Skip to content

Breach Notification

Definition

The legal obligation to inform regulators and affected individuals when personal data is compromised in a security incident. Timelines and thresholds differ by jurisdiction: 72 hours under GDPR, 60 days under HIPAA Breach Notification Rule for covered entities, and similar windows under the India DPDPA 2023.

Field
Data protection and incident response law
GDPR window
72 hours to the regulator
HIPAA window
60 days for covered entities
India equivalent
Similar window under DPDPA 2023

Common questions

Who decides whether a breach notification is actually required after an incident?+

Most laws set a risk-based trigger, requiring notification only when the breach is likely to result in harm to affected individuals, such as identity theft or financial loss, so the incident response team typically performs a documented risk assessment before deciding to notify.

What happens if an organisation misses its breach notification deadline?+

Regulators can impose fines or other enforcement action for late or absent notification independent of any penalty for the breach itself, which is why incident response plans build the notification clock into their timeline from the moment a breach is confirmed.

Does breach notification law require notifying the affected individuals as well as the regulator?+

Most frameworks require both, though the individual-notification threshold is often higher than the regulator-notification threshold, reserving direct notice to people for breaches assessed as posing a meaningful risk to them.

Related terms

Chain of Custody
The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
Dwell Time
The period between an attacker gaining initial access and their detection. Reducing dwell time is a primary goal of threat hunting. The...
Forensic Readiness
The organisational state in which people, processes, and technology are prepared to collect and preserve digital evidence with minimum disruption to business...
Incident Response (IR)
The organised methodology for handling and managing the aftermath of a security breach or cyberattack. IR encompasses preparation, detection, containment, eradication, recovery,...
Incident Ticket
The structured record opened in an IT service management or case management system when an alert is escalated to an incident. It...
Lessons-Learned Report
A post-incident review document identifying what succeeded, what failed, the root cause, and specific recommended changes to policy, tooling, or training. Produced...
Post-Incident Report
The formal written account produced after an incident is closed. It synthesises the timeline log into a structured narrative covering the incident...
Proportionality
The legal principle, central to European human rights law and to many constitutional systems, that any interference with a fundamental right must...
Timeline Log
A chronological, append-only record capturing every analyst action and finding during the response, time-stamped at the moment of entry in UTC. It...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.