CS0-003 Reporting and Communication Practice Question
An organization needs to report a data breach involving personal data of EU residents. Under GDPR, what is the maximum time allowed for notifying the supervisory authority after becoming aware of the breach?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
72 hours
GDPR Article 33 requires notification within 72 hours of becoming aware of a personal data breach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
48 hours
Why it's wrong here
The 48-hour window is a common misunderstanding because some U.S. state breach notification laws (e.g., California's amended law) require reporting to the state attorney general within 45 days, and certain sectoral rules like the NYDFS Cybersecurity Regulation require 72 hours for ransomware, but 48 hours is not the GDPR standard. GDPR Article 33 explicitly states "not later than 72 hours," making 48 hours incorrect even though it is stricter; regulators do not penalize earlier notification, but the legal safe harbor is 72 hours.
- ✗
7 days
Why it's wrong here
A 7-day reporting period is not compliant with the GDPR. While some internal incident response plans or third-party contracts may stipulate a 7-day window for preliminary reports, Article 33 of the GDPR requires notification to the supervisory authority "without undue delay and, where feasible, not later than 72 hours." The regulation imposes a hard outer limit of 72 hours only if feasible; if a controller delays to 7 days, it would already be in violation unless it documented reasons for the delay, but that documentation cannot extend the deadline to a full week.
- ✗
24 hours
Why it's wrong here
A 24-hour deadline is more stringent than the GDPR requires and is therefore not the correct legal threshold. The GDPR deliberately chose 72 hours to allow organizations time to conduct an initial assessment of the breach's scope, severity, and risk to data subjects. Requiring notification within 24 hours would often force organizations to report with incomplete information, potentially leading to inaccurate breach reports. Some other frameworks (like certain critical infrastructure reporting rules) use 24 hours, but for GDPR, the correct legal default is 72 hours.
- ✓
72 hours
Why this is correct
GDPR Article 33(1) mandates that a data controller notify the relevant supervisory authority of a personal data breach "without undue delay and, where feasible, not later than 72 hours" after becoming aware of it. This 72-hour window is the exact compliance threshold explicitly written into the regulation, and failing to meet it without documented justification is a violation. The notification must include the nature of the breach, the categories and approximate number of data subjects and records involved, the likely consequences, and the measures taken or proposed to mitigate harm.
Go deeper
Related to this question
About these practice questions
One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.