Compliance · · 4 min read

EDPB proposes one EU template for data-breach reports

A common European form would standardise how organisations report personal-data breaches, while leaving its implementation timetable undecided after consultation.

The European Data Protection Board has approved version 1.0 of a common form for reporting personal-data breaches. The proposal is open for public consultation until 5 August 2026, after which the EDPB is expected to decide when national supervisory authorities will begin using it in practice, according to Aisa International.

The initiative is intended to replace the different reporting formats used by data-protection authorities across EU member states. Organisations have so far faced varying structures and requirements when notifying breaches, including when dealing with the Czech Office for Personal Data Protection. A shared form would give controllers a single framework for presenting the details of an incident.

The template is extensive. It asks organisations to describe what happened, when it happened, who was affected, how the risks were assessed and what steps were taken in response. The stated aim is to make the process more consistent and easier to navigate, particularly for smaller organisations that may not have specialist legal teams. At the same time, the level of detail required means businesses will need reliable incident records and quick access to technical and legal information.

What the proposed form covers

The document is divided into seven broad areas. The first concerns the status of the submission: an organisation must indicate whether it is making an initial report, updating an earlier one or withdrawing a previous notification.

A second section records the organisation’s identity and role. It includes the relevant economic sector, using classifications from A to V, as well as the type of organisation involved. The form also requires controllers to identify processors and any joint controllers connected with the incident.

The timeline section asks for the date and time when the breach occurred and when it was discovered. If the notification is submitted after the statutory 72-hour period, the organisation must explain the delay. This makes the quality of internal incident logging particularly important, since the reporting clock depends on the timing of detection and the organisation’s assessment of its obligations.

The proposed form then asks organisations to classify the nature of the breach. They must say whether confidentiality, integrity or availability was compromised and indicate whether an internal or external malicious actor was responsible, where that is known.

Another part focuses on the people and information affected. Organisations must identify the relevant categories of data subjects, such as employees, customers, children or vulnerable people, and provide the number of records involved. Where the figures are not yet certain, the form allows an initial submission based on estimates. That report can later be amended through a follow-up notification.

Evidence, risk and cross-border incidents

The risk-assessment section requires an explanation of how the organisation judged the possible effects on individuals. It also asks for information about safeguards already in place, including measures such as encryption and multifactor authentication.

The final area deals with incidents spanning more than one country in the European Economic Area and with supporting documents. The examples identified by Aisa International include risk assessments, messages sent to affected individuals, phishing emails and ransomware notes. These requirements mean that notification is not limited to a short description of the event; authorities may also expect material showing how the organisation investigated and responded to it.

Responsibility can remain with the data controller even when the breach takes place at an outside service provider. The proposed form’s requirement to record processors and joint controllers reflects that allocation of roles. A company cannot assume that outsourcing data processing removes its own reporting duties.

The form also recognises that a controller may not know the precise number of affected people within 72 hours. An incomplete notification can be submitted using available estimates, followed by additional information once the investigation produces firmer figures. This provides a route for organisations to meet the initial deadline without waiting for every fact to be established.

No implementation date yet

The consultation deadline is 5 August 2026. Until the EDPB sets the next steps, the article does not identify a final date on which the common template will become compulsory for national authorities or organisations. Businesses therefore have time to examine how their breach-response procedures capture the information the proposed form requests.

Aisa International says it does not complete breach notifications for clients, keep manual records of leaked data or reconcile custodian transaction reports. The company describes its role as strategic compliance oversight and says that technical investigation and reporting should be handled by specialist information-security and legal advisers.

The publisher presents the proposed form as part of a broader shift towards more structured oversight of digital risks. For organisations, the practical implication is that breach preparation cannot depend solely on improvised work during a crisis. Accurate timelines, clear responsibility for processors, documented risk assessments and preserved evidence may all be needed if the common reporting approach moves ahead.

Aisa International’s article states that its information is general rather than personalised advice and warns that laws may change. It recommends seeking current guidance from qualified advisers and official government sources before relying on the proposal in a specific case.

data protectiongdprcybersecurityedpbcompliancedata breachesprivacy

Continue reading

Read this in another language