Cloud Privacy Standard Global

Privacy Breach Incident Response: The First 72 Hours

How to run privacy-breach response: detection to containment, the risk assessment that drives notification, GDPR's 72-hour clock against the US state patchwork, evidence discipline, and the drills that matter.

Regulation

GDPR Articles 33-34 (72-hour authority notification, individual notice for high risk); all 50 US state breach laws; HIPAA Breach Notification Rule; SEC 8-K materiality disclosure; NIS2, DORA, and sectoral overlays

Max Penalty

GDPR notification failures reach 10 million EUR or 2% of turnover (the substantive breach can hit the 4% tier); state laws add per-resident penalties; delayed or misleading disclosure has produced securities enforcement and executive liability

Enforcing Authority

Data protection authorities, state attorneys general, HHS OCR, the SEC for public companies, and sectoral regulators, often simultaneously for one incident

Official Source

ec.europa.eu

Executive Summary

  • A personal-data breach starts multiple legal clocks at once: GDPR's 72 hours to the authority, HIPAA's 60 days, state timelines from 'without unreasonable delay' to 30-45 day caps, and the SEC's four business days from materiality for public companies.
  • The clocks start at awareness, not at full understanding, and regulators accept phased notification; the unforgivable version is the one that arrives months late because the team wanted certainty first.
  • Notification decisions hang on a structured risk assessment (data types, volume, exposure, mitigations like encryption), which must be documented even when the conclusion is 'no notification required.'
  • The recurring enforcement themes are delay, minimization, and poor records: Uber's concealed 2016 breach produced a criminal conviction for its CSO; the ICO and DPAs routinely fine the response, not just the intrusion.
  • Preparedness is the whole game: a tested plan, a pre-briefed decision chain, breach-counsel and forensics retainers, notification templates, and tabletop exercises that include the privacy clock, not just the technical kill chain.

Breach response is the only privacy discipline conducted entirely under adversarial time pressure with incomplete information and the certainty of hindsight review. Its core paradox: the legal clocks demand decisions before the facts are knowable, and the enforcement record punishes waiting for certainty far more harshly than it punishes good-faith wrongness, so the winning posture is structured provisionality, notify on reasonable belief, phase in the details, log every judgment, refresh as facts land. Everything that makes the first 72 hours survivable is built earlier: the map that answers the scoping questions, the retainers that answer the phone, the templates that answer the regulators, and the drills that mean nobody is reading the plan for the first time while the clock runs. The organizations that emerge intact are rarely the best-defended; they are the best-rehearsed.

The clocksGDPR 72h (authority) + individual notice for high risk; states to 30-45d caps; HIPAA 60d; SEC 4 business days
Clock startsAt awareness, not at forensic certainty; phased notification is accepted
What gets finedDelay, minimization, missing records, and the Article 32 failures the breach reveals
Landmark casesUber (CSO convicted), Yahoo ($35M SEC), Marriott/BA (ICO), Meta (DPC)
GuidanceWP29/EDPB breach notification guidelines

Building readiness

Have the map ready. Data mapping and inventory answers the first day’s scoping questions.

Know the matrices. Global breach notification rules and the breach notification playbook cover the per-regime mechanics.

Mind the vendor chain. Vendor risk assessments put notification clocks into the contracts you will need.

Sector overlays. The HIPAA breach playbook covers the health-data variant.

Exposed data flows are breach surface: find what your website leaks to third parties before an incident makes it relevant, with a free scan.

Frequently Asked Questions

What legally counts as a breach, and when do the clocks start?

