The clocks an incident starts
About this documentUpdated 2026-09-18ShowHide
Sean McDermott, Co-Founder and CEO, UnGovr
Written by Sean McDermott (with AI assistance) using the LexLint law library, which supplied every legal instrument, status and date on these pages.
Every law named here links to its summary page on lexlint.org, translated to English (if needed) and restructured to a standard format for human and code use. Every case links to the court's or the regulator's own record where one could be reached.
© 2026 UnGovr, publishing as LexLint. The text, the figures and the theme-register file are licensed under Creative Commons Attribution-NonCommercial 4.0: share and adapt them for noncommercial purposes with credit to LexLint (UnGovr). Please contact LexLint at hello@ungovr.org to discuss commercial use. Logos and wordmarks belong to their owners.
Corpus figures as of 2026-09-18.
Every reporting clock in the corpus that an incident involving an agent can start: the incident and vulnerability duties of cybersecurity law and the breach duties of privacy law, by jurisdiction, each with the sentence that carries the clock, and the Open Secure AI Alliance's proposed SAFE timeline drawn on the same scale.
An incident involving an AGENT, a credential it leaked, a tool it misused, a system it took down, a person's data it exposed, starts clocks in the law of every place the affected systems and people are. None of those clocks was written for agents. They are the incident and vulnerability reporting duties of cybersecurity law and the breach notification duties of privacy law, and the corpus holds them by jurisdiction, each with the sentence that carries the clock and a link to the primary source.
This document lists them, and it draws the notification timeline of the Shared AI Findings Exchange (SAFE), the incident-learning scheme the Open Secure AI Alliance published for comment in 2026, on the same scale, because a member of that scheme would be reporting to a regulator and to the scheme from the same incident. Nothing here says which report an organisation must file. It says which clocks exist, who set them, and where the text is.
See only the clocks your own application starts: sign in and pick a project, or open the demo to try it on the demo's sample projects. The jurisdictions come from the project's declaration on my.lexlint.org, read the way the lint reads them: the declared places, the rungs above them, and the union a member state belongs to.
Reading the clocks
- Read from the sentence
- The corpus keeps each clock inside the obligation sentence and has not yet given it a field of its own. The rung a row sits on here is read out of that sentence when this page is built: a number followed by hours, days, weeks or months, in a line about notifying or reporting, not preceded by a word that makes it a floor, a retention window, a remedy period or a resolution test, and no longer than sixty days, because every longer period in these lines is one of those. A recurring cadence ("a progress report every fifteen days") is not drawn either. The sentence is printed beside every rung so the reading can be checked against the words.
- Different starts
- The clocks run from different moments: becoming aware of the incident in most rows, detecting it in some, the incident notification for a final report, a corrective measure becoming available for a vulnerability's final report. An ordering by length is not an ordering by expiry.
- Staged
- Most security clocks are staged: an early warning, a fuller notification, a final report. Each stage is a rung, and the tables show every stage sentence.
- Two families at once
- The corpus files a personal-data breach under privacy law whatever caused it, so a security incident that exposes personal data starts the privacy clock beside the security one.
- Business days
- A rung stated in business or working days is drawn at its calendar length and marked.
- A proposal, not a law
- The SAFE rungs are a scheme's proposal, quoted as read on 2026-09-18 while it was open for comment. Every other rung is a statute or regulation the corpus holds, with its status beside it.
1The proposal's timeline, and the statutory clocks beside it
The proposal's notification timeline sets six dated rungs and one recurring duty, quoted here as the proposal writes them (source: the SAFE proposal, read 2026-09-18). Beside each rung are the statutory clocks in this corpus that fall at or inside it: later than the proposal's previous rung, no later than this one. The first rung has no hours, so what sits there is every obligation stated as a standard rather than a number.
| The proposal's rung, as written | What it asks a member to do | Statutory clocks at or inside it |
|---|---|---|
| ASAP (as soon as possible) | notify the directly affected organization |
Security: "without undue delay" in 15, "immediately" in 11, "promptly" in 2, "as soon as possible" in 1, "without unreasonable delay" in 1 of 59 instruments Privacy: "without undue delay" in 38, "without unreasonable delay" in 35, "as soon as practicable" in 7, "immediately" in 5, "as soon as possible" in 4, "promptly" in 3, "forthwith" in 1, "as soon as reasonably practicable" in 1 of 130 instruments Privacy: "immediately" in 1 of 29 instruments
|
| 72 hours | notify customers with credible exposure |
1 hour: 1 security instrument 4 hours: 1 security instrument 6 hours: 1 security instrument 24 hours: 36 security instruments, 3 privacy instruments 48 hours: 2 security instruments, 1 privacy instrument, 1 privacy instrument 72 hours: 34 security instruments, 46 privacy instruments
|
| 4 business days | submit a confidential, initial SAFE incident report |
4 business days: 1 security instrument
|
| 14 days | issue a broader customer advisory when warranted |
5 business days: 1 security instrument, 2 privacy instruments 7 days: 1 security instrument, 2 privacy instruments 10 days: 1 privacy instrument 14 days: 1 security instrument, 2 privacy instruments
|
| 30 days | publish a preliminary factual report, subject to security, legal and investigative constraints, and provide a preliminary control-failure analysis |
15 days: 2 security instruments, 2 privacy instruments, 1 privacy instrument 20 days: 1 security instrument 1 month: 30 security instruments, 9 privacy instruments
|
| 90 days | publish remediation status |
40 days: 1 security instrument 45 days: 9 privacy instruments 60 days: 7 privacy instruments
|
| Weekly | weekly machine-readable updates while material risks remain unresolved | recurring, not drawn; the corpus's own progress-report cadences are left off the ladder for the same reason |
Every rung as a list Show the ladderHide the ladder
5 statutory rungs (1 hour, 4 hours, 6 hours, 24 hours, 48 hours) fall before the proposal's first dated rung of 72 hours. The rung most security instruments share is 24 hours (36 instruments in 35 jurisdictions). The rung most privacy instruments share is 72 hours (46 instruments in 46 jurisdictions). The rung most privacy instruments share is 48 hours (1 instruments in 1 jurisdictions). The longest security rung is 40 days. The longest privacy rung is 60 days. The longest privacy rung is 15 days.
A member on the statutory clocks reports to a regulator before the proposal's own confidential report is due. That is the ordinary shape of the law, and it is the reason the proposal's public report at 30 days may describe an incident already in a regulator's hands, under that regulator's confidentiality and publication rules.
2Security law: incident and vulnerability reporting, by jurisdiction
59 instruments in 53 jurisdictions sit in the corpus's cybersecurity topic under its incident-reporting family, as of 2026-09-18. 44 state a numeric clock; 7 state a standard such as "immediately" or "without undue delay" and no number; 8 state the duty without a clock in their obligation lines. Most bind the OPERATOR of a service inside the scope of the NIS2 Directive or its national transposition; the CRA binds the MAKER of a product with digital elements, software included. The sentence says which.
European Union Show the 2 instrumentsHide the 2 instruments
| Jurisdiction | Instrument, and the obligation lines that carry a clock |
|---|---|
|
Cyber Resilience Act, Manufacturer Reporting Obligations (Regulation (EU) 2024/2847, Art. 14)
24 hours72 hours14 daysNotify the CSIRT designated as coordinator for your main establishment and ENISA, through the single reporting platform, of any actively exploited vulnerability you become aware of in your product: an early warning within 24 hours of becoming aware, a vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure becomes available.
24 hours72 hours1 monthNotify the same recipients of any severe incident affecting the security of your product on the same 24-hour early warning and 72-hour incident notification clock, followed by a final report within one month of the incident notification.
Status since 2026-09-11Read from the corpus 2026-09-12
|
|
|
NIS2 Directive, Reporting Obligations (Directive (EU) 2022/2555, Art. 23)
24 hours72 hours1 monthNotify your CSIRT, or the competent authority where applicable, of any incident with a significant impact on the provision of your services: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report no later than one month after the incident notification.
without undue delayWhere appropriate, notify, without undue delay, the recipients of your services who a significant incident is likely to adversely affect, and communicate to recipients potentially affected by a significant cyber threat any measures or remedies they can take.
Status since 2024-10-18Read from the corpus 2026-09-08
|
None of these instruments is in the project's jurisdictions.
EU member states (the national layer) Show the 31 instrumentsHide the 31 instruments
| Jurisdiction | Instrument, and the obligation lines that carry a clock |
|---|---|
|
Netz- und Informationssystemsicherheitsgesetz (NISG), Incident Notification Obligations (NISG, BGBl. I Nr. 111/2018, §§ 19 und 21)
The obligation lines state no clock of their own.
Status since 2018-12-28Read from the corpus 2026-09-14
|
|
|
Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Significant-Incident Reporting Obligations (NISG 2026, BGBl. I Nr. 94/2025, §§ 34 und 35)
24 hoursNotify your competent sector-specific CSIRT, or, absent one, the national CSIRT, of every significant cybersecurity incident: an early warning within 24 hours of becoming aware, stating whether it is suspected to result from unlawful and culpable acts or to have cross-border effects.
72 hoursFollow with a fuller notification within 72 hours of becoming aware, updating the early warning with an initial evaluation of the incident's severity and impact and any indicators of compromise.
1 month72 hoursSubmit an interim report on request, and a final report no later than one month after the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once you have resolved it.
Status from 2026-10-01 [enacted, not yet in effect]Read from the corpus 2026-09-14
|
|
|
Loi du 26 avril 2024, Significant-Incident Notification Obligations (Loi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information d'intérêt général pour la sécurité publique, Artt. 34-37)
without undue delayNotify the national CSIRT of any significant incident without undue delay, following the arrangements set out in the protocol between the CSIRT and the National Crisis Centre.
24 hoursSubmit an early warning within 24 hours of becoming aware of the significant incident, stating whether it is suspected to result from unlawful or malicious action and whether it may have a cross-border impact.
72 hoursFollow with an incident notification within 72 hours, updating the early warning with an initial assessment of the incident's severity and impact and any available indicators of compromise.
1 monthSubmit an interim report if the national CSIRT or the competent sectoral authority asks for one, and a final report no later than one month after the incident notification, describing the incident in detail, its severity and impact, the likely threat or root cause, the mitigation measures applied and in progress, and any cross-border impact.
Status since 2024-10-18Read from the corpus 2026-09-14
|
|
|
Cybersecurity Act, Incident and Cyber-Threat Reporting Obligations (Zakon za kibersigurnost, ZKS) (Закон за киберсигурност (ЗКС), чл. 23, изм. с § 27 от Закона за изменение и допълнение на ЗКС, обн. ДВ, бр. 17 от 13.02.2026 г. (English: Cybersecurity Act, Art. 23, as substituted by § 27 of the Act Amending and Supplementing the Cybersecurity Act, State Gazette No. 17 of 13 February 2026))
24 hours72 hours24 hours1 month1 monthNotify СЕРИКС of every significant incident on this clock: an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours (24 hours if you are a trust service provider), an interim report on request, and a final report no later than one month after the incident notification (or, if unresolved by then, an interim report followed by a final report within one month of resolution).
72 hoursState in your early warning, where applicable, whether the incident is suspected to result from unlawful or malicious acts and whether it could have a cross-border effect; update that assessment with an initial severity and impact evaluation in your 72-hour notification; and cover in your final report the incident's scope and impact, its likely cause, your mitigation measures, and any cross-border effect.
without undue delayWhere appropriate and without undue delay, notify the recipients of your service of a significant incident likely to adversely affect them and of any measures they can take, and of a significant cyber threat and its nature.
