteration) and availability (loss or destruction).
It is worth fixing the concept from the outset: not every security incident is a data breach. An attack affecting only systems without personal data is an incident; it becomes a breach when that data —belonging to clients, employees, suppliers— is compromised. That classification is not a technical nuance: it determines which legal obligations are triggered and within what timeframe.
The most frequent scenarios in the corporate field are recognisable: ransomware that encrypts and exfiltrates databases, unauthorised access to a CRM after credential theft, the mistaken sending of a file containing data to the wrong recipient, the loss of an unencrypted laptop or device, or the improper publication of information through a configuration error. In all of them personal data is affected and, therefore, there are obligations to meet.
Does your organisation have a verified breach response protocol? Request a review with no obligation and we will assess your exposure alongside your insurance programme.
How long do I have to notify a breach to the AEPD?
This is the question that starts the clock. Article 33 of the GDPR states that the controller must notify the breach to the competent supervisory authority —in Spain, the AEPD— without undue delay and, where feasible, no later than 72 hours after having become aware of it.
The deadline runs from when the company becomes aware of the breach, not from when it occurred. And it allows one relevant exception: notification is not required when the breach is unlikely to result in a risk to the rights and freedoms of natural persons. That risk assessment must be documented: if the decision is not to notify, the reasoning must be justifiable.
If notification is not made within 72 hours, the GDPR allows it to be made later, accompanied by the reasons for the delay, and even in phases when not all the information is available at once. In any case, the controller must internally document every breach —facts, effects and corrective measures— in a record the AEPD may request. That record is, in practice, the organisation's proof of due diligence.
An operational nuance for large accounts: when your company acts as a processor for a client, it does not notify the AEPD directly but must inform the controller without undue delay so that the controller can meet the deadline. The contractual chain matters as much as the clock.
When must the breach be communicated to data subjects?
The second obligation differs from the first and has a higher threshold. Article 34 of the GDPR requires communicating the breach to the data subjects —the people whose data has been compromised— when it is likely to result in a high risk to their rights and freedoms, also without undue delay.
Not every breach notifiable to the AEPD is communicated to the data subjects: the AEPD is notified where there is a risk; data subjects are informed only where there is a high risk. The communication must use clear language and describe the nature of the breach, the likely consequences and the measures taken or proposed.
Article 34 itself provides for exceptions where communication to data subjects is not required, among them: that the controller has applied protection measures rendering the data unintelligible —typically robust encryption— to anyone not authorised; that subsequent measures have been taken which eliminate the likelihood of high risk; or that individual communication would involve disproportionate effort, in which case an equivalent public communication is used. The AEPD may also require the communication if it considers the risk to be high.
Do you need to put your obligations in order before an incident occurs? Let us discuss your situation. We coordinate the insurance with your response plan.
Penalties for non-compliance
Article 83 of the GDPR grades administrative penalties into two tiers, according to the obligation breached:
- Up to €10,000,000 or, in the case of an undertaking, 2% of total annual worldwide turnover of the preceding financial year, whichever is higher. This tier covers, among others, breaches of the security obligations and of breach-notification duties (arts. 33 and 34).
- Up to €20,000,000 or 4% of total annual worldwide turnover, whichever is higher, for the most serious infringements (principles of processing, data subjects' rights, international transfers).
The amount is not arbitrary. Article 83.2 requires each penalty to be graded having regard, among other factors, to the nature, gravity and duration of the infringement, its intentional or negligent character, the measures taken to mitigate the damage, the cooperation with the authority and the categories of data affected. In practice, a diligent and well-documented response is a mitigating factor; the absence of a protocol, an aggravating one. In Spain, Organic Law 3/2018 (LOPDGDD) complements the GDPR's penalty regime.
The point is not to dramatise the figure but to size the exposure: for a large account, 4% of worldwide turnover can comfortably exceed the nominal €20M ceiling. It is a magnitude that belongs to the management committee, not just to the IT department.
