Crisis Communication During Cyberattacks – Part 3 of 3: Data Breach After a Cyberattack: Crisis Communication and Notification of Affected Individuals
There is a point in a cyber crisis when the situation fundamentally changes: when it becomes clear that data has not only been encrypted, but has also been exfiltrated or disclosed without authorization. Until then, the organization is primarily the victim of a crime. From that point on, it must also address the individuals whose data has been affected and who now face risks of their own.
Why a Data Breach Changes the Crisis
Four shifts make communication particularly challenging at this stage.
A new target group emerges. Affected individuals are not necessarily customers. They may include employees, former employees, job applicants, supplier contacts, contacts at customer organizations, or other individuals. Their primary concern is not when systems will be restored, but rather: What data has been affected, what risks does this create for me, and what should I do now?
The timing is partly determined by external factors. Legal deadlines may dictate the communication schedule. In addition, attackers may increase the pressure by publishing stolen data.
The news often comes as a second wave. Evidence of data exfiltration may not emerge immediately from the forensic investigation. Organizations that provided reassurance too early may now have to correct previous statements – and such corrections can be perceived as an attempt to downplay or conceal the situation.
Careless communication can encourage unwarranted compensation claims. Affected individuals may also become potential claimants seeking damages or compensation for non-material harm; in some cases, such claims may be unfounded or disproportionate. Communication therefore needs to strike a careful balance between transparency, understanding and empathy for the concerns of those affected, while avoiding language that could be interpreted as an admission of liability.
The Legal Framework: Guidance, Not Legal Advice
In the event of a personal data breach, the timing, nature, and scope of communication are partly determined by legal obligations. The following overview is intended as guidance for communication planning. Any assessment of an individual case must be coordinated with the organization’s data protection officer and legal counsel.
Art. 33 GDPR – Notification to the supervisory authority: The controller must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it can be established that the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The risk assessment depends on the circumstances of the individual case, including the nature, sensitivity, and volume of the data involved and the potential consequences.
Art. 34 GDPR – Communication to affected individuals: If the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, affected individuals must be informed without undue delay. The communication must be provided in clear and plain language and include, among other things, the nature of the breach, its likely consequences, the measures taken, and a contact point. This obligation is not limited to affected individuals in Germany but applies throughout the EU.
Sector-specific regulations: Depending on the industry and size of the organization, additional notification and reporting requirements may apply, including DORA in the financial sector, NIS2 and the German BSI Act (BSIG) for important and particularly important entities, or the Cyber Resilience Act for manufacturers of digitally connected products. Some of these frameworks impose even shorter deadlines for initial notifications, including deadlines of 24 hours in certain cases, for example under the BSIG and DORA. Multiple obligations should be brought together in an integrated notification and communication process.
Public communication as an alternative: Under certain conditions, Art. 34 GDPR allows for a public communication or similarly effective measure where individual notification would involve disproportionate effort.
Individuals not affected and the wider public: Art. 34 GDPR does not generally require individuals who can demonstrably be shown not to have been affected to be notified. Other statutory, contractual, or regulatory obligations may nevertheless apply. From a communication perspective, addressing this group can still be useful. Regardless of a specific incident, individuals have a statutory right of access to their personal data, and publicly known data breaches are likely to result in an increase in inquiries from customers seeking to establish whether their data has been affected.
Extortion: A ransom demand does not automatically need to be included in communications to affected individuals. Whether and how it is addressed externally should be decided based on the specific circumstances and in coordination with the relevant teams. From a strategic communications perspective, ransom demands are generally not disclosed.
Contractual notification obligations within the supply chain: Organizations affected by a cyberattack are typically part of a wider supply chain and may have contractual commitments to customers requiring them to provide notification of incidents involving both personal data – for example under data processing agreements – and other confidential information, such as information protected by NDAs or trade secret provisions. Because customers may have their own statutory reporting obligations, these contractual notification deadlines can be even shorter than those imposed by law. Suppliers must also be informed in good time if, for example, the affected organization is unable to accept deliveries because its IT systems have been disrupted or sabotaged, potentially resulting in losses arising from delayed acceptance. In these contractual relationships with customers and suppliers in particular, there is a risk of claims for damages if communications create the impression that the organization was at fault for the attack – for example due to inadequate security measures, missing backups, or systems that had not been kept up to date.
The Five Questions Affected Individuals Need Answered
Communications to affected individuals are almost always subject to legal review, yet they still regularly fail to meet one simple requirement: recipients cannot understand them quickly enough. Affected individuals have five questions that any notification must answer clearly and unambiguously:
Am I affected?
Which of my data has been affected?
How could someone misuse this data?
What exactly should I do now to protect myself from harm?
Who can I contact if I have questions?
Six Principles for Communicating with Affected Individuals
Be specific, not vague. Clearly identify the categories of data affected. Where this can be established with confidence, it is equally important to state which sensitive data has not been affected. This helps limit unnecessary concern.
Provide practical guidance rather than reassurance. Affected individuals need specific steps they can take, not general assurances. This includes explaining potential consequences such as identity theft, phishing, or social engineering and what they should look out for in their particular situation. Providing specific sources of support – for example, by directing people to guidance from the German Federal Office for Information Security (BSI) – helps ensure that affected individuals are not left to deal with the situation on their own.
Commit to clear sender-verification rules. A clear commitment that the organization will never contact individuals unexpectedly to ask for passwords, login credentials, or bank account information can help protect against follow-up attacks.
