The clocks an incident starts

About this documentUpdated 2026-09-21ShowHide

Sean McDermott, Co-Founder and CEO, UnGovr

Written by Sean McDermott (with AI assistance) using the LexLint law library, which supplied every legal instrument, status and date on these pages.

Every law named here links to its summary page on lexlint.io, translated to English (if needed) and restructured to a standard format for human and code use. Every case links to the court's or the regulator's own record where one could be reached.

© 2026 UnGovr, publishing as LexLint. The text and the figures are licensed under Creative Commons Attribution-ShareAlike 4.0: share and adapt them, including commercially, with credit to LexLint (UnGovr) and under the same licence. Please contact LexLint at hello@ungovr.org to discuss other terms. Logos and wordmarks belong to their owners.

Corpus figures as of 2026-09-21.

Legal information, not legal advice. This document describes the law as written and dated; it does not apply it to any system. The notice at the foot says what that means.

Every reporting clock in the corpus that an incident involving an agent can start: the incident and vulnerability duties of cybersecurity law and the breach duties of privacy law, by jurisdiction, each with the sentence that carries the clock, and the Open Secure AI Alliance's proposed SAFE timeline drawn on the same scale.

An incident involving an AGENT, a credential it leaked, a tool it misused, a system it took down, a person's data it exposed, starts clocks in the law of every place the affected systems and people are. None of those clocks was written for agents. They are the incident and vulnerability reporting duties of cybersecurity law and the breach notification duties of privacy law, and the corpus holds them by jurisdiction, each with the sentence that carries the clock and a link to the primary source.

This document lists them, and it draws the notification timeline of the Shared AI Findings Exchange (SAFE), the incident-learning scheme the Open Secure AI Alliance (OSAA) published for comment in 2026, on the same scale, because a member of that scheme would be reporting to a regulator and to the scheme from the same incident. Nothing here says which report an organisation must file. It says which clocks exist, who set them, and where the text is.

Your project

See only the clocks your own application starts: sign in and pick a project, or open the demo to try it on the demo's sample projects. The jurisdictions come from the project's declaration on my.lexlint.io, read the way the lint reads them: the declared places, the rungs above them, and the union a member state belongs to.

Reading the clocks

Read from the sentence
The corpus keeps each clock inside the obligation sentence and has not yet given it a field of its own. The rung a row sits on here is read out of that sentence when this page is built: a number followed by hours, days, weeks or months, in a line about notifying or reporting, not preceded by a word that makes it a floor, a retention window, a remedy period or a resolution test, and no longer than sixty days, because every longer period in these lines is one of those. A recurring cadence ("a progress report every fifteen days") is not drawn either. The sentence is printed beside every rung so the reading can be checked against the words.
A clock an incident starts
Three of the families below are named for the event, so every reporting clock in them is one an incident starts. The frontier-model family is named for governance and holds other duties too, so a rung is drawn there only where the sentence names the event: an audit remediation report and a content-complaint status update are periods in that family, and neither is started by an incident.
Different starts
The clocks run from different moments: becoming aware of the incident in most rows, detecting it in some, the incident notification for a final report, a corrective measure becoming available for a vulnerability's final report. An ordering by length is not an ordering by expiry.
Staged
Most security clocks are staged: an early warning, a fuller notification, a final report. Each stage is a rung, and the tables show every stage sentence.
Two families at once
The corpus files a personal-data breach under privacy law whatever caused it, so a security incident that exposes personal data starts the privacy clock beside the security one.
Business days
A rung stated in business or working days is drawn at its calendar length and marked.
A proposal, not a law
The SAFE rungs are a scheme's proposal, quoted as read on 2026-09-18 while it was open for comment. Every other rung is a statute or regulation the corpus holds, with its status beside it.

1The proposal's timeline, and the statutory clocks beside it

Each flag is one law, and a link to it. The flag is the place whose law it is, in a heavier frame where that place is part of a country rather than a country itself. Hover for the law's name and the clock it sets; click to open it on LexLint.