24 hoursExpect СЕРИКС to acknowledge your early warning within 24 hours except where objectively impossible, and to provide initial information and, on request, guidance or further technical support.
Status since 2026-02-17Read from the corpus 2026-09-15
|
|
|
Security of Networks and Information Systems Law, Incident Notification Obligations (Art. 35B of the Security of Networks and Information Systems Law of 2020, N. 89(I)/2020, as amended by the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025)
without undue delayNotify the Digital Security Authority without undue delay, and in any event within six (6) hours of becoming aware of a significant incident, with an early warning stating, where applicable, whether the incident is suspected to result from unlawful or malicious acts and whether it may have a cross-border impact.
72 hoursFollow with an incident notification within 72 hours of becoming aware, updating the early warning and giving an initial assessment of the incident's severity and impact, including any indicators of compromise where available.
1 month15 daysSubmit an intermediate report on the Authority's request, and a final report within one month of the incident notification (or, for an incident still ongoing at that point, a progress report every fifteen days, and a final report within fifteen days of restoring the affected network or information system's normal operation).
24 hoursWhere you are a trust service provider, notify within 24 hours rather than 72 for a significant incident affecting the trust services you supply.
without undue delayWhere applicable, notify without undue delay the recipients of your services who may be affected by a significant cyber threat, of any measures or corrective action they can take, and notify them of a significant incident likely to adversely affect their use of the service.
Status since 2025-04-25Read from the corpus 2026-09-16
|
|
|
Cybersecurity Act (Zákon o kybernetické bezpečnosti), Incident Notification (Act No. 264/2025 Coll., Cybersecurity Act, Sections 15-16)
24 hoursIf you are in the higher-obligations regime, notify NÚKIB no later than 24 hours after detecting a qualifying cybersecurity incident, with an initial report giving your identifying details, basic incident data, and whether you believe the incident was caused by an unlawful intervention or could have a cross-border impact.
24 hoursIf you are in the lower-obligations regime, notify the Národní CERT on the same 24-hour clock instead, for a qualifying incident with significant impact on your service's provision.
72 hoursFor an incident with significant impact, follow with a report no later than 72 hours after detection that updates your initial assessment and gives the incident's impact and, where available, indicators of compromise.
30 days72 hours30 daysSubmit an interim report on request, and a final report no later than 30 days after the 72-hour report, or, if the incident is still ongoing at that point, a progress report followed by a final report within 30 days of resolution.
Status since 2025-11-01Read from the corpus 2026-09-14
|
|
|
BSI-Gesetz (BSIG), Incident Notification (BSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), § 32)
24 hoursNotify the BSI's and the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe's joint reporting office without delay, and in any event within 24 hours of becoming aware of a significant security incident, with an early warning stating whether the incident is suspected to be unlawful or malicious or to have cross-border effect.
72 hoursFollow with a full notification within 72 hours of becoming aware, confirming or updating the early warning and giving an initial assessment of the incident's severity and impact and, where available, indicators of compromise.
1 month72 hoursSubmit an intermediate report on the BSI's request, and a final report within one month of the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once you have finished handling it.
Status since 2025-12-06Read from the corpus 2026-09-12
|
|
|
NIS 2-loven, Significant-Incident Reporting and Recipient-Notice Duties (NIS 2-loven, §§ 12-13, 15)
24 hoursSend an early warning without undue delay, and no later than 24 hours after becoming aware of the significant incident, stating whether it is suspected to result from an unlawful or malicious act and whether it may have a cross-border effect.
72 hoursFollow with a notification, without undue delay and in any case within 72 hours of becoming aware of the incident, updating the early warning with an initial assessment of the incident's severity and impact, including any indicators of compromise where available.
1 month1 monthSubmit an interim report if your CSIRT asks for one, and a final report no later than one month after your notification, describing the incident in detail, its severity and impact, the likely threat or root cause, mitigating measures applied and under way, and any cross-border effects. If the incident is still ongoing at that point, submit a status report instead and the final report within one month of the incident being handled.
72 hours24 hoursIf you are a trust-service provider, send only the 72-hour-shaped notification, without undue delay and no later than 24 hours after becoming aware of the significant incident, rather than the separate two-step early-warning and notification sequence.
without undue delayNotify the recipients of your service, without undue delay, of a significant incident likely to adversely affect the delivery of your service to them, and inform any recipient potentially affected by a significant cyber threat of the measures or countermeasures they can take in response, and of the threat itself where relevant.
Status since 2025-07-01Read from the corpus 2026-09-15
|
|
|
Küberturvalisuse seadus (KüTS), Duty to Notify of a Cyber Incident (Küberturvalisuse seadus (Cybersecurity Act), RT I, 30.12.2025, 4, §§ 8 and 8-1)
24 hoursSubmit an initial report to RIA without delay and no later than 24 hours after becoming aware of a cyber incident that has, or could reasonably be expected to have, a significant effect on your system's security or your service's continuity, unless you are a security authority.
72 hours24 hoursFollow with an incident report no later than 72 hours after becoming aware of the significant incident, updating the initial report, unless you are a qualified trust service provider, in which case you report in a single stage within 24 hours instead.
1 month1 monthSubmit an interim report if RIA asks for one, and a final report within one month of the incident report, or, if the incident is still unresolved at that point, treat that report as interim and submit a further final report within one month of resolution.
Status since 2026-01-01Read from the corpus 2026-09-15
|
|
|
Anteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad, Incident Reporting Obligations (Anteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad, text approved by the Consejo de Ministros on 14 January 2025 (transposing Directive (EU) 2022/2555))
as soon as possibleExpect a duty to communicate to the recipients of your service, as soon as possible, a significant cyberthreat that could affect them and any mitigating measures they can take.
Status [proposed]Read from the corpus 2026-09-12
|
|
|
Real Decreto-ley 12/2018, Incident Notification Obligation (Real Decreto-ley 12/2018, de 7 de septiembre, de seguridad de las redes y sistemas de informacion, arts. 19, 21 y 22, developed by Real Decreto 43/2021, de 26 de enero)
without undue delayNotify the competent authority, through your reference CSIRT, without undue delay, of an incident that may have a significant disruptive effect on the provision of your service, whether on your own networks or a third-party provider's.
24 hours48 hours20 days72 hours40 daysFor a CRITICO-severity incident under the national notification instruction, notify immediately, follow up with an interim notification within 24 to 48 hours, and file a final notification within 20 days; for a MUY ALTO-severity incident, notify immediately, follow up within 72 hours, and file a final notification within 40 days; an ALTO-severity incident requires only an immediate initial notification.
Status since 2018-09-09Read from the corpus 2026-09-12
|
|
|
Kyberturvallisuuslaki, Significant-Incident Reporting Obligations (Kyberturvallisuuslaki (124/2025), 11-14 ja 22 §)
24 hours72 hours24 hoursFile an early notification within 24 hours of detecting the significant incident, stating whether it is suspected to result from an unlawful or hostile act and the likelihood of cross-border effects, and a follow-up notification within 72 hours of detection, both clocks running from detection rather than from each other; if you are a trust service provider whose trust services are affected, file your follow-up notification within 24 hours instead of 72.
1 month1 month1 monthProvide an interim report on the authority's request, or within one month of your follow-up notification if the incident is long-running, and a final report within one month of the follow-up notification, or within one month of the incident's resolution if it is still ongoing at that point, describing the incident, its likely root cause, mitigation measures taken, and any cross-border effects.
Status since 2025-04-08Read from the corpus 2026-09-15
|
|
|
Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Incident Notification (Loi n° 2018-133 du 26 février 2018, Titre Ier, art. 7 et 13)
The obligation lines state no clock of their own.
Status since 2018-05-10Read from the corpus 2026-09-12
|
|
|
Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Incident Notification (NIS2) (Article 17, texte adopté n° 78 (2024-2025), Sénat, 12 mars 2025 (notification des incidents))
24 hours72 hours1 month1 month1 monthNotify ANSSI without undue delay of any incident with an important impact on the provision of your services (one causing or liable to cause a severe operational disruption or financial loss for you, or considerable material, physical or non-material damage to another person), on a graduated clock: an initial notification within 24 hours of becoming aware of it, an intermediate notification within 72 hours updating the initial one and giving an initial assessment of severity and impact, a report on ANSSI's request, and a final report within one month (or, for an incident still being handled, a progress report at one month followed by a final report within one month of resolution).
24 hoursWhere you are a trust-service provider or one of the domain-name and registry services Articles 8(4) and 9(3) name, notify within 24 hours rather than 72 for the intermediate notification.
24 hoursExpect ANSSI to respond within 24 hours of your initial notification where possible, and expect the same penalty tiers as this jurisdiction's companion risk-management row.
Status [proposed]Read from the corpus 2026-09-12
|
|
|
Law 5160/2024, Significant-Incident Reporting Obligations (Law 5160/2024 (Ν. 5160/2024), Art. 16)
24 hoursNotify the CSIRT of the National Cybersecurity Authority, without undue delay and in any case within 24 hours of becoming aware of a significant incident, with an early warning stating whether unlawful or malicious action is suspected and whether the incident may have cross-border effects.
72 hoursFollow within 72 hours of becoming aware of the significant incident with an incident notification updating the early warning and adding an initial assessment of its severity and effects.
1 month72 hours1 monthSubmit a final report no later than one month after the 72-hour notification, describing the incident in detail, its severity and effects, the likely threat or root cause, mitigating measures applied, and any cross-border impact; if the incident is still ongoing at that point, submit a progress report instead and the final report within one month of its resolution.
without undue delayWithout undue delay, notify the recipients of your services of a significant incident likely to adversely affect the services they receive, and inform any recipients affected by a significant cyber threat of the threat and of the measures they can take in response.
Status since 2024-11-27Read from the corpus 2026-09-15
|
|
|
Zakon o kibernetičkoj sigurnosti and Uredba o kibernetičkoj sigurnosti, Incident and Cyber-Threat Reporting Obligations (Zakon o kibernetičkoj sigurnosti, Narodne novine, broj 14/2024, čl. 37.-44.; Uredba o kibernetičkoj sigurnosti, Narodne novine, broj 135/2024, čl. 64.-71. i 85.)
24 hours24 hours72 hours30 days30 daysNotify the competent CSIRT of every significant incident on this clock, set by the Cybersecurity Regulation rather than the Act itself: an early warning without delay and no later than 24 hours after becoming aware of it (24 hours also for a trust service provider's initial notification), an initial notification no later than 72 hours otherwise, an interim report if the CSIRT requests one, and a final report no later than 30 days after your initial notification, or, if the incident is still unresolved at that point, a progress report instead, repeated every 30 days once the incident has run past 60 days, followed by a final report within 30 days of your last progress report.
72 hoursNotify the recipients of your service, without delay and no later than 72 hours after you become aware of a significant incident likely to affect them, in a clear and easily verifiable way, and separately notify them of a serious cyber threat and of any protective measures or remedies they can take.
30 daysIf you are newly categorized as an essential or important entity, you have 30 days from the date you receive your Article 19(1) categorization notice before these notification duties bind you.
