AI Data Breach: The 72-Hour GDPR Notification Rule
An employee pastes customer data into an AI tool — is that a reportable breach? Often yes. Here is how the 72-hour rule under GDPR Art. 33 applies.
An employee pastes customer data into ChatGPT. Is that a data breach? Often, yes. When personal data reaches a third party with no legal basis, that is a breach of confidentiality. So the rule applies: you notify the supervisory authority without undue delay, ideally within 72 hours. Unless a risk to people is unlikely.
What counts as an AI data breach?
Many people picture only a hacker attack. That is too narrow. An unauthorised disclosure counts too. When data goes to an AI service with no contract and no legal basis, that is such a disclosure.
- A breach of confidentiality: data reaches an unauthorised third party.
- An AI service with no contract (DPA) and no legal basis counts as that third party.
- No hacker is needed — an accidental paste is enough.
- It can involve names, contact details, contracts or internal client files.
- What matters is whether personal data leaves your company's control.
The 72-hour deadline under Art. 33
If a risk to the people involved is likely, the duty in Art. 33 GDPR applies. You then notify without undue delay, ideally within 72 hours. Stay calm and work in clear steps.
- 1Detect the incident and stop any further data leaving.
- 2Assess the risk to the rights and freedoms of the people involved.
- 3If a risk is likely, notify the supervisory authority within 72 hours.
- 4The clock starts when you become aware of the breach.
- 5If details are missing, notify first and add information in phases.
When you must inform the people affected
Art. 34 GDPR goes beyond notifying the authority. It requires you to tell the affected people too. But this applies only when the risk to them is high.
- Article 34 applies when there is a high risk to the people affected.
- You then inform those individuals directly, in plain language.
- Describe the breach, its likely effects and your response.
- With special-category data under Art. 9 (e.g. health), risk is often high.
- You may skip the notice if the data was effectively encrypted.
Document every breach
A breach you decide not to report does not just vanish. Art. 33(5) requires an internal record. That way you can justify your decision later.
- Article 33(5) requires you to document every breach internally.
- This includes incidents you decide not to report.
- Record the facts, the impact and your reasoning.
- A breach log helps the authority and protects you during audits.
- Set a clear response procedure before an incident happens.
How to shrink the attack surface
The best breach is the one that never starts. You can lower the risk before any input happens. The key is less data and clear rules.
- Train your team: no real customer data in public AI tools.
- Clarify which AI services are allowed and which have a contract.
- According to OpenAI, inputs from its Enterprise and API products are not used to train the models; consumer accounts follow different rules.
- Minimise data before input (GDPR Art. 5) — share only what is needed.
- Replace identifying details with placeholders before text reaches the AI.
| Situation | Notify authority? | Inform individuals? |
|---|---|---|
| Customer data pasted into a public AI, high risk | Yes, within 72 hours | Yes (Art. 34) |
| Only pseudonymised data shared, low risk | Assess; usually just document | Usually no |
| Already public data, no real risk | No, but document it | No |
| Special-category data (Art. 9) exposed | Yes, promptly | Yes |
| Incident found, risk unclear | Document; notify if in doubt | After risk assessment |
This is exactly where ONYRI Sanitize helps. The tool detects sensitive data in your text and replaces it with reversible placeholders (tokens) before anything goes to an AI. The token-to-value map stays in your browser and is never sent to a server. After the AI replies, ONYRI restores the real values. One honest caveat: this is pseudonymisation, not anonymisation. Pseudonymised data stays personal data (GDPR Recital 26). ONYRI lowers your exposure, but it does not replace a DPA or a legal basis — and it does not remove your notification duties if a breach still happens.
An AI data breach is often human and fast. Stay calm and work the steps: assess the risk, notify within 72 hours, document everything. The best breach is the one that never starts — by putting less data into the prompt.
Frequently asked questions
- Is pasting customer data into ChatGPT a data breach?
- It can be. If personal data reaches an AI service acting as an unauthorised third party with no legal basis, that is a breach of confidentiality. Assess the risk and document the incident.
- When do the 72 hours start?
- The clock starts when you become aware of the breach, not after a full analysis. It is better to notify early and add missing details later.
- Do I have to report every breach?
- No. You can skip notifying the authority when a risk to people is unlikely. But you must still document every breach internally under Art. 33(5).
- Does pseudonymisation remove the duty to notify?
- No. It lowers the risk and often the severity. The duty to assess, document and, where needed, notify still stands.
Sources & references
- GDPR Regulation (EU) 2016/679, Art. 33, 34 — EUR-Lex
- EDPB — Personal data breach notification — European Data Protection Board
- ICO — Guidance on AI and data protection — ICO
- OpenAI — Enterprise Privacy (vendor documentation) — OpenAI
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.