Lilith Metaverse · Legal

Breach Notification Template — Germany (GDPR Art. 33)

1.

3sections1 minread

On this page

Template id: breach-notice-gdpr-de.v1 owner: Lilith-Privacy lead + EU counsel deadline: 72 hours from confirmation submission: competent German state DPA online breach portal (lead supervisory authority under the one-stop-shop)

Phased notification is permitted (Art. 33(4)): submit with known facts and mark sections "information to follow" rather than miss the clock.

Required content (GDPR Art. 33(3))#

  1. Nature of the breach: categories of data subjects and approximate number; categories of personal-data records and approximate number.
    • V3 data-class checklist: V1 account records / e-mail addresses / payment metadata / voice transcripts / recordings / consent-ledger entries / DSAR exports / Pixel Streaming session logs (IP addresses).
  2. DPO contact point: name and contact details of our data protection officer (from the de-DE privacy policy controller block).
  3. Likely consequences of the breach for data subjects.
  4. Measures taken or proposed: containment, mitigation, and the remediation steps from the incident case (cite the Operator Console case id internally; describe measures concretely in the notice).

Additional fields our submission always includes#

  • Timeline: when the breach started, when detected, when confirmed (the 72-hour clock anchor), and an explanation if notification exceeds 72 hours.
  • Cross-border scope: other EU/EEA member states affected (one-stop-shop routing).
  • Whether data-subject notification (Art. 34) is planned, and on what high-risk assessment.

Internal routing#

  • Drafted by: Lilith-Privacy lead. Reviewed by: EU counsel (mandatory before submission). Submitted by: counsel or DPO.
  • Evidence: the submitted notice, portal receipt, and timestamps are filed in the incident evidence bucket and referenced from the Operator Console case.