Preiskel & CoPreiskel & Co
Preiskel & Co
A boutique law firm in London
  • Home
  • About Us
    • Diversity, Social Responsibility, and Pro Bono
  • Services
    • Corporate
    • Commercial
    • Regulatory
    • Competition Litigation & Regulation
    • Data Protection, Privacy, and Retention
    • Intellectual Property
    • Dispute Resolution
    • Employment
  • Sectors
    • Telecommunications
    • IT, Technology, & Internet
    • Artificial Intelligence
    • Media and Broadcasting
    • Websites, Blogging, & Social Media
    • Film & Television
    • Gambling & Online Gaming
    • Leisure & Retail
    • Energy & Minerals
    • Cryptocurrency & Blockchain
    • Creative Industries
    • Digital Markets
  • People
    • Daniel Preiskel
    • Ronnie Preiskel
    • Tim Cowen
    • Jose Saras
    • Rob Kay
    • Karthyaeni Vittala
    • Tina Cowen
    • Grainne Brankin
    • Xavier Prida Riba
    • Martina Raciti
    • Maria Constantin
    • Peter Dally
    • Joanna Coombs-Huang
    • Sophia Yakhno
    • Hannah Leader
    • Alison MacFarlane
    • Ilanit Appelfeld
    • Daniel Oakland
    • Sue Warwick
    • D A T Green
    • Antony Corel
    • Keith Corkan
    • Stewart White
    • Robert Harvey
    • Kristiina Kekarainen
    • Sabina Leshchenko
    • Isabel Vanhaeverbeke
  • International
  • Blog
  • News
    • Publications
  • Contact
Menu back  

EDPB clarifies personal data breach notification requirements for non-EU controllers

April 25, 2023By Preiskel & Co

On 28 March 2023, the European Data Protection Board (“EDPB”) adopted updated guidelines on the obligation for non-EU established controllers to notify supervisory authorities (“SA”) following a personal data breach. Article 4(12) of the General Data Protection Regulation (“GDPR”) stipulates that a personal data breach occurs when there is an “accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed”.

According to Article 33(1) GDPR, data controllers must notify the SA of a personal data breach without undue delay, and where feasible, not later than 72 hours after having become aware of it. In addition to controllers being compelled to alert their national SA, in the event of a cross-border breach, this must also be brought to the attention of the SA of every EU member state where affected data subjects reside.

The “One-stop shop” (“OSS”) mechanism

In an attempt to deal with the administrative burden that controllers encounter when they have multiple EU members states’ SA’s to notify, the EDPB introduced the OSS mechanism, the guidelines for which were initially provided by the Article 29 Working Party (“WP29”) (the EDPB’s predecessor) on 13 December 2016.

The OSS mechanism permits controllers to notify just the lead SA of the member state where their main establishment and representative is located. This means that the responsibility of enforcement essentially lies with the lead SA, who is then encumbered with the duty of escalating the breach and coordinating with other concerned SA’s.

Updated guidelines for non-EU establishments

On 10 October 2022, the EDPB launched a consultation to discuss the applicability of the OSS mechanism and how the notification obligation should be clarified within the guidelines for non-EU based establishments who, in line with Article 27(1) GDPR, have a representative in the EU.

Following the consultation, the EDPB have now addressed the notification obligation for non-EU based establishments in paragraph 70-74 of the updated guidelines. Paragraph 73 confirms that “the mere presence of a representative in a Member State does not trigger the one-stop shop system. For this reason, the breach will need to be notified to every supervisory authority for which affected data subjects reside in their Member State”. The EDPB’s updated guidelines explicitly set out that the obligation to notify shall remain in the hands of the non-EU controller, which brings some much-needed clarity to the already endorsed WP29 guidelines.

The EDPB’s updated guidance further specifies that, for non-established EU entities, “the function of a representative in the Union is not compatible with the role of an external DPO”. In practice this means that, although a representative can be involved in the notification process when explicitly stipulated in the representative’s written mandate, “the responsibility to notify remains that of the controller in line with Article 27(5)” GDPR.

