Article · 14 MIN

When a personal data breach is likely to result in a high risk to individuals’ rights and freedoms

When a personal data breach is likely to result in a high risk to individuals’ rights and freedoms

Article 34 of the GDPR requires the controller to communicate the breach directly to affected individuals.

The notification must not be limited to a generic reassurance message.

It must help affected individuals understand:

  • what happened;
  • what personal data was affected;
  • what risks they face;
  • what the company has done;
  • what they should do next;
  • and who they can contact for more information.

In two January 8, 2026 enforcement decisions against two French telecom operators, the French Data Protection Authority, the CNIL, clarified that a data breach communication can be considered insufficient even when the company sends emails, creates a hotline, and offers a DPO contact channel.

The key lesson is simple:

A breach notification is not a public relations message. It is a risk-reduction tool for affected individuals.

Executive Summary

Data breach communication is one of the most sensitive obligations under the General Data Protection Regulation.

Under Article 34 of the GDPR, when a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller must communicate the breach to the affected individuals without undue delay.

This obligation is separate from the duty to notify the supervisory authority under Article 33 GDPR.

In January 2026, the CNIL issued two major enforcement decisions involving a large-scale cyberattack affecting customer data in the telecommunications sector. The regulator sanctioned the companies not only for security-related issues, but also for the content of the information provided to affected individuals.

The CNIL’s reasoning is particularly important because it explains what companies must actually say to individuals after a data breach.

A company cannot satisfy Article 34 GDPR merely by stating that:

  • an incident occurred;
  • measures were taken;
  • the regulator was notified;
  • and individuals should remain vigilant.

The communication must be concrete enough to help individuals understand the breach and take appropriate protective measures.

Key Legal Rule

What must a company communicate to individuals after a personal data breach?

A company must directly provide affected individuals with clear, useful, and sufficiently specific information enabling them to understand the nature of the data breach, the likely consequences, the remedial measures taken by the company, and the practical steps individuals can take to protect themselves.

This requirement derives from Article 34 GDPR, read together with Article 33(3)(b), (c), and (d) GDPR.

Why Article 34 GDPR Matters

Article 34 GDPR is often misunderstood.

Many organizations treat it as a communication obligation.

In reality, it is a protection obligation.

The purpose of informing individuals is not merely to preserve corporate reputation or show that the company is transparent.

The purpose is to help people reduce the risks created by the breach.

Those risks may include:

  • identity theft;
  • phishing;
  • social engineering;
  • SIM swap attempts;
  • account takeover;
  • banking fraud;
  • fraudulent phone calls;
  • targeted scams;
  • reputational harm;
  • loss of confidentiality;
  • and financial loss.

A notification that does not allow people to understand these risks may fail to meet the GDPR standard.

The CNIL’s January 2026 Decisions: Why They Matter

In two decisions issued on January 8, 2026, the CNIL examined communications sent to affected individuals after a large-scale personal data breach involving telecom customer data.

The companies had implemented several communication channels:

  • an initial email sent to affected individuals;
  • a free hotline available seven days a week;
  • an internal DPO ticketing system;
  • and additional support for individual requests.

At first glance, this may look like a serious response.

The CNIL accepted that the form of the communication was generally appropriate.

However, the regulator found that the content of the communication was insufficient.

This distinction is essential.

The issue was not whether affected individuals had been contacted.

The issue was whether the information they received was concrete enough to help them protect themselves.

The CNIL’s Core Message

The CNIL’s position can be summarized in one sentence:

A controller must not only inform affected individuals that a breach occurred; it must give them actionable information.

A generic statement such as “we have taken all necessary measures” is not enough.

A vague warning such as “be careful about fraudulent emails, SMS messages, or calls” may also be insufficient if it does not explain:

  • the likely scenarios individuals may face;
  • the warning signs they should look for;
  • the specific behaviors they should adopt;
  • and the protective measures recommended in light of the compromised data.

What Information Must Be Included in a GDPR Data Breach Notification to Individuals?

A GDPR-compliant communication to affected individuals should include at least the following categories of information.

1. The Nature of the Breach

The company should explain what happened in clear and simple terms.

