EU Digital Omnibus Seeks 96-Hour GDPR Breach Deadline
Updated:
August 22, 2026
The EU Digital Omnibus proposes extending the GDPR breach notification deadline from 72 hours to 96 hours, but the 96-hour deadline is not law as of August 20, 2026. GDPR Article 33 still requires qualifying personal data breaches to be reported to the competent supervisory authority within 72 hours after the controller becomes aware of the incident. The European Commission’s proposed reform would add another 24 hours and raise the reporting threshold from breaches that create a “risk” to those likely to create a “high risk” to people’s rights and freedoms.
The Commission introduced the Digital Omnibus on November 19, 2025 under legislative procedure 2025/0360(COD). The proposal covers GDPR, cybersecurity reporting, EU data rules, and other parts of the digital rulebook. The European Parliament currently lists the proposal as awaiting committee decision, with committee amendments most recently recorded on July 27, 2026.
What Happened With The GDPR Breach Reporting Reform
Current GDPR Article 33 requires controllers to notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a personal data breach. Reporting is generally required unless the breach is unlikely to create a risk to the rights and freedoms of individuals.
The Digital Omnibus would replace that rule with a 96-hour deadline. It would simultaneously raise the notification threshold so that a regulatory report is required when the personal data breach is likely to result in a high risk to individuals. Late reports would still require an explanation.
The threshold change may have a greater operational effect than the additional 24 hours. Some incidents that currently trigger Article 33 reporting could fall below the proposed high-risk threshold.
Timeline: From Commission Proposal To Latest Update
The Digital Omnibus remains an active legislative proposal rather than an enacted GDPR amendment.
- November 19, 2025: The European Commission published COM(2025) 837, proposing changes across several EU digital laws, including GDPR Article 33.
- November 25, 2025: The Commission formally asked the European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) for an opinion on the proposal’s privacy and data protection provisions.
- February 11, 2026: The EDPB and EDPS issued their joint opinion. They supported the higher breach-reporting threshold and the longer notification period.
- March 17, 2026: European Parliament research confirmed that the proposal would extend GDPR notification from 72 hours to 96 hours and introduce a Single-Entry Point for several EU cyber reporting obligations.
- June 10, 2026: The EDPB adopted a common personal data breach notification template and opened it for consultation. The consultation closed on August 5, 2026.
- June 22, 2026: The European Parliament recorded a joint committee draft report on the Digital Omnibus.
- July 27, 2026: Parliament recorded new committee amendments to the proposal.
- August 20, 2026: Procedure 2025/0360(COD) remains at the awaiting committee decision stage. The existing GDPR 72-hour rule remains legally binding.
What Changes Under GDPR Article 33
The proposal would make two central changes to personal data breach reporting.
First, the controller would have up to 96 hours after awareness of a qualifying breach to notify the competent supervisory authority. Current GDPR text sets that period at 72 hours.
Second, the regulatory threshold would move from “risk” to “high risk.” The proposed text states that the controller must report a breach that is likely to result in a high risk to the rights and freedoms of natural persons.
The 96-hour proposal concerns notification to supervisory authorities. It does not create a general 96-hour deadline for notifying affected individuals. GDPR Article 34 separately requires communication to affected people without undue delay when a breach is likely to create a high risk.
How The 96-Hour Reporting Process Would Work
The proposal would route GDPR breach reports through a new Single-Entry Point linked to EU cybersecurity reporting. Controllers would continue reporting directly to their competent supervisory authorities until that system becomes operational.
European Parliament research states that Single-Entry Point reporting obligations would apply 18 months after the Digital Omnibus enters into force. The application date could move to 24 months when Commission testing determines that the system is not sufficiently ready or secure. Alternative reporting channels would remain available during technical failures.
The proposal does not convert every EU cyber incident deadline into 96 hours. Existing reporting periods under laws such as NIS2, DORA, and the Critical Entities Resilience Directive would continue. The Single-Entry Point concerns the submission route rather than replacing every underlying statutory timetable.
Impact And Risks For Organizations
The proposed 24-hour extension gives privacy, legal, and security teams more time to determine what happened, assess affected data, and prepare a regulator notification with better verified information.
The higher reporting threshold could reduce the number of incidents sent to supervisory authorities. The EDPB and EDPS explicitly supported both this higher threshold and the longer reporting period in their February 11, 2026 opinion. They said the changes could significantly reduce administrative work without reducing personal data protection.
Companies still need fast detection and incident assessment. A 96-hour regulator deadline does not mean organizations can wait four days before investigating an intrusion. Security teams need to determine when awareness occurred, what information was exposed, and whether the incident crosses the statutory risk threshold.
Organizations reviewing recent data breaches can see why early technical evidence is important. Breach scope often changes after the first public disclosure as forensic work reveals additional systems, accounts, or data.