Status since 2024-11-30Read from the corpus 2026-09-16
|
|
|
Cybersecurity Act, Incident Notification and Cybersecurity Fine (2024. évi LXIX. törvény, 66. §; 418/2024. (XII. 23.) Korm. rendelet, 42. § és 77. §)
24 hours72 hours1 monthNotify the national cybersecurity incident-handling centre (Nemzeti Kiberbiztonsági Intézet, the NKI) of a cyber threat, near-incident or cybersecurity incident affecting your electronic information system: an initial notification without undue delay and in any case within 24 hours of becoming aware, an event notification within 72 hours that updates that report and assesses the incident's severity and impact, and a final report no later than one month after the event notification.
1 monthSubmit an interim status report if the centre asks for one, and, if the incident is still ongoing when the final report is due, a report on the results achieved so far followed by a final report within one month of the incident's resolution.
Status since 2025-01-01Read from the corpus 2026-09-14
|
|
|
European Union (NIS) Regulations 2018, Incident Notification (S.I. No. 360/2018, Regs. 18 and 22)
72 hoursNotify the State's CSIRT without delay and in any event not later than 72 hours after becoming aware of an incident with a significant impact on the continuity of your essential service, or a substantial impact on your digital service, including an incident affecting a third-party digital service provider you rely on.
Status since 2018-09-18Read from the corpus 2026-09-12
|
|
|
National Cyber Security Bill, Incident Response Powers and Reporting Obligations (Head 15, General Scheme, National Cyber Security Bill 2024)
24 hours72 hours1 monthNotify the CSIRT without undue delay of any incident with a significant impact on the provision of your service: an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours, and a final report within one month.
Status [proposed]Read from the corpus 2026-09-12
|
|
|
Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident Notification (D.Lgs. 4 settembre 2024, n. 138, Art. 25)
24 hoursNotify CSIRT Italia without unjustified delay, and in any event within 24 hours of becoming aware of a significant incident, with a pre-notification stating, where possible, whether the incident appears unlawful or malicious and whether it may have a cross-border impact.
72 hoursFollow with a full notification within 72 hours of becoming aware, updating the pre-notification and giving an initial assessment of the incident's severity and impact and, where available, indicators of compromise.
1 month1 monthSubmit an intermediate report on CSIRT Italia's request, and a final report within one month of the notification (or, for an incident still ongoing at that point, a monthly progress report and a final report within one month of the incident's resolution).
24 hoursWhere you are a trust-service provider, notify within 24 hours rather than 72 for an incident affecting the trust services you supply.
24 hoursExpect CSIRT Italia to respond within 24 hours of your pre-notification with an initial assessment and, on request, guidance or technical support on mitigation measures.
Status since 2024-10-16Read from the corpus 2026-09-12
|
|
|
Kibernetinio saugumo įstatymas (Law on Cyber Security), Incident Notification (Lietuvos Respublikos kibernetinio saugumo įstatymas Nr. XII-1428, as restated by Įstatymo Nr. XIV-2902 pakeitimo įstatymas of 11 July 2024, in force since 18 October 2024, Art. 18)
24 hoursNotify NKSC of a significant cyber incident without delay and in any event within 24 hours of becoming aware of it.
72 hours72 hours24 hoursFollow within 72 hours of becoming aware with the incident's severity and impact assessment and any evidence of compromise; report a minor incident within 72 hours without a separate 24-hour early warning.
1 monthSubmit a final report within one month of the incident's registration, and an interim report on NKSC's request.
Status since 2024-10-18Read from the corpus 2026-09-14
|
|
|
Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Incident Notification (Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité, Art. 14)
without undue delayNotify the competent authority, without undue delay, of any incident with a significant impact on the provision of your services: treat an incident as significant where it has caused or is capable of causing severe operational disruption or financial loss to you, or considerable material, physical or moral damage to another person.
24 hoursSubmit an early warning within 24 hours of becoming aware of the significant incident, stating whether it is suspected to result from unlawful or malicious acts or could have cross-border effect.
72 hoursFollow with a fuller incident notification within 72 hours of becoming aware, updating the early warning and giving an initial assessment of the incident's severity and impact and, where available, indicators of compromise.
1 month72 hoursSubmit an intermediate report if a CSIRT or the competent authority requests one, and a final report within one month of the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once you have finished handling it.
without undue delayWhere appropriate, notify the recipients of your services, without undue delay, of a significant incident likely to affect the services they receive from you, and of any measures or corrections they can apply in response to a significant cyber threat.
24 hours72 hoursIf you are a qualified trust-service provider, notify significant incidents affecting your trust services within 24 hours of becoming aware, without the 72-hour and later stages that apply to other entities.
Status since 2026-05-10Read from the corpus 2026-09-14
|
|
|
Nacionālās kiberdrošības likums, Coordinated Vulnerability Disclosure and Remediation (Nacionālās kiberdrošības likums (adopted 20.06.2024, in force 01.09.2024), 39.-40. panti)
5 business daysWhere you discover a vulnerability yourself in another subject's system, know that Article 39 lets you report it to the competent institution within five working days, anonymously if you choose, with your identity kept confidential.
Status since 2024-09-01Read from the corpus 2026-09-15
|
|
|
Nacionālās kiberdrošības likums, Incident Notification (Nacionālās kiberdrošības likums (adopted 20.06.2024, notification clock applying from 01.07.2025), 34. pants)
immediatelyImmediately take all action necessary to contain a detected cyber incident, immediately inform the competent cyber incident prevention institution (in practice CERT.LV for most private-sector and civilian public-sector subjects), and follow its instructions.
24 hoursFor a significant cyber incident, electronically submit an early warning to the competent institution without delay and no later than within 24 hours of becoming aware of it.
72 hours24 hoursFollow with an initial report within 72 hours of becoming aware (within 24 hours instead, if you are a trust service provider).
1 monthWithin one month of the initial report, submit a final report on the incident's resolution, or, if it is still unresolved at that point, a progress report followed by a final report once you have resolved it; submit an intermediate report if the competent institution requests one.
immediatelyWhere relevant, immediately inform your service recipients, including affected network or system users, of protective measures they can take, and, after coordinating with the competent institution, inform them of the significant incident or threat itself, unless disclosure would create a new significant-incident risk or conflict with national security.
Status since 2025-07-01Read from the corpus 2026-09-15
|
|
|
Cyberbeveiligingswet, Significant-Incident Reporting Obligations (Cyberbeveiligingswet, Artt. 25-29)
24 hoursGive your CSIRT and competent authority an early warning without delay, or within 24 hours of becoming aware of a significant incident if immediate reporting is not possible, stating whether the incident is suspected to result from unlawful or malicious action and whether it may have cross-border effects.
72 hoursFollow with a notification, without delay or within 72 hours, updating the early warning with an initial assessment of the incident's severity and effects.
1 month1 monthSubmit a final report no later than one month after your notification, describing the incident in detail, its severity and effects, the likely threat or root cause, mitigating measures applied, and any cross-border effects; if the incident is still ongoing at that point, submit a progress report instead and the final report within one month of resolution.
Status since 2026-08-15Read from the corpus 2026-09-12
|
|
|
Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), Zgłaszanie Incydentów Poważnych (Art. 11 ustawy z dnia 5 lipca 2018 r. o krajowym systemie cyberbezpieczeństwa (Dz.U. 2026 poz. 20), w brzmieniu nadanym ustawą z dnia 23 stycznia 2026 r. (Dz.U. 2026 poz. 252))
24 hoursNotify the competent sectoral CSIRT without delay, and in any event within 24 hours of detecting a significant incident, with an early warning.
72 hours1 month72 hoursFollow with a fuller notification within 72 hours of detection, a periodic report on the CSIRT's request, and a final report no later than one month after the 72-hour notification.
Status from 2027-04-03 [enacted, not yet in effect]Read from the corpus 2026-09-14
|
|
|
Regime Jurídico da Cibersegurança, Significant-Incident Reporting Obligations (Decreto-Lei n.º 125/2025, de 4 de dezembro, Artigos 40.º a 44.º)
24 hours72 hoursSubmit an initial notification without undue delay and within 24 hours of concluding that a significant incident exists or may exist, and, where necessary, update it within 72 hours with an initial assessment of the incident's severity and impact; if the incident resolves within two hours of detection, submit only the end-of-impact notification below.
24 hoursSubmit a notification that the incident's significant impact has ended, without undue delay and within 24 hours of that impact ending.
30 business daysSubmit a final report within 30 working days of your end-of-impact notification, describing the incident, its impact, the mitigating measures you took and any residual impact still present, and submit an interim report if the competent authority asks for one.
Status since 2026-04-03Read from the corpus 2026-09-15
|
|
|
Ordonanța de urgență nr. 155/2024, Incident Notification (Ordonanța de urgență a Guvernului nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetică a rețelelor și sistemelor informatice din spațiul cibernetic național civil, reportedly approved by Legea nr. 124/2025, art. 15-17)
without undue delayReport to the national cybersecurity-incident-response team, without undue delay, any incident with a significant impact on the provision of your services, through the Platforma națională pentru raportarea incidentelor de securitate cibernetică (PNRISC).
24 hours72 hours1 month72 hoursSubmit an early warning within 24 hours of becoming aware of a significant incident, stating whether it is suspected unlawful, malicious, or cross-border in impact; follow with a fuller incident report within 72 hours giving an initial severity and impact assessment and any known indicators of compromise; submit an interim report if the CSIRT requests one; and submit a final report within one month of the 72-hour report, or a progress report followed by a final report if the incident is still ongoing at that point.
24 hoursIf you are a trust service provider, report an incident affecting your trust services within a flat 24 hours of becoming aware of it, rather than on the graduated clock.
Status since 2024-12-31Read from the corpus 2026-09-15
|
|
|
Cybersäkerhetslag, Incident Notification (Cybersäkerhetslag (2025:1506), 2 kap. 5-10 §§)
24 hoursInform the authority the government designates (in practice the CSIRT-enhet at Försvarets radioanstalt) of a significant incident as soon as you can, and no later than 24 hours after becoming aware of it.
24 hours72 hoursFollow with a formal incident notification to the same authority as soon as you can; if you provide a trust service, no later than 24 hours after becoming aware, and otherwise no later than 72 hours after becoming aware.
1 month1 monthNo later than one month after your incident notification, submit a final report; if the significant incident is still ongoing at that point, submit a progress report instead and a final report within one month after you have resolved it.
Status since 2026-01-15Read from the corpus 2026-09-15
|
|
|
Zakon o informacijski varnosti (ZInfV-1), Significant-Incident Notification Obligations (Zakon o informacijski varnosti (ZInfV-1), Uradni list RS, št. 40/25, čl. 29-30)
24 hoursGive your competent CSIRT group an early warning without delay, at latest within 24 hours of detecting a significant incident, stating whether it is suspected to result from an unlawful or malicious act and whether it may have a cross-border effect.
72 hours1 month72 hours1 monthFollow with a full notification without delay, at latest within 72 hours, updating the early warning with an initial assessment of the incident's severity and impact and any available threat indicators, then an interim report if the CSIRT group asks for one, and a final report at latest one month after the 72-hour notification, or a progress report and a final report within one month of resolution if the incident is still ongoing at that point.
