Menu

Cyberattacks and Ransomware: What Companies Need to Know About GDPR Reporting, Data Breaches and Dark Web Extortion

A ransomware attack can trigger a range of legal obligations within hours. These include the requirement to notify the data protection authority within 72 hours under Article 33 GDPR, assessing whether affected individuals must be notified under Article 34 GDPR, and taking immediate steps to preserve evidence for potential criminal proceedings. Paulitsch Law advises companies and public-sector organizations across Austria throughout every stage of a cyber incident — from the initial emergency response and regulatory communications to the pursuit of compensation claims. This article highlights the key legal considerations companies should address when responding to a cyberattack.

Key Takeaways

  • 72-hour deadline: A personal data breach that is subject to notification must be reported to the data protection authority within 72 hours of the organization becoming aware of it (Article 33 GDPR).
  • High-risk breaches: Where a breach is likely to pose a high risk to the rights and freedoms of affected individuals, those individuals must also be notified (Article 34 GDPR).
  • Information can be provided in stages: Where all relevant information is not yet available, further details may be submitted subsequently without undue delay (Article 33(4) GDPR).
  • Criminal proceedings: Cyberattacks may constitute a range of criminal offences under Austrian law, including those covered by Sections 118a, 126a–126c, 148a and 144 StGB. Victims may join criminal proceedings as private claimants.
  • Dark web extortion: In cases of double extortion, the risk assessment must be continuously reviewed and comprehensively documented.

What should companies do immediately after a Ransomware attack?

The first few hours can be critical. Companies should immediately establish a crisis response team, bring in IT forensics specialists, isolate affected systems and secure all potentially relevant evidence, including log files, ransom notes and communications from the attackers. From the outset, every step taken should be documented in a clear and traceable manner. The accountability principle under Article 5(2) GDPR requires organizations to be able to demonstrate the measures they have taken. At the same time, the 72-hour reporting period under Article 33 GDPR begins once the organization becomes aware of the breach.

When must a cyberattack be reported to the data protection authority?

Under Article 33 GDPR, a personal data breach must generally be reported to the Austrian Data Protection Authority within 72 hours of the organization becoming aware of the breach. The notification must set out, among other things, the nature of the breach, the categories and approximate number of affected individuals and personal data records, the likely consequences, and the measures already taken or proposed to address the breach. If all relevant information is not yet available, the notification may be submitted in stages pursuant to Article 33(4) GDPR. A notification is only unnecessary where the breach is unlikely to result in a risk to the rights and freedoms of affected individuals. The assessment underlying this decision should be carefully documented.

Do affected individuals need to be notified?

Where a personal data breach is likely to result in a high risk to the rights and freedoms of affected individuals, those individuals must also be notified under Article 34 GDPR. In ransomware incidents involving prior data exfiltration, a high level of risk will generally have to be assumed (see EDPB Guidelines 01/2021). Any notification to affected individuals should be clear, concise and easy to understand. It should also include practical guidance, including a warning about potential fraud and phishing attempts carried out in the name of the affected organization. If it is impossible to establish with certainty which data was exfiltrated — for example, because the attackers have taken anti-forensic measures — companies should consider adopting a precautionary approach and treating the incident as presenting a high risk.

What should companies do in cases of data theft and dark web extortion?

A common ransomware tactic is double extortion: attackers first exfiltrate data, then encrypt the victim’s systems and threaten to publish or sell the stolen information. The pressure may escalate through the publication of the victim’s name on a leak site, often accompanied by a countdown, followed by an offer to sell the stolen data. Each new development may materially change the risk assessment. Companies should therefore continuously reassess the situation, document their findings and, where necessary, provide updated information to the data protection authority. Ongoing monitoring of the dark web can help organizations identify whether stolen data has been published or offered for sale. Companies should not contact the attackers or pay a ransom without first obtaining legal advice. Among other considerations, sanctions and criminal-law implications may arise depending on the circumstances.

How can companies pursue criminal action following a cyberattack?

Companies affected by a cyberattack should report the incident to the criminal police by filing a criminal complaint or submitting a statement of facts. Depending on the circumstances, the conduct of the attackers may constitute a number of criminal offences, including: unlawful access to a computer system (Section 118a StGB); data damage, disruption of the functionality of a computer system, and misuse of computer programs or access credentials (Sections 126a–126c StGB); fraudulent misuse of data processing (Section 148a StGB); and extortion, generally in attempted form (Sections 15 and 144 StGB). As victims of the offence, companies may join the criminal proceedings as private claimants (Sections 67 et seq. StPO), pursue claims for damages and request access to the case files under Section 68 StPO.

What mistakes should companies avoid?

Several mistakes recur in the aftermath of cyberattacks. These include missing the 72-hour GDPR reporting deadline, failing to properly document the incident, communicating externally too early or inconsistently, overwriting or deleting potentially relevant forensic evidence, and paying a ransom without first obtaining legal advice. A coordinated communications strategy and close cooperation between senior management, IT forensics, data protection specialists and legal counsel are essential to an effective response.

How can Paulitsch Law support companies following a cyberattack?

Paulitsch Law provides comprehensive legal support to companies and public-sector organizations throughout the entire cyber incident response process. This includes immediate legal advice to crisis management teams, coordination with IT forensics specialists, preparation and submission of GDPR breach notifications, notification of affected individuals, and communication with the Austrian Data Protection Authority and law enforcement authorities. Paulitsch Law also assists companies in joining criminal proceedings as private claimants and pursuing compensation claims. In addition, the firm advises organizations on preventive measures, including appropriate technical and organizational safeguards and the development of effective incident response plans. Based in Vienna, Paulitsch Law advises clients throughout Austria.

Frequently asked Questions (FAQ)

How long do I have to report a data breach under the GDPR?

As a general rule, a notifiable personal data breach must be reported within 72 hours of the organization becoming aware of it. Any delay must be justified.

Do I have to report a breach if I do not yet know which data has been affected?

Yes. A notification may be submitted in stages. Until the scope of the breach has been fully established, a precautionary risk assessment is advisable.

Do I have to pay a ransom?

No. There is no legal obligation to pay a ransom. Any decision to make a payment should only be considered after a thorough legal assessment.

Can a company affected by a cyberattack claim compensation?

Yes. Depending on the circumstances, compensation may be pursued by joining the criminal proceedings as a private claimant and/or through civil proceedings.

Contact

Have you been affected by a cyberattack or want to strengthen your organization’s preparedness?

Paulitsch Law provides rapid and discreet legal support and is a criminal law firm specialising in white-collar criminal law, compliance and cybercrime, based in Vienna 1010. The firm advises and represents private individuals, companies and their officers in all criminal matters – from the first questioning through to proceedings before the Supreme Court.

Contact: office@paulitsch.law · +43 1 361 4007 · www.paulitsch.law

Location: Hoher Markt 8–9, Staircase 2, 2nd floor, Unit 10, 1010 Vienna · Entrance: Judengasse 1

Author: Dr. Heidemarie Paulitsch, Attorney-at-Law (Rechtsanwältin) specialises in criminal law, white-collar criminal law and compliance and represents accused persons in all phases of criminal proceedings – from the first questioning to appellate proceedings.

Legal notice: This article is intended for general information and does not replace individual legal advice. The statements reflect the legal situation as at 7.9.2026. For the assessment of your specific case, please contact an attorney-at-law.

Dr. Heidemarie Paulitsch
Dr. Heidemarie Paulitsch
  • Criminal Law
  • White-Collar Crime

More Articles