Courseiva
Reporting and CommunicationmediumMultiple ChoiceObjective-mapped

CS0-003 Reporting and Communication Practice Question

Which compliance reporting requirement under GDPR mandates that organizations notify the relevant supervisory authority within a specific timeframe after becoming aware of a personal data breach?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

72 hours

GDPR Article 33 requires notification to the supervisory authority within 72 hours of awareness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • 72 hours

    Why this is correct

    GDPR Article 33(1) sets a hard, maximum deadline of 72 hours after the controller becomes aware of a personal data breach for notifying the supervisory authority, unless the breach is unlikely to result in a risk to individuals' rights and freedoms. The obligation is phrased as 'without undue delay and, where feasible, not later than 72 hours,' meaning 72 hours is the outer statutory limit, not a target. If notification is made after 72 hours, the controller must provide the reasons for the delay under Article 33(5). Thus, 72 hours is the correct and canonical compliance reporting requirement.

  • 7 days

    Why it's wrong here

    A seven-day window is not found anywhere in the GDPR for breach notification; it may be confused with contractually agreed reporting timelines or with other frameworks like the PCI DSS's requirement to notify an acquirer, but the GDPR's regulatory deadline is strictly 72 hours. Unlike some industry standards that allow weekly or monthly reporting, Article 33 tightens the timeframe for supervisory authorities, so any reply of '7 days' would be factually incorrect and dangerous for a compliance professional to rely on. The only extension allowed is a justified delay notification with reasons, not a blanket seven-day limit.

  • 24 hours

    Why it's wrong here

    The 24-hour figure is characteristic of the NIS Directive (and some state data breach statutes like California's amended CCPA/CPRA) for different types of incidents, but not for GDPR personal data breach reporting. GDPR Article 33 expressly provides 72 hours, not 24, and a controller that waits only 24 is still meeting the deadline, but 24 is not a requirement; thus it is an incorrect answer. Confusing the NIS 2 Directive's 24-hour 'early warning' with GDPR's 72-hour breach notification is a common error because both are EU-related cybersecurity frameworks.

  • 48 hours

    Why it's wrong here

    Though some incident-reporting regimes like the EU's NIS 2 Directive and certain state laws use shorter deadlines, GDPR Article 33(1) explicitly requires personal data breach notification to the relevant supervisory authority within 72 hours of becoming aware. 48 hours is not a GDPR threshold and picking it would misstate the legal maximum; a controller that acts at 48 hours is compliant, but the regulation itself never specifies this shorter window, so it is incorrect for a GDPR compliance-reporting requirement.

About these practice questions

One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.