Breach Notification (Article?33)

Controllers must report personal data breaches to the supervisory authority within 72 hours of detection, unless unlikely to risk individuals' rights. If high risk is likely, they must inform affected customers. Financial institutions must maintain established workflows and documentation for breach management.