Every reporting clock in the corpus on one time axis, with the SAFE proposal's rungs beside them 268 marks in four lanes, one per instrument at each of its rungs: 59 in the first day, 136 in the first week, 56 in the first month, 17 in the first quarter. The axis is logarithmic from one hour to ninety days. Each mark is the flag of the place whose law it is, and a link to that instrument's page, named by the place, the law and the clock it sets. First day notifications First week notifications First month final reports First quarter notifications The SAFE proposal, 72 hours: notify customers with credible exposure The SAFE proposal, 4 business days: submit a confidential, initial SAFE incident report The SAFE proposal, 14 days: issue a broader customer advisory when warranted The SAFE proposal, 30 days: publish a preliminary factual report, subject to security, legal and investigative constraints, and provide a preliminary control-failure analysis The SAFE proposal, 90 days: publish remediation status Security law China: National Cybersecurity Incident Reporting Measures (1 hour) Jordan: Cyber Security Law No. 16 of 2019, Article 8 private-sector incident-reporting and Center-cooperation duty (1 hour) China: National Cybersecurity Incident Reporting Measures (2 hours) European Union: DORA, Article 19 (reporting of major ICT-related incidents), with the time limits of Delegated Regulation (EU) 2025/301 (4 hours) China: National Cybersecurity Incident Reporting Measures (4 hours) Democratic Republic of the Congo: Digital Code, Livre II: Trust Service Provider Security-Incident Notification (4 hours) Jordan: Cyber Security Law No. 16 of 2019, Article 8 private-sector incident-reporting and Center-cooperation duty (4 hours) India: CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation (6 hours) European Union: Cyber Resilience Act, Manufacturer Reporting Obligations (24 hours) European Union: DORA, Article 19 (reporting of major ICT-related incidents), with the time limits of Delegated Regulation (EU) 2025/301 (24 hours) European Union: NIS2 Directive, Reporting Obligations (24 hours) Austria: Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Significant-Incident Reporting Obligations (24 hours) Belgium: Loi du 26 avril 2024, Significant-Incident Notification Obligations (24 hours) Bulgaria: Cybersecurity Act, Incident and Cyber-Threat Reporting Obligations (Zakon za kibersigurnost, ZKS) (24 hours) Cyprus: Security of Networks and Information Systems Law, Incident Notification Obligations (24 hours) Czech Republic: Cybersecurity Act (Zákon o kybernetické bezpečnosti), Incident Notification (24 hours) Germany: BSI-Gesetz (BSIG), Incident Notification (24 hours) Denmark: NIS 2-loven, Significant-Incident Reporting and Recipient-Notice Duties (24 hours) Estonia: Küberturvalisuse seadus (KüTS), Duty to Notify of a Cyber Incident (24 hours) Spain: Real Decreto-ley 12/2018, Incident Notification Obligation (24 hours) Finland: Kyberturvallisuuslaki, Significant-Incident Reporting Obligations (24 hours) France: Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Incident Notification (NIS2) (24 hours) Greece: Law 5160/2024, Significant-Incident Reporting Obligations (24 hours) Croatia: Zakon o kibernetičkoj sigurnosti and Uredba o kibernetičkoj sigurnosti, Incident and Cyber-Threat Reporting Obligations (24 hours) Hungary: Cybersecurity Act, Incident Notification and Cybersecurity Fine (24 hours) Ireland: National Cyber Security Bill, Incident Response Powers and Reporting Obligations (24 hours) Italy: Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident Notification (24 hours) Lithuania: Kibernetinio saugumo įstatymas (Law on Cyber Security), Incident Notification (24 hours) Luxembourg: Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Incident Notification (24 hours) Latvia: Nacionālās kiberdrošības likums, Incident Notification (24 hours) Netherlands: Cyberbeveiligingswet, Significant-Incident Reporting Obligations (24 hours) Poland: Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), Zgłaszanie Incydentów Poważnych (24 hours) Portugal: Regime Jurídico da Cibersegurança, Significant-Incident Reporting Obligations (24 hours) Romania: Ordonanța de urgență nr. 155/2024, Incident Notification (24 hours) Sweden: Cybersäkerhetslag, Incident Notification (24 hours) Slovenia: Zakon o informacijski varnosti (ZInfV-1), Significant-Incident Notification Obligations (24 hours) Slovakia: Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability Notification (24 hours) United States: Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) (24 hours) New York: New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent (24 hours) Micronesia: FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Incident Reporting Clock (24 hours) Ghana: Cybersecurity Act, Duty to Report Cybersecurity Incident (24 hours) Jordan: Cyber Security Law No. 16 of 2019, Article 8 private-sector incident-reporting and Center-cooperation duty (1 day) Kenya: Computer Misuse and Cybercrimes Act, Reporting of Cyber Threat (24 hours) Kiribati: Cybersecurity Act 2026, Duty to Report a Cybersecurity Incident (24 hours) Liechtenstein: Cyber-Sicherheitsgesetz (CSG), Incident Notification (24 hours) Montenegro: Law on Information Security, Cyber Threat and Incident Reporting (24 hours) Marshall Islands: