GDPR Articles 33-34, Breach Notification
Regulation (EU) 2016/679, Arts. 33-34
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018.
A breach notification rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Notify the CNIL within 72 hours of becoming aware of a personal-data breach affecting a person in France, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A controller must notify the CNIL within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No France-specific derogation from the General Data Protection Regulation (GDPR) timeline or threshold is identified; treat this as the GDPR-uniform baseline rather than an independently confirmed French addition.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometrics
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.