One of the most time-sensitive obligations under the GDPR is the requirement for data controllers to notify their supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Art. 33 para. 1 […]