Template id: breach-notice-gdpr-de.v1 owner: Lilith-Privacy lead + EU
counsel deadline: 72 hours from confirmation submission: competent German
state DPA online breach portal (lead supervisory authority under the
one-stop-shop)
Phased notification is permitted (Art. 33(4)): submit with known facts and mark sections "information to follow" rather than miss the clock.
Required content (GDPR Art. 33(3))#
- Nature of the breach: categories of data subjects and approximate
number; categories of personal-data records and approximate number.
- V3 data-class checklist: V1 account records / e-mail addresses / payment metadata / voice transcripts / recordings / consent-ledger entries / DSAR exports / Pixel Streaming session logs (IP addresses).
- DPO contact point: name and contact details of our data protection officer (from the de-DE privacy policy controller block).
- Likely consequences of the breach for data subjects.
- Measures taken or proposed: containment, mitigation, and the remediation steps from the incident case (cite the Operator Console case id internally; describe measures concretely in the notice).
Additional fields our submission always includes#
- Timeline: when the breach started, when detected, when confirmed (the 72-hour clock anchor), and an explanation if notification exceeds 72 hours.
- Cross-border scope: other EU/EEA member states affected (one-stop-shop routing).
- Whether data-subject notification (Art. 34) is planned, and on what high-risk assessment.
Internal routing#
- Drafted by: Lilith-Privacy lead. Reviewed by: EU counsel (mandatory before submission). Submitted by: counsel or DPO.
- Evidence: the submitted notice, portal receipt, and timestamps are filed in the incident evidence bucket and referenced from the Operator Console case.