GDPR Article 4(12) defines a personal data breach as a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data, wider than intrusion: the misdirected email, the lost laptop, the ransomware encryption of records (availability counts), the employee snooping, the bucket left public all qualify. US state laws define breach around unauthorized acquisition (sometimes access) of specified categories, name plus SSN, driver's license, financial account, increasingly health, biometric, and login credentials, with definitions and categories varying by state, which is why a fifty-state analysis accompanies any consumer breach. HIPAA presumes an impermissible use or disclosure of PHI is a breach unless a documented four-factor assessment shows low probability of compromise. The clocks: GDPR, notification to the supervisory authority without undue delay and where feasible within 72 hours of becoming aware, awareness meaning reasonable certainty a breach occurred, not completed forensics, with the WP29/EDPB guidance blessing phased submissions (initial within 72 hours, supplements as facts develop) and requiring documented justification for anything later; individuals get notice without undue delay when the breach poses a high risk to them (Article 34). US states: 'most expedient time possible' with hard caps in many (30 days in Colorado and Florida, 45 in several others), AG or regulator copies above thresholds, and consumer-reporting-agency notice at scale. HIPAA: individuals within 60 days of discovery, HHS within 60 days (immediately for 500+, with media notice in affected regions). Public companies: SEC Form 8-K Item 1.05 within four business days of determining materiality, a determination that cannot be unreasonably delayed. Processors and vendors have their own clocks to you: GDPR Article 33(2) says without undue delay, and well-drafted DPAs specify 24-72 hours, which is why the vendor-notification term you negotiated years ago becomes the most-read sentence in the contract.

What should the first 72 hours actually look like?

Hour zero to four, stabilize and convene: the detecting team escalates per the plan's severity matrix (privacy-relevant indicators, personal data possibly involved, trigger the privacy track, not just the security one), the incident commander convenes the core cell (security lead, privacy counsel, the DPO where one exists, communications, the affected business owner), and, decision one, counsel establishes privilege framing for the investigation and engages breach counsel and forensics from the retainer list; containment starts in parallel (isolate, revoke, patch, preserve), with the standing tension, kill the attacker's access without destroying the evidence, resolved by forensics guidance, not improvisation. Hours four to twenty-four, scope and preserve: what systems, what data categories, roughly how many subjects, which jurisdictions (residency of affected individuals drives the legal matrix), what exposure mode (exfiltrated, accessed, encrypted, exposed), against the data map, which is the difference between answering these questions from inventory and answering them from archaeology; evidence preservation is formalized (images, logs with their retention clocks checked before they rotate, chain of custody), and the notification-analysis workstream starts drafting the regulator matrix while facts are still arriving. Hours twenty-four to seventy-two, decide and notify: the risk assessment (next question) produces notify/no-notify positions per regime; where GDPR applies and the threshold is met, the Article 33 notification files inside the window with what is known (nature, categories and approximate numbers, DPO contact, likely consequences, measures taken and proposed), explicitly phased; simultaneous tracks handle law enforcement liaison (which can justify delaying individual notice in some regimes, never the GDPR authority notice), vendor and customer contractual notices (your B2B customers' DPAs have clocks too, and if you are the processor, your notification duty runs to controllers now), insurance carrier notice per policy terms, and holding-statement communications. Throughout: a decision log, timestamped, who decided what on what information, because the response will be judged in hindsight and the log is the proof the judgment was reasonable at the time.

How does the notification risk assessment work?

Two thresholds under GDPR, likelihood of risk (Article 33, authority notice, unless the breach is 'unlikely to result in a risk') and high risk (Article 34, individual notice), assessed on factors the EDPB guidance structures: nature and sensitivity of the data (credentials, financial, health, special categories, children's data all escalate; pseudonymized or robustly encrypted data with keys uncompromised de-escalates, the encryption safe harbor most state laws mirror); volume and identifiability; exposure mode and audience (published on a leak site is not the same as briefly misdirected to one known recipient who confirms deletion, the 'trusted recipient' mitigation the guidance recognizes); ease of identification and potential consequences (identity theft, fraud, discrimination, physical safety for location or shelter data, reputational harm for intimate data); and mitigating measures taken after the fact (credential resets, card reissuance, the attacker's access window). HIPAA's four factors run the same analysis in different clothes. The discipline points: document the assessment even when concluding no notification, Article 33(5) requires records of all breaches, including the reasoning for the ones you did not report, and the DPA's first request in any later dispute is that register; do not let the desire for a no-notify conclusion write the analysis, the recurring enforcement pattern is a strained 'low risk' assessment that reads terribly next to what the forensics later showed; and where the call is close, notify, under-notification carries fines and the record shows over-notification essentially never does. One more clock inside the clock: as facts develop (forensics discovers the exfiltration was larger), the assessment refreshes, and a no-notify position can flip weeks in, which is legally fine if the record shows diligence and looks like concealment if it does not.

