The short version: the vendor had the incident and you have the duty. Under Article 33 of the GDPR the controller notifies the supervisory authority, and a university deploying an edtech platform is almost always the controller. The ten steps below run from the vendor’s first email to the closed file, each with its owner and its artefact.
Every institutional deployment plan covers procurement, assessment and rollout. Very few cover the morning the supplier writes to say something has happened, which is the only part of the plan that runs against a statutory clock.
Step 1: Establish what you have been told, and start the clock
Owner: data protection officer. Artefact: a timestamped incident record, opened immediately.
Article 33(1) requires the controller to notify “without undue delay and, where feasible, not later than 72 hours after having become aware of it”. The clock therefore starts at awareness, not at the end of your investigation, and Article 33(2) puts the trigger in the vendor’s hands: “the processor shall notify the controller without undue delay after becoming aware of a personal data breach.”
Record the exact time their message arrived and what it said. If a delay later becomes unavoidable, Article 33(1) permits it — a notification made after 72 hours “shall be accompanied by reasons for the delay” — but a reason has to be a fact you wrote down at the time.
Step 2: Confirm your own position before you accept theirs
Owner: data protection officer. Artefact: a one-line role determination in the incident record.
Vendors sometimes write as though the incident is theirs to report. Usually it is not. If you determined the purposes and means of the processing — you chose to deploy the platform, for your assessment or support purposes, on your students — you are the controller and the notification duty is yours regardless of whose infrastructure failed.
Check the contract at this point rather than later. A supplier that has been operating outside your documented instructions may have become a controller in its own right for that processing, which changes who reports what. The clauses that decide it are the same ones set out in is student work used to train AI models.
Step 3: Contain it without destroying the evidence
Owner: IT lead. Artefact: a containment log with times and named actions.
Suspend the integration rather than deleting the tenant. Disabling single sign-on and provisioning stops further exposure while keeping the account and its logs intact; tearing the environment down destroys the material you need for both the notification and the contract discussion. The provisioning routes to reverse are the ones in how to set up SSO and LMS integration.
Ask the vendor in writing to preserve their logs, and say so in the same message that acknowledges their notification. Log retention policies delete evidence on a schedule that has no interest in your investigation.

Step 4: Scope it in the terms the notification form asks for
Owner: data protection officer with the registry. Artefact: a scoping note in Article 33(3) structure.
Do not scope in your own vocabulary and translate later. Article 33(3) requires the notification to describe “the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned”.
Two things are specific to student work and are routinely under-counted. Special category data arrives inside submitted text without being labelled as such — health, disability and family circumstances turn up in reflective writing and in methods sections. And a doctoral chapter may contain research participants’ data, which means a second population of data subjects who are not your students at all.
Step 5: Decide whether it is notifiable, against the right test
Owner: data protection officer. Artefact: a written risk determination, whichever way it goes.
The Article 33(1) exemption is narrow: notification is required “unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.” Note what the test is not. It is not whether the institution is embarrassed, not whether the vendor thinks it is serious, and not whether anyone has complained.
Write the determination down even when the answer is no. Article 33(5) requires the controller to “document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken”, and that documentation must “enable the supervisory authority to verify compliance with this Article”. A decision not to notify is exactly the decision that documentation exists to defend.
Step 6: Notify the supervisory authority
Owner: data protection officer. Artefact: the submitted notification and its reference number.
Article 33(3) sets the minimum content, and it is short enough to work from directly: the nature of the breach with the categories and approximate numbers above; the name and contact details of the data protection officer or other contact point; the likely consequences; and the measures taken or proposed, including where appropriate measures to mitigate adverse effects.
You are not required to have finished. Article 33(4) is explicit that where the information cannot all be provided at once, “the information may be provided in phases without undue further delay”. Institutions miss the deadline far more often by waiting for completeness than by lacking facts.
Step 7: Decide whether the students have to be told
Owner: data protection officer with the academic registrar. Artefact: a communication decision and, if it is yes, the text.
This is a separate test with a higher threshold. Article 34(1) applies “when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons”, and the communication must be in “clear and plain language”.
Article 34(3) then provides three exemptions, and they are worth knowing before an incident rather than during one:
- Appropriate technical and organisational protection measures were in place and applied to the data affected, “in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption”;
- Subsequent measures have ensured the high risk is no longer likely to materialise; or
- It would involve disproportionate effort — in which case there must instead be “a public communication or similar measure whereby the data subjects are informed in an equally effective manner”.
Note also Article 34(4): if you have not communicated, the supervisory authority may require you to, or may decide the exemptions are met. The decision is reviewable, so make it reviewably.

Step 8: Handle the academic consequences GDPR does not reach
Owner: graduate school director. Artefact: a list of affected candidates and the action offered to each.
This step exists because a leaked draft thesis is not only a privacy problem. It is unpublished scholarly work, and its author may now have a priority problem, a publisher problem or an embargo problem that no data protection process will surface.