Status since 2025-06-18Read from the corpus 2026-09-15
|
|
|
Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability Notification (Zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplní niektorých zákonov, v znení zákona č. 366/2024 Z. z., § 24 a § 5 ods. 5)
24 hoursReport without undue delay, and no later than 24 hours after becoming aware of it, an early warning of a significant cyber security incident, stating in particular whether it may have been caused by unlawful conduct or may have a cross-border effect.
72 hoursNo later than 72 hours after becoming aware of it, report a notification updating and completing the early warning, in particular an initial assessment of the incident's severity and impact.
1 month72 hoursNo later than one month after the 72-hour notification, report a final report describing the incident, its severity and impact, the threat type or probable root cause, the mitigating measures taken and under way, and any cross-border impact.
30 days30 daysWhere a cross-border-impact incident is still ongoing when the final report is due, report an updated final report within 30 days of restoring normal network and system operation, or, if it remains unresolved at the final-report stage, within 30 days of its eventual resolution.
Status since 2025-01-01Read from the corpus 2026-09-15
|
None of these instruments is in the project's jurisdictions.
United States, federal Show the 1 instrumentHide the 1 instrument
| Jurisdiction | Instrument, and the obligation lines that carry a clock |
|---|---|
|
SEC Cybersecurity Risk Management, Governance, and Incident Disclosure (Regulation S-K Item 106; Form 8-K Item 1.05) (17 CFR 229.106; 17 CFR 249.308 (Form 8-K Item 1.05))
4 business daysIf your organization is an SEC reporting company, determine, without unreasonable delay after you discover a cybersecurity incident, whether the incident is material, and if it is, file a Form 8-K under Item 1.05 within four business days after you make that determination.
Status since 2023-12-18Read from the corpus 2026-09-18
|
None of these instruments is in the project's jurisdictions.
Asia and the Pacific Show the 9 instrumentsHide the 9 instruments
| Jurisdiction | Instrument, and the obligation lines that carry a clock |
|---|---|
|
Cyber Security Act, Computer Emergency Response Team, Duty to Report a Cyber Incident (Cyber Security Act, 2026 (Act No. 81 of 2026), s. 9)
The obligation lines state no clock of their own.
Status since 2025-05-21Read from the corpus 2026-09-18
|
|
|
Data Security Law, Risk Monitoring and Incident Reporting Duty (Data Security Law of the People's Republic of China, Art. 29)
immediatelyOn an actual data-security incident, immediately take disposal measures, promptly notify affected users as provided, and report the incident to the competent authority; the statute states no numeric deadline, only immediacy and promptness.
Status since 2021-09-01Read from the corpus 2026-09-12
|
|
|
Government Regulation on the Operation of Electronic Systems and Transactions, security-incident reporting duty (Government Regulation No. 71 of 2019 (PP PSTE), Pasal 24(3))
immediatelyReport the incident immediately, at the first opportunity, to law enforcement officials and the relevant Ministry or Agency; the Government Regulation states no numeric clock for this report, only immediacy.
Status since 2019-10-10Read from the corpus 2026-09-16
|
|
|
CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation (Directions under section 70B(6) of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In (Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, 28 April 2022))
6 hoursReport a listed cyber security incident, including a targeted attack, a data breach, a data leak, unauthorised access to your IT systems, or an attack through a malicious or fake mobile app, to CERT-In within six hours of noticing it or being notified of it, by email, phone, or fax; current reporting formats and channels are published on CERT-In's own website.
Status since 2022-06-27Read from the corpus 2026-09-12
|
|
|
Digital Code, digital resilience incident notification (Digital Code, Law No. 178, Art. 63)
72 hoursNotify the sectoral regulator with jurisdiction over your sector no later than 72 hours after you discover the incident; if you notify later than that, explain the reason for the delay in the notice.
48 hoursIf you process data as a processor for a record owner, notify that record owner of an incident within the period your contract sets, and in any event no later than 48 hours after you discover it.
Status since 2026-02-06Read from the corpus 2026-09-18
|
|
|
Information and Communications Network Act, Report on Computer Security Incidents (Arts. 48-3 and 48-4 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. (Act No. 20069, Jan. 23, 2024))
immediatelyImmediately report a computer security incident to the Minister of Science and ICT or to the Korea Internet and Security Agency upon discovering it; a report already made for the same incident under another statute satisfies this duty and need not be repeated.
Status since 2022-06-10Read from the corpus 2026-09-12
|
|
|
Law on Cyber Security, Cyber-Attack Notification Duty for Other Legal Persons (Law of Mongolia on Cyber Security, adopted 17 December 2021, in force 1 May 2022, Art. 17.3)
The obligation lines state no clock of their own.
Status since 2022-05-01Read from the corpus 2026-09-15
|
|
|
Law on Cybersecurity, cybersecurity incident notification duty (Law No. O'RQ-764 (15 April 2022) "On Cybersecurity," Arts. 3, 16, 22-24)
The obligation lines state no clock of their own.
Status since 2022-07-17Read from the corpus 2026-09-18
|
|
|
Cybersecurity Law, Incident Response and Reporting Duties (Law No. 116/2025/QH15 (Law on Cybersecurity), arts. 40(1)(c), 41(2)-(4))
24 hours72 hoursWhen a cybersecurity incident occurs, implement that plan immediately and simultaneously report it to the specialised cybersecurity protection force. The Law states no fixed number of hours for this report, unlike the 24-hour and 72-hour clocks the same enterprise faces under Article 25(2) for a content-takedown or a user-information request, which are a content-moderation duty this row does not carry.
Status since 2026-07-01Read from the corpus 2026-09-16
|
None of these instruments is in the project's jurisdictions.
Africa, the Middle East and elsewhere Show the 16 instrumentsHide the 16 instruments
| Jurisdiction | Instrument, and the obligation lines that carry a clock |
|---|---|
|
Llei 22/2022, Incident Handling and Notification Obligation (Llei 22/2022, del 9 de juny, arts. 14 i 15)
72 hours72 hoursNotify the CSIRT-AD, without delay and in any event within 72 hours of becoming aware of it, of any incident that has or may have significant effects on your essential or important service, including information on any cross-border effects; where you cannot yet establish that effect, you may omit it if you send a justificatory report within 72 hours of the notification explaining why.
without undue delayWhere appropriate, notify the recipients of your service, without undue delay, that a significant incident is likely to affect them and what measures or remedies they can take in response.
Status since 2022-06-23Read from the corpus 2026-09-18
|
|
|
Lei de Protecção das Redes e Sistemas Informáticos, Incident-Management Planning, Alert Dissemination and CERT Coordination Duties (Lei n.º 7/17, Artigos 15.º, 16.º, 40.º e 41.º)
The obligation lines state no clock of their own.
Status in effectRead from the corpus 2026-09-18
|
|
|
Mandatory Reporting of Attacks and Intrusions to ARTCI (Décret n°2021-917 du 22 décembre 2021, Arts. 16-17)
immediatelyInform ARTCI immediately of any attack, intrusion or other disruption likely to impede your information system's proper functioning.
Status since 2021-12-22Read from the corpus 2026-09-18
|
|
|
Cybersecurity Act, Duty to Report Cybersecurity Incident (Cybersecurity Act, 2020 (Act 1038), ss. 47(2) and 47(5)-(6), and Second Schedule item 47(6))
24 hoursReport a cybersecurity incident to the relevant Sectoral Computer Emergency Response Team, or to the National Computer Emergency Response Team where the institution has no Sectoral team, within twenty-four hours after the incident is detected.
24 hoursFailing to report within the twenty-four-hour window is an administrative penalty of not less than two hundred and fifty penalty units and not more than five thousand penalty units, payable to the Cyber Security Authority.
Status since 2020-12-29Read from the corpus 2026-09-18
|
|
|
Notification of Serious Incidents and Risk to the National Cybersecurity Incident-Response Team (Log nr. 78/2019, Art. 8)
The obligation lines state no clock of their own.
Status since 2020-09-01Read from the corpus 2026-09-15
|
|
|
Cyber Security Law No. 16 of 2019, Article 8 private-sector incident-reporting and Center-cooperation duty (Cyber Security Law No. (16) of 2019, Article 8(b))
1 hour4 hours1 dayWhere the incident is Critical or High severity, in particular where it touches critical infrastructure, a security or military body, a ministry or government institution, a government-owned or government-invested company, a supply chain feeding those entities, or where it disrupts essential services entirely at a higher-education institution, the Center's own Incident Response and Reporting Policy sets a reporting clock as short as 30 minutes for a Critical-tier incident, rising through roughly 1 hour for High, 4 hours for Medium, and 1 day for Low; an ordinary private company or individual establishment with no such touchpoint is typically classified Medium or Low.
Status in effectRead from the corpus 2026-09-16
|
|
|
Computer Misuse and Cybercrimes Act, Reporting of Cyber Threat (Computer Misuse and Cybercrimes Act (No. 5 of 2018), s. 40)
24 hoursImmediately inform the National Computer and Cybercrimes Co-ordination Committee, established under section 4 of the Act, of an attack, intrusion, or other disruption to the functioning of another computer system or network, within twenty-four hours of the attack, intrusion, or disruption.
Status since 2018-05-30Read from the corpus 2026-09-14
|
|
|
Cyber-Sicherheitsgesetz (CSG), Incident Notification (Cyber-Sicherheitsgesetz (CSG) vom 5. Dezember 2024, LGBl. 2025 Nr. 111, Art. 6)
24 hoursNotify the Stabsstelle Cyber-Sicherheit (Cyber Security Office) without delay, and in any event within 24 hours of becoming aware of a significant security incident, with an early warning stating, where relevant, whether the incident is suspected to result from unlawful or malicious acts or to have cross-border effect.
72 hoursFollow with a full notification within 72 hours of becoming aware, updating the early warning where relevant and giving an initial assessment of the incident's severity and impact and, where available, indicators of compromise.
1 month72 hoursSubmit an intermediate report on the Stabsstelle Cyber-Sicherheit's request, and a final report within one month of the 72-hour notification, describing the incident's severity and impact in detail, the likely threat or root cause, and the mitigation measures taken.
Status since 2025-02-01Read from the corpus 2026-09-15
|
|
|
Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Incident and Vulnerability Notification Duties (Loi n° 05-20 relative à la cybersécurité, Chapitre II, Section 3, Arts. 27, 30 et 33, promulguée par le Dahir n° 1-20-69 du 4 hija 1441 (25 juillet 2020), Bulletin Officiel n° 6906 du 16 hija 1441 (6 août 2020))
The obligation lines state no clock of their own.
Status in effectRead from the corpus 2026-09-17
|
|
|
Law on Information Security, Cyber Threat and Incident Reporting (Law on Information Security, Arts. 28 to 37)
24 hoursWhere a cyber threat or incident could significantly affect the continuity of your service, submit an initial notification to the Cybersecurity Agency within 24 hours of becoming aware of it, on the prescribed form (Article 30).
72 hours30 daysFor an incident the Agency rates medium, submit a first report within 72 hours of your initial notification, a further report without delay on any new development, continuing reports every 72 hours while the incident lasts, and a final report within 30 days of resolving it (Article 33).
Status since 2024-12-05Read from the corpus 2026-09-18
|
|
|
Cybersecurity Law, Incident Notification and Responsible Vulnerability Disclosure (Lei n.º 13/2026, arts. 57 a 66)
promptlyIf you operate a data centre or a cloud-computing platform, also notify your own subscribers promptly of an incident, including a data leak, that affects or may affect their content.
