CISSP Security and Risk Management Practice Question
Under the GDPR, a data controller experiences a personal data breach that is likely to result in a risk to the rights and freedoms of individuals. What is the maximum time frame within which the controller must notify the supervisory authority?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to rights and freedoms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
72 hours
Why this is correct
Under GDPR Article 33(1), a data controller must notify the competent supervisory authority of a personal data breach "without undue delay" and, where feasible, not later than 72 hours after becoming aware of it. This strict timeframe is critical for enabling authorities to assess the breach's impact and advise on necessary mitigation steps promptly. Failure to adhere to this 72-hour deadline without proper justification can lead to significant penalties under the regulation.
- ✗
24 hours
Why it's wrong here
While some sector-specific regulations or national laws, such as certain provisions within HIPAA for healthcare breaches or specific state data breach notification laws, may mandate a 24-hour reporting window, this is not the standard requirement under the General Data Protection Regulation (GDPR). GDPR sets a distinct, slightly longer, but still urgent, timeframe for notifying supervisory authorities. Conflating these different regulatory requirements can lead to non-compliance with GDPR.
- ✗
48 hours
Why it's wrong here
A 48-hour notification period is not explicitly stipulated within the General Data Protection Regulation (GDPR) for reporting personal data breaches to the supervisory authority. While it falls between some shorter and longer regulatory requirements, GDPR specifically mandates notification "without undue delay" and, where feasible, within 72 hours. Relying on a 48-hour window could lead to a missed deadline if awareness occurs early in that period and the 72-hour mark is subsequently breached.
- ✗
7 days
Why it's wrong here
A notification period of seven days for a personal data breach would be considered a significant violation of the General Data Protection Regulation (GDPR) requirements. GDPR explicitly demands notification to the supervisory authority "without undue delay" and within a maximum of 72 hours from discovery. Waiting an entire week would almost certainly be deemed an "undue delay," severely hindering timely intervention and potentially exposing data subjects to prolonged risk, leading to substantial fines.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Data controller
An entity that determines the purposes and means of processing personal data.
Key term
GDPR
The General Data Protection Regulation (GDPR) is a European Union law that sets strict rules for how organizations collect, store, process, and protect the personal data of individuals within the EU.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.