Identify doctoral and research-master’s candidates in the affected population and contact them separately from any general notice. Offer three things: a written statement of what was exposed and when, which is what a journal or a funder will ask for; a review of any embargo or hold already in place; and a note on the candidate’s file. Route that conversation through whoever owns your thesis licensing position, because the candidate is the copyright holder and will reasonably ask what the institution’s licence did and did not permit.
Step 9: Re-open the contract while the incident is still live
Owner: contracts. Artefact: a redline of the data processing agreement.
Leverage is at its maximum in the fortnight after an incident and gone by renewal. Four amendments earn their place:
- A notification deadline in hours, not “without undue delay”. Twenty-four is normal and gives you a working margin inside your own 72.
- A minimum content requirement for their notification, mirroring Article 33(3), so you are not conducting an interview against a clock.
- A log preservation obligation triggered by the notification itself.
- An audit or evidence right — the security assurance you were shown at procurement, re-supplied annually.
The wider question set to put to the supplier at this point is the one in the procurement question bank, and the export, deletion and transition terms are the ones covered at step four of how to roll out an AI writing platform university-wide.
Step 10: Close the file properly
Owner: data protection officer. Artefact: a closed record and two updated documents.
Update the record of processing if the incident revealed a flow you had not documented, and update the assessment if it revealed a risk you had not assessed — the review sequence is in how to run a data protection review before deploying an AI writing tool. Then check the shadow-usage question in both directions, because an incident in an approved tool tends to push people back to unapproved ones: the staff-side rules are in can our staff put student work into an AI tool.
A realistic timeline
| Elapsed | What must have happened | Owner |
|---|---|---|
| Hour 0 | Incident record opened, arrival time and content logged | DPO |
| Hours 0–4 | Role determination; containment; log preservation requested in writing | DPO, IT lead |
| Hours 4–24 | Scoping in Article 33(3) structure; special category and participant data identified | DPO, registry |
| Hours 24–48 | Risk determination written; Article 34 decision drafted | DPO, registrar |
| By hour 72 | Supervisory authority notified, in phases if necessary | DPO |
| Days 3–10 | Student and candidate communications; academic consequences handled | Registrar, graduate school |
| Weeks 2–6 | Contract redlined; record and assessment updated; file closed | Contracts, DPO |
The single most useful thing this table does is show that four of the seven rows happen before you know very much. That is the design, not a failure of the process.
If you would like the vendor notification clause, the Article 33(3) scoping template and this timeline mapped onto your own incident procedure, request an institutional evaluation and we will work through them with your data protection lead.
Frequently asked questions
When does the 72-hour clock start?
When the controller becomes aware of the breach, which in a vendor incident is normally the moment their notification reaches you. It does not start when your investigation concludes, and Article 33(2) obliges the processor to notify you without undue delay after becoming aware.
The vendor had the incident. Why are we the ones notifying?
Because Article 33 places the duty on the controller, and a university that chose to deploy the platform for its own purposes is the controller. Whose servers failed does not change that.
What if we cannot establish the full facts in 72 hours?
Notify anyway. Article 33(4) expressly allows the information to be provided in phases without undue further delay, and Article 33(1) allows a late notification accompanied by reasons for the delay.
Do we have to tell the students?
Only where the breach is likely to result in a high risk to their rights and freedoms, which is a higher threshold than the notification duty. Article 34(3) then provides three exemptions, including where the data was rendered unintelligible by measures such as encryption.
Can the regulator overrule our decision not to tell them?
Yes. Article 34(4) allows the supervisory authority to require communication to data subjects, or to decide that one of the exemptions is met.
Do we have to record breaches we decide not to notify?
Yes. Article 33(5) requires documentation of any personal data breach, its effects and the remedial action taken, in a form that lets the supervisory authority verify compliance.
Does FERPA impose a breach notification duty on US institutions?
FERPA does not contain a general breach-notification requirement of the kind Article 33 sets out. US institutions are typically caught by state breach-notification statutes instead, which vary in trigger, timescale and content. Confirm which applies to you before an incident rather than during one.
What about research participants’ data inside a thesis?
Treat them as a second affected population. They are data subjects whose data you hold under a different approval, they are not contactable through your student records, and the ethics committee that approved the collection should be told.
Should we suspend the platform?
Suspend the integration, not the tenant. Disabling sign-in and provisioning contains the exposure while preserving the logs and the account you will need for the notification and the contract discussion.
What is the single most valuable contract change afterwards?
A vendor notification deadline expressed in hours rather than “without undue delay”, with a minimum content requirement mirroring Article 33(3). It is the clause that decides whether your own 72 hours is usable.
Who should own the response?
The data protection officer owns the statutory clock and the file. The IT lead owns containment, the registrar owns communication, and the graduate school owns the academic consequences. A response owned by one person misses at least one of those.
What is the most common failure?
Waiting for a complete picture before notifying. The regulation anticipates incomplete facts and provides for phased reporting; it does not provide for a missed deadline because the investigation was still running.
