YOUR
Search

    20.09.2026

    Data breach notification: what changes with the EDPB common template


    On 10 June 2026, the European Data Protection Board (“EDPB”) adopted a draft common template for the notification of personal data breaches and submitted it to public consultation. The consultation closed on 5 August 2026. The EDPB must now finalise the template and determine the timetable for its adoption by national supervisory authorities. The initiative fulfils the commitment made by the EDPB in the July 2025 Helsinki Statement to simplify the application of the GDPR – particularly for micro, small and medium-sized organisations – through practical and directly usable tools, and pursues the objective of harmonising, across the European Economic Area, the information collected in connection with notifications under Article 33 GDPR.

     

    Comparison with the Italian DPA’s template

    But what, in concrete terms, changes compared with the template used by the Italian Data Protection Authority?

    In terms of content, relatively little changes. The main differences concern the classification of the breach and its causes, risk assessment, the cross-border dimension and certain simplifications – such as the scale used to assess the severity of the impact on data subjects – which remains more detailed in the Italian DPA’s template.

    First, the EDPB template introduces a structured sub-classification of breaches. For confidentiality breaches, it distinguishes between data that have actually been exfiltrated or disclosed; exfiltration or disclosure considered likely despite the absence of evidence; exfiltration or disclosure reasonably ruled out in light of the available evidence; and cases in which an assessment is not yet possible. It also includes a specific question on whether the data are intelligible to unauthorised third parties, reflecting the condition for exemption from notifying data subjects under Article 34(3)(a) GDPR. For integrity breaches, by contrast, it distinguishes between data alteration with no evidence of unlawful use; alteration with evidence of unlawful use but with the possibility of restoration; and alteration with evidence of unlawful use and no possibility of restoration. Finally, for availability breaches, it distinguishes between temporary and permanent unavailability.

    The EDPB also replaces the free-form description of the breach with a closed taxonomy of twenty-five types of incident, including ransomware, phishing and social engineering, likely exploitation of a security vulnerability (known CVE or zero-day), unauthorised access, data exfiltration, misconfiguration or incorrect access permissions, lost or stolen devices, personal data displayed to the wrong recipient, unintended publication, and personal data deleted or destroyed. Similarly, it replaces free-form descriptions of pre-existing technical and organisational measures and of measures planned to prevent future breaches with structured lists. This approach reduces the heterogeneity of notifications and facilitates their comparative analysis by supervisory authorities.

    As regards risk assessment, the proposal expressly provides for the scenario in which the breach is “unlikely to result in a risk” to the rights and freedoms of data subjects. This option is absent from the Italian DPA’s template, where the choice is between high risk, no high risk, and the need for further assessment, without distinguishing between a risk that exists but is not high and a risk that is unlikely within the meaning of Article 33(1) GDPR. This distinction has significant legal significance, since it reflects the condition under which the GDPR permits the notification to the supervisory authority to be omitted altogether. The template also requires the methodology used and the main factors taken into account in the assessment to be expressly stated. Under the Italian DPA’s template, this requirement gave rise to a free-form explanation, whereas under the EDPB proposal it takes on a more formalised character.

    Further additions concern the cross-border dimension. The template requires the approximate number of data subjects concerned in each country involved – information not provided for in the Italian DPA’s template – as well as a list of the other supervisory authorities in the European Economic Area to which the breach has been notified or is expected to be notified. The Italian DPA’s template, by contrast, merely asks which authorities have already received the notification. A separate section is then devoted to controllers not established in the European Economic Area but subject to the GDPR pursuant to Article 3(2), whereas in the Italian DPA’s template the position of such entities is addressed only indirectly, through the section concerning the representative under Article 27.

    Conversely, the EDPB template simplifies certain aspects that the Italian DPA’s template retains. The scale for the severity of the potential impact on data subjects comprises four levels (minor, moderate, severe and to be determined), compared with the five provided for in the Italian template (negligible, low, medium, high and not yet determined). As a result, intermediate positions – particularly the distinction between low and medium impact – are less clearly defined and could lead to a precautionary upward adjustment of the assessment. For a controller not established in the European Economic Area that is required to designate a representative under Article 27 GDPR, the template merely requires the representative’s name and contact details, whereas the Italian DPA’s template provides for a dedicated section containing full identification and contact details. Finally, as regards the cross-border dimension, the EDPB distinguishes only between countries where the controller has an establishment and countries where affected data subjects are located, whereas the Italian DPA’s template identifies a third dimension, namely the establishments actually involved in the breach. This may not coincide with the first category and provides a more granular representation of the geographical scope of the incident.

     

    Some critical considerations 

    The first issue concerns the relationship between the content of the template and the minimum content of the notification laid down by the GDPR. Article 33(3) GDPR sets out four minimum elements: the nature of the breach, including, where possible, the categories and approximate number of data subjects and personal data records concerned; the contact details of the data protection officer or another point of contact; the likely consequences; and the measures taken or proposed to address the breach. With approximately 120 fields and conditional completion rules, the EDPB template goes significantly beyond this core. This is not in itself unlawful, given that it is a soft-law instrument, but its operational implementation through national portals risks turning into a de facto obligation something that the GDPR does not require: in enforcement proceedings, a field left blank or completed only in general terms could be treated as an indication of inadequate accountability, even in the absence of an explicit legal basis requiring that level of detail.

