For the data protection lead of a UK or EU company who just heard "I think I sent that file to the wrong person." The notice to the ICO or your EU authority is due 72 hours after you became aware, and the weekend counts.
Full version — $69.99 once · the Obsidian vault that keeps every breach on this board and in the Article 33(5) register · get the vault
18 notes, 2 Bases, 1 canvas: 7 rule notes, 4 templates, 6 filled examples, the Start note. Core plugins only — no community plugins. You check your own breach here for free first; the vault is one payment, not a subscription.
00 Start here.mdBreach board.baseBreach board.canvasBreach register.baseBreaches/2026-09-18 Payroll file sent to wrong client.mdBreaches/2026-09-22 Lost laptop with CRM export.mdBreaches/2026-09-23 Encrypted USB stick lost.mdBreaches/2026-09-24 Mailing vendor ransomware.mdNotices/2026-09-18 Message to affected staff - payroll file.mdNotices/2026-09-22 ICO notice - lost laptop.mdRules/Article 33 - the 72-hour clock.mdRules/Article 33(3) - what the notice must contain.mdRules/Article 33(5) - the breach register.mdRules/Article 34 - telling the people affected.mdRules/Other clocks - NIS2 and telecoms.mdRules/Risk triage - none, risk, high.mdRules/Which authority - UK and EU.mdTemplates/Authority notice draft.mdTemplates/Breach card.mdTemplates/Message to affected people.mdTemplates/Post-incident review.md# Start here - GDPR breach board This vault is a kanban board for personal-data breaches under GDPR (EU) and UK GDPR. Every incident becomes one card. The card moves through five columns until it is closed, and every card stays in the breach register that Article 33(5) asks you to keep. ## The five columns 1. **1 Detected** - someone reported something. Write down the minute you became aware. 2. **2 Assessing** - decide the risk: none, risk, or high risk. See [[Risk triage - none, risk, high]]. 3. **3 Notify authority** - risk or high risk: the notice to the ICO or your EU authority is due 72 hours after you became aware. See [[Article 33 - the 72-hour clock]]. 4. **4 Tell people** - high risk: tell the people affected without undue delay. See [[Article 34 - telling the people affected]]. 5. **5 Closed** - lessons written, register row complete. The column is the `stage` property on each card. Change it and the card jumps to the next column in **Breach board.base**. The canvas **Breach board.canvas** is a wall view of the same cards: drag a card there, then set `stage` to match. ## Your first 5 minutes 1. Open **Breach board.base** and click through the views: 1 Detected, 2 Assessing, 3 Notify authority, 4 Tell people, 5 Closed, Clock. 2. Open the filled example [[2026-09-22 Lost laptop with CRM export]]. It is in column 3 with its notice due on Fri 25 Sep 2026 at 09:15. 3. New incident: create a note in `Breaches/`, then run **Insert template** and pick **Breach card**. Fill `aware` first. 4. Read [[Which authority - UK and EU]] once, and write your authority on the card. ## What is in here - 7 rule notes: [[Article 33 - the 72-hour clock]] · [[Article 33(3) - what the notice must contain]] · [[Article 34 - telling the people affected]] · [[Article 33(5) - the breach register]] · [[Which authority - UK and EU]] · [[Other clocks - NIS2 and telecoms]] · [[Risk triage - none, risk, high]] - 4 templates in `Templates/`: Breach card · Authority notice draft · Message to affected people · Post-incident review - 2 Bases: **Breach board.base** (the kanban) and **Breach register.base** (the Article 33(5) register) - 1 canvas: **Breach board.canvas** - 6 filled examples: [[2026-09-18 Payroll file sent to wrong client]] · [[2026-09-22 Lost laptop with CRM export]] · [[2026-09-23 Encrypted USB stick lost]] · [[2026-09-24 Mailing vendor ransomware]] · [[2026-09-22 ICO notice - lost laptop]] · [[2026-09-18 Message to affected staff - payroll file]] ## Install 1. Unzip the file. 2. In Obsidian choose **Open folder as vault** and pick the unzipped folder. (Menu names can differ slightly by Obsidian version and UI language.) 3. To add it to an existing vault instead, copy the whole folder into that vault. No community plugins are needed. It uses only core plugins: Templates, Bases and Canvas. Bases needs Obsidian 1.9 or newer. This vault is a working tool, not legal advice. Check the current guidance of your own authority before you file.
A working tool, not legal advice. Check your authority's current guidance before you file.
This page is the working piece. The full pack has everything below.
Aware Fri 2 Oct 2026 at 18:30 -> notice due Mon 5 Oct 2026 at 18:30, weekend counted. Miss GDPR Art. 33 and Art. 83(4) allows fines up to €10,000,000 or 2% of turnover.
