Complete Guide: Data Breach Response Timeline and Legal Requirements

There’s no single deadline for reporting a data breach. That’s the part most guides skip. Depending on who’s affected, where they live, and what industry you’re in, you could be working against a 72-hour clock, a 30-day clock, a 60-day clock, or a “without unreasonable delay” standard that has no fixed number attached to it at all. Get the wrong deadline and you’re not just late. You’re exposed to fines that stack by jurisdiction, and to a plaintiff’s attorney who now has a second cause of action beyond the breach itself.

This guide lays out the actual response timeline hour by hour, then breaks down what US federal law, state law, and GDPR each require and by when. It’s built for security leaders, legal counsel, and operators who need the real deadlines, not a vague reassurance that “prompt notification” is best practice. If your organization is still building out that response capability, cybersecurity services cover the monitoring and readiness work that sits underneath every deadline in this guide.

TL;DR

The clock starts at discovery, not at the attack. Nearly every law in this guide measures its deadline from the day the breach was discovered or reasonably should have been discovered, not from the day the intrusion happened. Get your discovery date right and documented, because it anchors every other deadline.

There’s no single US federal breach law. The United States regulates breach notification through a patchwork: state laws (50 states plus DC, each different), sector rules (HIPAA for health data, GLBA and the FTC Safeguards Rule for financial data, SEC rules for public companies), and, for anyone with EU data subjects, GDPR. A single breach can trigger 4 or 5 of these at once, each with a different deadline.

The fastest clocks are 72 hours (GDPR) and 4 business days (SEC materiality determination). The most common state standard is 30 to 45 days, though several states now hold to a fixed 30-day deadline. HIPAA gives covered entities up to 60 days. Missing any one of these can mean separate penalties, even if you hit every other deadline.

Why this timeline matters more than the breach itself

Security teams tend to treat a breach as a technical event: find the intrusion, contain it, fix it. Legal and compliance teams see something different. From the moment discovery happens, a set of independent, overlapping clocks start running, and each one has its own definition of “discovery,” its own recipient list, and its own penalty for lateness. A breach that’s technically resolved in 48 hours can still produce a legal violation months later if a notification letter went out on day 46 under a law that required day 30.

That’s the core problem this guide solves. The technical response and the legal response run on different timelines, and treating them as one process is where most organizations lose control. Calance’s write-up on why businesses of all sizes are now targets of cyber attacks covers the threat side of this problem in more depth.

The incident response timeline: hour by hour

Every legal deadline in this guide references “discovery,” so it’s worth being precise about what happens between discovery and the point where notification decisions get made. The technical response generally follows the National Institute of Standards and Technology’s incident handling model: preparation, detection and analysis, containment and eradication, and post-incident recovery. Here’s how that maps to the first 90 days.

Time windowWhat happensWho’s involved
Hour 0 to 1Detection confirmed. Incident declared. Response team activated. Evidence preservation begins.IT/security, incident commander
Hour 1 to 24Scope assessment starts. Short-term containment (isolating systems, blocking accounts, cutting network segments). Outside counsel and forensics engaged.Security, legal, forensics vendor
Hour 24 to 72Deeper forensic analysis. Initial determination of what data types and how many people are affected. GDPR’s 72-hour clock expires here if EU data subjects are involved.Legal, forensics, DPO if applicable
Day 3 to 10Long-term containment and eradication. Root cause identified. Legal maps which state, federal, and international laws apply based on affected residents.Legal, security, compliance
Day 10 to 30Notification drafting and review. AG filings prepared for states with a 30-day deadline. SEC materiality determination made if a public company. FTC Safeguards Rule 30-day clock expires here for financial institutions.Legal, communications, executive team
Day 30 to 60Remaining state notifications sent (45- and 60-day states). HIPAA’s 60-day deadline expires here for covered entities. Credit monitoring and call center stood up.Legal, communications, customer support
Day 60 to 90Media notification where required (HIPAA breaches over 500 individuals). Post-incident review begins. Regulatory follow-up inquiries handled.Legal, security, executive team

This isn’t a fixed script. A breach involving only 3 US states and no health, financial, or EU data might resolve its legal obligations by day 30. A breach touching health records, EU residents, and a public company’s investors runs every track at once, and the earliest deadline in the mix governs your actual working timeline, not the latest one. Calance’s overview of security operations centers walks through how continuous monitoring shortens the detection window that starts this whole clock.

