Skip to content
+370 5 212 1506 info@dat.lt

Personal data breach: when to notify VDAI and the people affected

24 September 2026 · Good to know

Every personal data breach must be recorded in your breach log. The State Data Protection Inspectorate (VDAI) is notified without undue delay and, where feasible, not later than 72 hours after you become aware of the breach, unless the breach is unlikely to result in a risk to people’s rights and freedoms. The people affected are told only when the risk is high. These are three separate decisions, and each should be written down with its reasons. An email sent to the wrong recipient by mistake is also a breach.

We have already given the short answer to whether every breach must be notified in the FAQ of our GDPR audit service. A checklist for the first hours is in the Privacio answer “Ką daryti įvykus duomenų saugumo pažeidimui?” (in Lithuanian). Here we explain the whole legal decision: when the clock starts, whom to notify, what to record, and what can go wrong.

What counts as a breach

Article 4(12) GDPR defines a breach broadly: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. The definition is not limited to cyber attacks: it also covers an email sent to a wrong address, recipients’ addresses visible to everyone, a lost laptop, or data deleted without a backup.

The European Data Protection Board (EDPB) Guidelines 9/2022 divide breaches into three types: confidentiality (data disclosed), integrity (data altered) and availability (access lost or data destroyed). One incident can be all three at once.

When the 72 hours start

Article 33(1) GDPR requires notification “without undue delay and, where feasible,” not later than 72 hours. The 72 hours are an upper limit, not a target. If everything is clear after a few hours, there is no reason to wait three days.

The time runs from becoming aware. The EDPB guidelines say the controller should be regarded as aware when it has a reasonable degree of certainty that a security incident has occurred that has compromised personal data. This does not mean the investigation can wait. The same guidelines require prompt action to establish whether a breach has actually happened.

If you do not notify within 72 hours, the notification must give the reasons for the delay (Article 33(1) GDPR). If not everything is known yet, the information may be provided in phases (Article 33(4) GDPR). The notification must contain at least four things: the nature of the breach and, where possible, the approximate number of people and records; the contact details of the DPO or another contact point; the likely consequences; and the measures taken or proposed (Article 33(3) GDPR).

When the breach happens at a service provider

A service provider processing data on your behalf must notify you without undue delay after becoming aware of a breach (Article 33(2) GDPR). You, as the controller, notify VDAI. The EDPB guidelines explain two important details. The processor does not have to assess the risk before telling you. And you are in principle considered aware when the processor informs you. So your 72 hours usually start from the processor’s notice.

The data processing agreement must provide that the processor assists you with the obligations in Articles 32–36 (Article 28(3)(f) GDPR). It is worth checking whether the agreement says how quickly, and to whom, the processor reports. If it does not, the 72-hour clock may start running in the inbox of someone who does not know what to do with that message. When a data processing agreement is required is covered in Data processing agreement: when required and the risk without one.

When to tell the people affected

People are told only when the breach is likely to result in a high risk to their rights and freedoms (Article 34(1) GDPR). The communication is written in clear and plain language and states the nature of the breach, the contact point, the likely consequences and the measures (Article 34(2) GDPR).

It is not required in three cases (Article 34(3) GDPR): the data were protected so that they are unintelligible to an unauthorised person, for example encrypted; measures were taken after the breach so that the high risk is no longer likely to materialise; or informing each person individually would involve disproportionate effort. In the last case a public communication is made instead. Even if you decided not to inform people, VDAI may require you to do so (Article 34(4) GDPR). What the security duty requires is covered in GDPR security measures: what Article 32 actually requires.

An email to the wrong recipient

Must the person be informed when their data have been sent to another addressee by mistake? Not always. The person must be informed only if the risk is high (Article 34(1) GDPR). VDAI does not need to be notified if the breach is unlikely to result in a risk (Article 33(1) GDPR). A single email with non-sensitive data that the recipient has deleted may carry no risk, but this has to be assessed case by case. But it must always be entered in the breach log.

The EDPB Guidelines 01/2021 contain two cases that show where the line is. In one, a list of course participants with names, email addresses and two people’s dietary requirements was sent by mistake to fifteen former participants. The controller noticed at once and asked for deletion. Conclusion: neither VDAI nor the people had to be notified, but the breach must be documented. Note that the dietary requirements here were health data, and notification was still not needed. Health data do not in themselves mean a high risk; the risk assessment decides. In the other, a document listing more than 60 000 people with their social security numbers was attached to an email by mistake. Conclusion: all three steps are needed, that is, document, notify the authority and inform the people.