Government And Regulator Actions
The European Commission presented the general Digital Omnibus on November 19, 2025. The Commission estimates its broader digital simplification measures could save businesses up to €5 billion in administrative costs through 2029. That estimate applies to the wider package rather than the Article 33 breach amendment alone.
The EDPB and EDPS support the proposed breach-reporting changes but have raised objections to other parts of the package. Their joint opinion warns that proposed changes to the definition of personal data could reduce existing privacy protections and create legal uncertainty.
The European Parliament’s ITRE and LIBE committees share responsibility for the file. Parliament lists Aura Salla and Marina Kaljurand as rapporteurs and records committee amendments dated July 27, 2026.
Financial, Legal And Business Impact
The central business benefit would be additional investigation time and potentially fewer mandatory notifications for lower-risk incidents.
Organizations should keep their present 72-hour procedures active. Adopting the proposed 96-hour timetable before the legislation takes effect could result in a late GDPR notification under current law.
A broader cybersecurity compliance program can help companies track incident-response procedures, risk assessments, evidence, and regulatory obligations across multiple frameworks. The Digital Omnibus could change reporting mechanics, but organizations will still need documented controls and reliable evidence to support regulatory decisions.
Latest EDPB Breach Reporting Work
The EDPB adopted a common personal data breach notification template on June 10, 2026. Its consultation period ran until August 5, 2026. The template is intended primarily for national data protection authorities to implement through their reporting tools.
The EDPB said it would decide the implementation timeline after the consultation. Meeting records indicate that the Board is considering how the template could interact with the proposed Single-Entry Point once the Digital Omnibus becomes clearer.
This work means breach reporting processes may become more standardized while lawmakers continue negotiating the wider Digital Omnibus.
How Bright Defense Can Reduce GDPR Breach Risk
Bright Defense can help organizations reduce the technical weaknesses and compliance gaps that can lead to personal data breaches. Its penetration testing services cover web applications, APIs, networks, and cloud environments, with attack simulation, exploitation testing, prioritized findings, remediation guidance, and retest support.
Penetration testing can expose authentication flaws, vulnerable software, insecure APIs, and other weaknesses before attackers exploit them. Regular testing gives security teams technical evidence they can use to prioritize corrective work.
Bright Defense’s continuous cybersecurity compliance service covers risk assessments, control monitoring, remediation tracking, incident response planning, evidence management, and compliance readiness. Those activities can help an organization maintain the records needed to assess a breach quickly and support its decision on whether regulatory notification is required.
Organizations building an ongoing program can use the Bright Defense continuous compliance guide for a deeper explanation of continuous control monitoring, regular reporting, and compliance gap management.
The proposed 96-hour deadline gives teams more assessment time. Strong detection, tested incident-response procedures, and accurate compliance evidence remain necessary under either timetable.
What Remains Unclear About The Digital Omnibus
The final wording of GDPR Article 33 remains unsettled. Parliament has not adopted its final first-reading position, and the proposal remains at the committee stage as of August 20, 2026.
The 96-hour deadline could survive unchanged, receive amendments during negotiations, or be removed from the final regulation. The same uncertainty applies to the proposed high-risk threshold and details of the Single-Entry Point.
The general Digital Omnibus should not be confused with the separate Digital Omnibus on AI. The AI Omnibus entered into force on July 27, 2026. The GDPR-containing Digital Omnibus under procedure 2025/0360(COD) remains pending.
Why The Digital Omnibus GDPR Reform Is Significant
The current GDPR breach notification deadline remains 72 hours as of August 20, 2026, while the proposed Digital Omnibus would extend that deadline to 96 hours and raise the reporting threshold to high-risk breaches. Organizations should continue working from the existing Article 33 rule until EU lawmakers complete the legislative process and the final regulation takes legal effect.
The proposed reform reaches further than an extra 24 hours. It could change which breaches require regulator notification, create a common reporting route, and introduce more standardized breach documentation across the EU.
Sources
- European Commission – Digital Omnibus Regulation Proposal (November 19, 2025)
- EUR-Lex – COM(2025) 837, Digital Omnibus Proposal (November 19, 2025)
- EUR-Lex – GDPR Article 33, Notification Of A Personal Data Breach To The Supervisory Authority
- European Parliament Legislative Observatory – Procedure 2025/0360(COD), current status accessed August 20, 2026
- European Parliamentary Research Service – Simplifying Cybersecurity Reporting (March 17, 2026)
- European Data Protection Board And European Data Protection Supervisor – Joint Opinion 2/2026 (February 11, 2026)
- European Data Protection Board – Common Personal Data Breach Notification Template (June 10, 2026)
- European Commission – Simpler Digital Rules To Help EU Businesses Grow (November 19, 2025)
- European Committee Of The Regions – Digital Simplification And Data Union Strategy Opinion (2026)


