CS0-003 Reporting and Communication Practice Question
A company experiences a data breach involving personal data of EU citizens. Under GDPR, what is the maximum time frame to notify the supervisory authority?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
72 hours
GDPR Article 33 requires notification within 72 hours of becoming aware of a breach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
7 days
Why it's wrong here
A seven-day window significantly exceeds the strict timeline mandated by the General Data Protection Regulation (GDPR) for reporting data breaches. While some national frameworks or non-EU regulations allow for longer reporting periods, relying on a one-week threshold would place an organization in direct non-compliance with European standards, potentially resulting in severe administrative fines.
- ✗
24 hours
Why it's wrong here
Although a 24-hour reporting window is enforced by certain sector-specific regulations, such as those governing critical infrastructure or specific telecommunications providers, it is not the standard baseline for GDPR compliance. Attempting to meet this ultra-short deadline globally may lead to incomplete forensic investigations and inaccurate initial reports to supervisory authorities.
- ✗
48 hours
Why it's wrong here
A 48-hour notification period is incorrect because it does not align with the standard regulatory timeline established by the European Union. While some internal corporate incident response plans target a 48-hour window to allow for internal review before the official regulatory deadline, it is not the legally mandated timeframe under GDPR Article 33.
- ✓
72 hours
Why this is correct
Under Article 33 of the GDPR, organizations must notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If the notification is delayed beyond this window, the controller must provide a reasoned justification for the delay.
Go deeper
Related to this question
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.