Federal notification requirements: 4 different clocks

The United States has no general federal data breach notification law. Instead, notification duties come from sector-specific rules that apply based on the type of organization and the type of data. Here’s how the main ones compare.

FrameworkWho it coversDeadlineTriggering threshold
SEC Item 1.05 (Form 8-K)Public companies4 business days after determining an incident is materialAny incident determined material, regardless of headcount
HIPAA Breach Notification RuleCovered entities and business associates handling protected health information60 calendar days from discovery (individuals, HHS for breaches of 500+, media)Any breach of unsecured PHI, unless a 4-factor risk assessment shows low probability of compromise
FTC Safeguards Rule (GLBA)Non-bank financial institutions30 days from discovery, notice to the FTCUnauthorized acquisition of unencrypted data affecting 500 or more consumers
GDPR Article 33 and 34Any organization processing EU residents’ personal data72 hours to the supervisory authority; “without undue delay” to affected individuals if high riskAny breach likely to result in risk to rights and freedoms of natural persons

A few things worth calling out directly.

The SEC rule runs on materiality, not headcount. Item 1.05 of Form 8-K doesn’t care how many records were exposed. It cares whether a reasonable investor would consider the incident important to an investment decision. That determination has to happen “without unreasonable delay” after discovery, and once you’ve made it, the 4-business-day clock starts. Companies have been penalized for slow-walking that determination, not just for missing the filing deadline itself.

HIPAA’s 60 days is a ceiling, not a target. The rule’s actual requirements call for notification “without unreasonable delay,” and 60 days is the outer limit. Regulators have treated sitting on a known breach for weeks, even inside the 60-day window, as its own violation. Discovery under HIPAA is also broader than most people expect: the clock starts the day any workforce member or agent knew or should have known about the breach, not the day the compliance team found out. Calance’s guide to cybersecurity essentials for law firms covers a similar discovery-and-disclosure problem in a different regulated context.

The FTC Safeguards Rule only applies to non-bank financial institutions, think mortgage brokers, auto dealers that extend financing, and payday lenders, not the retail banks themselves, which fall under separate interagency guidance. The FTC’s own guidance confirms the rule requires notice to the FTC, not to individuals directly, though state law will almost always require the individual notice separately.

GDPR’s 72 hours starts at awareness, not at the end of your investigation. If you can’t have every detail ready in time, the rule allows phased notification: file what you know within 72 hours, then supplement as facts firm up. Waiting for a complete picture before filing anything is the most common way organizations blow this deadline.

State law: the real complexity

All 50 states and DC have their own breach notification statutes, and none of them are identical. There’s no federal preemption, so a breach touching residents in multiple states means complying with every applicable state law simultaneously, not just the strictest one, though in practice, building your response around the strictest deadline is the only workable approach.

Deadline standardStates (examples)Notes
30 days, fixedCalifornia (effective 2026), Colorado, Florida, WashingtonAmong the strictest deadlines in the country
45 days, fixedRhode Island, Ohio, Arizona, WisconsinSecond tier of fixed deadlines
60 days, fixedTexas, ConnecticutLonger fixed window, still a hard deadline
“Most expedient time possible, without unreasonable delay,” no fixed day countNew York, Illinois, Michigan, and roughly 20 othersNo numeric deadline, but regulators evaluate reasonableness case by case

A few practical points that matter more than the table.

Attorney general notification thresholds vary independently of the individual-notice deadline. Most states require AG notification once a breach crosses 250, 500, or 1,000 affected residents, and some, like New Jersey, require the AG to be notified before individuals are. Missing that sequencing is a separate violation from missing the individual notice.

“Unauthorized acquisition” and “unauthorized access” are not the same trigger. Most states only require notification when data was actually acquired by an unauthorized party. California and New York are among the states that also cover unauthorized access alone, even without confirmed acquisition, which means a broader set of incidents becomes reportable in those states.

California’s private right of action changes the incentive calculus. Under the CCPA, consumers can sue directly over a breach involving certain categories of unencrypted, unredacted personal information, with statutory damages of $100 to $750 per consumer, per incident, regardless of whether anyone can show actual harm. For a breach affecting 100,000 California residents, that’s a potential exposure range of $10 million to $75 million before a single regulatory fine or lawsuit for negligence is added on top.

Build a reference document before you need it. The organizations that move fastest during a real breach keep a standing table of every state’s timeline, covered data categories, and AG notification threshold, reviewed at least annually since these laws change often. Figuring this out for the first time during an active incident costs days you don’t have. A vulnerability assessment that maps where regulated data actually lives is a useful starting point for building that reference document.

