Independent comparison · no paid rankings
Home / Blog / Compliance / Data breach: organize host alerts before the 72-hour deadline

Data breach: organize host alerts before the 72-hour deadline

GDPR's 72-hour window leaves no time to improvise who calls whom. Without a contractual alert channel with your host, you start late before understanding the incident.

Hébergeurs.eu Editorial Team 4 min read Updated Jul 19, 2026

Saturday 2 p.m.: the host detects abnormal hypervisor access. An internal tier-3 ticket opens. Your DPO learns Monday morning from a generic "incident resolved" email. You have 36 hours left to analyze, decide, and notify the regulator — with incomplete logs and no shared timeline.

GDPR requires the controller to notify the supervisory authority within 72 hours when a breach poses a risk — unless unlikely. The clock does not start when you feel ready. It starts when you become aware. If your host delays alerting you, you lose time before opening the file.

Who must know what — and when

Three parties are involved:

You (controller). Risk assessment, authority notification, data subject information if high risk, breach register.

Host (processor). Without undue delay notification to you, assistance, containment, evidence preservation.

Possible vendor / integrator. Application access, business logs — often missing from the alert chain.

StepTarget timingOwnerEvidence
Technical detectionH0Host + customer monitoringSIEM alert / ticket
Customer notification≤ 4–24 h (contractual)HostEmail + named contact
Risk assessment≤ 48 hYouDPO note
Authority notification≤ 72 h if requiredYouForm / register

GDPR's 72 hours do not fix a host that informs you after the weekend "to avoid alarm."

What the DPA must contain — before the incident

Negotiate explicitly:

  1. 24/7 incident contact (not sales support only).
  2. Maximum notification deadline to you (e.g. 4 business hours, 12 h off-hours).
  3. Minimum content: nature, discovery date, systems, data types, immediate measures.
  4. Cooperation: logs, disk images, admin access list, account freeze.
  5. No evidence destruction before written agreement.

Ask for the provider's incident notification template. If none exists, that is a signal.

On your side: internal runbook with DPO / CISO / leadership decision tree, authority notification template, list of processing hosted by provider.

Scenarios to table-top once a year

Ransomware on backup. Data exfiltrated? Encryption only? Does the host have hypervisor logs?

Compromised admin account. Who notifies whom? API key revocation — customer or assisted?

Leak via misconfigured bucket. Shared responsibility: host vs you — DPA must clarify zones.

Sub-processor incident. Cascade deadline: require sub-processor → host → you.

A two-hour drill reveals missing phone numbers, "24/7" support time zones, and outdated processing registers.

The climax: learning late is already failing the process

Here is what "enterprise security" pages do not guarantee.

The peak: treat host alert as mandatory coverage — not a support bonus.

Decide and move forward without blind spots

Reread your DPA this week: notification deadline, incident contact, cooperation. Fill gaps or switch hosts — see our directory and compare tool.

Write a one-page runbook: who calls whom, which logs to request in the first hour. Link with Admin audit trail and Data deletion for post-incident phase.

Schedule a table-top before quarter end. Time it.

Frequently asked questions

Must the host notify us of a breach?

Yes if the DPA requires it: deadline, scope, 24/7 contact, minimum information.

Who notifies the regulator — us or the host?

Usually you as controller. Clarify roles before the incident.

72 hours — from when?

From when you become aware — hence the contractual provider deadline.

What if the host discovers the incident before we do?

Require immediate notification, log preservation, and written report — by contract.


GDPR's 72 hours are not bought on incident day — they are contracted on signing day.

HDS & compliance hosts

Filter European hosts by HDS, ISO and data residency.

Browse HDS hosts
Blog

Related reading

All articles →