Courseiva
Reporting and CommunicationhardMultiple ChoiceObjective-mapped

CS0-003 Reporting and Communication Practice Question

An organization needs to report a data breach involving personal data of EU residents. Under GDPR, what is the maximum time allowed for notifying the supervisory authority after becoming aware of the breach?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

72 hours

GDPR Article 33 requires notification within 72 hours of becoming aware of a personal data breach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • 48 hours

    Why it's wrong here

    The 48-hour window is a common misunderstanding because some U.S. state breach notification laws (e.g., California's amended law) require reporting to the state attorney general within 45 days, and certain sectoral rules like the NYDFS Cybersecurity Regulation require 72 hours for ransomware, but 48 hours is not the GDPR standard. GDPR Article 33 explicitly states "not later than 72 hours," making 48 hours incorrect even though it is stricter; regulators do not penalize earlier notification, but the legal safe harbor is 72 hours.

  • 7 days

    Why it's wrong here

    A 7-day reporting period is not compliant with the GDPR. While some internal incident response plans or third-party contracts may stipulate a 7-day window for preliminary reports, Article 33 of the GDPR requires notification to the supervisory authority "without undue delay and, where feasible, not later than 72 hours." The regulation imposes a hard outer limit of 72 hours only if feasible; if a controller delays to 7 days, it would already be in violation unless it documented reasons for the delay, but that documentation cannot extend the deadline to a full week.

  • 24 hours

    Why it's wrong here

    A 24-hour deadline is more stringent than the GDPR requires and is therefore not the correct legal threshold. The GDPR deliberately chose 72 hours to allow organizations time to conduct an initial assessment of the breach's scope, severity, and risk to data subjects. Requiring notification within 24 hours would often force organizations to report with incomplete information, potentially leading to inaccurate breach reports. Some other frameworks (like certain critical infrastructure reporting rules) use 24 hours, but for GDPR, the correct legal default is 72 hours.

  • 72 hours

    Why this is correct

    GDPR Article 33(1) mandates that a data controller notify the relevant supervisory authority of a personal data breach "without undue delay and, where feasible, not later than 72 hours" after becoming aware of it. This 72-hour window is the exact compliance threshold explicitly written into the regulation, and failing to meet it without documented justification is a violation. The notification must include the nature of the breach, the categories and approximate number of data subjects and records involved, the likely consequences, and the measures taken or proposed to mitigate harm.

About these practice questions

One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.