Guide

Breach Notification Clauses in a DPA: What Timeline to Require

When a vendor is breached, your own 72-hour GDPR clock is already running before you even hear about it, unless the DPA requires fast notice. Here's what timeline to actually require.

Published August 18, 2026·Last updated August 18, 2026

GDPR gives you 72 hours from becoming aware of a breach to notify your supervisory authority, in most cases. If a vendor sits on a breach for a week before telling you, your 72-hour clock has already run out before you even had a chance to respond, and that gap is entirely a function of what your DPA requires the vendor to do.

Why “without undue delay” isn’t enough

Article 33 requires processors to notify controllers of a breach “without undue delay,” which is the language you’ll see in most standard DPAs. The problem is that phrase is vague enough to cover a same-day notification or, in a vendor’s more generous interpretation, several days. A DPA that just repeats the statutory language without adding a specific timeline is passing the ambiguity straight to you.

What to actually require

  1. A specific notification window, commonly 24 to 48 hours from the vendor becoming aware of a breach, tighter than the statutory “without undue delay” language, so you have real runway before your own 72-hour obligation to the regulator.
  2. Notification content requirements, the vendor should commit to providing (or promptly following up with) the nature of the breach, categories and approximate number of affected data subjects and records, likely consequences, and measures taken or proposed, not just “we had an incident.”
  3. A defined notification channel, a specific email address or contact, not “we’ll let you know somehow,” so the notice doesn’t get lost in a general support inbox.
  4. Cooperation obligations beyond the initial notice, ongoing assistance as you investigate and respond, not a single notification with no further support.

Why the vendor’s own incident response maturity matters

A DPA’s notification clause is only as good as the vendor’s actual ability to detect a breach quickly in the first place. When evaluating a vendor handling sensitive data, it’s worth asking about their incident detection and response practices directly, a strong contractual timeline doesn’t help if the vendor doesn’t realize they’ve been breached for weeks.

Our recommendation

CookieYes

Ask your consent platform, and every vendor touching visitor data, what their breach notification timeline actually is. CookieYes's DPA includes breach notification commitments as part of its standard processor obligations, worth using as a baseline when comparing other vendors' terms.

Try CookieYes

If a vendor won’t commit to a specific window

Some vendors, particularly larger ones with standardized, non-negotiable terms, will only offer the statutory “without undue delay” language regardless of what you ask for. In that case, the practical mitigation is knowing this going in: build extra buffer into your own internal breach response plan for vendor-sourced incidents, and weight it as a real factor, not a minor one, when choosing between vendors handling comparably sensitive data.

The bottom line

“Without undue delay” sounds reasonable until you’re the one running out of runway on a regulatory deadline because a vendor took its time telling you what happened. A specific notification window, not just statutory language, is what actually protects your own compliance timeline.

This guide is educational and not legal advice. For your specific incident response obligations, consult a privacy attorney.