Saturday 2 p.m.: the host detects abnormal hypervisor access. An internal tier-3 ticket opens. Your DPO learns Monday morning from a generic "incident resolved" email. You have 36 hours left to analyze, decide, and notify the regulator — with incomplete logs and no shared timeline.
GDPR requires the controller to notify the supervisory authority within 72 hours when a breach poses a risk — unless unlikely. The clock does not start when you feel ready. It starts when you become aware. If your host delays alerting you, you lose time before opening the file.
Who must know what — and when
Three parties are involved:
You (controller). Risk assessment, authority notification, data subject information if high risk, breach register.
Host (processor). Without undue delay notification to you, assistance, containment, evidence preservation.
Possible vendor / integrator. Application access, business logs — often missing from the alert chain.
| Step | Target timing | Owner | Evidence |
|---|---|---|---|
| Technical detection | H0 | Host + customer monitoring | SIEM alert / ticket |
| Customer notification | ≤ 4–24 h (contractual) | Host | Email + named contact |
| Risk assessment | ≤ 48 h | You | DPO note |
| Authority notification | ≤ 72 h if required | You | Form / register |
GDPR's 72 hours do not fix a host that informs you after the weekend "to avoid alarm."
What the DPA must contain — before the incident
Negotiate explicitly:
- 24/7 incident contact (not sales support only).
- Maximum notification deadline to you (e.g. 4 business hours, 12 h off-hours).
- Minimum content: nature, discovery date, systems, data types, immediate measures.
- Cooperation: logs, disk images, admin access list, account freeze.
- No evidence destruction before written agreement.
Ask for the provider's incident notification template. If none exists, that is a signal.
On your side: internal runbook with DPO / CISO / leadership decision tree, authority notification template, list of processing hosted by provider.
Scenarios to table-top once a year
Ransomware on backup. Data exfiltrated? Encryption only? Does the host have hypervisor logs?
Compromised admin account. Who notifies whom? API key revocation — customer or assisted?
Leak via misconfigured bucket. Shared responsibility: host vs you — DPA must clarify zones.
Sub-processor incident. Cascade deadline: require sub-processor → host → you.
A two-hour drill reveals missing phone numbers, "24/7" support time zones, and outdated processing registers.
The climax: learning late is already failing the process
Here is what "enterprise security" pages do not guarantee.
The peak: treat host alert as mandatory coverage — not a support bonus.
Decide and move forward without blind spots
Reread your DPA this week: notification deadline, incident contact, cooperation. Fill gaps or switch hosts — see our directory and compare tool.
Write a one-page runbook: who calls whom, which logs to request in the first hour. Link with Admin audit trail and Data deletion for post-incident phase.
Schedule a table-top before quarter end. Time it.
Frequently asked questions
Must the host notify us of a breach?
Yes if the DPA requires it: deadline, scope, 24/7 contact, minimum information.
Who notifies the regulator — us or the host?
Usually you as controller. Clarify roles before the incident.
72 hours — from when?
From when you become aware — hence the contractual provider deadline.
What if the host discovers the incident before we do?
Require immediate notification, log preservation, and written report — by contract.
GDPR's 72 hours are not bought on incident day — they are contracted on signing day.