Even if the recipient confirms deletion, the risk is only reduced: the breach has still happened. The guidelines point out that the controller cannot force recipients to delete the message, so it cannot be fully certain they will. The practical steps for this case are in the Privacio answer “Išsiuntėme duomenis ne tam žmogui — ar reikia pranešti?” (in Lithuanian).

What to record in the breach log

Article 33(5) GDPR requires you to document every breach: the facts, its effects and the remedial action taken. That documentation must enable VDAI to verify your compliance with Article 33. So the log is not a formality; it is your evidence.

At a minimum, record:

  • when it happened, when you became aware and when it was fixed;
  • what data and how many people were affected;
  • what you did, for example asked the recipient to delete, changed passwords;
  • whether you notified VDAI and the people, and if not, why not;
  • what you will change so it does not happen again.

The fourth point matters most. The EDPB guidelines recommend documenting the reasons for your decisions and, where a breach is not notified, recording why you consider there is no risk. If you rely on an exception in Article 34(3) GDPR, keep evidence that it really applies.

What can go wrong

First mistake: a decision not to notify, never written down. Six months later a person files a complaint, and the organisation cannot show why it then believed there was no risk. How complaints are handled is explained in “Complaint to VDAI: how long it takes and what happens next”.

Second: waiting for all the facts while the 72 hours run out. The Regulation allows notification in phases precisely so that you do not have to wait.

Third: the log entry is skipped. The duty to document applies to every breach, including those not notified to VDAI (Article 33(5) GDPR).

Fourth: the service provider reports the incident a week later, because nothing was agreed in the contract. People stay unprotected for that week, and you cannot show that your contract secured the processor’s assistance (Article 28(3)(f) GDPR).

The consequences are not only reputational. The controller’s obligations under Articles 25–39 GDPR, including notification and documentation, fall within the fine range of up to 10 million euros or, for an undertaking, up to 2 % of total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(4)(a) GDPR). For public authorities and bodies, Article 33(1) of the Law on Legal Protection of Personal Data (ADTAĮ) sets a lower cap: up to 0.5 % of the current year’s budget and other gross annual income received in the previous year, but no more than thirty thousand euros. This cap does not apply where the body carries out commercial economic activity (Article 33(3) ADTAĮ). When deciding on a fine and its amount, the supervisory authority also takes into account the manner in which it learned of the infringement, in particular whether, and to what extent, the controller or processor notified it (Article 83(2)(h) GDPR). So a breach that VDAI learns about from a complaint rather than from you may be assessed more strictly.

When to call a lawyer

  • Special categories of data, personal identification numbers, copies of ID documents or financial data are affected, and you need to assess whether the risk is high.
  • Many people are affected, or the data has already been published or is circulating.
  • The 72 hours have already passed and a notification with reasons for the delay has to be prepared.
  • The breach happened at a service provider and it is unclear who is the controller and who notifies.
  • After notifying, you received an inquiry from VDAI. We cover this in “Letter or inquiry from VDAI: what to do”.

Frequently asked questions

Do we have to notify VDAI if we emailed personal data to the wrong person?

Not always. VDAI is notified if the breach is likely to result in a risk to the person’s rights and freedoms (Article 33(1) GDPR). A single email with non-sensitive data that the recipient deleted straight away may carry no risk. Where the email contains more sensitive data, the assessment needs more care: the EDPB guidelines state that where health data or other special categories of data are involved, damage is likely. But the duty to inform the person does not arise automatically. In the EDPB case above, health data were involved and no notification was needed. The risk assessment decides. In every case, the breach must be entered in the log.

What happens if we notify VDAI later than 72 hours?

You must still notify, but together with the reasons for the delay (Article 33(1) GDPR). The EDPB guidelines state that the controller must be able to justify the delay, and records of what was done and when help with that. A late notification is better than none, because when imposing a fine the supervisory authority takes into account whether, and to what extent, the controller notified (Article 83(2)(h) GDPR).

Can we inform people with a general notice on our website?

Only exceptionally. A public communication is allowed where informing each person individually would involve disproportionate effort, and it must inform them in an equally effective manner (Article 34(3)(c) GDPR). Normally people are informed directly, for example by email, in clear and plain language.

How to start

If a breach has already happened, write to us what happened, when you became aware and what data is affected. We will tell you whether VDAI and the people must be notified, and help prepare the notification and the log entry. If no breach has happened yet, it is worth having a breach management procedure and a log template ready in advance.

You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).

Email: info@linden.lt

More about this service: external data protection officer service.

Get a free assessment

Related articles