Status from 2026-09-29 [enacted, not yet in effect]Read from the corpus 2026-09-18
|
|
|
Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, Reporting of Cyber Threats to the National CERT (Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, section 21, Reporting of Cyber Threats)
immediatelyImmediately inform the National Computer Emergency Response Team (CERT) Coordination Center of any attack, intrusion, or other disruption liable to hinder the functioning of another computer system or network.
7 daysReport the incident to the National CERT within 7 days of its occurrence. Failing to do so is itself an offence, punishable by denial of internet services and a mandatory fine of N2,000,000 payable into the National Cyber Security Fund.
Status in effectRead from the corpus 2026-09-17
|
|
|
Law on Information Security, Incident Reporting Obligations (Zakon o informacionoj bezbednosti ("Sl. glasnik RS", br. 91/2025), čl. 13-14, 24-25)
24 hoursNotify the single incident-reporting system, through the Ministry's or the Office for Information Security's website, of an incident that may significantly disrupt information security, without delay and at the latest within 24 hours of becoming aware of it.
15 daysSubmit a final report within 15 days after the incident ends, covering its type, cause, duration, scope of impact, any cross-border effect, and the steps you took to remedy it.
Status since 2026-01-01Read from the corpus 2026-09-18
|
|
|
Cybersecurity Incident Reporting and Emergency Response (Décret-loi n° 2023-17 du 11 mars 2023, relatif à la cybersécurité, Arts. 17-20, 24-25)
immediatelyImmediately inform the national contact point or your emergency response center of any cybersecurity incident or attack, and comply with the emergency measures either one orders.
30 daysWhere an incident or attack has disrupted your information system or communications network, or endangered the national cyberspace's security, remedy the failure within thirty days of the Agency's warning, or expect the minister of communication technologies to order the temporary isolation of your systems.
Status since 2023-09-11Read from the corpus 2026-09-18
|
|
|
Cybersecurity Law, Reporting and Cooperation Duties (Law No. 7545 (12 March 2025), Art. 7)
promptlyProvide the Cybersecurity Directorate promptly with any data, information, document, hardware, software, or other contribution it requests in connection with its duties.
Status since 2025-03-19Read from the corpus 2026-09-14
|
|
|
Law No. 08/L-173 on Cyber Security, Incident Reporting and Enforcement (Law No. 08/L-173 on Cyber Security, Arts. 6, 8 and 24)
24 hoursAs an operator of essential services, notify the Agency for Cyber Security immediately, and no later than 24 hours after becoming aware, of a cyber incident with a significant impact on system security or service continuity, and notify affected persons or the public within a reasonable time where individual notice is impractical.
immediatelyAs a digital service provider, notify the Agency for Cyber Security immediately upon becoming aware of a cyber incident with a significant impact on the digital service you provide.
Status since 2023-03-14Read from the corpus 2026-09-18
|
None of these instruments is in the project's jurisdictions.
3Privacy law: personal-data breach notification, by jurisdiction
130 instruments in 123 jurisdictions sit in the corpus's privacy topic under its breach-notification family, as of 2026-09-18. 73 state a numeric clock; 36 state a standard and no number; 21 state the duty without a clock in their obligation lines. These bind the party that decides why and how personal data is processed, which for an agent is nearly always its OPERATOR, and the clock runs to the supervisory authority and, separately, to the people affected. The GDPR row is stated once for the EU and once for each member state, because each state's authority is the recipient.
European Union Show the 1 instrumentHide the 1 instrument
| Jurisdiction | Instrument, and the obligation lines that carry a clock |
|---|---|
|
GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the competent supervisory authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting EU personal data, unless the breach is unlikely to risk individuals' rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-23
|
None of these instruments is in the project's jurisdictions.
EU member states (the national layer) Show the 27 instrumentsHide the 27 instruments
| Jurisdiction | Instrument, and the obligation lines that carry a clock |
|---|---|
|
GDPR Articles 33-34, Breach Notification in Austria (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the Datenschutzbehorde without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Austria, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the GBA/APD within 72 hours of becoming aware of a personal-data breach affecting a person in Belgium, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify KZLD within 72 hours of becoming aware of a personal-data breach affecting a person in Bulgaria, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them, using KZLD's own Bulgarian-language notification template.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification in Cyprus (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the ODPC without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Cyprus, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify UOOU within 72 hours of becoming aware of a personal-data breach affecting a person in Czechia, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification in Germany (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the competent German data protection authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Germany, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification in Denmark (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify Datatilsynet without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Denmark, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification in Estonia (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the Estonian Data Protection Inspectorate without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Estonia, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2019-01-15Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34 and LOPDGDD Article 69, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34; LOPDGDD, Art. 69, Art. 73(r)-(s))
72 hoursNotify the AEPD within 72 hours of becoming aware of a personal-data breach affecting a person in Spain, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-12-07Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification in Finland (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the Data Protection Ombudsman without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Finland, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2019-01-01Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the CNIL within 72 hours of becoming aware of a personal-data breach affecting a person in France, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification in Greece (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the Hellenic Data Protection Authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Greece, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify AZOP within 72 hours of becoming aware of a personal-data breach affecting a person in Croatia, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
Infotorveny Sections 25/J-25/K, Breach Notification, Inserted by Act XXXVIII of 2018 (2011. evi CXII. torveny, 25/J-25/K. section, as inserted by 2018. evi XXXVIII. torveny 17. section)
72 hoursNotify NAIH without delay, and no later than 72 hours after becoming aware of it, of a personal-data breach affecting a person in Hungary, per Infotorveny Section 25/J(1).
Status since 2019-04-26Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification in Ireland (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the Data Protection Commission without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Ireland, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the Garante within 72 hours of becoming aware of a personal-data breach affecting a person in Italy, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification in Lithuania (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify VDAI without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Lithuania, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification in Luxembourg (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the CNPD without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Luxembourg, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification in Latvia (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the Data State Inspectorate without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Latvia, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification in Malta (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the IDPC without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Malta, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34 and UAVG Article 42, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34; UAVG, Art. 42)
72 hoursNotify the AP within 72 hours of becoming aware of a personal-data breach affecting a person in the Netherlands, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them, subject to UAVG Article 42's national exception.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify UODO within 72 hours of becoming aware of a personal-data breach affecting a person in Poland, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification in Portugal (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the CNPD without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Portugal, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify ANSPDCP within 72 hours of becoming aware of a personal-data breach affecting a person in Romania, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify IMY within 72 hours of becoming aware of a personal-data breach affecting a person in Sweden, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the Slovenian Information Commissioner within 72 hours of becoming aware of a personal-data breach affecting a person in Slovenia, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
|
|
|
GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the Slovak Office for Personal Data Protection within 72 hours of becoming aware of a personal-data breach affecting a person in Slovakia, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
|
None of these instruments is in the project's jurisdictions.
United Kingdom Show the 1 instrumentHide the 1 instrument
| Jurisdiction | Instrument, and the obligation lines that carry a clock |
|---|---|
|
UK GDPR Articles 33-34 and PECR, Breach Notification in the United Kingdom (UK GDPR, Arts. 33-34; Privacy and Electronic Communications Regulations (PECR), as amended by the Data (Use and Access) Act 2025)
72 hoursNotify the ICO without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in the United Kingdom, unless the breach is unlikely to risk their rights and freedoms.
72 hoursNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms, and if you are a telecoms or ISP-type provider, notify a PECR breach to the ICO within 72 hours.
Status since 2018-05-25Read from the corpus 2026-08-24
|
None of these instruments is in the project's jurisdictions.
United States, federal Show the 2 instrumentsHide the 2 instruments
| Jurisdiction | Instrument, and the obligation lines that carry a clock |
|---|---|
|
GLBA Safeguards Rule Breach Notification Amendment (16 CFR Section 314.4(j))
30 daysNotify the FTC within 30 days of discovering a security event that has compromised unencrypted customer information for 500 or more consumers.
Status since 2024-05-13Read from the corpus 2026-08-23
|
|
|
HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D (Sections 164.400-164.414))
60 daysNotify affected individuals without unreasonable delay and no later than 60 days after discovering a breach of unsecured protected health information.
Status since 2009-09-23Read from the corpus 2026-08-23
|
None of these instruments is in the project's jurisdictions.
United States, states Show the 57 instrumentsHide the 57 instruments
| Jurisdiction | Instrument, and the obligation lines that carry a clock |
|---|---|
|
Alaska Personal Information Protection Act, breach notification duty (Alaska Stat. Secs. 45.48.010-45.48.070)
without unreasonable delayDisclose a breach of the security of an information system containing an Alaska resident's personal information to each affected resident in the most expeditious time possible and without unreasonable delay.
Status enacted, not yet in effectRead from the corpus 2026-08-27
|
|
|
Alabama Data Breach Notification Act of 2018 (Ala. Code sec. 8-38-1 et seq. (Act 2018-396))
The obligation lines state no clock of their own.
Status enacted, not yet in effectRead from the corpus 2026-08-27
|
|
|
Arkansas Personal Information Protection Act, breach notification and security (Ark. Code Ann. secs. 4-110-101 to 4-110-108)
without unreasonable delayNotify each affected Arkansas resident of a breach of security without unreasonable delay.
45 daysNotify the Arkansas Attorney General if the breach affects more than 1,000 individuals, at the same time as consumer notice or within 45 days of determining a reasonable likelihood of harm, whichever occurs first.
Status enacted, not yet in effectRead from the corpus 2026-08-27
|
|
|
Arizona data breach notification law (A.R.S. secs. 18-551 to 18-552)
45 daysNotify each affected Arizona resident of a breach of system security involving their personal information without unreasonable delay and no later than 45 days after determining the breach occurred.
Status enacted, not yet in effectRead from the corpus 2026-08-27
|
|
|
California Data Breach Notification Law, as amended by SB 446 (Cal. Civ. Code section 1798.82, as amended by SB 446 (2025, Ch. 319))
30 daysNotify affected California residents of a breach of their unencrypted personal information within 30 calendar days of discovery or notification.
15 daysNotify the California Attorney General within 15 days of consumer notification when a breach affects more than 500 California residents.
Status since 2026-01-01Read from the corpus 2026-08-23
|
|
|
C.R.S. 6-1-716, Notification of Security Breach (C.R.S. section 6-1-716)
30 daysIf you experience unauthorized acquisition of unencrypted computerized personal information of Colorado residents, notify affected residents without unreasonable delay and within 30 days of determining a breach occurred.
Status since 2018-09-01Read from the corpus 2026-08-23
|
|
|
Breach of security re computerized data containing personal information (Conn. Gen. Stat. § 36a-701b)
60 daysNotify each affected Connecticut resident of a breach of security involving personal information without unreasonable delay and no later than 60 days after discovery, unless federal law requires a shorter time.
Status enacted, not yet in effectRead from the corpus 2026-09-02
|
|
|
Consumer Security Breach Notification (D.C. Code §§ 28-3851 to 28-3853 (Title 28, Chapter 38, Subchapter II))
without unreasonable delayIf your business conducts business in the District of Columbia and discovers a breach of the security of a system containing a District resident's personal information, notify each affected resident in the most expedient time possible and without unreasonable delay.
