Supervisory Authority Notification
A supervisory authority notification is the report an organization must make to its data protection regulator after discovering a personal data breach. Under the GDPR framework, this notification is generally required without undue delay and, where feasible, within 72 hours of the organization becoming aware of the breach. If the notification is made later than 72 hours, it must be accompanied by reasons for the delay.
Under Article 33 of the GDPR, a supervisory authority notification is the controller's obligation to notify the competent independent data protection regulator of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it; notifications submitted after that window must be accompanied by reasons for the delay. A processor's related duty is distinct: the processor must notify the controller without undue delay after becoming aware of a breach, and the processor does not notify the supervisory authority directly. The supervisory authority is the independent regulator that oversees compliance, receives breach notifications, and investigates. This entry describes a regulatory compliance obligation and its associated deadlines; it is not a cyber insurance coverage term. Whether costs arising from preparing and making such a notification, or resulting regulatory investigation and defense, are covered depends on the specific policy wording, endorsements, exclusions, and jurisdiction. Note also that notification obligations, thresholds, and deadlines are defined differently across regulatory regimes; the 72-hour timeframe described here reflects the GDPR framework and should not be assumed to apply to other jurisdictions or sector-specific rules.
Why it matters
Supervisory authority notification is one of the most time-pressured obligations an organization faces after discovering a personal data breach. Under the GDPR framework, the clock starts when the organization becomes aware of the breach, and the notification is generally required without undue delay and, where feasible, within 72 hours. Because that window is short, the practical challenge is that an organization must often assess and report a breach before it fully understands the scope, cause, and impact. Missing the deadline or failing to provide adequate reasons for a delay can itself become a compliance failure, independent of the breach that triggered it.
This obligation sits at the intersection of regulatory compliance and incident response, but it is not itself a form of resilience or risk transfer. Making a timely and accurate notification does not reduce the likelihood or severity of the underlying incident; it is a legal duty owed to the regulator. It also should not be confused with cyber insurance coverage. Whether the costs of preparing a notification, or of any resulting regulatory investigation and defense, are covered depends on the specific policy wording, endorsements, exclusions, and jurisdiction. Organizations that assume insurance will absorb these obligations may be surprised by gaps between what a policy responds to and what a regulator requires.
A further reason this term matters is that notification obligations are not uniform. The 72-hour timeframe and the aware-based trigger described here reflect the GDPR framework specifically. Other jurisdictions and sector-specific rules define thresholds, deadlines, and even who must be notified differently, so an organization operating across regimes cannot rely on a single notification playbook. Treating the GDPR standard as universal is a common and consequential error.
Who it's relevant to
Inside Supervisory Authority Notification
Common questions
Answers to the questions practitioners most commonly ask about Supervisory Authority Notification.
