Skip to content
Compliance

Do we have to tell anyone? Breach notification in plain language

Regulators, customers, partners — after a breach, who must hear about it, and by when? The clocks start earlier than most teams think, and the decision needs a written trail either way.

Do we have to tell anyone? Breach notification in plain language — Response Red advisory illustration72h

The essentials

  • Clocks generally start at awareness of a likely breach — not at full understanding. GDPR's 72-hour supervisory notice is the famous one; it is not alone.
  • Duties stack in layers: data-protection regulators, affected individuals, contracts with customers and partners, and sector rules (finance, health, critical infrastructure) — each with its own trigger and deadline.
  • Not every incident is notifiable — most regimes are risk-based. But the assessment must be done, and documented, even when the conclusion is "no".
  • Facts from forensics feed the decision; counsel makes it. Neither works alone.
  • Over-notification has real costs too — panic, churn, legal exposure — which is why precision of scope matters in both directions.

Notification law sounds like a specialist topic until the week you need it, when it becomes three practical questions: which regimes apply to this data and these people, what do they each require, and when does each clock expire.

The trap is waiting for perfect information. The regimes anticipate uncertainty — GDPR explicitly allows notification in phases — what they do not forgive is silence past the deadline with no record of the reasoning.

Do this now

  1. Fix the awareness timestamp. Record when the organization became aware of a likely breach — that moment anchors every deadline, and regulators ask for it specifically.
  2. Get counsel in the loop. Privacy counsel — internal or external — owns the legal determination. Bringing them in late is how deadlines get missed and privilege gets lost.
  3. Map the applicable regimes. Whose data (which countries, which states), what kind (personal, health, financial), and what contracts promise. The map yields a concrete list of duties and deadlines.
  4. Run the risk assessment on real scope. What was actually accessed or taken, for whom, with what likely harm — from forensics, not assumption. This is what separates notifiable from not.
  5. Draft notices from facts. What happened, what data, what you are doing, what recipients should do. Written plainly and accurately; the phased approach lets you update as facts firm up.
  6. Keep the decision log. Every assessment, decision, and its timing — including decisions not to notify. That record is your defense if the judgment is ever questioned.

What not to do

  • Do not wait for the full forensic report if a clock expires first — notify in phases.
  • Do not blanket-notify everyone in panic; scope precision protects both the affected and you.
  • Do not let communications polish override legal accuracy in the notices.
  • Do not forget contractual duties — customer agreements often have tighter clocks than regulators.
  • Do not skip documenting a "no notification needed" conclusion; undocumented is indistinguishable from unconsidered.

Preserve the evidence

Whatever else happens, these are the artifacts the investigation — and any insurance claim, dispute, or prosecution — will be built from:

  • The awareness timestamp and how it was established.
  • The regime map and deadline list.
  • The risk assessment tied to forensic scope.
  • Copies of all notices sent and the decision log.

Keep a clear head

Notification decisions get made under the twin fears of saying too much and too little. The stabilizer is sequence: facts from scoping, law from counsel, decisions on the record, updates as knowledge improves. Regulators consistently treat honest, documented, phased notification better than polished silence.

Questions victims ask

Does every breach have to be reported?

No. Most regimes trigger on risk to individuals — a breach of encrypted data with the keys safe, for instance, often carries no duty. The obligation that always exists is doing and recording the assessment.

We are past 72 hours and only just found out the scope. Are we sunk?

The clock ran from awareness, so document what was known when, notify now with the reason for the timing, and supply the rest in phases. A late, well-documented notice with a credible explanation is a defensible position; hoping nobody asks is not.

Data subjects in multiple countries — do we notify each regulator?

Potentially several, though mechanisms like GDPR's lead-authority system consolidate the EU side. The multi-jurisdiction map is precisely the piece counsel builds first — it is tedious exactly once, and then it is your template.

When the first hour is over, we take it from there.

Scoping, containment, forensics, and recovery — expert-led and evidence-safe, with AI removing the waiting. Engage a responder or talk to us about readiness.