Courseiva
Reporting and Communication →mediumMultiple Choice

CS0-003 Reporting and Communication Practice Question

A company experiences a data breach involving personal data of EU citizens. Under GDPR, what is the maximum time frame to notify the supervisory authority?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

72 hours

GDPR Article 33 requires notification within 72 hours of becoming aware of a breach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    7 days

    Why it's wrong here

    A seven-day window significantly exceeds the strict timeline mandated by the General Data Protection Regulation (GDPR) for reporting data breaches. While some national frameworks or non-EU regulations allow for longer reporting periods, relying on a one-week threshold would place an organization in direct non-compliance with European standards, potentially resulting in severe administrative fines.

  • ✗

    24 hours

    Why it's wrong here

    Although a 24-hour reporting window is enforced by certain sector-specific regulations, such as those governing critical infrastructure or specific telecommunications providers, it is not the standard baseline for GDPR compliance. Attempting to meet this ultra-short deadline globally may lead to incomplete forensic investigations and inaccurate initial reports to supervisory authorities.

  • ✗

    48 hours

    Why it's wrong here

    A 48-hour notification period is incorrect because it does not align with the standard regulatory timeline established by the European Union. While some internal corporate incident response plans target a 48-hour window to allow for internal review before the official regulatory deadline, it is not the legally mandated timeframe under GDPR Article 33.

  • ✓

    72 hours

    Why this is correct

    Under Article 33 of the GDPR, organizations must notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If the notification is delayed beyond this window, the controller must provide a reasoned justification for the delay.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.