GDPR Art. 83(4)(a): breaches of Art. 33/34 can be fined up to €10,000,000 or 2% of worldwide annual turnover (UK GDPR: £8,700,000 or 2%). Irish DPC fined Twitter €450,000 in December 2020 for a late Art. 33 notice.
Buy the full version — $69.99· ReadyStack
Real numbers from this tool, line by line.

You find out about a personal-data breach on a Friday at 18:30. A colleague says the payroll file went to the wrong client, or a sales laptop was left on a train. Under GDPR Article 33, and the same article in UK GDPR, the notice to the supervisory authority is due without undue delay and, where feasible, not later than 72 hours after you became aware. From Fri 2 Oct 2026 at 18:30, that is Mon 5 Oct 2026 at 18:30. 48 of those 72 hours fall on the weekend. The clock counts hours, not working days.
The clock starts when you are aware, meaning you have a reasonable degree of certainty that a security incident has compromised personal data (EDPB Guidelines 9/2022). If a processor, such as your newsletter vendor, finds the breach, Article 33(2) says it tells you without undue delay. Your 72 hours then start when its email reaches you. In one example on the board, a vendor report arrives Thu 24 Sep 2026 at 08:40, so the deadline is Sun 27 Sep 2026 at 08:40, a Sunday.
Missing the deadline costs money. Article 83(4)(a) allows fines up to €10,000,000 or 2% of worldwide annual turnover for breaching Articles 33 and 34. Under UK GDPR the standard maximum is £8,700,000 or 2%. In December 2020 the Irish Data Protection Commission fined Twitter €450,000 for a late notice and weak breach documentation.
Not every breach goes to the authority. If a breach is unlikely to result in a risk to people, you do not notify. You still have to write it down. Article 33(5) asks you to document any breach: the facts, its effects and what you did about it. That is the step people skip. A lost USB stick with 212 job applications, encrypted with the key kept elsewhere, is not notified, but it still needs a register row that gives the reason.
If the risk is high, a second duty applies. Article 34 says you tell the people affected without undue delay, in plain language, with a contact point, the likely consequences and the measures taken. A payroll spreadsheet with National Insurance numbers and bank details for 38 staff meets that test. An export of 1,240 customer names and order histories with no payment data usually leads to a notice to the authority, but no letter to customers.
Other clocks can run at the same time. NIS2 entities send an early warning within 24 hours, a notification within 72 hours and a final report within one month. Telecoms and internet access providers report every personal data breach within 24 hours, whatever the risk.
This Obsidian kanban template puts all of that on one board. Each breach is a note with a stage property, and the core Bases plugin shows five columns: 1 Detected, 2 Assessing, 3 Notify authority, 4 Tell people, 5 Closed. A Clock view lists every open card with its aware time and notify_by deadline. A register view shows every breach, whatever its column, with the fields Article 33(5) needs. A canvas gives you a wall view you can drag cards around on.
The vault has 21 files: 18 notes, 2 Bases and 1 canvas. That covers 7 rule notes, 4 templates (Breach card, Authority notice draft, Message to affected people, Post-incident review) and 6 filled examples. It needs no community plugins, only Templates, Bases and Canvas.
Try your own breach in the browser first. Enter the minute you became aware, UK or EU, the risk level and any parallel regime. You get the deadline, the weekend hours, and whether you must notify and tell people.
It turns every personal-data breach into a card on a five-column board in Obsidian: Detected, Assessing, Notify authority, Tell people, Closed. Each card carries the minute you became aware and the 72-hour notice deadline, and every card also shows up in the Article 33(5) breach register view, including breaches you decided not to notify.
Data protection leads, DPOs and founders at small and mid-size companies under EU GDPR or UK GDPR who already keep notes in Obsidian. It fits a team that gets a few incidents a year, such as misdirected emails, lost laptops or a processor reporting ransomware, and needs a register the ICO or an EU authority can read.
A free kanban template has columns but no law: it does not know that 72 hours count weekends, that a card with risk none must still stay in the Article 33(5) register, or that NIS2 and the telecoms 24-hour rule run as separate clocks. A spreadsheet has the register but no board, no notice draft and no worked examples.
In the browser you get the Article 33 clock for one breach: the authority deadline from the minute you became aware, how many hours fall on a weekend, whether to notify and whether to tell people. Example: aware Fri 2 Oct 2026 at 18:30 gives a notice due Mon 5 Oct 2026 at 18:30. The vault map and the Start here note are free to read.
The vault is $69.99 once, not a subscription. GDPR Art. 83(4)(a) allows fines up to €10,000,000 or 2% of worldwide annual turnover for breaches of Articles 33 and 34; under UK GDPR the standard maximum is £8,700,000 or 2%. The Irish DPC fined Twitter €450,000 in December 2020 for a late notice and weak breach documentation.
One question, answered by the person who built it. Your email only if you want the answer sent.