Status since 2007-07-01Read from the corpus 2026-09-06
|
|
|
Computer Security Breaches (Del. Code Ann. tit. 6, §§ 12B-101 to 12B-104)
60 daysNotify affected Delaware residents of a breach of security without unreasonable delay and no later than 60 days after determining the breach occurred.
Status enacted, not yet in effectRead from the corpus 2026-08-27
|
|
|
Florida Information Protection Act, breach notification (Fla. Stat. § 501.171)
30 daysNotify the Florida Department of Legal Affairs of a breach of security affecting 500 or more individuals in Florida as expeditiously as practicable, and no later than 30 days after determining a breach occurred or having reason to believe one occurred.
30 days15 daysNotify each affected Florida individual of a breach no later than 30 days after determining a breach occurred, unless you obtain a written 15-day extension for good cause.
Status enacted, not yet in effectRead from the corpus 2026-08-27
|
|
|
Georgia Personal Identity Protection Act, notification of security breach (O.C.G.A. Sec. 10-1-912)
without unreasonable delayGive notice of a breach of the security of a system containing a Georgia resident's personal information in the most expedient time possible and without unreasonable delay.
Status enacted, not yet in effectRead from the corpus 2026-08-27
|
|
|
Notification of Breaches of Personal Information (9 GCA §§ 48.10-48.80)
without unreasonable delayDisclose a breach of the security of your system to any affected Guam resident without unreasonable delay once you know or reasonably believe the breach caused or will cause identity theft or other fraud.
as soon as practicableIf you hold a Guam resident's computerized personal information for another owner or licensee rather than for yourself, notify that owner or licensee as soon as practicable after discovering a breach.
Status in effectRead from the corpus 2026-09-05
|
|
|
Hawaii Security Breach of Personal Information Act, notice of security breach (Haw. Rev. Stat. Secs. 487N-1, 487N-2)
without unreasonable delayProvide clear and conspicuous notice, without unreasonable delay, to a Hawaii resident affected by a security breach of a system containing their personal information, describing the incident, the type of information exposed, and remedial steps taken.
Status enacted, not yet in effectRead from the corpus 2026-08-27
|
|
|
Personal Information Security Breach Protection (Iowa Code § 715C.2)
without unreasonable delayNotify affected Iowa residents of a breach of security in the most expeditious manner possible and without unreasonable delay.
5 business daysNotify the Iowa Attorney General's consumer protection division within five business days of notifying consumers, if the breach requires notifying more than 500 Iowa residents.
Status enacted, not yet in effectRead from the corpus 2026-08-27
|
|
|
Identity Theft Act, breach of security disclosure duty (Idaho Code § 28-51-105)
as soon as possibleGive notice to each affected Idaho resident as soon as possible, and in the most expedient time possible without unreasonable delay, after discovering a breach of system security involving personal information.
24 hoursIf you are a government agency, also notify the Idaho Attorney General within 24 hours of discovering the breach; this duty does not extend to a private commercial entity.
Status enacted, not yet in effectRead from the corpus 2026-08-28
|
|
|
Personal Information Protection Act, data breach notification (815 ILCS 530/1 et seq. (P.A. 94-36, eff. 2006-01-01))
without unreasonable delayNotify affected Illinois residents of a data breach in the most expedient time possible and without unreasonable delay after discovering unauthorized acquisition of their computerized personal information, which includes unique biometric data used to authenticate an individual.
Status since 2006-01-01Read from the corpus 2026-08-23
|
|
|
Disclosure of Security Breach Act (Ind. Code §§ 24-4.9-3-1, 24-4.9-3-3, 24-4.9-4-1, 24-4.9-4-2)
45 daysDisclose a breach to affected Indiana residents without unreasonable delay and no later than 45 days after discovering that the unauthorized acquisition has resulted in or could result in identity deception, identity theft, or fraud.
Status enacted, not yet in effectRead from the corpus 2026-08-27
|
|
|
Kansas Breach Notification Act, notice of security breach (K.S.A. 50-7a02(a)-(f))
The obligation lines state no clock of their own.
Status enacted, not yet in effectRead from the corpus 2026-08-28
|
|
|
Student Data Privacy Act, breach notice for student data (K.S.A. 72-6318)
immediatelyImmediately notify the affected Kansas student, or the student's parent or guardian, of a breach or unauthorized disclosure of student data if your entity has access to that data.
Status enacted, not yet in effectRead from the corpus 2026-08-28
|
|
|
Notification to affected persons of computer security breach (KRS 365.732)
without unreasonable delayNotify an affected Kentucky resident of a breach involving unencrypted personal information in the most expedient time possible and without unreasonable delay.
Status since 2014-07-15Read from the corpus 2026-08-27
|
|
|
Database Security Breach Notification Law, definitions (La. R.S. 51:3073)
The obligation lines state no clock of their own.
Status since 2006-01-01Read from the corpus 2026-08-28
|
|
|
Database Security Breach Notification Law, notice duty (La. R.S. 51:3074(C), (E), (I))
60 daysNotify each affected Louisiana resident of a breach involving personal information in the most expedient time possible and without unreasonable delay, no later than 60 days after discovery.
Status since 2006-01-01Read from the corpus 2026-08-28
|
|
|
Security Breach statute, credit monitoring offer required (Mass. Gen. Laws ch. 93H, § 3A)
The obligation lines state no clock of their own.
Status enacted, not yet in effectRead from the corpus 2026-08-28
|
|
|
Security Breach statute, duty to report breach of personal information (Mass. Gen. Laws ch. 93H, § 3)
as soon as practicableNotify the Massachusetts Attorney General, the Director of Consumer Affairs and Business Regulation, and each affected Massachusetts resident as soon as practicable and without unreasonable delay after learning of a breach of security involving personal information.
Status enacted, not yet in effectRead from the corpus 2026-08-28
|
|
|
Maryland Personal Information Protection Act (MPIPA), breach notification (Md. Code Ann., Com. Law §§ 14-3501, 14-3504 (Title 14, Subtitle 35))
45 daysNotify each affected Maryland individual as soon as reasonably practicable, and no later than 45 days after discovering or being notified of the breach, once you determine a likelihood that personal information has been or will be misused.
7 days45 daysWhere notification is delayed because a law enforcement agency says it would impede an investigation, notify within 7 days after that delay is cleared, or by the original 45-day deadline, whichever is later.
Status enacted, not yet in effectRead from the corpus 2026-09-02
|
|
|
Notice of Risk to Personal Data (10 M.R.S. secs. 1347-1349)
30 daysNotify affected Maine residents of a breach of security as expediently as possible and without unreasonable delay, no more than 30 days after becoming aware of the breach and identifying its scope, absent a law enforcement delay.
Status enacted, not yet in effectRead from the corpus 2026-08-27
|
|
|
Identity Theft Protection Act, breach of security notice duty (MCL 445.72)
The obligation lines state no clock of their own.
Status since 2006-07-02Read from the corpus 2026-08-28
|
|
|
Identity Theft Protection Act, personal information and personal identifying information defined (MCL 445.63(q), (r))
The obligation lines state no clock of their own.
Status since 2011-04-01Read from the corpus 2026-08-28
|
|
|
Minnesota breach notification (Minn. Stat. § 325E.61)
without unreasonable delayDisclose a breach of the security of the system to an affected Minnesota resident in the most expedient time possible and without unreasonable delay. Minnesota sets no fixed numeric-day cap, unlike several peer states.
immediatelyNotify the data owner immediately upon discovering a breach if you maintain, but do not own, the affected data.
Status enacted, not yet in effectRead from the corpus 2026-08-27
|
|
|
Notice of security breach of personal information (Mo. Rev. Stat. Sec. 407.1500)
without unreasonable delayNotify each affected Missouri consumer of a breach of security involving their personal information without unreasonable delay.
without unreasonable delayNotify the Missouri Attorney General's office and every nationwide consumer reporting agency without unreasonable delay if you provide notice to more than 1,000 consumers at one time.
Status since 2009-08-28Read from the corpus 2026-08-27
|
|
|
Breach notification law, notice of security breach (Miss. Code Ann. § 75-24-29(2)-(3))
without unreasonable delayDisclose a breach of security to all affected Mississippi individuals without unreasonable delay, unless your investigation reasonably determines the breach will not likely result in harm.
Status since 2011-07-01Read from the corpus 2026-08-28
|
|
|
Notification of security breach (Mont. Code Ann. § 30-14-1704)
without unreasonable delayNotify affected Montana residents of a breach of security without unreasonable delay, and simultaneously submit an electronic copy of the notification to the Attorney General's consumer protection office.
Status enacted, not yet in effectRead from the corpus 2026-08-27
|
|
|
Identity Theft Protection Act, security breach notification (N.C. Gen. Stat. Secs. 75-61, 75-65)
without unreasonable delayNotify each affected North Carolina resident of a security breach involving their personal information without unreasonable delay, consistent with the legitimate needs of law enforcement.
Status enacted, not yet in effectRead from the corpus 2026-09-02
|
|
|
Notice of Security Breach for Personal Information (N.D. Cent. Code ch. 51-30)
without unreasonable delayDisclose a breach of the security system to any affected North Dakota resident in the most expedient time possible and without unreasonable delay.
Status enacted, not yet in effectRead from the corpus 2026-08-28
|
|
|
Nebraska Financial Data Protection and Consumer Notification of Data Security Breach Act (Neb. Rev. Stat. § 87-803)
The obligation lines state no clock of their own.
Status enacted, not yet in effectRead from the corpus 2026-08-27
|
|
|
Notice of Security Breach (RSA 359-C:19-21)
as soon as possibleNotify affected New Hampshire residents and the Attorney General's office as soon as possible on determining a security breach of personal information occurred.
Status since 2007-01-01Read from the corpus 2026-09-02
|
|
|
New Jersey Identity Theft Prevention Act, breach notification (N.J. Stat. § 56:8-163)
without unreasonable delayDisclose the breach to each affected New Jersey resident in the most expedient time possible and without unreasonable delay. New Jersey sets no fixed numeric-day cap.
Status since 2006-01-01Read from the corpus 2026-08-27
|
|
|
Data Breach Notification Act (NMSA 1978 Secs. 57-12C-1 to 57-12C-12)
45 daysNotify each affected New Mexico resident of a security breach involving their personal identifying information in the most expedient time possible and no later than 45 calendar days after discovery.
Status enacted, not yet in effectRead from the corpus 2026-08-28
|
|
|
Security breach of personal information, notification (NRS 603A.220)
without unreasonable delayDisclose a security breach of personal information to an affected Nevada resident in the most expedient time possible and without unreasonable delay. Nevada sets no fixed numeric deadline.
Status enacted, not yet in effectRead from the corpus 2026-09-02
|
|
|
Stop Hacks and Improve Electronic Data Security (SHIELD) Act, breach notification duty (N.Y. Gen. Bus. Law § 899-aa)
30 daysDisclose a breach of the security of your system to each affected New York resident in the most expedient time possible and without unreasonable delay, and no later than 30 days after discovering the breach.
Status since 2019-10-23Read from the corpus 2026-08-27
|
|
|
Security Breach Notification Act (Ohio Rev. Code Sec. 1349.19)
45 daysNotify an affected Ohio resident of a security breach involving their personal information in the most expedient time possible and no later than 45 days after discovery.
without unreasonable delayNotify every nationwide consumer reporting agency without unreasonable delay if a single breach affects more than 1,000 Ohio residents.