Overall, the outcome of these reviewed and updated guidelines affirms the notion that, following a personal data breach, non-EU controllers who are subject to the GDPR will have to deal with all relevant SAs separately and their responsibilities cannot be entirely delegated to their national SA or representative.

Perhaps unsurprisingly, this has led to criticisms from non-EU establishments who are now left to their own devices to notify several different EU and national authority bodies within the respective timescales following a personal data breach, with very little coordination support afforded to them from the EU. This could potentially leave non-EU establishments with the burden of submitting up to 27 individual notifications when a personal data breach results in a cross-border detriment to data subjects around the EU.

 

Find the EDPB updated guidelines here.

Please contact Jose Saras and Xavier Prida if you have any questions regarding the above.

The material in this article is only for general review of the topics covered and does not constitute legal advice. No legal or business decision should be based on its content.

This article is written in English language. Preiskel & Co LLP is not responsible for any translation of all or part of its content into any language.

Latest Preiskel & Co blog posts
  • AI and Copyright: Balancing Creative Rights and Innovation in the UK
    August 18, 2026
  • Know When You’re Talking to AI: The EU AI Act’s Transparency Obligations Come into Force on 2 August 2026
    August 10, 2026
  • Logged Off: How The UK’s Social Media Ban Proposes To Redefine Growing Up
    June 23, 2026
  • Preiskel & Co advises MOW on the Search Only Contract – the first contract giving publishers control over AI scraping
    June 22, 2026
  • Danny Preiskel Speaks on MEF Connect Panel on ‘Regulator vs Reality: Who’s Actually Driving the New Rules of Wholesale?’
    May 18, 2026
  • ICO Guidance on Storage and Access Technologies – What’s New
    May 14, 2026
  • Danny Preiskel Speaking at Comms Council UK ‘Telecoms Compliance in Practice’ 12th May 2026
    May 8, 2026
  • Preiskel & Co Film Team Advises on The Bridge Documentary
    May 1, 2026
  • ICO Guidance on Automated Decision Making: Key Lessons for Organisations
    April 28, 2026
  • Preiskel & Co LLP Co-Sponsors the Ithaca Competition Conference 2026
    April 9, 2026
  • Recognised Legitimate Interest under the Data (Use and Access) Act: A narrow Lawful Basis for Public Interest Scenarios
    April 8, 2026
  • New Article by Preiskel on The Sling: Is Social Media Like Alcohol and Tobacco?
    April 8, 2026

The Preiskel Blog

  • AI and Copyright: Balancing Creative Rights and Innovation in the UK 18 Aug 2026
  • Logged Off: How The UK’s Social Media Ban Proposes To Redefine Growing Up 23 Jun 2026
  • Preiskel & Co advises MOW on the Search Only Contract – the first contract giving publishers control over AI scraping 22 Jun 2026
  • Preiskel & Co Film Team Advises on The Bridge Documentary 1 May 2026

Preiskel news

  • Jose Saras Ranked Band 1 in Chambers FinTech 2026
  • Preiskel & Co provide telecoms advice to 1GLOBAL on partnership with Monzo to launch Monzo Mobile
  • Preiskel & Co Secures Major Costs Win for Groupe Hardis in Commercial Dispute
  • Danny Preiskel Speaks on MEF Connect Panel on ‘Regulator vs Reality: Who’s Actually Driving the New Rules of Wholesale?’
Preiskel & Co LLP
4 King's Bench Walk,
Temple,
London
EC4Y 7DL
United Kingdom

Tel: +44 20 7332 5640
Email: info@preiskel.com

Find us on:

TwitterLinkedinMail
© Preiskel & Co LLP 2026 | Site map | Legal notices | Cookie Policy | Privacy

         

We use analytic cookies to help us understand how many visitors we have and how they move around our website. This helps us improving our website. You can accept or reject our use of analytic cookies and update your choices at any time. See our Cookie Policy to learn more about how we use essential and analytic cookies and to update your choices.