πŸ†˜ Emergency Guide Β· πŸ”΄ High Urgency

Customer Data Breach Response

Customer data has been exposed β€” names, emails, payment information, or worse. Multiple laws require you to notify affected individuals and regulators within specific timeframes. Here is your checklist.

🚨 THE CLOCK IS TICKING

GDPR requires notification within 72 hours. HIPAA gives you 60 days to notify individuals. Most US state laws require 30-60 days. Failure to notify multiplies penalties. Start the clock.

Step 1: Contain and Stop the Breach

You cannot notify customers while the breach is still happening. Close the vulnerability, reset compromised credentials, isolate affected systems, and stop additional data exfiltration before you move to notification. Document everything you do β€” regulators will ask for this log.

Step 2: Determine What Was Exposed and Who Is Affected

This is the most important investigation step. Work with your IT provider or a forensics firm to determine:

  • β€’ What data types were exposed (names, emails, SSNs, payment cards, health info, passwords)
  • β€’ How many individuals are affected β€” this determines which regulations are triggered
  • β€’ When the breach occurred β€” notification deadlines are based on discovery date
  • β€’ How the breach happened β€” this determines your remediation steps
  • β€’ Whether the data was encrypted β€” most laws exempt encrypted data from notification requirements

Step 3: Determine Which Laws Apply

LawDeadlineNotify RegulatorNotify IndividualsApplicable If
GDPR72 hoursβœ… DPAIf high riskEU/UK residents' data
CCPAAs soon as possibleβœ… AGβœ…California residents
HIPAA60 daysβœ… HHS OCRβœ…PHI exposure
State Laws30-60 daysVariesβœ…Residents of each state
PDPA (SG)As soon as practicableβœ… PDPCIf significant harmSingapore residents

Compliance Toolkit: Breach Notification Templates

Ready-to-use notification letter templates for GDPR, CCPA, HIPAA, and state law breaches. Plus a regulatory gap analysis worksheet.

View Compliance Toolkit β†’

Step 4: Notify Affected Individuals

Your notification must include (at minimum):

  • β€’ A clear description of what happened
  • β€’ What types of data were involved
  • β€’ What you are doing about it
  • β€’ What the affected person should do (monitor credit reports, change passwords, enable MFA)
  • β€’ Your contact information for questions
  • β€’ Whether you are offering credit monitoring (required by some state laws for SSN breaches)

Notification method: written notice (letter or email). Substitute notice (website posting + media) is allowed when contact information is unavailable or the number of affected individuals makes individual notice unreasonably expensive.

Step 5: Notify Regulators

GDPR: Notify your lead EU Data Protection Authority within 72 hours via their online portal. For UK GDPR, notify the ICO. If you miss the 72-hour deadline, explain why β€” do not skip notification just because you are late.

HIPAA: If 500+ individuals affected, notify HHS OCR immediately and local media. If fewer than 500, log it and report in your annual breach summary.

CCPA: Notify the California AG. No specific deadline stated but "most expedient time possible" is interpreted as within days to weeks.

State Laws: Check requirements in every state where affected individuals reside. Most require AG notification, some require credit reporting agency notification for large breaches.

Step 6: Post-Incident β€” Prevent It from Happening Again

  1. 1. Root cause analysis. How did this happen? What control failed? Document thoroughly for regulators and insurance.
  2. 2. Update your security program. Close the vulnerability. Strengthen the controls that failed.
  3. 3. Review your incident response plan. What worked? What did not? Update the plan based on what you learned.
  4. 4. Retrain staff. If human error was involved, train on what went wrong β€” without blame.
  5. 5. Engage legal counsel. Data breach class-action lawsuits are increasingly common. Have a lawyer review your response.