Run the personal data breach decision tree under GDPR Articles 33-34 and EDPB Guidelines 9/2022: classify the breach, assess risk to rights and freedoms, track the 72-hour notification deadline from awareness, decide on communication to data subjects, and draft the supervisory authority notification, the data subject communication, and the internal register entry. Use when a data leak, ransomware incident, misdirected email, or lost device raises the question of whether and whom to notify. The workflow drafts; the controller or DPO decides and sends.