Skip to content

Your app leaked data. Under GDPR, the 72-hour clock has already started.

Under Article 33 of the GDPR, if personal data your company controls is exposed and that creates a risk to people, you must notify your national data protection authority without undue delay and, where feasible, within 72 hours of becoming aware of it. If the risk to people is high, Article 34 also requires telling the affected users directly. You must document every breach, even ones you don't report. Failing these obligations can bring fines of up to €10 million or 2% of global turnover. For a small startup, the practical move is a one-page response plan written before you need it.

By VibeGuard Team4 min read

Here's a situation that happens to small teams more often than you'd think. On a Tuesday afternoon, a user emails to say they could see someone else's invoice. Or a researcher sends a polite note that your database is readable. Or you notice it yourself while testing.

If any of the people affected are in the EU, a deadline started the moment you found out. The GDPR gives you 72 hours to tell your data protection authority, and it doesn't pause while you work out what happened.

This isn't legal advice, and if it happens to you, talk to a lawyer. But the rules are short and readable, and they're much easier to take in on a calm day than during an incident.

What counts as a breach

The GDPR defines a personal data breach as a security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

That's broader than "we got hacked". An open storage bucket, a database table anyone could query, an admin page without a login, an email sent to the wrong list: if personal data was reachable by people who shouldn't have had it, that's a breach. You don't need proof that anyone actually downloaded it. Exposure itself is the disclosure.

The 72 hours

Article 33 says that when a breach happens, the controller (you, if it's your app and your users) must notify the competent supervisory authority "without undue delay and, where feasible, not later than 72 hours after having become aware of it".

There's one exception. You don't have to notify if the breach is "unlikely to result in a risk to the rights and freedoms" of the people affected. A leaked list of newsletter signups with no other data might fall there. Exposed ID photos, passwords, health or financial information won't.

Two details founders miss:

The clock starts when you become aware, meaning when you have a reasonable degree of certainty that a breach has occurred. The European Data Protection Board's guidance allows a short initial investigation to establish that, but not an open-ended one.

You can notify in phases. If you don't have the full picture at hour 70, send what you know and follow up. A late notification must come with the reasons for the delay.

When you must tell users too

Article 34 raises the bar. If a breach is likely to result in a high risk to people, you must also tell them directly, in clear and plain language, without undue delay.

There are exceptions: for example, if the data was encrypted in a way that makes it unreadable, or you've taken steps that mean the high risk is no longer likely to materialise. But for most small apps where real personal data sat in the open, expect to email your users.

What you have to document, always

Article 33(5) requires you to document every personal data breach: the facts, the effects and what you did about it. That includes the ones you decide not to report. If the regulator asks later, "we decided it was low risk" needs to exist in writing, with your reasoning, dated.

What happens if you get it wrong

Failing the notification obligations falls under Article 83(4), which allows fines of up to €10 million or 2% of total worldwide annual turnover, whichever is higher. Regulators consider many factors, including how you behaved once you knew. Prompt, honest notification is treated very differently from silence.

For an early-stage startup the fine is rarely the biggest cost. The emails to users, the customer who pauses a contract, and two weeks of the founding team doing nothing else usually cost more.

The one-page plan to write now

You don't need a security team. You need a page, written today, that answers:

  1. Who decides whether something is a breach? (Probably you.)
  2. Which data protection authority is yours? Find its breach notification form and bookmark it. It depends on where your company is established.
  3. What personal data do you hold, and where? Database tables, storage buckets, email tool, analytics, support inbox.
  4. How would you contact every user quickly? Make sure you can export emails and send a plain message.
  5. Who is your lawyer, or who would you call?
  6. Where will you log what happened, with timestamps?

Then reduce the odds of needing it. Most of the breaches small apps have are the ones in our pre-launch security checklist: database rules, file storage, secrets in the frontend. The Tea app leak is a good example of the storage one, and of what happens when old data you no longer need is still sitting there.

GDPR has one more rule that helps here. You're supposed to keep personal data only as long as you need it. Every table you clean up is data that can't leak.

Questions founders ask

Does GDPR apply to my startup if I'm not in the EU?

It can. GDPR applies to organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour. If you actively sell to EU users, assume it applies and check with a lawyer for your specific case.

What if we found the exposure ourselves and nobody used it?

A breach under GDPR includes unauthorised access or disclosure, and data that was publicly reachable was disclosed whether or not you can prove it was taken. You then assess the risk. If it's unlikely to result in a risk to people, you may not need to notify, but you must still document the breach and your reasoning.

What if we can't gather all the details in 72 hours?

Article 33 allows you to provide information in phases. Send what you know within the deadline and follow up. If you notify late, you must explain the reasons for the delay.

Sources

  1. Art. 33 GDPR: Notification of a personal data breach to the supervisory authority · gdpr-info.eu
  2. Art. 34 GDPR: Communication of a personal data breach to the data subject · gdpr-info.eu
  3. Art. 83 GDPR: General conditions for imposing administrative fines · gdpr-info.eu
  4. Guidelines 9/2022 on personal data breach notification under GDPR · European Data Protection Board, 28 Mar 2023

Is your app one of them?

An independent security check of your live app, from €59, with fix prompts for the coding tool you already use. Read-only, and it never touches your code.

Check my app

Keep reading

All articles