Status since 2007-03-30Read from the corpus 2026-08-29
|
|
|
Security Breach Notification Act (Okla. Stat. tit. 24, Secs. 162-166)
without unreasonable delayProvide notice of a breach of security involving personal information without unreasonable delay.
60 daysNotify the Oklahoma Attorney General within 60 days of consumer notice if the breach affects 500 or more Oklahoma residents (1,000 or more for a breach maintained by a credit bureau).
Status since 2026-01-01Read from the corpus 2026-08-28
|
|
|
Notice of breach of security (ORS 646A.604)
The obligation lines state no clock of their own.
Status enacted, not yet in effectRead from the corpus 2026-08-27
|
|
|
Breach of Personal Information Notification Act (73 P.S. secs. 2302, 2303, 2305, 2308 (Act 94 of 2005))
without unreasonable delayNotify each affected Pennsylvania resident of a breach of system security involving personal information without unreasonable delay.
Status since 2006-06-20Read from the corpus 2026-08-28
|
|
|
Ley de Información al Ciudadano sobre la Seguridad de Bancos de Información (data breach notification) (Ley Núm. 111 de 7 de septiembre de 2005, según enmendada; 10 L.P.R.A. §§ 4051-4055)
The obligation lines state no clock of their own.
Status in effectRead from the corpus 2026-09-05
|
|
|
Identity Theft Protection Act of 2015, notification of breach (R.I. Gen. Laws secs. 11-49.3-4, 11-49.3-5)
45 days30 daysNotify affected Rhode Island residents of a breach posing a significant risk of identity theft within 45 days of confirming the breach, or within 30 days if you are a state or municipal agency.
Status enacted, not yet in effectRead from the corpus 2026-08-27
|
|
|
Business data breach of security, notification statute (S.C. Code Ann. sec. 39-1-90)
without unreasonable delayNotify each affected South Carolina resident of a breach of security involving personal identifying information in the most expedient time possible and without unreasonable delay.
Status since 2009-07-01Read from the corpus 2026-09-02
|
|
|
Breach of system security, notification statute (SDCL secs. 22-40-19 to 22-40-26 (SL 2018 ch. 135))
60 daysNotify each affected South Dakota resident of a breach of system security not later than 60 days after discovery, absent a law enforcement delay.
Status since 2018-07-01Read from the corpus 2026-08-28
|
|
|
Identity Theft Enforcement and Protection Act, breach notification (Tex. Bus. & Com. Code sec. 521.053, as amended by Tex. SB 768, 88th Legislature (2023))
60 daysNotify each affected Texas resident of a breach of system security involving their sensitive personal information without unreasonable delay and no later than 60 days after determining the breach occurred.
30 daysNotify the Texas Attorney General as soon as practicable and no later than 30 days after determining the breach occurred, if the breach affects 250 or more Texas residents.
Status since 2009-04-01Read from the corpus 2026-08-23
|
|
|
Protection of Personal Information Act (Utah Code 13-44-101 et seq.)
promptlyIf unencrypted Utah-resident data combining a name with a Social Security number, a driver license or state ID number, or a financial account or card number with its access code is breached, investigate promptly in good faith and notify each affected Utah resident without unreasonable delay.
Status since 2024-05-01Read from the corpus 2026-08-23
|
|
|
Breach of personal information notification (Va. Code Ann. § 18.2-186.6)
without unreasonable delayNotify the Virginia Office of the Attorney General and each affected Virginia resident of a breach of system security involving personal information without unreasonable delay after discovery.
Status enacted, not yet in effectRead from the corpus 2026-09-02
|
|
|
Disclosure of Breach of Security (Identity Theft and Privacy Protection) (14 V.I.C. §§ 2208-2209)
without unreasonable delayNotify an affected Virgin Islands resident without unreasonable delay after discovering that unencrypted personal information (a name combined with a Social Security number, driver's license number, or financial account number with its access code) was acquired without authorization.
Status in effectRead from the corpus 2026-09-05
|
|
|
Security Breach Notice Act (9 V.S.A. sec. 2435)
45 daysNotify an affected Vermont consumer of a security breach in the most expedient time possible and without unreasonable delay, and no later than 45 days after discovery.
14 business daysNotify the Attorney General or the Department of Financial Regulation, as applicable, with a preliminary description of the breach within 14 business days of discovery.
Status since 2007-01-01Read from the corpus 2026-08-27
|
|
|
Notice of security breaches involving personal information (RCW 19.255, as amended by HB 1071 (2019 c 241); originally enacted 2005 c 368)
30 daysNotify affected Washington residents of a breach of unsecured personal information, including biometric identifiers, in the most expedient time possible and no more than 30 calendar days after discovery.
Status since 2020-03-01Read from the corpus 2026-09-02
|
|
|
Notice of unauthorized acquisition of personal information (Wis. Stat. sec. 134.98)
45 daysMake reasonable efforts to notify each affected Wisconsin individual of an unauthorized acquisition of their personal information within a reasonable time, not to exceed 45 days after learning of it.
Status enacted, not yet in effectRead from the corpus 2026-08-28
|
|
|
Breach of Security of Consumer Information (W. Va. Code secs. 46A-2A-101 to 46A-2A-105)
without unreasonable delayNotify each affected West Virginia resident of a breach of security involving personal information without unreasonable delay.
Status enacted, not yet in effectRead from the corpus 2026-08-28
|
|
|
Breach of the security of a computerized data system, notification duty (Wyo. Stat. Ann. secs. 40-12-501 to 40-12-511)
as soon as possibleGive notice as soon as possible to each affected Wyoming resident once your investigation determines misuse of their personal identifying information has occurred or is reasonably likely.
Status enacted, not yet in effectRead from the corpus 2026-08-28
|
None of these instruments is in the project's jurisdictions.
Asia and the Pacific Show the 17 instrumentsHide the 17 instruments
| Jurisdiction | Instrument, and the obligation lines that carry a clock |
|---|---|
|
Privacy Act 1988 (Cth), Notifiable Data Breaches Scheme (Privacy Act 1988 (Cth), Part IIIC, ss. 26WE, 26WK, 26WL)
as soon as practicablePrepare a statement about an eligible data breach and give a copy to the Information Commissioner as soon as practicable after becoming aware of reasonable grounds to believe the breach happened.
Status since 2018-02-22Read from the corpus 2026-09-06
|
|
|
Personal Data Protection Act, 2026, breach notification duties (Personal Data Protection Act, 2026, Act No. 63 of 2026, s.20)
The obligation lines state no clock of their own.
Status since 2025-11-06Read from the corpus 2026-08-29
|
|
|
Personal Data Protection Order 2025, breach notification (Personal Data Protection Order, 2025 (S 1/2025), Part 7 (ss.25-29))
3 daysBrunei's Personal Data Protection Order 2025 has required, since this duty (Part 7) took effect 1 January 2026 under Government Gazette No. S 11/2025, an organisation to notify the Authority within 3 days of assessing that a breach is notifiable, meaning it is likely to cause significant harm or is of significant scale, and to notify each affected individual, for a breach involving any personal data including a voiceprint or faceprint.
Status since 2026-01-01Read from the corpus 2026-08-29
|
|
|
Personal Information Protection Law, Data Breach Notification (PIPL Art. 57)
immediatelyUpon discovering an actual or possible leak, alteration, or loss of personal information, immediately take remedial measures and notify both the competent personal information protection department and every affected individual, unless the remedial measures can be shown to effectively prevent harm.
Status since 2021-11-01Read from the corpus 2026-08-23
|
|
|
Law on Personal Data Protection, breach notification (Law No. 27 of 2022 on Personal Data Protection, Article 46)
72 hoursAn app that suffers a failure of personal data protection affecting an individual in Indonesia must give written notification within 72 hours to the affected individual and to the supervisory institution, describing the data disclosed and the remedial measures taken.
Status since 2022-10-17Read from the corpus 2026-08-29
|
|
|
Digital Personal Data Protection Act, 2023, breach notification duties (Digital Personal Data Protection Act, 2023 (DPDPA), No. 22 of 2023, breach notification, s.8(6))
72 hoursIndia's data-breach notification duty, covering personal data including a biometric identifier, has not yet commenced and is scheduled to take effect 13 May 2027. Once in force, an app must notify the Data Protection Board and each affected data principal of a personal data breach without delay, and must supply the Board a detailed follow-up report within 72 hours of becoming aware of the breach.
Status from 2027-05-13 [enacted, not yet in effect]Read from the corpus 2026-08-29
|
|
|
Act on the Protection of Personal Information, breach notification (Act No. 57 of 2003, as amended by Act No. 37 of 2021, Art. 26)
The obligation lines state no clock of their own.
Status since 2022-04-01Read from the corpus 2026-08-29
|
|
|
Personal Information Protection Act, breach notification duties (Act No. 10465 (as amended by Act No. 19234, 2023), Art. 34; Enforcement Decree Arts. 39-40)
The obligation lines state no clock of their own.
Status since 2023-09-15Read from the corpus 2026-08-23
|
|
|
Law on Personal Data and Their Protection, breach notification (Law No. 94-V (21 May 2013), Art. 25(2))
The obligation lines state no clock of their own.
Status since 2024-07-01Read from the corpus 2026-08-29
|
|
|
Personal Data Protection Act, breach notification duties (Personal Data Protection Act, No. 9 of 2022, as amended by Act No. 22 of 2025, s.23)
The obligation lines state no clock of their own.
Status since 2025-03-18Read from the corpus 2026-08-29
|
|
|
Law on Protection of Personal Data, breach notification (Law on Protection of Personal Data (17 December 2021), Art. 25.1.3; Art. 10.5)
The obligation lines state no clock of their own.
Status since 2022-05-01Read from the corpus 2026-08-29
|
|
|
Personal Data Protection Act, data protection officer and breach notification (Act 709 (Malaysia) ss.12A-12B, as inserted by Act A1727 s.6, in force 2025-06-01)
as soon as practicableAn app that controls or processes the personal data of individuals in Malaysia must appoint a Data Protection Officer, and a data controller who reasonably believes a personal data breach has occurred must notify the Commissioner as soon as practicable, and must notify affected data subjects without unnecessary delay where the breach causes or is likely to cause significant harm.
Status since 2025-06-01Read from the corpus 2026-08-29
|
|
|
Privacy Act 2020, Notifiable Privacy Breaches (Privacy Act 2020 (NZ), No 31, ss. 112-118)
as soon as practicableNotify the Privacy Commissioner as soon as practicable after becoming aware that a notifiable privacy breach, one reasonably believed to have caused or be likely to cause serious harm, has occurred.
as soon as practicableNotify each affected individual, or give public notice if individual notice is not reasonably practicable, as soon as practicable after becoming aware of a notifiable privacy breach, unless a statutory exception or permitted delay applies.
Status since 2020-12-01Read from the corpus 2026-09-06
|
|
|
Data Privacy Act of 2012, breach notification (Republic Act No. 10173 (2012), Section 20(f))
promptlyAn app that reasonably believes sensitive personal information or identity-fraud-enabling information of an individual in the Philippines has been acquired by an unauthorized person, in a way likely to cause serious harm, must promptly notify the National Privacy Commission and the affected individuals.
