Use ENISA's methodology to assess severity, determine your 72-hour DPA notification obligation, and generate a breach register record — entirely in your browser.
Step-by-step assessment for GDPR data breach response. Calculates notification obligations under Art. 33 & 34 using the ENISA methodology, with a built-in 72-hour countdown timer.
Free account required · All calculations run in your browser
The 72-hour countdown for DPA notification (GDPR Art. 33) starts from the moment you became aware of the breach. Enter accurate times — this drives the notification deadline.
When did your organisation first become aware?
Please enter the discovery date and time.When did the breach itself take place?
A breach may affect confidentiality, integrity, or availability of personal data. Select all that apply.
Select all categories involved in the breach. Higher-sensitivity categories significantly increase severity.
These factors are used by the ENISA methodology to calculate the final severity score and notification obligations.
Pre-filled based on your responses. Complete the description and sign-off fields. Print or save for your records.