Examples:

  • unauthorized access to a customer database;
  • exposure of account information;
  • compromise of a business tool;
  • theft of identification data;
  • accidental disclosure to unauthorized recipients.

The explanation should be understandable to non-technical individuals.

It should not disclose sensitive security details that could create new risks.

2. The Categories of Personal Data Affected

The company should identify the types of personal data involved.

Examples:

  • name;
  • surname;
  • email address;
  • postal address;
  • phone number;
  • date and place of birth;
  • customer identifier;
  • contract data;
  • billing data;
  • IBAN or banking information;
  • login identifiers;
  • identity documents;
  • health data;
  • professional information.

This section is critical because the risk depends heavily on the type of data exposed.

A breach involving only an email address does not create the same level of risk as a breach involving identity data, banking data, or contractual information.

3. The Likely Consequences of the Breach

The company must explain the likely consequences for affected individuals.

This is often the weakest part of breach notifications.

A useful notification should not merely say “there may be a risk of fraud.”

It should explain the concrete scenarios individuals may face.

Examples:

  • phishing emails pretending to come from the company;
  • SMS messages requesting payment or account confirmation;
  • phone calls from fraudsters impersonating customer support;
  • attempts to obtain passwords or verification codes;
  • fraudulent use of identity information;
  • targeted scams using customer data;
  • unauthorized banking solicitations;
  • account takeover attempts.

The objective is not to create panic.

The objective is to make the risk intelligible.

4. The Measures Taken by the Company

The company must describe the measures taken or proposed to address the breach.

This does not mean disclosing sensitive technical details.

The CNIL recognizes that some security measures must remain confidential to avoid exposing the information system to further attacks.

However, not all remedial measures are confidential.

A company can usually describe corrective steps in simple, non-sensitive terms.

Examples:

  • compromised accounts were revoked;
  • access rights were reviewed;
  • vulnerabilities were corrected;
  • monitoring was reinforced;
  • access controls were strengthened;
  • suspicious sessions were terminated;
  • affected systems were isolated;
  • additional authentication controls were deployed;
  • incident response measures were activated;
  • the supervisory authority was notified;
  • a criminal complaint was filed where relevant.

A statement such as “all necessary measures have been taken” is too abstract.

The communication should describe the main categories of corrective measures without compromising security.

5. The Measures Individuals Should Take

The notification should provide practical instructions.

Examples:

  • do not communicate passwords, verification codes, or personal data by phone, email, or SMS;
  • do not click links in suspicious messages;
  • do not open attachments if the sender or context is uncertain;
  • verify the sender’s address before responding;
  • access customer accounts only through official websites or apps;
  • change passwords if account credentials may have been exposed;
  • activate multi-factor authentication where possible;
  • monitor bank accounts if financial data is involved;
  • report suspicious messages to the appropriate authorities or platforms;
  • contact the company through official channels if in doubt.

This is the part of the notification that transforms information into protection.

6. The Contact Point for Additional Information

The communication must provide the name and contact details of the Data Protection Officer or another relevant contact point.

This may include:

  • a DPO email address;
  • a dedicated privacy support address;
  • a hotline;
  • a customer support page;
  • or an incident-specific contact form.

A second-level support channel is useful.

However, the CNIL’s January 2026 decisions show that a second-level channel cannot replace the essential information that must be provided directly in the initial communication.

First-Level and Second-Level Information: The CNIL’s Important Distinction

One of the most useful aspects of the CNIL’s 2026 decisions is the distinction between first-level and second-level information.

First-Level Information

First-level information is the information that must be communicated directly to affected individuals.

It must include the essential elements required by Article 34 GDPR.

This information should be available in the initial breach notification.

It should not require the individual to call a hotline or submit a request.

Second-Level Information

Second-level information includes additional details that individuals may obtain through:

  • a hotline;
  • DPO contact;
  • customer support;
  • FAQ page;
  • help center;
  • or dedicated incident portal.

Second-level information is useful.

It can improve the quality of the response.

However, it cannot compensate for a first-level notification that lacks essential information.

The initial message must be complete enough to allow individuals to understand the breach and take immediate action.

