Skip to main content
Category: Regulatory & Privacy Compliance

Supervisory Authority Notification

Also known as: Breach Notification to the Supervisory Authority, Personal Data Breach Notification, Article 33 Notification
Simply put

A supervisory authority notification is the report an organization must make to its data protection regulator after discovering a personal data breach. Under the GDPR framework, this notification is generally required without undue delay and, where feasible, within 72 hours of the organization becoming aware of the breach. If the notification is made later than 72 hours, it must be accompanied by reasons for the delay.

Formal definition

Under Article 33 of the GDPR, a supervisory authority notification is the controller's obligation to notify the competent independent data protection regulator of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it; notifications submitted after that window must be accompanied by reasons for the delay. A processor's related duty is distinct: the processor must notify the controller without undue delay after becoming aware of a breach, and the processor does not notify the supervisory authority directly. The supervisory authority is the independent regulator that oversees compliance, receives breach notifications, and investigates. This entry describes a regulatory compliance obligation and its associated deadlines; it is not a cyber insurance coverage term. Whether costs arising from preparing and making such a notification, or resulting regulatory investigation and defense, are covered depends on the specific policy wording, endorsements, exclusions, and jurisdiction. Note also that notification obligations, thresholds, and deadlines are defined differently across regulatory regimes; the 72-hour timeframe described here reflects the GDPR framework and should not be assumed to apply to other jurisdictions or sector-specific rules.

Why it matters

Supervisory authority notification is one of the most time-pressured obligations an organization faces after discovering a personal data breach. Under the GDPR framework, the clock starts when the organization becomes aware of the breach, and the notification is generally required without undue delay and, where feasible, within 72 hours. Because that window is short, the practical challenge is that an organization must often assess and report a breach before it fully understands the scope, cause, and impact. Missing the deadline or failing to provide adequate reasons for a delay can itself become a compliance failure, independent of the breach that triggered it.

This obligation sits at the intersection of regulatory compliance and incident response, but it is not itself a form of resilience or risk transfer. Making a timely and accurate notification does not reduce the likelihood or severity of the underlying incident; it is a legal duty owed to the regulator. It also should not be confused with cyber insurance coverage. Whether the costs of preparing a notification, or of any resulting regulatory investigation and defense, are covered depends on the specific policy wording, endorsements, exclusions, and jurisdiction. Organizations that assume insurance will absorb these obligations may be surprised by gaps between what a policy responds to and what a regulator requires.

A further reason this term matters is that notification obligations are not uniform. The 72-hour timeframe and the aware-based trigger described here reflect the GDPR framework specifically. Other jurisdictions and sector-specific rules define thresholds, deadlines, and even who must be notified differently, so an organization operating across regimes cannot rely on a single notification playbook. Treating the GDPR standard as universal is a common and consequential error.

Who it's relevant to

Legal and Compliance Professionals
Legal and compliance teams typically own the assessment of whether an incident constitutes a notifiable personal data breach and the preparation of the notification itself. They must track the point at which the organization became aware, manage the 72-hour window under the GDPR framework, and document reasons for any delay. They also need to distinguish the GDPR obligation from differing thresholds and deadlines in other regulatory regimes and sector-specific rules.
Chief Information Security Officers and Incident Response Teams
Because the notification clock is tied to awareness of a breach, security and incident response functions play a critical role in surfacing incidents promptly and providing the factual detail needed to assess notifiability. Their handoff to legal and compliance often determines whether the organization can meet the deadline. Note that incident response and this notification duty are related but not the same: containing and investigating an incident does not discharge the separate legal obligation to report it.
Risk Managers and Resilience Planners
Notification obligations should be built into breach response plans and playbooks so the organization can act within the required timeframe. Risk managers should be aware that meeting a notification deadline is a compliance activity, not a substitute for mitigation, and that it does not by itself reduce the risk of an incident. They should also confirm how processor relationships are structured so that a processor's delay does not cause the controller to miss its own deadline.
Insurance Brokers and Underwriters
Brokers and underwriters need to understand this obligation to advise on and assess whether a policy responds to costs associated with preparing a notification or defending a resulting regulatory investigation. Whether such costs are covered depends on the specific policy wording, endorsements, exclusions, and jurisdiction. The obligation is a regulatory duty, not a coverage trigger, and coverage should not be assumed to align with the regulatory deadline or scope.

Inside Supervisory Authority Notification

Regulatory Trigger
The obligation to notify a supervisory authority typically arises when a personal data breach meets a defined threshold under an applicable data protection regime. Whether a given incident triggers notification depends on the specific regulatory regime, the nature of the data involved, and the assessed risk to affected individuals rather than on any insurance policy wording.
Notification Timeframe
Many data protection regimes impose a defined deadline for notifying the supervisory authority once a breach is discovered or assessed. The exact clock, its starting point, and any allowance for phased or delayed notification vary by regime, so the applicable law and its interpretation govern rather than a fixed universal period.
Content of the Notification
A notification to a supervisory authority commonly describes the nature of the incident, the categories and approximate number of individuals and records affected, likely consequences, and measures taken or proposed to address the breach. The precise required contents depend on the governing regime and may be provided in stages as information becomes available.
Relationship to Cyber Insurance
This is a legal and compliance obligation, not a coverage term. However, cyber policies frequently provide third-party regulatory defense and, subject to the specific wording and applicable law, coverage for certain regulatory fines and penalties where insurable, as well as first-party breach response services such as legal counsel who assist with drafting and submitting the notification.
Distinction from Data Subject Notification
Notifying the supervisory authority is separate from notifying affected individuals. The two obligations can carry different thresholds, timeframes, and content requirements, and satisfying one does not necessarily satisfy the other.
Scope Boundaries
This concept concerns notification to a data protection or privacy regulator. It does not by itself address notifications to other authorities such as sector regulators, law enforcement, or securities regulators, which may be governed by different rules. It is also distinct from resilience activities such as incident response and business continuity.

