Data Breach Notification: The Regulatory Timelines You Are Required to Meet

Retool's new app builder is where AI-generated code ships safely
Building apps with AI is easy. Getting them to production safely is another story.
A significant data breach does not trigger one notification obligation — it triggers multiple simultaneous clocks running under different regulatory frameworks, with different start events, different recipients, and different content requirements. Missing any one of them creates additional regulatory exposure on top of the breach itself.
The clock-start events matter as much as the deadlines: GDPR's 72-hour clock starts when you 'become aware' of a personal data breach; the SEC's 4-day clock starts when you 'determine' materiality; HIPAA's 60-day clock starts at 'discovery.' These are not the same moment — a confirmed ransomware infection is a breach 'discovery' but may not be 'material' for SEC purposes until the investigation establishes scope. Legal counsel must be involved in determining the clock-start event for each framework. This guide maps the obligations so your legal and compliance team have the framework before an incident occurs.
GDPR: 72-hour supervisory authority notification
GDPR Article 33 applies to organizations that process personal data of EU residents — regardless of where the organization is headquartered.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
HIPAA: 60-day breach notification rule
HIPAA's Breach Notification Rule applies to covered entities (healthcare providers, health plans, healthcare clearinghouses) and their business associates (organizations handling PHI on their behalf).
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Briefings like this, every morning before 9am.
Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.
SEC: 4 business day material incident disclosure
The SEC's cybersecurity disclosure rules, effective December 2023, apply to publicly traded companies registered with the SEC.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
US state breach notification laws
All 50 US states plus DC, Puerto Rico, and US territories have data breach notification laws. The coverage varies significantly — which state's law applies depends on where the affected individuals reside, not where your company is located.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Building a notification readiness process
Notification readiness cannot be built during an incident. These elements must be in place before.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
The bottom line
The regulatory notification landscape is complex and jurisdiction-dependent, but the core obligation is consistent across frameworks: notify the relevant authorities and affected individuals within the required window, with the required content, through the required channels. Missing any deadline creates compounded liability. The preparation that prevents missed notifications is done before the incident: data mapping, pre-identified legal counsel, and templated notifications that can be adapted in hours rather than drafted from scratch under pressure.
Frequently asked questions
Does GDPR apply to non-EU companies?
Yes. GDPR applies to any organization that processes personal data of EU residents, regardless of where the organization is established. A US-headquartered company with European customers, European employees, or European website visitors that processes personal data of those individuals is subject to GDPR. The relevant supervisory authority for non-EU organizations with a designated EU representative is typically the authority in the EU member state where the representative is established.
What is the difference between breach notification and regulatory reporting?
Breach notification typically refers to the obligation to notify affected individuals (customers, employees) whose personal data was compromised. Regulatory reporting refers to notification to government authorities (EU supervisory authorities, HHS, SEC, state AGs). Both may be required simultaneously. GDPR requires both authority notification (Article 33) and individual notification for high-risk breaches (Article 34). HIPAA requires both individual notification and HHS reporting. US state laws typically require both individual notification and in some cases AG notification.
Can you delay breach notification if law enforcement requests it?
Yes, with conditions. In the US, law enforcement agencies (FBI, Secret Service) can request a delay in breach notification if disclosure would impede an ongoing criminal investigation. The delay is typically limited to 30 days and must be formally requested by law enforcement. For the SEC's 4-business-day rule, the SEC allows delayed disclosure if the US Attorney General determines immediate disclosure would pose a substantial risk to national security or public safety. Any delay request should be documented in writing and reviewed by counsel.
Sources & references
Free resources
Critical CVE Reference Card 2025–2026
25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.
Ransomware Incident Response Playbook
Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.
Get threat intel before your inbox does.
50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.
Unsubscribe anytime. We never sell your data.

Founder & Cybersecurity Evangelist, Decryption Digest
Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.
Win a $2,495 Black Hat pass.
Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.