Status since 2012-08-15Read from the corpus 2026-08-29
|
|
|
Personal Data Protection Act, data breach notification (Personal Data Protection Act 2012, Part 6A, ss.26A-26E, as added by Act 40 of 2020)
3 daysAn app that experiences a data breach affecting an individual's personal data in Singapore must assess whether the breach is likely to cause significant harm or is of significant scale, and if so must notify the PDPC as soon as practicable and in any case within 3 calendar days of that assessment, and must also notify each affected individual unless a statutory exception applies.
Status since 2021-02-01Read from the corpus 2026-08-29
|
|
|
Personal Data Protection Act, breach notification (Personal Data Protection Act B.E. 2562 (2019), Section 37(4))
72 hoursAn app that experiences a personal data breach affecting an individual in Thailand must notify the Personal Data Protection Committee's Office without delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to pose a risk to the affected individuals; where the breach is likely to cause high risk, the app must also notify each affected individual without delay.
Status since 2022-06-01Read from the corpus 2026-08-29
|
|
|
Law on Personal Data Protection, breach notification (Law No. 91/2025/QH15, Article 23)
72 hoursAn app that detects a violation of Vietnam's personal data protection rules likely to cause harm to national defense and security, social order, or an individual's life, health, honor, dignity, or property must notify the agency in charge of personal data protection within 72 hours.
Status since 2026-01-01Read from the corpus 2026-08-29
|
None of these instruments is in the project's jurisdictions.
The Americas outside the United States Show the 2 instrumentsHide the 2 instruments
| Jurisdiction | Instrument, and the obligation lines that carry a clock |
|---|---|
|
Data Protection Act 2021, personal data breach notification (Data Protection Act, 2021 (Act No. 45 of 2021), ss. 60-62)
72 hoursWhere feasible, notify the Data Protection Commissioner of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to risk a person's rights and freedoms.
without undue delayWhere a personal data breach is likely to result in a high risk to a person's rights and freedoms, notify that person without undue delay.
Status enacted, not yet in effectRead from the corpus 2026-09-05
|
|
|
PIPEDA breach of security safeguards regime (S.C. 2000, c. 5, ss. 10.1-10.3)
The obligation lines state no clock of their own.
Status since 2018-11-01Read from the corpus 2026-09-02
|
None of these instruments is in the project's jurisdictions.
Africa, the Middle East and elsewhere Show the 23 instrumentsHide the 23 instruments
| Jurisdiction | Instrument, and the obligation lines that carry a clock |
|---|---|
|
ADGM Data Protection Regulations, breach notification (ADGM Data Protection Regulations 2021, personal data breach notification provisions)
72 hoursAn app that is a controller or processor established in or targeting the ADGM free zone and that suffers a personal data breach must notify the Commissioner of Data Protection without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to pose a risk to individuals' rights.
Status since 2021-02-14Read from the corpus 2026-08-29
|
|
|
Federal Decree-Law on the Protection of Personal Data, breach notification (Federal Decree-Law No. 45 of 2021, Art. 9)
The obligation lines state no clock of their own.
Status since 2022-01-02Read from the corpus 2026-08-29
|
|
|
Personal Information Protection Act 2016, breach of security notification (Personal Information Protection Act 2016 (Bermuda), 2016:43, s. 14 (breach of security))
without undue delayNotify the Privacy Commissioner, then any affected individual, without undue delay of a breach of security that is likely to adversely affect an individual.
Status in effectRead from the corpus 2026-09-07
|
|
|
FADP Article 24, Breach Notification in Switzerland (Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 24)
as soon as possibleNotify the FDPIC as soon as possible once you become aware of a data security breach likely to result in a high risk to a Swiss data subject's personality or fundamental rights.
Status since 2023-09-01Read from the corpus 2026-08-24
|
|
|
Law on Personal Data Protection, breach notification (Law of Georgia on Personal Data Protection, Law No. 3144-XI, Arts. 29-30, as amended by Law No. 1289 (17 December 2025))
72 hoursAn app that suffers an incident affecting the personal data of a person in Georgia must notify the State Audit Office within 72 hours of identification, and must notify affected data subjects immediately or without unreasonable delay where there is a high probability of significant damage or a significant threat to their fundamental rights.
Status since 2024-03-01Read from the corpus 2026-08-29
|
|
|
Protection of Privacy Law, breach notification duty (Privacy Protection Regulations (Data Security), 5777-2017, Art. 11(d)(1); Protection of Privacy Law, 5741-1981, monetary sanctions schedule item (21))
immediatelyAn app that suffers a severe security incident affecting the personal data of a person in Israel must immediately notify the Head of the Privacy Protection Authority under the Data Security Regulations' Art. 11(d)(1) duty; the regulations' own text, including any data-subject notification duty, is not set out here and should be confirmed directly before relying on it for full compliance detail.
Status since 2018-05-08Read from the corpus 2026-08-29
|
|
|
Act No. 90/2018, Breach Notification in Iceland (Log nr. 90/2018 (breach notification provisions))
72 hoursNotify Personuvernd without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Iceland, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-07-15Read from the corpus 2026-08-24
|
|
|
Personal Data Protection Law, breach notification (Law No. 24 of 2023, Art. 20)
24 hours72 hoursAn app that suffers a serious breach of data security or safety that could cause significant harm to an individual in Jordan must notify the affected individuals within 24 hours of discovery and must notify the Unit within 72 hours of discovery with the source, mechanism, and affected individuals; a Controller found grossly negligent or engaged in misconduct in a breach is liable to compensate the affected Data Subject.
Status since 2024-03-17Read from the corpus 2026-08-29
|
|
|
Data Protection (General) Regulations, 2021 (Data Protection (General) Regulations, 2021 (Legal Notice No. 263 of 2021), regs. 7, 10, 37, 49-50)
7 days14 daysNotify a data subject in writing within seven days of declining a rectification request, or within fourteen days of declining a restriction request, giving reasons.
Status since 2022-01-14Read from the corpus 2026-09-04
|
|
|
Data Protection Act, 2019, personal data breach notification (Data Protection Act, 2019 (No. 24 of 2019), s. 43 (notification and communication of breach))
72 hoursNotify the Data Commissioner within seventy-two hours of becoming aware of a personal data breach that carries a real risk of harm, giving reasons if you notify later.
48 hoursAs a data processor, notify the data controller within forty-eight hours of becoming aware of a breach.
Status since 2019-11-25Read from the corpus 2026-09-04
|
|
|
Data Protection Act 2021 Revision, personal data breach notification (Data Protection Act (2021 Revision), s. 16 (personal data breaches))
5 daysNotify the Ombudsman and each affected data subject of a personal data breach without undue delay and no later than five days after becoming aware of it, describing the breach, its consequences, and the measures taken or recommended.
Status since 2019-09-30Read from the corpus 2026-09-07
|
|
|
DSG Breach Notification in Liechtenstein (DSG, LGBl. 2018 Nr. 272, breach notification provisions)
without undue delayNotify the Datenschutzstelle without undue delay after becoming aware of a personal data breach affecting a person in Liechtenstein that presents a risk to their rights and freedoms, under the DSG.
Status since 2019-01-01Read from the corpus 2026-08-24
|
|
|
Data Protection Act 2017, personal data breach notification (Data Protection Act 2017 (Act No. 20 of 2017), ss. 25-26 (notification and communication of personal data breach))
72 hoursNotify the Data Protection Commissioner without undue delay, and where feasible within 72 hours, of becoming aware of a personal data breach, giving reasons if notification is later.
without undue delayCommunicate a personal data breach to the affected data subject without undue delay where it is likely to result in a high risk to their rights and freedoms, unless an exception in section 26(3) applies.
Status since 2018-01-15Read from the corpus 2026-09-05
|
|
|
Personal Data Act, Breach Notification in Norway (personopplysningsloven LOV-2018-06-15-38, breach notification provisions)
72 hoursNotify Datatilsynet without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Norway, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-07-20Read from the corpus 2026-08-24
|
|
|
Personal Data Protection Law, breach notification (Royal Decree No. 6/2022, breach notification provision)
The obligation lines state no clock of their own.
Status since 2023-02-13Read from the corpus 2026-08-29
|
|
|
Personal Data Privacy Protection Law, breach notification (Law No. 13 of 2016, Arts. 13-14)
forthwithAn app that is a Processor handling the personal data of an individual in Qatar, including a voiceprint or faceprint, must forthwith notify its Controller of any breach or risk of one, and a Controller must inform the affected individual and the Competent Department where a breach of security precautions may cause serious damage to the data or the individual's privacy; the PDPPL states no fixed notification timeline.
Status since 2017-01-01Read from the corpus 2026-08-29
|
|
|
Federal Law No. 152-FZ, Article 21 Part 3.1, Breach Notification (Federal Law No. 152-FZ, Art. 21, part 3.1, added by Federal Law No. 266-FZ (in force 1 September 2022))
24 hours72 hoursNotify Roskomnadzor within 24 hours of detecting an unlawful or accidental transfer, provision, distribution, or access to personal data of a person in Russia, and file a full follow-up report within 72 hours.
Status since 2022-09-01Read from the corpus 2026-08-24
|
|
|
Personal Data Protection Law, breach notification (Royal Decree No. M/19, Art. 20)
The obligation lines state no clock of their own.
Status since 2023-09-14Read from the corpus 2026-08-29
|
|
|
Data Protection Act, 2023, personal data breach notification (Data Protection Act, 2023 (Act 24 of 2023), ss. 43-44 (notification and communication of a personal data breach))
72 hoursNotify the Information Commission of a personal data breach no later than 72 hours after becoming aware of it, giving reasons for any later notification.
promptlyPromptly inform the affected data subjects where a breach is likely to affect a significant number of individuals and their rights and freedoms.
Status since 2023-12-22Read from the corpus 2026-09-06
|
|
|
Loi n°007/PR/2015, obligation de notification des violations de données à l'ANSICE (Loi n°007/PR/2015 du 10 février 2015, art. 61)
The obligation lines state no clock of their own.
Status since 2015-02-10Read from the corpus 2026-09-07
|
|
|
Personal Data Protection Law (KVKK), breach notification (Law No. 6698, Art. 12(5))
The obligation lines state no clock of their own.
Status since 2016-04-07Read from the corpus 2026-08-29
|
|
|
Personal Data Protection Act, 2022, security and breach notification (Personal Data Protection Act, 2022 (Act No. 11 of 2022), s. 27 (security of personal data))
without undue delayNotify the Personal Data Protection Commission without undue delay of any security breach affecting personal data you process.
Status since 2023-05-01Read from the corpus 2026-09-06
|
|
|
National Digital Identification Act 2024, personal data breach notification (National Digital Identification Act 2024, No. 3 (Samoa), ss. 47-50 (personal data breach notification))
72 hoursAs a relying party or data processor in the National Digital Identification System, notify the Registrar General of a personal data breach within 72 hours of becoming aware of it, describing the categories and approximate number of records concerned.
without undue delayWhere a personal data breach is likely to result in a high risk to a registered person's rights, ensure the Registrar General can communicate the breach to that person without undue delay, in plain language, with advice on mitigating measures.
Status since 2024-02-05Read from the corpus 2026-09-07
|
None of these instruments is in the project's jurisdictions.
Every clock here runs from a moment the reporting party has to establish and evidence: awareness, detection, a materiality finding, a corrective measure. An AGENT that keeps the record of what it did, when, and on whose instruction gives its OPERATOR the thing every report on this page is built from, and the The 6 parties document says which party that is in each arrangement.