How to respond to a breach, step by step
The quality of the response —and its cost— depends on having prepared it beforehand. An orderly protocol follows, in essence, these phases:
- Containment. Isolate the affected systems, revoke compromised access and stop the spread. The goal is to limit the scope before investigating.
- Forensic analysis. Determine what happened, which data has been affected and how many people. This yields the information the notification requires and the risk assessment.
- Notification decision. With the facts in hand, decide —and document— whether to notify the AEPD (art. 33) and whether the risk is high enough to communicate to the data subjects (art. 34), respecting the 72 hours.
- Communication. Prepare and carry out the communications to the authority, to the data subjects and, where appropriate, the public response, with a clear and consistent message.
- Lessons learned. Close the breach with corrective measures, update the internal record and review controls to reduce recurrence.
Each phase consumes specialist resources —forensic experts, lawyers, communication— that most organisations do not have in-house. That is where insurance cover stops being theoretical.
Does cyber insurance cover the penalties and costs of a breach?
Cyber insurance for companies is designed, in large part, to fund precisely this response. Without repeating the detail of the pillar's cover here, in the face of a breach it usually intervenes, subject to the policy, on several fronts:
- Crisis management and forensic analysis: the technical services that determine the scope and cause of the incident.
- Legal notification advice: the legal support to meet the deadlines and content of Articles 33 and 34.
- Costs of communicating to data subjects: individual notification, call centres and, where appropriate, monitoring services for the data subjects.
- Civil liability for claims by third parties who consider themselves harmed by the breach.
- Legal defence and, where legally insurable, the penalties: whether GDPR administrative fines are insurable depends on the jurisdiction and the policy, a point worth verifying case by case.
The key word is insurability: not in every jurisdiction nor in every policy is the administrative penalty insurable, and that is a point that should not be taken for granted. What usually is covered —forensics, legal, communication and liability towards data subjects— represents the bulk of the real cost of a breach. We place this line within our full range of cover areas for large accounts, coordinated with the rest of the programme.
As an independent broker, we compare the scope of breach-response cover across companies before recommending one, because the devil is in the exclusions and the sub-limits. Cyber insurance does not replace GDPR compliance: it funds and accompanies it.
Frequently asked questions
How long is there to notify a data breach? To the AEPD, without undue delay and no later than 72 hours after becoming aware of it (GDPR art. 33), unless the breach is unlikely to pose a risk to data subjects.
Does insurance pay GDPR fines? Only where administrative penalties are legally insurable; cyber insurance usually covers legal defence, management and liability towards data subjects. Whether the fine is insurable depends on the jurisdiction and the policy.
Must data subjects always be informed? Not always: only when the breach entails a high risk to their rights (GDPR art. 34); there are exceptions (e.g. unintelligible encrypted data).
What is the difference between a security incident and a data breach? Not every incident is a breach; a breach exists when personal data is affected (destruction, loss, alteration or unauthorised access). The classification determines the obligations.
Sources and regulations
- Regulation (EU) 2016/679 (GDPR), Articles 4.12 (definition of a personal data breach), 33 (notification to the supervisory authority), 34 (communication to the data subject) and 83 (general conditions for imposing administrative fines).
- Organic Law 3/2018 of 5 December (LOPDGDD) — development and penalty regime in Spain.
- Spanish Data Protection Agency (AEPD) — guidance and notification system for personal data security breaches.
- ENISA (European Union Agency for Cybersecurity) — recommendations on incident handling and breach notification.
New Brokers is an independent insurance broker registered with the DGSFP under code J0140. This content is for guidance only and does not constitute legal or binding advice; cover, guarantees and terms are governed by each policy and company. We work under the client's mandate, with access to the whole market —including Lloyd's— and defence in the event of a claim.
Do you want to put your obligations in order in the face of a breach and the insurance that funds them? Request an analysis of your cyber-risk exposure. We compare the market for you.
