72 hours
GDPR Article 33 requirement to notify the supervisory authority after becoming aware of a personal data breach
4 business days
SEC Form 8-K requirement for public companies to disclose material cybersecurity incidents after determining materiality
60 days
HIPAA maximum notification window to affected individuals and HHS after discovery of a breach of protected health information
50 states + DC
all US states plus DC have data breach notification laws with different covered data types, timelines, and AG notification requirements

SponsoredRetool

Retool's new app builder is where AI-generated code ships safely

Building apps with AI is easy. Getting them to production safely is another story.

Start building for free today

A significant data breach does not trigger one notification obligation — it triggers multiple simultaneous clocks running under different regulatory frameworks, with different start events, different recipients, and different content requirements. Missing any one of them creates additional regulatory exposure on top of the breach itself.

The clock-start events matter as much as the deadlines: GDPR's 72-hour clock starts when you 'become aware' of a personal data breach; the SEC's 4-day clock starts when you 'determine' materiality; HIPAA's 60-day clock starts at 'discovery.' These are not the same moment — a confirmed ransomware infection is a breach 'discovery' but may not be 'material' for SEC purposes until the investigation establishes scope. Legal counsel must be involved in determining the clock-start event for each framework. This guide maps the obligations so your legal and compliance team have the framework before an incident occurs.

GDPR: 72-hour supervisory authority notification

GDPR Article 33 applies to organizations that process personal data of EU residents — regardless of where the organization is headquartered.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

HIPAA: 60-day breach notification rule

HIPAA's Breach Notification Rule applies to covered entities (healthcare providers, health plans, healthcare clearinghouses) and their business associates (organizations handling PHI on their behalf).

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

SEC: 4 business day material incident disclosure

The SEC's cybersecurity disclosure rules, effective December 2023, apply to publicly traded companies registered with the SEC.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

US state breach notification laws

All 50 US states plus DC, Puerto Rico, and US territories have data breach notification laws. The coverage varies significantly — which state's law applies depends on where the affected individuals reside, not where your company is located.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Building a notification readiness process

Notification readiness cannot be built during an incident. These elements must be in place before.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

The bottom line

The regulatory notification landscape is complex and jurisdiction-dependent, but the core obligation is consistent across frameworks: notify the relevant authorities and affected individuals within the required window, with the required content, through the required channels. Missing any deadline creates compounded liability. The preparation that prevents missed notifications is done before the incident: data mapping, pre-identified legal counsel, and templated notifications that can be adapted in hours rather than drafted from scratch under pressure.

Frequently asked questions

Does GDPR apply to non-EU companies?

Yes. GDPR applies to any organization that processes personal data of EU residents, regardless of where the organization is established. A US-headquartered company with European customers, European employees, or European website visitors that processes personal data of those individuals is subject to GDPR. The relevant supervisory authority for non-EU organizations with a designated EU representative is typically the authority in the EU member state where the representative is established.

What is the difference between breach notification and regulatory reporting?

Breach notification typically refers to the obligation to notify affected individuals (customers, employees) whose personal data was compromised. Regulatory reporting refers to notification to government authorities (EU supervisory authorities, HHS, SEC, state AGs). Both may be required simultaneously. GDPR requires both authority notification (Article 33) and individual notification for high-risk breaches (Article 34). HIPAA requires both individual notification and HHS reporting. US state laws typically require both individual notification and in some cases AG notification.

Can you delay breach notification if law enforcement requests it?

Yes, with conditions. In the US, law enforcement agencies (FBI, Secret Service) can request a delay in breach notification if disclosure would impede an ongoing criminal investigation. The delay is typically limited to 30 days and must be formally requested by law enforcement. For the SEC's 4-business-day rule, the SEC allows delayed disclosure if the US Attorney General determines immediate disclosure would pose a substantial risk to national security or public safety. Any delay request should be documented in writing and reviewed by counsel.

Sources & references

  1. SEC Cybersecurity Disclosure Rules - Form 8-K Requirements
  2. HHS HIPAA Breach Notification Rule
  3. IAPP Data Breach Notification Chart

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Black Hat Giveaway

Win a $2,495 Black Hat pass.

Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.

Joins Decryption Digest daily briefing. Unsubscribe anytime.

Giveaway: Black Hat USA 2026 Full-Access Pass ($2,495 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $2,495 Black Hat USA 2026 pass.