Provide genuinely accessible contact options. Any designated point of contact must have sufficient capacity to handle inquiries. A hotline that cannot be reached or an inbox that does not provide timely responses will only exacerbate the crisis.
Express regret without prejudging the cause. An organization can express regret about the impact of the incident and take responsibility for investigating it without prejudging a cause that has not yet been established or implying liability or fault.
Inform affected individuals before they hear it from other sources whenever possible. An additional loss of trust occurs when people learn from the media or third parties that their data has been published.
Individuals Not Affected: No GDPR Notification Requirement, but Still a Communication Decision
Art. 34 GDPR does not generally require organizations to notify individuals who can demonstrably be shown not to have been affected. However, this does not automatically mean that remaining silent is the right communication strategy. Once an incident becomes public knowledge, uncertainty can also arise among customers whose data has not been affected.
Reports of a data breach often lead to an increase in access requests under Art. 15 GDPR from individuals wanting to know what personal data is being processed about them. These requests generally have to be answered within one month. This can become a significant challenge during a data breach, when information and systems may be unavailable or only partially accessible. In such circumstances, providing reliable reassurance to individuals who have not been affected can be useful – provided that the statement will stand up to further investigation and that no other notification obligations prevent it.
There is also a broader dynamic that can turn a crisis into a scandal: consequences for third parties, an identifiable question of responsibility, and stakeholders who amplify the issue, such as consumer protection organizations, supervisory authorities, or specialist law firms. Whether communication with individuals who have not been affected is appropriate must therefore always be carefully assessed and decided on a case-by-case basis.
Communication with Affected Individuals Is Where Trust Is Won or Lost
A data breach is often the point that determines how a cyber crisis will ultimately be remembered. Statutory notification requirements define the timing and minimum information that must be provided. From a communication perspective, however, meeting these minimum requirements is not enough.
What matters is whether affected individuals can quickly understand what has affected them, what has not, what risks this creates, and what they can do to protect themselves. Equally important are the organization’s attitude, its accessibility, and the way it continues to engage with affected individuals as the situation develops.
Frequently Asked Questions About Crisis Communication in the Event of a Data Breach
When must affected individuals be informed after a data breach?
Under Art. 34 GDPR and other applicable laws, affected individuals must be notified without undue delay if the personal data breach is likely to result in a high risk to their rights and freedoms. The specific risk assessment must be made on a case-by-case basis. The GDPR does not specify a fixed deadline in hours or days for notifying affected individuals. However, delayed notifications – i.e. notifications that are not provided without undue delay – can regularly give rise to claims for damages and may also result in substantial fines imposed by supervisory authorities.
What must a notification to affected individuals include?
It must explain clearly and in plain language what has happened, the likely consequences, the measures taken by the organization, and how to contact a designated point of contact. From a communication perspective, it should also explain as specifically as possible which data has been affected and what recipients can do to mitigate potential harm. Referring affected individuals to publicly available sources of support – such as information provided by the German Federal Office for Information Security (BSI) – can provide additional practical guidance and reassurance.
Who is considered affected by a cyberattack?
Not only customers. Depending on the data involved, affected individuals may also include employees, former employees, job applicants, supplier contacts, business partners, or other natural persons. Moreover, a cyberattack may affect not only personal data but also other confidential information and data belonging to customers and suppliers.
What should a company do if stolen data is published on the dark web?
Affected individuals should, wherever possible, be informed proactively. The organization should avoid distributing links to or locations of the stolen data, provide a reliable channel for inquiries, and explain transparently what new information has emerged since the initial notification. It should also communicate that it is actively cooperating with law enforcement authorities.
Do customers who are not affected also need to be informed?
Generally not under Art. 34 GDPR if it can be reliably established that they are not affected. However, from a reputational perspective, or due to other statutory, contractual, or regulatory obligations, communication may still be advisable or required.
Dr. Matthias Orthwein, LL.M. (Boston)
Dr. Orthwein was admitted to the bar in 2003 and became a partner at SKW Schwarz in 2011. He received his Master of Laws (LL.M.) in American Law from Boston University (USA) in 2000 and his doctorate from the University Muenster in 2003 with a topic in telecommunications law.
He advises his clients in all areas of IT law, in particular cloud and software contract law using new agile software developing and contract methods, the commercial use of data and artificial intelligence (AI) as well as digital transformation projects. Together with his clients, he develops and brings to life new digital platforms and business models. He is an experienced expert in national and international data protection law issues in particular with regard to the use of cloud services.
The Lexology Index Germany 2025 lists him as a “world's leading practitioner” in the data category. In 2025, Handelsblatt / Best Lawyers again recommends him as a lawyer in the categories “IT law” and “data protection law.” He is once again listed in the JUVE Handbook 2025 as a “frequently recommended lawyer” for IT and data protection law.
Dr. Orthwein is a lecturer for IT and data protection law in applied AI at the Technical University of Rosenheim.
Dr. Orthwein is member of the German Society for Law and Informatics, the International Association of Privacy Professionals, the German Outsourcing Association and the German-American Lawyers Association. He is Senior Vice Chairman of the Technology Law Committee of the International Bar Association.
Whether it’s a cyber incident, a product recall, or legal disputes, communication is the decisive factor in determining how strongly a crisis affec...
- Crisis communication
- Crisis prevention
Crises are the ultimate test for every leader and communication professional. As external turbulence increases, manuals, processes, and structures ...
- Crisis prevention
- krisen-resilienz
Crises are not only threats – they are also opportunities. Those who are prepared can limit damage, strengthen stakeholder trust, and even emerge f...
- Crisis communication
- Crisis prevention