What the CNIL Considered Too Vague

The CNIL criticized communications that included general statements such as:

  • all necessary measures were taken;
  • systems were reinforced;
  • individuals should remain vigilant;
  • there is a risk of fraudulent emails, SMS messages, or calls.

These statements are not necessarily wrong.

The problem is that they may be too general.

The CNIL expects the controller to go one step further.

The company should explain, in simple terms:

  • what kinds of fraud may occur;
  • how fraudsters may contact individuals;
  • what information fraudsters may try to obtain;
  • what individuals should refuse to communicate;
  • what links or attachments they should avoid;
  • and what official channels they should use.

What a Strong GDPR Breach Notification Looks Like

A strong Article 34 GDPR notification is usually structured around six questions:

  1. What happened?
  2. What data was affected?
  3. What risks does this create for me?
  4. What has the company done?
  5. What should I do now?
  6. Who can I contact?

This structure is simple, but it matches the purpose of the GDPR.

It helps individuals move from uncertainty to action.

Sample Structure for a GDPR Data Breach Notification to Individuals

Below is a practical structure companies can adapt.

Subject Line

Important information about a personal data security incident affecting your account

Opening

We are contacting you because a personal data security incident has affected certain information associated with your account.

What Happened

Describe the incident in simple terms.

What Data Was Involved

List the categories of personal data affected.

What Risks This May Create

Explain likely fraud or misuse scenarios.

What We Have Done

Describe key corrective measures without compromising security.

What You Should Do

Provide practical protective steps.

Who to Contact

Provide the DPO or dedicated support contact.

Additional Resources

Provide official resources where relevant.

Compliance Checklist for Article 34 GDPR

A company preparing a breach notification to individuals should verify the following points.

Legal Trigger

  • Has a personal data breach occurred?
  • Is the breach likely to result in a high risk to individuals’ rights and freedoms?
  • Has the supervisory authority been notified under Article 33 GDPR where required?
  • Is communication to individuals required under Article 34 GDPR?

Content of the Notification

  • Does the message describe the nature of the breach?
  • Does it identify the categories of data affected?
  • Does it explain the likely consequences?
  • Does it describe the main remedial measures taken?
  • Does it provide practical recommendations for individuals?
  • Does it provide the DPO or other contact point?

Quality of the Information

  • Is the language clear?
  • Is the message understandable for a non-technical audience?
  • Are the risks concrete rather than abstract?
  • Are the recommendations actionable?
  • Does the message avoid unnecessary technical details?
  • Does it avoid disclosing sensitive security information?

Governance

  • Has the legal team reviewed the notification?
  • Has the DPO validated the Article 34 analysis?
  • Has the cybersecurity team validated the technical accuracy?
  • Has the communications team ensured clarity without minimizing legal risk?
  • Has customer support been briefed?
  • Are hotline scripts consistent with the written notification?
  • Is the notification archived for evidence purposes?

Why Generic Breach Notifications Create Legal Risk

Many organizations try to reduce reputational exposure by keeping breach notifications as general as possible.

This is understandable from a communications perspective.

However, it can create GDPR exposure.

The more generic the notification, the harder it becomes to prove that individuals were actually enabled to protect themselves.

A legally sound breach notification must strike a balance between:

  • not over-disclosing technical security information;
  • not creating unnecessary panic;
  • not minimizing the risk;
  • and not depriving individuals of information they need to act.

This balance is precisely where legal, cybersecurity, DPO, and communications teams must work together.

Governance Lesson: Data Breach Communication Must Be Prepared Before the Breach

The strongest breach communications are rarely improvised.

They are prepared through governance.

Companies should maintain:

  • breach notification templates;
  • incident classification criteria;
  • internal escalation procedures;
  • pre-approved decision trees;
  • DPO and legal review workflows;
  • cybersecurity validation steps;
  • customer support scripts;
  • executive reporting protocols;
  • and post-incident evidence files.

A data breach creates urgency.

Urgency exposes weak governance.

The companies that respond best are not those that write the fastest email.

They are those that already know what information must be gathered, validated, translated, and communicated.