What do regulators actually punish in breach response?

The enforcement record is remarkably consistent: the response gets punished at least as often as the intrusion. Delay: Uber's 2016 breach, concealed for a year and dressed as a bug bounty, produced a $148 million multistate settlement and, singularly, a federal criminal conviction of its chief security officer (2022) for obstruction, the case every incident commander should know by name; Yahoo's delayed disclosure produced a $35 million SEC penalty and securities litigation; the ICO's Interserve fine (4.4 million GBP) and the Irish DPC's Meta breach fines cite response and security failures together. Minimization and misstatement: SEC actions against companies whose disclosures downplayed known facts (the First American and Pearson orders) established that a breach statement is a securities statement; state AGs pursue the same theory under consumer-protection law. Poor records: DPAs asking for the Article 33(5) breach register and the risk assessments behind non-notifications, and finding neither, converts a defensible judgment call into an accountability violation. Security failures revealed by the breach: the fine often lands on Article 32 (the measures that should have prevented or contained), Marriott's 18.4 million GBP and British Airways' 20 million GBP ICO fines were framed as security-failure penalties surfaced by breaches, and HHS OCR resolution agreements read the same way. Repeat findings across these cases: unencrypted data that the safe harbor would have shielded; logs that had rotated before forensics arrived (retention set for cost, not investigation); vendor breaches where the contract had no notification clock and the controller learned from the press; and communications that promised more certainty than existed ('no evidence of misuse' as the first line, contradicted by week three). The composite lesson: regulators forgive being breached and do not forgive responding badly, and 'badly' is measured almost entirely by speed, candor, and paperwork.

What does real preparedness look like, beyond having a plan document?

The artifacts that matter, in the order they get used. A plan someone can execute at 2 a.m.: severity matrix with privacy triggers, role assignments by function with named deputies, the decision chain for notification calls (who can say 'notify' and who can say 'don't,' because the second is the dangerous power), escalation paths to executives and the board, and the first-24-hours checklist, short enough to actually follow. The retainer stack, engaged before any incident: breach counsel (privilege architecture and the fifty-state matrix are not learn-on-the-fly skills), forensics (retainer SLAs measured in hours; the first-response quality determines whether you ever know what happened), notification vendors for at-scale consumer notice (mail houses, call centers, credit monitoring, procured in advance because post-breach procurement is slow and price-gouged), and the cyber insurer's requirements woven in, many policies require using panel vendors and prompt notice, and coverage disputes over late carrier notification are a genre. Pre-positioned content: notification templates per regime (Article 33 form fields, state AG formats, HIPAA individual-notice content requirements), holding statements, customer-facing FAQs, all pre-cleared through legal so the 72-hour window is spent on facts, not wordsmithing. The data map and vendor register, current: every scoping question in the first day is a map query, and the vendor register with notification clauses is how you know who owes you notice and whom you owe. Drills that include the privacy clock: tabletops twice a year where the scenario forces the notification decision with incomplete facts (the realistic condition), including one vendor-breach scenario (you learn from a processor, late) and one where the first assessment is wrong and must flip; grade the drill on decision-log quality and clock performance, not on whether the fictional attacker was defeated. And the register discipline: every incident, including the near-misses and the no-notify conclusions, recorded with its assessment, because the register is simultaneously your Article 33(5) compliance, your trend data, and the proof, when the big one comes, that your judgment has a track record.

Regulatory Crosswalk

GDPR Articles 33-34state breach statutesHIPAA Breach Notification RuleNIST SP 800-61ISO/IEC 27035

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.