Even with the greatest caution, it can happen: If a personal data breach occurs, controllers and processors must comply with breach obligations in very short periods of time. The new draft guidelines of the European Data Protection Board (EDPB) on personal data breaches notification requirements now provide further guidance and make best practice recommendations. Some aspects have become clearer, others have not.