CISO Tribune

Analysis

Breach notification timelines: the clocks that start when you're breached

The major breach notification deadlines compared — GDPR's 72 hours, the SEC's four business days, NYDFS, NIS2, and US state laws — and how to run them in parallel.

By CISO Tribune Editorial · Published May 26, 2026 · 2 min read

TL;DR: A serious incident starts several regulatory clocks at once, each with a different trigger, deadline, and audience: GDPR's 72 hours to a data-protection authority, NIS2's 24-hour early warning, the SEC's four business days from materiality, NYDFS's 72 hours to the superintendent, and a patchwork of state laws for individuals. The operational answer is a notification matrix built before the incident — because during one, there's no time to research who must hear what by when.

What are the major clocks?

GDPR (EU/UK): notify the supervisory authority without undue delay, within 72 hours where feasible, of becoming aware of a personal data breach; document everything even when not notifying; tell affected individuals without undue delay if the risk to them is high.

NIS2 (EU, covered sectors): early warning to the authority within 24 hours of awareness of a significant incident, fuller notification within 72 hours, final report within a month — as transposed by each member state.

SEC (US public companies): Form 8-K Item 1.05 within four business days of determining the incident is material. The determination — not discovery — starts the clock, but must be made without unreasonable delay.

NYDFS Part 500 (NY financial services): notice to the superintendent within 72 hours of determining a covered cybersecurity event occurred, with specific ransomware and extortion-payment provisions.

US state laws: all 50 states require notifying affected individuals (and often attorneys general) of breaches of defined personal information, with deadlines ranging from "most expedient time possible" to fixed day counts. Sectoral rules — HIPAA for health data, GLBA-related rules for banking — layer on top, as do contractual notice obligations to enterprise customers, which are often the shortest clocks of all.

Why do the triggers matter as much as the deadlines?

Because they differ. GDPR runs from awareness of a personal data breach; the SEC from a materiality determination; NYDFS from determination of a covered event; contracts often from discovery. A single incident can be reportable under one regime and not another, and the same facts can start clocks days apart. This is why the incident log with timestamps — when discovered, when escalated, when each determination was made — is not bureaucracy; it's the evidence that each clock was honored.

How do you run five clocks at once?

Three structures, built in peacetime. The notification matrix: one table — regulator/party, trigger, deadline, content required, filing mechanism, owner — covering every jurisdiction and major contract you touch, maintained by counsel and reviewed annually. The determination committee: a standing group (legal, CISO, CFO, communications) with criteria and authority to make the GDPR-awareness, SEC-materiality, and state-law calls, minuted. Pre-drafted skeletons: the 8-K, the DPA notification, the customer notice — written calmly in advance, blanks for facts. Companies that notify well aren't faster investigators; they've simply already answered every question except the ones only the incident can answer.

Frequently asked questions

How fast must a breach be reported under GDPR?
A personal data breach must be notified to the supervisory authority without undue delay and, where feasible, within 72 hours of the controller becoming aware of it — with affected individuals notified without undue delay when the breach poses a high risk to them.
What is the SEC's breach disclosure deadline?
Public companies must file Form 8-K Item 1.05 within four business days of determining a cybersecurity incident is material — a clock that starts at the materiality determination, which itself must be made without unreasonable delay.
Do all US states have breach notification laws?
Yes — all 50 states, plus DC and territories, have breach notification statutes, with varying definitions, thresholds, and deadlines. Multi-state incidents typically trigger many of them at once, which is why counsel runs a state-by-state analysis.

CISO Tribune Editorial

Editorial Desk

The CISO Tribune editorial desk reports on security leadership: who holds the role, who is leaving it, and what the moves mean. Every appointment entry is verified against a primary source before publication.