Common questions

Answers to the questions practitioners most commonly ask about Supervisory Authority Notification.

Does my cyber insurance policy handle supervisory authority notification for me?
Not automatically. Supervisory authority notification is a legal obligation that rests with the insured (typically as data controller), not with the insurer. What a policy may provide, subject to the specific wording, is access to breach counsel and incident response resources that help you assess and prepare notifications, and coverage for certain associated costs. The insurer supporting the process does not transfer the legal duty to notify, and missing a regulatory deadline remains your responsibility regardless of coverage.
Is notifying a supervisory authority the same as notifying the affected individuals?
No. These are distinct obligations with different triggers, recipients, timelines, and thresholds. Notification to a supervisory authority is directed to a regulator, while notification to affected data subjects is directed to individuals. Depending on the applicable regime, one may be required without the other, and the assessment thresholds can differ. Treating them as a single step risks missing one obligation, so they should be tracked separately.
When does the clock for notifying a supervisory authority typically start?
Under many regimes the notification timeline is tied to when the organization becomes aware of a qualifying incident, rather than when the incident first occurred. The exact trigger, the length of the window, and how 'awareness' is interpreted vary by regulatory regime and jurisdiction, so the precise starting point should be confirmed against the applicable law and, where relevant, with breach counsel.
Should we engage our insurer before or after notifying the supervisory authority?
Many policies contain conditions requiring prompt notice to the insurer and, in some cases, prior consent before incurring certain costs or engaging vendors. Because regulatory deadlines can be short, coordinating early with the insurer and any panel breach counsel is often practical, subject to the specific policy conditions and consent requirements. Confirm the notice provisions in your own policy so that meeting a regulatory deadline does not inadvertently breach a coverage condition.
What information does a supervisory authority notification generally need to contain?
Requirements differ across regulatory regimes, but notifications commonly call for a description of the incident, the categories and approximate scope of data or individuals affected, likely consequences, and the measures taken or proposed in response. Some regimes permit phased or supplementary notification where full details are not yet available. Because the mandated content is set by the applicable law rather than by the policy, verify the specific fields required in each relevant jurisdiction.
How can we prepare so notification is feasible within a tight regulatory window?
Preparation is a resilience and incident response matter rather than an insurance one. Practical steps often include pre-identifying which regulators may have jurisdiction, maintaining data mapping to understand what categories of data are held and where, establishing decision-making and escalation processes for assessing whether a threshold is met, and pre-arranging access to breach counsel. Insurance may fund some of these resources depending on wording, but the readiness to act within the window depends on your own processes.

Common misconceptions

A cyber insurance policy automatically handles supervisory authority notification, so the insured has no independent legal duty.
The duty to notify a supervisory authority is a legal obligation resting on the data controller under the applicable regime. A cyber policy may fund or provide access to breach counsel who assist with the process, but this is subject to the specific policy wording and does not transfer or discharge the underlying legal responsibility. Insurance is a form of risk transfer for certain costs and liabilities; it does not substitute for compliance.
Notifying the supervisory authority and notifying affected individuals are the same step.
These are distinct obligations that can have different triggers, deadlines, and required content. Depending on the assessed risk to individuals and the governing regime, an incident may require notifying the regulator, the individuals, both, or neither, so each obligation must be assessed separately.
If regulatory fines are potentially covered by a cyber policy, the insurer will always pay any penalty imposed.
Whether regulatory fines and penalties are covered depends on the specific policy wording, applicable exclusions and conditions, and whether such fines are insurable as a matter of law in the relevant jurisdiction. In some jurisdictions certain penalties are uninsurable, so coverage cannot be assumed and should be confirmed against the wording and governing law.

Best practices

Determine in advance which supervisory authorities may have jurisdiction over your data processing and document their applicable notification thresholds, timeframes, and content requirements, recognizing these differ across regimes.
Establish an incident assessment process that promptly evaluates whether a given incident meets the regulatory notification trigger, and record the reasoning behind any decision to notify or not notify.
Engage breach counsel early, and where a cyber policy provides breach response services, confirm the notification process and insurer requirements before an incident so pre-approved panel firms and consent conditions do not delay a time-sensitive filing.
Treat supervisory authority notification and affected-individual notification as separate obligations, tracking the distinct deadlines and content requirements for each.
Review your cyber policy wording with your broker to understand how it treats regulatory defense costs and whether any coverage for fines and penalties applies, subject to insurability under the relevant jurisdiction, rather than assuming automatic coverage.
Maintain documentation of the incident, the assessment, and the notification itself, since regulators and insurers may both require an evidenced account of what was known and when.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.