GDPR
In EU data protection, the GDPR is the regulation governing the processing of personal data, with strict handling requirements and breach duties. The seventy-two-hour deadline people quote is the notification to the supervisory authority under article 33; telling affected individuals is a separate duty, without undue delay, and only on high risk.
How it works
The GDPR governs how organisations may process the personal data of people in the EU, setting principles (lawfulness, purpose limitation, minimisation and others), rights for individuals, and obligations for those who process the data. Article 32 requires security appropriate to the risk, and, importantly, requires the ability to demonstrate that those measures are effective, not merely present. The breach duties are commonly misstated. Article 33 requires notification to the supervisory authority (in Spain the AEPD) without undue delay and where feasible within seventy-two hours of becoming aware of a breach. Article 34 is the separate obligation to communicate the breach to the affected individuals, without undue delay, and only when it is likely to result in a high risk to their rights. The two deadlines are different duties to different audiences.
What goes wrong
Conflating the two breach obligations is the error that hurts during an actual incident. A team that believes it has seventy-two hours to tell affected individuals mismanages the response, when in fact that clock is for the authority and the duty to individuals is triggered by high risk and phrased differently. On the security side, the more consequential gap is article 32’s requirement to demonstrate that measures are effective: an organisation documents its controls and never verifies them, so it can evidence that a control exists but not that it works, which is exactly the distance an attacker exploits. Assumed effectiveness is not the same as demonstrated effectiveness, and the regulation asks for the latter.
Where this shows up in an audit
Article 32’s demonstrable-effectiveness requirement is where technical testing meets the regulation: a penetration test produces evidence that the security measures protecting personal data actually resist attack, rather than a paper claim that they are in place. Findings are framed against both the technical weakness and the processing it endangers, and where high-risk processing is involved they feed a data protection impact assessment. The programme is typically owned by a data protection officer and sits under the national LOPDGDD. This is the technical testing that evidences article 32.