CISSP Security and Risk Management Practice Question
Under the GDPR, a data controller experiences a personal data breach that is likely to result in a risk to the rights and freedoms of individuals. What is the maximum time frame within which the controller must notify the supervisory authority?
⚠ Common exam trap
The trap is conflating the 72-hour supervisory authority notification deadline with the separate 'without undue delay' obligation for notifying data subjects under Article 34, or with shorter breach-notification timelines from other jurisdictions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
72 hours
Article 33 of the GDPR requires that a controller notify the competent supervisory authority of a personal data breach likely to result in a risk to the rights and freedoms of natural persons without undue delay and, where feasible, no later than 72 hours after becoming aware of it. This 72-hour window is the regulatory maximum, and failure to meet it must be accompanied by reasons for the delay. The 72-hour clock starts when the controller becomes aware, not when the breach occurred.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
72 hours
Why this is correct
Under GDPR Article 33(1), a data controller must notify the competent supervisory authority of a personal data breach "without undue delay" and, where feasible, not later than 72 hours after becoming aware of it. This strict timeframe is critical for enabling authorities to assess the breach's impact and advise on necessary mitigation steps promptly. Failure to adhere to this 72-hour deadline without proper justification can lead to significant penalties under the regulation.
- ✗
24 hours
Why it's wrong here
While some sector-specific regulations or national laws, such as certain provisions within HIPAA for healthcare breaches or specific state data breach notification laws, may mandate a 24-hour reporting window, this is not the standard requirement under the General Data Protection Regulation (GDPR). GDPR sets a distinct, slightly longer, but still urgent, timeframe for notifying supervisory authorities. Conflating these different regulatory requirements can lead to non-compliance with GDPR.
- ✗
48 hours
Why it's wrong here
A 48-hour notification period is not explicitly stipulated within the General Data Protection Regulation (GDPR) for reporting personal data breaches to the supervisory authority. While it falls between some shorter and longer regulatory requirements, GDPR specifically mandates notification "without undue delay" and, where feasible, within 72 hours. Relying on a 48-hour window could lead to a missed deadline if awareness occurs early in that period and the 72-hour mark is subsequently breached.
- ✗
7 days
Why it's wrong here
A notification period of seven days for a personal data breach would be considered a significant violation of the General Data Protection Regulation (GDPR) requirements. GDPR explicitly demands notification to the supervisory authority "without undue delay" and within a maximum of 72 hours from discovery. Waiting an entire week would almost certainly be deemed an "undue delay," severely hindering timely intervention and potentially exposing data subjects to prolonged risk, leading to substantial fines.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
GDPR
The General Data Protection Regulation (GDPR) is a European Union law that sets strict rules for how organizations collect, store, process, and protect the personal data of individuals within the EU.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.