Dashboard
1 · Notification
2 · Controller
3 · Breach facts
4 · Risk & measures
5 · Communication
6 · Cross-border
7 · Output
Your data stays in your browser. Stored in localStorage on this device only — nothing is sent to a server.
EDPB Common Template (v1.0, adopted 8 June 2026) — This form implements the European Data Protection Board's common template for personal data breach notification under GDPR Art. 33. Public consultation closes 5 Aug 2026. Fields and structure follow the official template; the ENISA severity methodology is retained as a supplementary risk-scoring tool.

§1 — Information on the notification

EDPB Template §1 · Type, sub-type, and reference numbers

1.1 Type of notification

§2 — Controller & reporting person

EDPB Template §2 · Identification, DPO, involved parties

2.1 About the data controller
2.2 Identity of the reporting person
2.3 DPO & contact point
2.4 Involvement of other parties

§3 — Initial information on the breach

EDPB Template §3 · Timeline, nature, data subjects, data records, measures in place

3.1 Timeline
3.2 Nature & circumstances of the breach

Nature of the breach * (select all that apply)

3.3 Categories & number of data subjects
3.4 Categories & number of personal data records
3.5 Measures in place when the breach occurred

§4 — Risk assessment & measures

EDPB Template §4 · Consequences, risk, mitigation, prevention

4.1 Likely consequences & adverse effects

Nature of potential impact for data subjects * (select all)

4.2 Risk assessment (EDPB) + ENISA severity scoring

ENISA-style severity scoring (supplementary)

This supplementary scoring uses the ENISA methodology to compute a numerical severity. It supports — but does not replace — the controller's own risk assessment above.

4.3 Measures taken to address the breach
4.4 Measures to prevent similar breaches

§5 — Communication to data subjects

EDPB Template §5 · Art. 34 obligations

Communication status

§6 — Cross-border & other authorities

EDPB Template §6 · Police/judicial, other SAs, cross-border processing

6.1 Other authorities notified
6.2 Cross-border processing (EEA-established controller)
6.3 Processing at non-EEA establishments

§7 — Output & generated documents

Severity verdict, obligations, generated notification letters, and attachments

Severity verdict
Press Assess (toolbar) after completing Sections 3–4.
Obligations under GDPR
Computed from severity, risk assessment, and sensitivity flags.
SA notification letter (Art. 33)
Press Assess to generate.
Data subject communication (Art. 34)
Generated when severity is High/Critical or risk assessment indicates high risk.
7 · Attachments