CISSP Security and Risk Management Practice Question
Under the GDPR, what is the maximum time frame for notifying the supervisory authority of a personal data breach?
⚠ Common exam trap
The trap is mixing up the 72-hour supervisory authority notification with the 'without undue delay' data subject notification, or recalling a different regulation's timeline (e.g., 24 or 48 hours) and selecting it under pressure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
72 hours
Article 33 of the GDPR requires that, in the case of a personal data breach, the controller notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of the breach. This 72-hour window is the maximum time frame specified by the regulation. If notification is not made within 72 hours, it must be accompanied by reasons for the delay.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
72 hours
Why this is correct
Article 33(1) of the GDPR requires data controllers to notify the competent supervisory authority "without undue delay and, where feasible, not later than 72 hours after having become aware of it." This timeframe applies specifically when the personal data breach is likely to result in a risk to the rights and freedoms of natural persons, ensuring prompt action to mitigate potential harm and facilitate regulatory oversight.
- ✗
7 days
Why it's wrong here
A notification period of 7 days (168 hours) significantly exceeds the strict 72-hour deadline stipulated by Article 33(1) of the GDPR for reporting personal data breaches to the relevant supervisory authority. Such a prolonged delay would almost certainly be considered "undue delay" and could lead to severe non-compliance penalties, as prompt notification is crucial for mitigating potential harm to data subjects and demonstrating accountability.
- ✗
24 hours
Why it's wrong here
While some sector-specific regulations or national laws, particularly in critical infrastructure or financial services, may impose a more stringent 24-hour breach notification requirement, the General Data Protection Regulation (GDPR) specifically sets the standard timeframe at 72 hours. Adhering to a 24-hour window for GDPR purposes would exceed the regulatory minimum but is not the mandated period, making it an incorrect answer for this specific regulation.
- ✗
48 hours
Why it's wrong here
A 48-hour notification period, while seemingly prompt, does not align with the explicit requirements of the General Data Protection Regulation (GDPR) regarding personal data breach reporting. Article 33(1) clearly specifies a maximum of 72 hours for notifying the supervisory authority, making 48 hours an arbitrary and incorrect duration in this specific regulatory context and potentially leading to non-compliance if relied upon as the definitive timeframe.
Go deeper
Related to this question
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.