Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Who should be accountable for meeting GDPR breach…
Governance, Ownership & Risk

Who should be accountable for meeting GDPR breach notification and subject access deadlines?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Governance, Ownership & Risk

The appointed DPO has a central accountability role, but the process depends on support from security, legal, and operational teams. Companies must notify regulators and affected individuals within 72 hours for certain breaches, and respond to access or erasure requests within one month. Clear ownership, records, and tooling are necessary to meet those timelines reliably.

Who should own GDPR breach notifications and rights-request deadlines?

Accountability should sit with a clearly designated owner, typically the DPO or an equivalent privacy lead, but execution has to be shared across security, legal, operations, and customer-facing teams. The real test is not who drafts the response, but who can evidence timely decisions, escalation, and delivery under GDPR’s fixed clock.

Because both breach notification and subject access work are time-bound obligations, ownership needs to be explicit before an incident or request arrives. If the organisation only has informal “help as needed” responsibility, deadlines slip at handoff points, especially when facts are partial and approvals are slow.

A workable model is a single accountable owner with delegated tasks: security gathers facts, legal validates notification content and scope, operations retrieves records, and the business side confirms impact and requester identity where relevant. The accountable owner should control the workflow, not personally perform every task.

For breach response, the process must support rapid triage, legal decisioning, and regulator-facing drafting inside the 72-hour window. For subject access and erasure requests, the same ownership model should drive intake, tracking, and exception handling so one-month deadlines are not missed because evidence collection started too late.

What matters most is traceability. Teams should be able to show when the clock started, who approved each step, what data was reviewed, and why any extension or refusal was applied. Without that record, an organisation may have taken the right action but still fail to prove it.

Good ownership also reduces ambiguity when a request spans systems or vendors. If no one is explicitly responsible for chasing records, confirming deletion, or coordinating notification language, the organisation ends up with fragmented actions and inconsistent answers. That is where deadline risk usually becomes operational rather than theoretical.

Why DPO accountability still depends on cross-functional execution

Under GDPR, the DPO or privacy lead is the natural accountability point because the role is designed to coordinate compliance and monitor control effectiveness. But accountability is only credible if the surrounding functions are obligated to respond quickly, because the deadlines are operational, not advisory.

This is especially important when the issue involves multiple systems, third parties, or mixed ownership of records. The DPO can coordinate the response, but security may hold the incident facts, legal may interpret notification duties, and engineering or operations may need to retrieve, delete, or export data from production systems.

A useful way to think about the split is decision ownership versus evidence ownership. The accountable lead decides what must happen and by when; other teams own the evidence needed to make that decision safely and defensibly. That distinction prevents privacy compliance from becoming a bottleneck handled by one overstretched person.

For governance purposes, accountability should be documented in policy, incident runbooks, and request-handling procedures. If the organisation cannot identify who approves a breach notice, who logs the request, and who closes the record, then it does not really have ownership, only expectation.

Where the deadlines are tight, clear escalation paths matter as much as the named role. A request that sits in a queue for two weeks is usually not a technical failure, it is a management failure in prioritisation, handoffs, or resourcing.

What makes deadline compliance fail in practice

Most deadline failures come from delay before the work starts, not from the final response step. Breach facts are incomplete, request scope is unclear, records are scattered, and no one has authority to force fast action across teams.

Another common failure mode is treating every request as a bespoke case. That slows triage, creates inconsistent decisions, and makes it hard to measure whether the organisation can actually meet the statutory clock. Standard intake, standard logging, and standard escalation criteria are what make the process repeatable.

Tooling matters because deadlines depend on visibility. Case management, ticketing, evidence logs, and access to authoritative records all reduce the chance that a request is lost, duplicated, or answered from stale information. If the evidence trail is weak, the organisation may miss the deadline even when the underlying data exists.

For GDPR-specific reading, the EU General Data Protection Regulation (GDPR) remains the clearest reference for the legal timeframes, while NIST Privacy Framework is useful for structuring privacy risk management around repeatable processes and accountability.

Risk and Threat Considerations

When ownership is unclear, the risk is not just missed deadlines, it is inconsistent decisions, incomplete notifications, and poor evidence that can magnify both regulatory exposure and incident impact. Attackers also benefit when breach response is slow, because delayed containment and delayed disclosure can preserve their access longer.

Failure mechanism: Responsibility fragments across teams, critical facts are gathered too late, and no one has the authority to force closure inside the statutory window. That creates missed notices, incomplete responses, and weak records that are hard to defend later.

Impact: The organisation can face supervisory scrutiny, remediation overhead, and reputational damage, while affected individuals lose confidence in the organisation’s handling of their data and rights.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPREU General Data Protection RegulationThe question is directly about GDPR breach and rights-request deadlines.
Recommendation — Map breach and access workflows to GDPR time limits and assign clear accountability for each response step.
NIST SP 800-53 Rev 5AU-2 — Audit EventsDeadline compliance depends on evidencing who did what and when during response handling.
AU-6 — Audit Record Review, Analysis, and ReportingReviewing case records is essential for proving timely handling of GDPR obligations.
Recommendation — Log request intake, escalation, decisions, and closure so deadline performance is auditable. Review case logs routinely to detect delays and missing evidence before deadlines slip.
ISO/IEC 27001:2022A.5.34 — Privacy and protection of PIIGDPR deadlines are privacy-governance obligations that need an assigned operating model.
Recommendation — Assign privacy ownership and documented procedures for breach and data-subject request handling.
CIS Controls v8CIS-17 — Incident Response ManagementBreach notification deadlines are an incident-response coordination problem as well as a legal one.
Recommendation — Use a formal incident workflow with clear escalation and time-bound decision points.

Practitioner Guidance

What to prioritise: Assign one accountable owner for the full workflow, then pre-assign who supplies breach facts, legal review, records retrieval, and final sign-off. If that split is not written down, it will be improvised under pressure and deadlines will suffer.

What to verify: Check that the organisation can produce a dated case record showing request intake, clock start, decision points, escalation, and closure. If the evidence trail cannot be reconstructed quickly, the process is not reliable enough for audit or incident review.

Practitioner takeaway: GDPR deadline compliance is less about a single named role and more about whether that role can coordinate fast, documented action across the functions that actually hold the information.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org