    The requirement to expressly state the methodology and factors considered in the risk assessment, while consistent in the abstract with the principle of accountability, nevertheless presents a delicate aspect. The notification – prepared under the pressure of the seventy-two-hour deadline and with no real opportunity for a considered review of its wording – becomes key documentary evidence in any subsequent administrative sanctioning proceedings and civil litigation concerning damage caused by a data breach. The focus of the authority’s assessment could thus shift from the incident itself to the quality of the procedural compliance reflected in the notification, which is then read ex post with the benefit of hindsight.

    The requirement to describe the systems, software, services and infrastructure involved, together with their location, also raises a further issue concerning the controller’s own operational security. The transmission to the authority of even a general map of the controller’s IT infrastructure should at least be accompanied by the possibility of identifying certain information as confidential or security-sensitive, similarly to what is provided for under NIS2 in dealings with CSIRTs. The introduction of a confidentiality flag, or of a structural distinction between public information and technical information subject to confidentiality, appears to be a reasonable request to put forward during the consultation process.

    The harmonising effect of the template must, however, also be assessed in light of the broader framework of incident notification obligations to which controllers are typically subject today. In addition to the GDPR, parallel notification obligations are provided for under the NIS framework, DORA for financial entities, the CER framework, and so on. From this perspective, the template does not appear to have been designed to enable a “report once, share many” approach, consistent with the architecture of the Digital Omnibus, which proposes a single reporting point at European level coordinated by ENISA. A model that operated alongside existing national portals without replacing them and without interacting with NIS2 and DORA would risk becoming yet another format, adding a further layer of fragmentation rather than reducing it.

    Finally, it should be emphasised that the document adopted by the EDPB for public consultation defines a common template, but does not in itself establish a single European portal for breach notifications, nor does it automatically provide for the replacement of national procedures.

    Against this background, the balance between the seventy-two-hour deadline and the level of detail required regarding the nature of the incident, the root cause and the infrastructure involved appears difficult to sustain in practice, particularly for smaller organisations. The foreseeable outcomes are precautionary over-notification, the systematic submission of incomplete notifications followed by follow-ups that are effectively never closed, or defensive drafting characterised by generic wording. None of these scenarios genuinely serves either the authority or the data subjects. It would be consistent with the structure of Article 33 GDPR to draw a clearer distinction between the minimum content that can reasonably be required within seventy-two hours and the technical post-mortem, the latter to be submitted at a later stage within more realistic timeframes.

    This is compounded by the absence of genuine proportionality between the model applicable to large controllers and the model usable by micro and small enterprises. In the field dedicated to the type of organisation, the template distinguishes between micro-enterprises, SMEs, large enterprises and other categories, but this classification does not trigger any simplification of the subsequent fields. This approach sits uneasily with the logic of Article 30(5) GDPR, which exempts micro and small enterprises from maintaining records of processing activities under certain conditions, and with the Helsinki Statement, through which the EDPB itself undertook to promote proportionate tools for smaller organisations. It would be desirable for the final template to provide for a simplified completion process for micro-enterprises and SMEs, centred on a minimum set of information corresponding to Article 33(3) GDPR.

     

    Assessment and proposals

    The simplification and harmonisation pursued therefore do not amount to a reduction in the information required; on the contrary, in certain areas, the greater granularity actually requires more detailed completion. The potential advantage of the EDPB’s proposed scheme lies primarily in the standardisation of the categories used, the greater predictability of the information required, and the possibility of adopting a common language in internal data breach management procedures and in dealings with the various European supervisory authorities.

    From a constructive perspective, three course corrections appear particularly useful: the introduction of a principle of no adverse inference in favour of a controller that submits an incomplete notification in good faith and supplements it within the prescribed timeframe; the provision of a confidentiality flag for security-sensitive information transmitted to the authority; and the automatic activation of a simplified completion process for micro-enterprises and SMEs, calibrated to the minimum content of Article 33(3) GDPR.

    ADVANT Nctm steps up its focus on the digital economy: launch of the Digital, Tech and Data Department
    ADVANT Nctm is taking a further step forward in the digital economy with the…
    Read more
    Artificial intelligence putting corporate governance to the test: adequate arrangements, model 231 and liability
    The use of artificial intelligence is (also) progressively becoming part of…
    Read more
    GEMA v. Suno: a new european precedent on the relationship between generative AI and copyright
    The very recent judgment handed down by the Regional Court of Munich in the GEMA…
    Read more
    Online contracts and terms requiring specific approval: the Italian Supreme Court reconsiders an established practice
    By Order No. 20945 of 20 June 2026, the Third Civil Division of the Italian…
    Read more
    Chat Control: where does the UE proposal on combating children sexual abuse online stand?
    For more than four years, the European Union has been negotiating a proposal for…
    Read more
    EU KIDS Act: Brussels rewrites the rules for digital services for Minors
    On 17 September 2026, the European Commission presented its proposal for a…
    Read more
    THE RULES OF ARTIFICIAL INTELLIGENCE: FROM THE “PRIMACY” OF THE AI ACT TO MULTILEVEL FRAGMENTATION
    Until recently, the AI Act could present itself as “the world’s first regulatory…
    Read more
    ARTIFICIAL INTELLIGENCE: NEW CRIMINAL LAW IMPLICATIONS REGARDING CORPORATE LIABILITY UNDER ITALIAN LEGISLATIVE DECREE No. 231/2001
    On 15 September 2026, Legislative Decree No. 160 of 9 September 2026 (the…
    Read more