The hardest part of incident notification is not writing the report — it is that several obligations run simultaneously, to different recipients, measured from different moments. This matrix puts them side by side so the differences are visible before an incident rather than during one.
| Regime | Who is told | Deadline | Clock starts at |
|---|---|---|---|
| GDPR / UK GDPR | Data protection authority; individuals if high risk | 72 hours | Becoming aware of a personal data breach |
| NIS2 | Competent authority / CSIRT | Early warning 24h; notification 72h; final report 1 month | Becoming aware of a significant incident |
| DORA | Competent authority | Initial, intermediate and final reports on staged deadlines | Classification as a major ICT incident |
| SEC (US listed) | Public filing | 4 business days | Determination that the incident is material |
| NYDFS Part 500 | Regulator | 72 hours | Determining a reportable event occurred |
| NCA (Saudi) | National authority | Short, sector-dependent | Detection of the incident |
| Saudi PDPL | Authority; individuals where required | Prescribed period | Awareness of the breach |
| Customer contracts | The customer | Frequently 24–48 hours | Usually awareness, as defined in the contract |
Read the last row again. Contractual deadlines are routinely shorter than every regulatory one, and unlike regulation you negotiated them. Teams that plan around 72 hours discover on day one that a customer notification was due yesterday.
The trigger is the real difference
Deadlines get quoted; triggers decide behaviour. Three distinct patterns appear above:
- Awareness (GDPR, NIS2, PDPL) — you may take a short period to establish that a breach occurred, but you may not defer indefinitely by not deciding.
- Determination (SEC, DORA, NYDFS) — the clock starts when you conclude the incident is material or major. That determination must itself be made without unreasonable delay, so slowness in deciding is its own exposure.
- Detection (several national regimes) — the tightest, because it starts before you understand what happened.
Map obligations to the systems they cover
GRC Copilot keeps regulatory and contractual obligations mapped against the data and systems they apply to, so the notification question is answered from a register.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Building one process
- Maintain a notification matrix listing every obligation that could apply to you, with recipient, deadline, trigger, channel and who is authorised to file.
- Register the portals in advance. Several require accounts and credentials, and creating them at hour 60 is a predictable failure.
- Design for partial information. Every regime above permits or expects supplementing an initial report. Waiting for a complete picture is the more common breach.
- Operate to the shortest applicable clock as your working assumption, and let slower obligations follow.
- Separate the decision from the response. Materiality and notifiability are legal determinations informed by security, not calls for the responder at 3am.
- Record what you decided not to report, with reasoning. Regulators examine that register.
Track it across suppliers too
When a supplier is breached, your clock starts when you become aware — so their contractual notification deadline directly determines whether you can meet yours. A supplier with a 72-hour clause leaves you with no time at all. This is why supplier breach notification is worth negotiating hard.
Frequently asked questions
Are the 72 hours business days?
Calendar hours under GDPR-style regimes, including weekends. The SEC deadline is expressed in business days, which is unusual.
Can we delay the clock by not determining materiality?
No. Where a regime keys on determination, that determination must be made without unreasonable delay.
What if several regimes apply at once?
They all apply. Work to the shortest, notify with what you know, and supplement each on its own timeline.
Does encryption remove the duty?
Under several privacy regimes it can remove the duty to notify individuals where data was unintelligible and keys uncompromised. Regulator notification duties often still apply.
Key takeaways
- Contractual deadlines are usually the shortest and are the ones you agreed to.
- Triggers differ — awareness, determination and detection are not the same moment.
- Register portals in advance and design to file with partial facts.
- Your supplier's notification clause determines whether you can meet your own.