# Breach Notification Template — Germany (GDPR Art. 33)

Template id: `breach-notice-gdpr-de.v1` owner: Lilith-Privacy lead + EU
counsel deadline: 72 hours from confirmation submission: competent German
state DPA online breach portal (lead supervisory authority under the
one-stop-shop)

Phased notification is permitted (Art. 33(4)): submit with known facts and
mark sections "information to follow" rather than miss the clock.

## Required content (GDPR Art. 33(3))

1. **Nature of the breach**: categories of data subjects and approximate
   number; categories of personal-data records and approximate number.
   - V3 data-class checklist: V1 account records / e-mail addresses / payment
     metadata / voice transcripts / recordings / consent-ledger entries /
     DSAR exports / Pixel Streaming session logs (IP addresses).
2. **DPO contact point**: name and contact details of our data protection
   officer (from the de-DE privacy policy controller block).
3. **Likely consequences** of the breach for data subjects.
4. **Measures taken or proposed**: containment, mitigation, and the
   remediation steps from the incident case (cite the Operator Console case
   id internally; describe measures concretely in the notice).

## Additional fields our submission always includes

- Timeline: when the breach started, when detected, when confirmed (the
  72-hour clock anchor), and an explanation if notification exceeds 72 hours.
- Cross-border scope: other EU/EEA member states affected (one-stop-shop
  routing).
- Whether data-subject notification (Art. 34) is planned, and on what
  high-risk assessment.

## Internal routing

- Drafted by: Lilith-Privacy lead. Reviewed by: EU counsel (mandatory before
  submission). Submitted by: counsel or DPO.
- Evidence: the submitted notice, portal receipt, and timestamps are filed in
  the incident evidence bucket and referenced from the Operator Console case.
