Back to blog
Comparisons

Incident reporting deadlines compared: GDPR, NIS2, DORA, SEC, NCA and PDPL

One incident can start half a dozen clocks running to different regulators on different triggers. A side-by-side matrix of who must be told, how fast, and from what moment the clock starts.
GRC Copilot Team
Incident reporting deadlines compared: GDPR, NIS2, DORA, SEC, NCA and PDPL

The hardest part of incident notification is not writing the report — it is that several obligations run simultaneously, to different recipients, measured from different moments. This matrix puts them side by side so the differences are visible before an incident rather than during one.

RegimeWho is toldDeadlineClock starts at
GDPR / UK GDPRData protection authority; individuals if high risk72 hoursBecoming aware of a personal data breach
NIS2Competent authority / CSIRTEarly warning 24h; notification 72h; final report 1 monthBecoming aware of a significant incident
DORACompetent authorityInitial, intermediate and final reports on staged deadlinesClassification as a major ICT incident
SEC (US listed)Public filing4 business daysDetermination that the incident is material
NYDFS Part 500Regulator72 hoursDetermining a reportable event occurred
NCA (Saudi)National authorityShort, sector-dependentDetection of the incident
Saudi PDPLAuthority; individuals where requiredPrescribed periodAwareness of the breach
Customer contractsThe customerFrequently 24–48 hoursUsually awareness, as defined in the contract
Read the last row again. Contractual deadlines are routinely shorter than every regulatory one, and unlike regulation you negotiated them. Teams that plan around 72 hours discover on day one that a customer notification was due yesterday.

The trigger is the real difference

Deadlines get quoted; triggers decide behaviour. Three distinct patterns appear above:

  • Awareness (GDPR, NIS2, PDPL) — you may take a short period to establish that a breach occurred, but you may not defer indefinitely by not deciding.
  • Determination (SEC, DORA, NYDFS) — the clock starts when you conclude the incident is material or major. That determination must itself be made without unreasonable delay, so slowness in deciding is its own exposure.
  • Detection (several national regimes) — the tightest, because it starts before you understand what happened.

Map obligations to the systems they cover

GRC Copilot keeps regulatory and contractual obligations mapped against the data and systems they apply to, so the notification question is answered from a register.

Building one process

  1. Maintain a notification matrix listing every obligation that could apply to you, with recipient, deadline, trigger, channel and who is authorised to file.
  2. Register the portals in advance. Several require accounts and credentials, and creating them at hour 60 is a predictable failure.
  3. Design for partial information. Every regime above permits or expects supplementing an initial report. Waiting for a complete picture is the more common breach.
  4. Operate to the shortest applicable clock as your working assumption, and let slower obligations follow.
  5. Separate the decision from the response. Materiality and notifiability are legal determinations informed by security, not calls for the responder at 3am.
  6. Record what you decided not to report, with reasoning. Regulators examine that register.

Track it across suppliers too

When a supplier is breached, your clock starts when you become aware — so their contractual notification deadline directly determines whether you can meet yours. A supplier with a 72-hour clause leaves you with no time at all. This is why supplier breach notification is worth negotiating hard.

Frequently asked questions

Are the 72 hours business days?

Calendar hours under GDPR-style regimes, including weekends. The SEC deadline is expressed in business days, which is unusual.

Can we delay the clock by not determining materiality?

No. Where a regime keys on determination, that determination must be made without unreasonable delay.

What if several regimes apply at once?

They all apply. Work to the shortest, notify with what you know, and supplement each on its own timeline.

Does encryption remove the duty?

Under several privacy regimes it can remove the duty to notify individuals where data was unintelligible and keys uncompromised. Regulator notification duties often still apply.

Key takeaways

  • Contractual deadlines are usually the shortest and are the ones you agreed to.
  • Triggers differ — awareness, determination and detection are not the same moment.
  • Register portals in advance and design to file with partial facts.
  • Your supplier's notification clause determines whether you can meet your own.
#incident-reporting #deadlines #gdpr #nis2 #dora #sec #nca #pdpl #matrix