Your data stays in your browser. Stored in localStorage on this device only — nothing is sent to a server.
EDPB Common Template (v1.0, adopted 8 June 2026) — This form implements the European Data Protection Board's common template for personal data breach notification under GDPR Art. 33. Public consultation closes 5 Aug 2026. Fields and structure follow the official template; the ENISA severity methodology is retained as a supplementary risk-scoring tool.
§2 — Controller & reporting person
EDPB Template §2 · Identification, DPO, involved parties
2.1 About the data controller
Name of the organisation *
Sector
— select —
Private
Public
Type of organisation
— select —
Freelance or Microenterprise
Small or Medium Enterprise
Large Enterprise
Others
Further description of organisation type
Classification of economic activity (NACE Rev. 2.1)
— select —
A — Agriculture, Forestry and Fishing
B — Mining and Quarrying
C — Manufacturing
D — Electricity, Gas, Steam and Air Conditioning
E — Water Supply; Sewerage, Waste Management
F — Construction
G — Wholesale and Retail Trade
H — Transportation and Storage
I — Accommodation and Food Service
J — Publishing, Broadcasting, Content Production
K — Telecom, IT, Information Services
L — Financial and Insurance
M — Real Estate
N — Professional, Scientific and Technical
O — Administrative and Support Service
P — Public Administration and Defence
Q — Education
R — Human Health and Social Work
S — Arts, Sports and Recreation
T — Other Service Activities
U — Activities of Households as Employers
V — Extraterritorial Organisations
Contact details (address, phone, email) *
Type of identifier
— select —
Company ID
Organisation number
VAT number
Controller established in EEA?
Yes
No
Name of representative in EEA *
Contact details of representative *
2.2 Identity of the reporting person
Description of function *
Contact details *
2.3 DPO & contact point
Is a DPO designated? *
— select —
Yes
No
DPO name *
DPO contact details *
More information about the incident can be obtained from
DPO
Reporting person
Other — specify below
Contact person name
Function
Contact details
2.4 Involvement of other parties
Are other parties (processors, joint controllers) involved? *
— select —
Yes
No
← Back
Next → Breach facts
§3 — Initial information on the breach
EDPB Template §3 · Timeline, nature, data subjects, data records, measures in place
3.1 Timeline
When did the breach occur? *
— select —
On a specific day
From a date to a date
From a date and still ongoing
Cannot be determined
To be determined (incomplete notification only)
Date & time controller became aware of breach * (start of 72-hour clock)
Reasons for late notification *
How was the breach discovered? *
— select —
Detection by the data controller
Detection and communication by the data processor
Communication by a data subject
Communication by an external party
Press news
Other
Further description of how the breach was discovered *
Date of notification by other party
Further comments on timeline
3.2 Nature & circumstances of the breach
Nature of the breach * (select all that apply)
Confidentiality breach
Integrity breach
Availability breach
Type of confidentiality breach *
— select —
Data are exfiltrated or disclosed
Likely exfiltrated or disclosed (no evidence)
NOT exfiltrated nor disclosed (reasonable evidence)
Not possible to assess
To be determined
Was the data unintelligible to unauthorised persons? *
— select —
Yes — protection still intact (e.g. encrypted)
Protective measures taken but likely subvertable
No
Not possible to assess
To be determined
Type of integrity breach *
— select —
Alteration, no evidence of illegal/wrong use
Alteration with illegal use, damages reversible
Alteration with illegal use, damages NOT reversible
Type of availability breach *
— select —
Temporary availability issue
Permanent availability issue
Not determined
Nature of the incident * (select all that apply)
Abuse of access privileges
Ransomware / encrypted device
Hacking / malware
Phishing / social engineering
Security vulnerability exploited
Unauthorised access to IT systems
Data exfiltration
Data subject mix-up
Device lost or stolen
E-waste (data on obsolete device)
Incorrect disposal of paper
Mail lost / misdelivery
Misconfiguration
Incorrect access permissions
Paper lost or stolen
Data deleted / destroyed
Data displayed to wrong recipient
Data sent by mistake
Email without BCC / open list
Technical malfunction
Unauthorised data modification
Unintended publication
Verbal unauthorised disclosure
Other
Cause of the breach *
— select —
Internal non-malicious
Internal malicious
External non-malicious
External malicious
To be determined
Unknown
Further description of the nature of the incident *
Systems, software, services, and infrastructure involved *
3.3 Categories & number of data subjects
Categories of concerned data subjects * (select all that apply)
Customers (current & prospects)
Employees (former, current, candidates)
Military or law enforcement staff
Minors
Patients
Students
Subscribers
Users
Vulnerable individuals
Additional (specify below)
Further description of data subjects
3.4 Categories & number of personal data records
Type of breached data * (select all that apply)
Basic data (name, DOB)
Contact details
Biometric data
Criminal convictions
Political opinions
Racial or ethnic origin
Religious / philosophical beliefs
Sex life or sexual orientation
Trade union membership
Genetic data
Health data
Economic and financial data
Employment-related health data
Identification data (national ID)
Location data
Official documents (scanned)
Payment methods (cards, bank)
Profile data (social, credit score)
User credentials
Additional (specify)
Further description of breached data
3.5 Measures in place when the breach occurred
Relevant measures in place * (select all that apply)
Pseudonymisation
Backup / Recovery plan
Data encryption
DP & InfoSec policies
DP & security training
Incident log
Levels of access to data
Logical access control (MFA)
Periodic audits
Physical access control
Up-to-date IT systems
Other (specify below)
Further description of measures in place
← Back
Next → Risk & measures
§5 — Communication to data subjects
EDPB Template §5 · Art. 34 obligations
Communication status
Has the breach been communicated to data subjects? *
— select —
Yes
No, but will be communicated on a specific date
No, but will be communicated (date TBD)
No, investigation still ongoing
No — unlikely to result in high risk (Art. 34(1))
No — Art. 34(3) condition met
Future date of communication
← Back
Next → Cross-border
§6 — Cross-border & other authorities
EDPB Template §6 · Police/judicial, other SAs, cross-border processing
6.1 Other authorities notified
Reported to police / judicial authorities?
— select —
Yes
No
Unknown
Notified other supervisory / control bodies?
— select —
Yes
No
Unknown
Further information (authority name, case ID)
6.2 Cross-border processing (EEA-established controller)
Does the breach involve cross-border processing by an EEA-established controller? *
— select —
Yes
No
Unknown
Lead supervisory authority *
— select —
EEA countries where controller has an establishment (click to select)
EEA countries where affected data subjects are located (click to select)
Approximate number of data subjects per selected country
EEA supervisory authorities notified or to be notified
6.3 Processing at non-EEA establishments
Does the breach involve processing by a non-EEA controller to which GDPR applies? *
— select —
Yes
No
Unknown
EEA countries where affected data subjects are located (click to select)
EEA supervisory authorities notified or to be notified
← Back
Assess & generate → Output