A common form for the whole Union, to notify a breach to the authority. Here is why it was created, when you use it, who fills it in and where it is sent.
When a data breach happens, you have 72 hours to notify the authority, and in that window you have to gather information, assess the risk and complete a notification — exactly when the team is under pressure. Until now, each authority had its own form, with its own fields. For a company operating in several countries, that meant just as many versions to fill in.
This is where the news comes in: the EDPB has adopted a common template for these notifications. Let us take it step by step — no jargon.
On 8 June 2026, the EDPB adopted version 1.0 of a template for personal data breach notification and released it for public consultation. In short, it is a structured form, with a common set of fields, that any controller can use to notify a breach to a supervisory authority.
The idea behind it is simple: a notification should not be a free composition. If everyone fills in the same fields, the authority gets the information it needs every time, and the controller no longer guesses what to write. As it is in public consultation, the text can still be refined, but the direction is clear: one single format, valid across the Union.
The answer has two parts. The first is about incomplete notifications. Under the pressure of 72 hours, it is easy to forget a detail, and a notification missing information means follow-ups and delays. A form with clear fields guides you not to skip anything.
The second is about fragmentation. A company present in five countries faced five different forms. A single template, plus the one-stop-shop mechanism for cross-border cases, turns an unpredictable process into a predictable one. Less time lost on form, more time for what really matters: limiting the damage.
The template is helpful and recommended when you already have the obligation to notify, that is, in the situations under Article 33 GDPR: a breach that may result in a risk to the rights and freedoms of individuals must be notified to the authority within 72 hours of becoming aware of it.
A few practical things the form handles explicitly:
Note: not every incident is notified. The logic remains risk-based. For how notification to the Romanian authority works in practice, see our article on notifying a breach to ANSPDCP.
The short answer: it is filled in by the data controller, and the recipient is the supervisory authority.
In practice, the reporting person is usually the data protection officer (DPO) or a legal or authorised representative of the organisation — the template explicitly asks for this person's name, function and contact details, plus the DPO's details. It is also where you list any other parties involved: a processor or a joint controller.
The recipient is the competent supervisory authority. In Romania, this is ANSPDCP. If the breach concerns cross-border processing, the notification goes to the lead authority, through the one-stop-shop mechanism — and this is where the advantage of a common form shows best.
The form is divided into seven areas. You can use them right now as a checklist of the information you need to be able to gather quickly:
A predictable form is far easier to complete at 3 a.m., when the incident has just happened, than a blank page. But the form only helps if you already have the information. That is why the important part happens before the breach: a well-kept incident register, a clear DPO or contact point, and a process by which, within a few hours, you can say what happened, who it affects and what you did. For how a seemingly trivial incident turns into a serious problem, see our article on a GDPR incident with medical data in an Excel file.
It is a standardised form, adopted by the European Data Protection Board (EDPB) on 8 June 2026 as version 1.0 and released for public consultation. It sets a common set of fields a controller completes when notifying a data breach to a supervisory authority, so that notifications are complete and consistent across the Union.
The obligation to notify a breach already exists, under Article 33 GDPR. The template standardises how you do it. As it is in public consultation, it is not yet a single mandatory form everywhere; in Romania you notify through the ANSPDCP channel. But it reflects exactly the information authorities expect, so it is worth using as a checklist now.
Within 72 hours of becoming aware of the breach (Article 33 GDPR), where it may result in a risk to the rights and freedoms of individuals. If you do not have all the information, you can notify in phases: a preliminary notification followed by a complementary one. Where the risk is high, you must also inform the affected individuals (Article 34).
It is filled in by the data controller, usually through the data protection officer (DPO) or a legal or authorised representative. It is sent to the competent supervisory authority — in Romania, ANSPDCP. For cross-border processing, the notification goes to the lead authority through the one-stop-shop mechanism.
We assist you with the notification to ANSPDCP, the risk assessment and setting up an incident-response process — so that, when it happens, you act calmly, not in a panic. Get in touch.