The 72-hour rule in data breach notification and practical obligations
When a personal data breach occurs, the most valuable resource is time — and there is very little of it. The obligation to notify the authority without undue delay, and in any event within a tight window, means the decisions you make in the first hours shape your entire legal exposure.
The clock starts at awareness
The notification window begins when the organisation becomes aware of the breach, not when it is fully investigated. This is widely misunderstood. You are expected to notify on the basis of what is reasonably known, and to supplement as facts develop — silence while you investigate is not a safe option.
What the notification must contain
At minimum, the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed. Where affected individuals face high risk, they too must be informed in clear, plain language.
Preparation beats reaction
The organisations that handle breaches well are those that prepared before one occurred: a written incident-response plan, defined roles, pre-drafted notification templates and a tested escalation path. When the clock is running, you do not want to be writing the process from scratch.
How we help
We help organisations build breach-response frameworks and act as rapid counsel when an incident occurs. If you would like your response plan reviewed — or need help right now — reach out immediately.
Keep reading
Let's assess your case together and map out the right path.
In person, by phone or by email — reach us through the channel that suits you best. Our first meeting is always free.