A nine-question triage for the first hours of a personal-data breach. Returns the Article 33 notifiable-or-document verdict, the 72-hour deadline computed from your awareness time, the required notification contents, and a starter draft you can hand to counsel. Runs in your browser; no email required.
Triage a live breach — without us ever seeing your answers. Everything stays in your browser. Nothing is transmitted or tracked.
The first-hours decisions. The triage walks the calls a Data Protection Officer faces under the General Data Protection Regulation (GDPR): is this breach notifiable, by when, with what contents, and what must you not do in the first hour.
What you get. An Article 33 notifiable-or-document verdict, the 72-hour deadline from your awareness time, the required notification contents, and a starter draft for counsel.
What it isn't. This is general guidance for a time-critical situation, not legal advice and not a substitute for counsel. Responsibility for meeting the GDPR remains with you.
Version 1 · Updated 2026-07-21
For anyone who might be told first about a personal-data breach and needs the shape of the next 72 hours.
When you have worked through this, you will have: your notify-or-document triage verdict from the free assessment, and a 72-hour battle-card someone can hold at the start of an incident. Download this as a PDF.
When you outgrow the free tier, the Solo toolkit turns the card into a worked response — the triage steps, the Article 33 notification template, and the do-not-touch list — with a Start here catalog to sequence them. See the Solo, Team and Enterprise editions →
Everything behind this free assessment — the working documents, templates, runbooks, and depth to put it into practice. Three editions to fit how you work.
See the full toolkit & pricing →One-time purchase · files you own forever · 30-day money-back guarantee.