Courseiva
Reporting and Communication →mediumMultiple Choice

CS0-003 Reporting and Communication Practice Question

Which compliance reporting requirement under GDPR mandates that organizations notify the relevant supervisory authority within a specific timeframe after becoming aware of a personal data breach?

⚠ Common exam trap

CS0-004 often tests specific regulatory timeframes, so candidates who confuse GDPR's 72-hour rule with shorter windows from other breach notification laws (e.g., 24 hours) or internal SLAs pick the wrong answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

72 hours

Under GDPR Article 33, organizations must notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to data subjects' rights and freedoms. This 72-hour window is a core GDPR compliance requirement. The other timeframes do not match the regulation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    72 hours

    Why this is correct

    GDPR Article 33(1) sets a hard, maximum deadline of 72 hours after the controller becomes aware of a personal data breach for notifying the supervisory authority, unless the breach is unlikely to result in a risk to individuals' rights and freedoms. The obligation is phrased as 'without undue delay and, where feasible, not later than 72 hours,' meaning 72 hours is the outer statutory limit, not a target. If notification is made after 72 hours, the controller must provide the reasons for the delay under Article 33(5). Thus, 72 hours is the correct and canonical compliance reporting requirement.

  • ✗

    7 days

    Why it's wrong here

    A seven-day window is not found anywhere in the GDPR for breach notification; it may be confused with contractually agreed reporting timelines or with other frameworks like the PCI DSS's requirement to notify an acquirer, but the GDPR's regulatory deadline is strictly 72 hours. Unlike some industry standards that allow weekly or monthly reporting, Article 33 tightens the timeframe for supervisory authorities, so any reply of '7 days' would be factually incorrect and dangerous for a compliance professional to rely on. The only extension allowed is a justified delay notification with reasons, not a blanket seven-day limit.

  • ✗

    24 hours

    Why it's wrong here

    The 24-hour figure is characteristic of the NIS Directive (and some state data breach statutes like California's amended CCPA/CPRA) for different types of incidents, but not for GDPR personal data breach reporting. GDPR Article 33 expressly provides 72 hours, not 24, and a controller that waits only 24 is still meeting the deadline, but 24 is not a requirement; thus it is an incorrect answer. Confusing the NIS 2 Directive's 24-hour 'early warning' with GDPR's 72-hour breach notification is a common error because both are EU-related cybersecurity frameworks.

  • ✗

    48 hours

    Why it's wrong here

    Though some incident-reporting regimes like the EU's NIS 2 Directive and certain state laws use shorter deadlines, GDPR Article 33(1) explicitly requires personal data breach notification to the relevant supervisory authority within 72 hours of becoming aware. 48 hours is not a GDPR threshold and picking it would misstate the legal maximum; a controller that acts at 48 hours is compliant, but the regulation itself never specifies this shorter window, so it is incorrect for a GDPR compliance-reporting requirement.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.