π¨ THE CLOCK IS TICKING
GDPR requires notification within 72 hours. HIPAA gives you 60 days to notify individuals. Most US state laws require 30-60 days. Failure to notify multiplies penalties. Start the clock.
Step 1: Contain and Stop the Breach
You cannot notify customers while the breach is still happening. Close the vulnerability, reset compromised credentials, isolate affected systems, and stop additional data exfiltration before you move to notification. Document everything you do β regulators will ask for this log.
Step 2: Determine What Was Exposed and Who Is Affected
This is the most important investigation step. Work with your IT provider or a forensics firm to determine:
- β’ What data types were exposed (names, emails, SSNs, payment cards, health info, passwords)
- β’ How many individuals are affected β this determines which regulations are triggered
- β’ When the breach occurred β notification deadlines are based on discovery date
- β’ How the breach happened β this determines your remediation steps
- β’ Whether the data was encrypted β most laws exempt encrypted data from notification requirements
Step 3: Determine Which Laws Apply
| Law | Deadline | Notify Regulator | Notify Individuals | Applicable If |
|---|---|---|---|---|
| GDPR | 72 hours | β DPA | If high risk | EU/UK residents' data |
| CCPA | As soon as possible | β AG | β | California residents |
| HIPAA | 60 days | β HHS OCR | β | PHI exposure |
| State Laws | 30-60 days | Varies | β | Residents of each state |
| PDPA (SG) | As soon as practicable | β PDPC | If significant harm | Singapore residents |
Compliance Toolkit: Breach Notification Templates
Ready-to-use notification letter templates for GDPR, CCPA, HIPAA, and state law breaches. Plus a regulatory gap analysis worksheet.
View Compliance Toolkit βStep 4: Notify Affected Individuals
Your notification must include (at minimum):
- β’ A clear description of what happened
- β’ What types of data were involved
- β’ What you are doing about it
- β’ What the affected person should do (monitor credit reports, change passwords, enable MFA)
- β’ Your contact information for questions
- β’ Whether you are offering credit monitoring (required by some state laws for SSN breaches)
Notification method: written notice (letter or email). Substitute notice (website posting + media) is allowed when contact information is unavailable or the number of affected individuals makes individual notice unreasonably expensive.
Step 5: Notify Regulators
GDPR: Notify your lead EU Data Protection Authority within 72 hours via their online portal. For UK GDPR, notify the ICO. If you miss the 72-hour deadline, explain why β do not skip notification just because you are late.
HIPAA: If 500+ individuals affected, notify HHS OCR immediately and local media. If fewer than 500, log it and report in your annual breach summary.
CCPA: Notify the California AG. No specific deadline stated but "most expedient time possible" is interpreted as within days to weeks.
State Laws: Check requirements in every state where affected individuals reside. Most require AG notification, some require credit reporting agency notification for large breaches.
Step 6: Post-Incident β Prevent It from Happening Again
- 1. Root cause analysis. How did this happen? What control failed? Document thoroughly for regulators and insurance.
- 2. Update your security program. Close the vulnerability. Strengthen the controls that failed.
- 3. Review your incident response plan. What worked? What did not? Update the plan based on what you learned.
- 4. Retrain staff. If human error was involved, train on what went wrong β without blame.
- 5. Engage legal counsel. Data breach class-action lawsuits are increasingly common. Have a lawyer review your response.