Skip to content

Notification Trigger

Definition

The threshold condition that activates a legal notification obligation. Under GDPR the trigger is any personal data breach that poses a risk to individuals; below-risk breaches must be documented internally but not reported. Under many US state laws, the trigger is unauthorised access to defined categories of personal information without a risk qualification.

GDPR trigger
Any personal data breach posing risk to individuals
GDPR below-risk case
Must be logged internally, not reported externally
Typical US state trigger
Unauthorised access to defined categories of personal information
Key difference
US triggers often apply without a separate risk assessment step

Common questions

Why does the difference in triggers matter for a multinational breach response?+

An organisation with data subjects in the EU and multiple US states may need to run a GDPR risk assessment for one population while simultaneously applying a stricter, access-based test for another, so the same incident can require notification in one jurisdiction and only internal logging in another.

Who decides whether a breach crosses the GDPR risk threshold?+

The data controller makes the initial risk assessment, but that judgment can later be reviewed by the relevant supervisory authority, which is why organisations document the reasoning behind a decision not to notify.

Related terms

Covered Entity / Business Associate
Terms used in the US HIPAA framework. Covered entities are healthcare providers, health plans, and healthcare clearinghouses. Business Associates are contractors that...
Data Fiduciary
The term used in India's Digital Personal Data Protection Act 2023 for an entity that determines the purpose and means of processing...
Personal Data Breach
Under GDPR, a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal...
Safe Harbour (Encryption)
A provision in many breach notification frameworks that exempts organisations from individual notification obligations if the breached data was encrypted and the...
Supervisory Authority
The national data protection regulator responsible for enforcing GDPR in a given EU member state, such as the UK Information Commissioner's Office...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.