TL;DR for the DPO
New EDPB breach-notification template in public consultation (flagged in the Italian DPA's 17 June 2026 newsletter). Goal: same information, same structure, across EU authorities. The deadline (72 hours, Art. 33) and the risk criteria do not change: what changes is HOW the notification is presented.
The three points that matter
- Harmonisation = predictability: anyone with clients or establishments in several EU countries currently faces different national forms; a common template cuts errors and time in the 72-hour race.
- The requested information mirrors Art. 33(3): nature of the breach, categories and volumes of data and subjects, likely consequences, measures taken and planned, DPO contacts. If your internal procedure already captures these, the notification becomes a transcription.
- It is a consultation: the template may still change, but the direction is clear and it pays to align internal forms with the European structure NOW.
What to do now, in practice
1) Check that your clients' breach procedure captures the Art. 33(3) elements in a structured way (the 'Internal data breach procedure' template in the generator already covers them); 2) prepare the channels: who fills in, who validates, who transmits; 3) for multi-country clients, monitor the outcome of the consultation on the EDPB website - once final, adopt the template as your single internal standard.
Why it matters for your clients
The value for the controller is panic reduction: when a breach happens, having a procedure that produces exactly the information the authority will ask for - in the same order - turns the 72 hours from a blind race into guided form-filling. It is the right moment to sell (or refresh) a breach-procedure upgrade.
Official source:EDPB - public consultation on the breach notification template; Italian DPA newsletter, 17 June 2026Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free