• Data breach management

    We help you in the first 72 hours: we assess the risk, notify the Spanish Data Protection Agency (AEPD) where required and inform the people affected.


We act fast when your data is exposed. An email sent to the wrong recipient, ransomware or a stolen laptop can be a personal data breach. If it is likely to result in a risk to people, the GDPR requires notifying the AEPD without undue delay and, at the latest, within 72 hours of becoming aware of it. We help you decide whether to notify, do it properly and prevent it from happening again.

Has this happened to you?

If you recognise any of these situations, you may be facing a security breach:

  • You sent an email containing personal data to the wrong recipient or with all addresses visible.
  • Ransomware has encrypted your computers or servers.
  • Someone on your team fell for a phishing email and handed over their credentials.
  • A laptop, mobile phone or USB stick containing data has been lost or stolen.
  • A supplier tells you it has suffered an attack.
  • A former employee has taken customer data.


What does the law require after a security breach?

The GDPR requires you to act quickly and document everything. In addition, some sectors have their own incident notification obligations:

Obligation Rule Since
Notify the breach to the AEPD without undue delay and, at the latest, within 72 hours, unless it is unlikely to result in a risk GDPR, Art. 33 25 May 2018
Communicate the breach to the people affected when it is likely to result in a high risk to them GDPR, Art. 34 25 May 2018
Document all breaches, including those not notified GDPR, Art. 33(5) 25 May 2018
Inform the controller without undue delay when the processor suffers the breach GDPR, Arts. 28(3)(f) and 33(2) 25 May 2018
Apply security measures appropriate to the risk GDPR, Art. 32 25 May 2018
Notify cybersecurity incidents (operators of essential services and digital service providers) Royal Decree-law 12/2018 Depending on the case
Notify major ICT-related incidents (financial entities) Regulation (EU) 2022/2554 (DORA) 17 January 2025

So when there is a breach, the clock is ticking: making the right decisions in the first hours avoids penalties and protects the people affected.


What we do when a security breach occurs


First hours

We help you contain the breach and gather the key information: what data, how many people, since when and through which channel.


Risk assessment

We analyse whether the breach poses a risk to people and whether it must be notified, using the AEPD criteria. If you have a data protection officer, we coordinate with them.


Notification to the AEPD

We prepare the notification and file it on your behalf within the deadline. If information is still missing, we complete it in phases, as the GDPR allows.


Communication to those affected

We draft the notice to customers, employees or students when it is mandatory: clear, without causing alarm and with the content required by Article 34. We also prepare the replies to their data subject requests.


Suppliers and processors

If the failure comes from a supplier, we review the data processing agreement and request the information and cooperation it is obliged to provide.


Causes and measures

We identify why it happened, whether human error, phishing, ransomware or unauthorised access, and propose measures to prevent it from happening again.


Breach register

We document every incident in the breach register, including those not notified, as required by Article 33(5) GDPR.


AEPD requests

In addition, if the AEPD requests information or opens proceedings, we prepare the response and the submissions.


What your company gets

Risk assessmentin writing, with the decision on whether to notify and why.

Notification to the AEPDprepared and filed within the deadline.

Notice to those affected when mandatory, ready to send.

Breach register kept up to date to show how the breach was handled.

Root-cause report with the measures to prevent it from happening again.

Breach protocol so your team knows what to do next time.


How we work

We apply our work protocol in four phases to data breaches.


1. Analysis

First, we gather the facts: what data, how many people, since when and whether the breach is still active.


2. Planning

Next, we assess the risk and decide whether to notify the AEPD and inform those affected.


3. Adaptation

Then we file the notification, draft the notices and coordinate the technical measures with your IT team.


4. Success

Finally, we document the incident, close the causes and leave a protocol in place for next time.


Who we work for

  • SMEs that have suffered phishing, ransomware or the theft of a laptop.
  • Companies with sensitive data on health, minors or finances, where the risk to people is higher.
  • Schools with student and family data on platforms and email.
  • Service providers that process their clients’ data as processors and must inform them without undue delay.

Why Auratech

  • Real experience. We are practising data protection officers, so we know what the AEPD checks when it receives a notification.
  • Judgement, not panic. Not every breach must be notified: we tell you when it is necessary and when documenting it is enough.
  • Information security. We also have lawyers certified by AENOR in ISO 27001, the reference standard for managing security incidents.
  • From urgency to prevention. After the breach, we help you prevent it from happening again: measures, training and protocol.

Frequently asked questions

It is any security incident that destroys, loses, alters or exposes personal data, whether due to an attack or an error. For example, an email sent to the wrong recipient, a stolen laptop or ransomware.

No. A breach only needs to be notified when it is likely to result in a risk to people’s rights. However, all breaches must be documented in the breach register (Art. 33(5) GDPR).

From the moment the company becomes aware of the breach, that is, when it has a reasonable degree of certainty that it has occurred. If it cannot gather all the information in time, it can notify in phases.

Only if the breach is likely to result in a high risk to them, for example if health, banking or children’s data have been exposed. There are exceptions, such as the data being encrypted (Art. 34(3) GDPR).

A late notification must explain the reasons for the delay. In addition, failing to notify a breach when required is a GDPR infringement separate from the security failure itself.

The supplier, as processor, must inform you without undue delay, but the decision to notify the AEPD remains with your company. That is why the data processing agreement should set the deadline and content of that notice.


Auratech | Legal Solutions

Contact us!

Fill in the fields