What a compliant notification actually has to say

Most laws in this guide specify content requirements, not just deadlines, and a notice that’s timely but incomplete can still trigger a violation. Across state, federal, and GDPR frameworks, a defensible notification generally includes:

  • A plain description of what happened and when it was discovered.
  • The specific categories of personal information involved, not a vague reference to “data.”
  • What the organization is doing in response, including containment and remediation steps already taken.
  • Contact information for questions, and where required, information about credit monitoring or identity protection services being offered.
  • Contact details for relevant consumer reporting agencies, where state law requires it.

GDPR notifications to supervisory authorities carry additional required fields under Article 33(3): the nature of the breach, approximate numbers of people and records affected, the data protection officer’s contact information, likely consequences, and the measures taken or proposed to address them. If the 72-hour deadline is missed, the filing has to explain why.

Evidence preservation: the step most timelines skip

How an organization handles evidence in the first hours after discovery affects more than the technical investigation. It shapes legal exposure, insurance coverage, and the ability to later prove what the response team knew and when. Altering or destroying evidence, even by accident, such as wiping a compromised server before forensics has imaged it, can amount to spoliation, with real legal consequences independent of the breach itself.

A defensible evidence trail includes:

  • A timestamped incident log starting from the first sign of trouble, not from the moment the breach was confirmed.
  • Preserved system images and logs before any remediation touches affected systems.
  • A documented chain of custody for anything handed to outside forensics or law enforcement.
  • Records of every internal and external notification, including drafts and the dates they were sent.

This log is also what proves you met your notification deadlines if a regulator later questions the timeline. Without it, you’re asking an investigator to take your word for it. This is one of the areas where an outsourced SOC either earns its cost or doesn’t; Calance’s checklist for outsourcing your SOC lays out what a provider’s evidence-handling process should actually look like.

Multi-jurisdiction response: build for the hardest case, not the average one

If your organization has customers, employees, or users in more than one region, plan your response system around the most demanding combination of laws you could plausibly face, not the deadline that applies to your headquarters state. A few practices make that manageable.

Map your data footprint before an incident, not during one. Know where your customers and employees legally reside so you can identify which state, federal, and international laws apply the moment scope is understood.

Set escalation rules in advance. Security, legal, privacy, and communications each need to know who decides what and by when, written down before a breach, not negotiated during one. A CISO-as-a-service arrangement is one way organizations without a full-time security executive get this escalation structure in place before it’s needed.

Notify under the most stringent applicable standard when timelines conflict. If California gives you 30 days and Illinois has no fixed number, treat 30 days as your operating deadline across both, since it satisfies the stricter requirement without violating the looser one.

Separate the legal notification track from the operational response track. Containment and eradication can continue after notifications go out. Waiting for the technical fix to be complete before starting the legal clock is one of the most common ways organizations blow a fixed deadline. A zero trust architecture helps here too, since limiting lateral movement in advance narrows the scope question that both tracks depend on.

Common mistakes that turn a breach into a legal problem

Waiting for certainty before notifying anyone. Nearly every framework in this guide, including GDPR and most state laws, allows notification with an estimated scope, followed by supplemental updates as facts firm up. Waiting for a complete forensic picture before filing anything is the single most common way organizations blow a fixed deadline.

Treating “discovery” as the day executives found out. Under HIPAA and most state laws, discovery is imputed to the organization the moment any employee or agent knew or should have known, not the moment it reached the general counsel’s desk. A breach that sat unreported in a help desk ticket for 3 weeks doesn’t get the organization a 3-week extension.

Assuming encryption is an automatic safe harbor. Many state laws exempt encrypted data from notification requirements, but only if the encryption key wasn’t also compromised. The FTC Safeguards Rule makes this explicit: data is treated as unencrypted if an unauthorized party also accessed the key.

Notifying individuals before the AG in states that require the opposite sequence. New Jersey and a handful of other states require AG notification first. Getting the order backward is a separate violation from the deadline itself.

Skipping the media notification requirement. Under HIPAA, breaches affecting more than 500 people in a state or jurisdiction require notice to prominent media outlets in that area, not just to the affected individuals and HHS. This step gets missed more often than any other HIPAA requirement. Calance’s rundown of warning signs of a cyber attack you can’t ignore covers the detection failures that tend to precede these late, incomplete responses.

