The classic trap
Recital 87 clarifies Article 33: the CNPD does not only sanction late notification, it primarily sanctions the inability to detect the breach. When an organisation discovers a leak three months later through an unhappy customer or a journalist, this proves that detection measures were inadequate. The CNIL has publicly reminded that the 72-hour clock runs from the moment the breach should have been detected with reasonable means, not from actual discovery.
The detectability test: what the CNPD actually checks
During a post-incident audit, the authority reconstructs the full timeline and systematically asks:
- Do you have a SIEM or EDR logging abnormal access to personal data?
- Are logs retained long enough to reconstruct the incident (minimum 6 months recommended)?
- Is there a documented procedure to qualify a security event as a GDPR breach, with a target deadline?
- Do IT teams and the DPO have a clear escalation channel, tested at least once a year?
- Can you demonstrate the exact date and time of awareness, not a vague range?
- Are your processors contractually required to notify you within 24h (Article 33(2)) and do they comply in practice?
If a single brick is missing, recital 87 turns against you: late notification becomes an aggravating circumstance, not an excuse.
How Luxgap automates this risk
Our Luxgap Breach Detection Clock makes the scenario of a late-discovered breach impossible. The tool connects an AI agent to your telemetry sources (Microsoft Defender, Azure Sentinel, CrowdStrike, Wazuh, M365 Audit Log, AWS CloudTrail, Active Directory) and qualifies each security event as a potential GDPR incident in real time, triggering a cryptographically timestamped 72-hour clock at the first relevant alert.
- Automatically detects abnormal exfiltrations (volume, timing, cloud destinations) across M365 and Azure environments without manual rule configuration.
- Classifies each alert against the EDPB 9/2022 grid (confidentiality, integrity, availability) and proposes a preliminary qualification in under 5 minutes.
- Starts a blockchain-sealed 72-hour clock from awareness, opposable to the CNPD to demonstrate Article 33 diligence.
- Alerts the DPO and CISO via Teams or Slack with a prefilled incident file (nature, data categories, estimated volume, containment measures).
- Generates the draft CNPD notification in the format expected by the Luxembourg portal, ready to validate in a 30-minute session.
- Produces a timestamped PDF report demonstrating the full detection-qualification-notification chain, opposable during an audit.
Available as part of a Luxgap DPO or CISO mandate or as a standalone SaaS module depending on your scope. Request your demonstration and our teams connect the tool to your real sources within 48h to measure your current detection time before any engagement.