ALL ARTICLES
DATA PROTECTION

The 72-hour rule in data breach notification and practical obligations

BY Logo Law 24 Jun 2026 6 min read
The 72-hour rule in data breach notification and practical obligations

When a personal data breach occurs, the most valuable resource is time — and there is very little of it. The obligation to notify the authority without undue delay, and in any event within a tight window, means the decisions you make in the first hours shape your entire legal exposure.

The clock starts at awareness

The notification window begins when the organisation becomes aware of the breach, not when it is fully investigated. This is widely misunderstood. You are expected to notify on the basis of what is reasonably known, and to supplement as facts develop — silence while you investigate is not a safe option.

What the notification must contain

At minimum, the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed. Where affected individuals face high risk, they too must be informed in clear, plain language.

Preparation beats reaction

The organisations that handle breaches well are those that prepared before one occurred: a written incident-response plan, defined roles, pre-drafted notification templates and a tested escalation path. When the clock is running, you do not want to be writing the process from scratch.

How we help

We help organisations build breach-response frameworks and act as rapid counsel when an incident occurs. If you would like your response plan reviewed — or need help right now — reach out immediately.

SHARE
FREE INITIAL CONSULTATION

Let's assess your case together and map out the right path.

In person, by phone or by email — reach us through the channel that suits you best. Our first meeting is always free.