Penalties: what’s actually at stake by framework

  • State law: Penalties range widely, from roughly $100 to $750,000 or more per violation depending on the state, with some, like Florida, allowing fines up to $500,000 per breach. Class action exposure often exceeds the regulatory fine itself.
  • HIPAA: Civil penalties range from about $141 to over $2 million per violation category per year, depending on the level of negligence the Office for Civil Rights finds.
  • GDPR: Fines for notification failures under Article 83(4)(a) can reach 10 million euros or 2% of global annual turnover, whichever is higher.
  • SEC: Enforcement has focused less on the 4-day deadline itself and more on misleading or incomplete disclosures once a filing is made, with settled actions citing understated scope and severity as the core violation.
  • CCPA: Statutory damages of $100 to $750 per consumer, per incident, available through a private right of action, separate from any regulatory fine.

The financial picture behind these numbers is consistent across independent research: IBM’s Cost of a Data Breach report has repeatedly found that breaches involving extensive regulatory scrutiny and slow containment carry meaningfully higher total costs than incidents resolved quickly under a rehearsed response plan. Calance’s list of warning signs your outsourced SOC provider isn’t making the cut is worth a read if slow containment, not slow paperwork, is the actual risk driving up your exposure.

If your organization is building or testing its own response plan, Calance’s team can walk through the monitoring, escalation, and compliance work that makes these deadlines achievable rather than theoretical, and Calance’s small business guide to a cybersecurity plan that actually works is a solid starting point for organizations without a dedicated security team yet.

Frequently asked questions

What is the deadline for reporting a data breach? 

It depends on which law applies. GDPR requires notice to the supervisory authority within 72 hours of awareness. Several US states now require individual notification within 30 days. HIPAA allows up to 60 days. SEC-regulated public companies have 4 business days after determining an incident is material. A single breach can trigger more than one of these at once.

Does GDPR apply to US companies?

Yes, if the company processes personal data belonging to people located in the EU, regardless of where the company itself is based. A US retailer with EU customers is subject to GDPR’s breach notification rules for that portion of its data.

What happens if a company doesn’t report a data breach on time? 

Consequences vary by framework but typically include regulatory fines, mandatory corrective action plans, and, in states with a private right of action like California, direct consumer lawsuits. Late notification is often treated as a separate violation from the breach itself, meaning an organization can be penalized twice: once for the incident and once for the delay.

How is “discovery” defined for breach notification purposes?

Most laws define discovery as the first day the breach was known, or reasonably should have been known through ordinary diligence, to any employee or agent of the organization, not the date senior leadership or legal counsel became aware. This broad definition means internal delay in escalating a suspected incident doesn’t pause the notification clock.

Do all states require notifying the attorney general? 

Most do, once the number of affected residents crosses a threshold, commonly 250, 500, or 1,000 people, though the exact number varies by state. A few states, including New Jersey, require the AG to be notified before individuals receive notice.

Is encrypted data exempt from breach notification requirements? 

Generally, yes, but only if the encryption key itself wasn’t also compromised. If an attacker accessed both the encrypted data and the key needed to read it, most laws, including the FTC Safeguards Rule, treat that data as unencrypted for notification purposes.

What should a breach notification letter include? 

At minimum: what happened and when it was discovered, the specific categories of personal information involved, the steps taken in response, and contact information for questions or for credit monitoring services where required. Vague descriptions that avoid naming the data types involved are a common reason notices get challenged.

How does a multi-state breach get handled? 

Legal counsel typically maps every affected state’s requirements, then builds a single operating timeline around the strictest applicable deadline and content requirements. Complying with each state’s law individually, on its own separate timeline, is possible but operationally harder than standardizing on the toughest standard across the board.

Can a company delay notification for a law enforcement investigation? 

Yes, in most frameworks. GDPR, HIPAA, and most state laws allow a delay if law enforcement determines that notification would interfere with a criminal investigation, but this generally requires a written request from law enforcement, not just an internal decision to wait, and the delay is typically capped once law enforcement clears it.

Does having cyber insurance change the notification deadlines?

 No. Insurance can cover the cost of notification, credit monitoring, legal fees, and some fines, but it doesn’t extend or replace any statutory deadline. The clock for GDPR, HIPAA, SEC, state law, and GLBA all runs regardless of what the policy covers.

By

Leave a Reply

Your email address will not be published. Required fields are marked *