A proposed common template for personal data breach notifications recently published by the European Data Protection Board (“EDPB“) for consultation has the potential to assist organisations in streamlining personal data breach reporting across the EU while also raising additional complexity and challenges for businesses.

In line with the EDPB’s Helsinki Statement on enhanced clarity, support and engagement, the template is designed to help organisations and Data Protection Authorities (“DPAs“) to “structure, harmonise, and unify their data breach notification processes“, with the aim of simplifying GDPR compliance and improving consistency across the EU.

Standardising breach notifications across the EU

Under Article 33 GDPR, controllers must notify relevant DPAs of certain personal data breaches without undue delay and, where feasible, within 72 hours. Article 33(3) GDPR sets out the minimum information to be included within the data breach notification. However, in practice, notification requirements and formats have varied across Member States, creating operational complexity—particularly for organisations operating across multiple jurisdictions.

The EDPB’s new template seeks to address these challenges by introducing a standardised format for breach notifications across the EU. The template aims to:

  • ensure that notifications contain the information required by Article 33 GDPR;
  • make it easier for organisations to submit a timely notification; and
  • promote greater consistency in how breaches are reported and assessed.

Key takeaways

  • The template is designed for implementation by DPAs through an IT tool, incorporating predefined values and options, with guidance to support completion. It broadly follows the structure of Article 33(3) GDPR, however, the detail requested in the template goes far beyond the minimum requirements set out in Article 33(3) GDPR.
  • The template includes classifications of confidentiality, integrity and availability and a wide range of predefined incident types (e.g. ransomware, hacking, malware, phishing, data exfiltration and incorrect access permissions) and types of breached data (e.g. ‘basic’ data (name, surname, date of birth), contact information, biometric data, employment related health data, location data). The template also includes a predefined list of relevant measures in place when the breach occurred (e.g. pseudonymisation, encryption, incident logging, access controls, periodic audits).
  • The template requires organisations to complete an assessment of the consequences of the breach and contains a list of predefined measures taken to prevent a similar breach occurring. The template also includes a cross-border section covering the lead supervisory authority and impacted jurisdictions. Finally, the template contains an attachments section, where organisations can attach copies of communications, risk assessments, ransomware notes, phishing messages etc.
  • The template accommodates phased reporting, allowing notifications to be marked as complete, incomplete or withdrawn in line with Article 33(4) GDPR. Given the level of detail required— much of which may not be available in the immediate aftermath of an incident— organisations will need the ability to indicate that further information will follow as investigations continue.
  • The adoption of a common notification template sits within a broader trend towards greater regulatory coordination and simplification at EU level. The initiative aligns with the EDPB’s wider efforts to enhance consistency in the application of the GDPR and complements ongoing discussions on cross-regulatory cooperation in the digital sphere, particularly as organisations navigate overlapping obligations in areas such as cybersecurity, incident reporting, and digital regulation more generally.
  • It is not yet clear how the draft notification template will sit alongside the ongoing Digital Omnibus proposals. The Digital Omnibus proposes the introduction of a single EU breach reporting portal and common template, which would address the duplicative reporting and administrative burden resulting from overlapping obligations for organisations under the GDPR, NIS2, DORA and other frameworks. Based on a “report once, share many” principle, the Omnibus proposed a centralised portal operated by ENISA, which would use a harmonised incident reporting form.
  • The template will need to be adopted by each EU DPA – although adoption of the template is not mandatory, it is likely to see widespread adoption by DPAs given the make-up of the EDPB.  However, the timeline for adoption is not yet clear.

Implementation and consultation

The template is currently subject to public consultation until 5 August 2026.

Following the consultation, the EDPB will determine the timeline and approach for implementation by DPAs.