Courseiva
Security and Risk ManagementhardMultiple ChoiceObjective-mapped

CISSP Security and Risk Management Practice Question

Under the GDPR, a data controller experiences a personal data breach that is likely to result in a risk to the rights and freedoms of individuals. What is the maximum time frame within which the controller must notify the supervisory authority?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

72 hours

GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to rights and freedoms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • 72 hours

    Why this is correct

    Under GDPR Article 33(1), a data controller must notify the competent supervisory authority of a personal data breach "without undue delay" and, where feasible, not later than 72 hours after becoming aware of it. This strict timeframe is critical for enabling authorities to assess the breach's impact and advise on necessary mitigation steps promptly. Failure to adhere to this 72-hour deadline without proper justification can lead to significant penalties under the regulation.

  • 24 hours

    Why it's wrong here

    While some sector-specific regulations or national laws, such as certain provisions within HIPAA for healthcare breaches or specific state data breach notification laws, may mandate a 24-hour reporting window, this is not the standard requirement under the General Data Protection Regulation (GDPR). GDPR sets a distinct, slightly longer, but still urgent, timeframe for notifying supervisory authorities. Conflating these different regulatory requirements can lead to non-compliance with GDPR.

  • 48 hours

    Why it's wrong here

    A 48-hour notification period is not explicitly stipulated within the General Data Protection Regulation (GDPR) for reporting personal data breaches to the supervisory authority. While it falls between some shorter and longer regulatory requirements, GDPR specifically mandates notification "without undue delay" and, where feasible, within 72 hours. Relying on a 48-hour window could lead to a missed deadline if awareness occurs early in that period and the 72-hour mark is subsequently breached.

  • 7 days

    Why it's wrong here

    A notification period of seven days for a personal data breach would be considered a significant violation of the General Data Protection Regulation (GDPR) requirements. GDPR explicitly demands notification to the supervisory authority "without undue delay" and within a maximum of 72 hours from discovery. Waiting an entire week would almost certainly be deemed an "undue delay," severely hindering timely intervention and potentially exposing data subjects to prolonged risk, leading to substantial fines.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.