Common Mistakes in Data Breach Notifications

Mistake 1: Treating the Notification as a Reputation Management Exercise

A breach notification should not be written only to reassure.

It must help affected individuals understand and reduce risk.

Mistake 2: Using Abstract Security Language

Statements such as “we reinforced our systems” may be insufficient if they do not describe the type of corrective action taken.

Mistake 3: Under-Explaining the Risk

A message that refers vaguely to “fraudulent emails, SMS messages, or calls” may not be enough.

Individuals need concrete examples and protective instructions.

Mistake 4: Relying Too Much on a Hotline

A hotline can provide additional support.

It cannot replace essential first-level information.

Mistake 5: Failing to Align Internal Scripts With External Notices

If customer support scripts contain more precise risk scenarios than the initial notification, regulators may question why those details were not communicated directly to individuals.

Mistake 6: Sending a Notification Without Preserving Evidence

Companies should document why the notification was sent, what it contained, when it was sent, to whom it was sent, and how internal teams validated its content.

What CEOs and CFOs Should Understand

Data breach notification is not only a legal compliance issue.

It can affect:

  • regulatory exposure;
  • customer trust;
  • litigation risk;
  • insurance coverage;
  • crisis management;
  • public reputation;
  • operational workload;
  • customer support costs;
  • and executive accountability.

For CEOs and CFOs, the key question is not whether the company has a privacy policy.

The key question is whether the company can communicate clearly, quickly, and lawfully when personal data has already been compromised.

That requires preparation before the incident.

What In-House Legal Teams and DPOs Should Do Now

Companies should review their breach response playbooks in light of the CNIL’s January 2026 decisions.

Priority actions include:

  • update Article 34 notification templates;
  • create risk-specific wording libraries;
  • define what remedial measures can be disclosed safely;
  • prepare fraud prevention guidance for affected individuals;
  • ensure DPO contact information is operational;
  • align customer support scripts with legal notices;
  • preserve evidence of notification decisions;
  • run breach communication simulations;
  • and integrate legal review into incident response workflows.

The objective is not to over-communicate.

The objective is to communicate with enough precision to satisfy the GDPR’s protective purpose.

 

Frequently Asked Questions

What is Article 34 GDPR?

Article 34 GDPR requires a controller to communicate a personal data breach to affected individuals when the breach is likely to result in a high risk to their rights and freedoms.

Is notifying the data protection authority enough?

No.

Notification to the supervisory authority under Article 33 GDPR is separate from communication to individuals under Article 34 GDPR.

A company may have to do both.

What is the purpose of informing individuals after a data breach?

The purpose is to help individuals understand the breach and take steps to protect themselves.

The communication must be useful, concrete, and understandable.

Does a company have to disclose all cybersecurity measures taken?

No.

A company does not have to disclose sensitive technical details that could compromise security.

However, it should describe the main categories of remedial measures in simple terms when doing so does not create additional security risk.

Can a company rely on a hotline instead of putting all information in the initial email?

No.

A hotline can provide additional support, but essential information must be included in the first-level communication sent directly to affected individuals.

What are examples of practical recommendations for individuals?

Examples include not clicking suspicious links, not opening unexpected attachments, not sharing passwords or verification codes, verifying official communication channels, monitoring accounts, and reporting suspicious messages.

What makes a breach notification too vague?

A notification may be too vague if it merely states that an incident occurred, that measures were taken, and that individuals should remain vigilant, without explaining concrete risks and protective steps.

Should the notification mention phishing risks?

Yes, where relevant.

However, mentioning phishing in general terms may not be enough.

The communication should explain how the phishing attempts may occur and what behaviors individuals should adopt.

Who should validate a data breach notification before it is sent?

At minimum, the DPO, legal team, cybersecurity team, and communications team should coordinate before sending the notification.

Customer support should also be briefed before individuals start responding.

Why are the CNIL’s January 2026 decisions important?

They clarify that the content of breach communications matters as much as the fact of communication itself.

A company can send emails, create a hotline, and offer DPO support while still failing to meet Article 34 GDPR if the initial information is too general.

Primary Legal Sources