The Guidelines on Data Breach Notification under Regulation 2016/679 explain the obligation to notify and communicate breaches contained in the AVG. Among other things, the Guidelines discuss some of the steps that controllers and processors can take to comply with this obligation. They also provide examples of different types of breaches and state who should be notified in different scenarios.
Refer to The Guidelines on Data Breach Notification under Regulation 2016/679 here.