Cybersecurity Act 2025, Cybersecurity Incident Reporting Obligations (24 hours) Serbia: Law on Information Security, Incident Reporting Obligations (24 hours) Tonga: Cybersecurity Act 2025, Duty to Report a Cybersecurity Incident (24 hours) Kosovo: Law No. 08/L-173 on Cyber Security, Incident Reporting and Enforcement (24 hours) United States: Computer-Security Incident Notification Requirements for Banking Organizations and Their Bank Service Providers (36 hours) Spain: Real Decreto-ley 12/2018, Incident Notification Obligation (48 hours) Kyrgyzstan: Digital Code, digital resilience incident notification (48 hours) Ethiopia: Critical Infrastructure Cybersecurity Proclamation, Cyber Incident Reporting to National CERT (48 hours) European Union: Cyber Resilience Act, Manufacturer Reporting Obligations (72 hours) European Union: DORA, Article 19 (reporting of major ICT-related incidents), with the time limits of Delegated Regulation (EU) 2025/301 (72 hours) European Union: NIS2 Directive, Reporting Obligations (72 hours) Austria: Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Significant-Incident Reporting Obligations (72 hours) Belgium: Loi du 26 avril 2024, Significant-Incident Notification Obligations (72 hours) Bulgaria: Cybersecurity Act, Incident and Cyber-Threat Reporting Obligations (Zakon za kibersigurnost, ZKS) (72 hours) Cyprus: Security of Networks and Information Systems Law, Incident Notification Obligations (72 hours) Czech Republic: Cybersecurity Act (Zákon o kybernetické bezpečnosti), Incident Notification (72 hours) Germany: BSI-Gesetz (BSIG), Incident Notification (72 hours) Denmark: NIS 2-loven, Significant-Incident Reporting and Recipient-Notice Duties (72 hours) Estonia: Küberturvalisuse seadus (KüTS), Duty to Notify of a Cyber Incident (72 hours) Spain: Real Decreto-ley 12/2018, Incident Notification Obligation (72 hours) Finland: Kyberturvallisuuslaki, Significant-Incident Reporting Obligations (72 hours) France: Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Incident Notification (NIS2) (72 hours) Greece: Law 5160/2024, Significant-Incident Reporting Obligations (72 hours) Croatia: Zakon o kibernetičkoj sigurnosti and Uredba o kibernetičkoj sigurnosti, Incident and Cyber-Threat Reporting Obligations (72 hours) Hungary: Cybersecurity Act, Incident Notification and Cybersecurity Fine (72 hours) Ireland: European Union (NIS) Regulations 2018, Incident Notification (72 hours) Ireland: National Cyber Security Bill, Incident Response Powers and Reporting Obligations (72 hours) Italy: Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident Notification (72 hours) Lithuania: Kibernetinio saugumo įstatymas (Law on Cyber Security), Incident Notification (72 hours) Luxembourg: Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Incident Notification (72 hours) Latvia: Nacionālās kiberdrošības likums, Incident Notification (72 hours) Netherlands: Cyberbeveiligingswet, Significant-Incident Reporting Obligations (72 hours) Poland: Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), Zgłaszanie Incydentów Poważnych (72 hours) Portugal: Regime Jurídico da Cibersegurança, Significant-Incident Reporting Obligations (72 hours) Romania: Ordonanța de urgență nr. 155/2024, Incident Notification (72 hours) Sweden: Cybersäkerhetslag, Incident Notification (72 hours) Slovenia: Zakon o informacijski varnosti (ZInfV-1), Significant-Incident Notification Obligations (72 hours) Slovakia: Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability Notification (72 hours) United States: Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) (72 hours) United States: Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 252.204-7012) (72 hours) New York: New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent (72 hours) Kyrgyzstan: Digital Code, digital resilience incident notification (72 hours) Andorra: Llei 22/2022, Incident Handling and Notification Obligation (72 hours) Micronesia: FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Incident Reporting Clock (72 hours) Liechtenstein: Cyber-Sicherheitsgesetz (CSG), Incident Notification (72 hours) Montenegro: Law on Information Security, Cyber Threat and Incident Reporting (72 hours) Marshall Islands: Cybersecurity Act 2025, Cybersecurity Incident Reporting Obligations (72 hours) United States: SEC Cybersecurity Risk Management, Governance, and Incident Disclosure (Regulation S-K Item 106; Form 8-K Item 1.05) (4 business days) Latvia: Nacionālās kiberdrošības likums, Coordinated Vulnerability Disclosure and Remediation (5 business days) Nigeria: Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, Reporting of Cyber Threats to the National CERT (7 days) Sierra Leone: Cyber Security and Crime Act, 2021, Reporting of Cyber Security Incidents (7 days) European Union: Cyber Resilience Act, Manufacturer Reporting Obligations (14 days) Cyprus: Security of Networks and Information Systems Law, Incident Notification Obligations (15 days) Serbia: Law on Information Security, Incident Reporting Obligations (15 days) Spain: Real Decreto-ley 12/2018, Incident Notification Obligation (20 days) European Union: Cyber Resilience Act, Manufacturer Reporting Obligations (1 month) European Union: DORA, Article 19 (reporting of major ICT-related incidents), with the time limits of Delegated Regulation (EU) 2025/301 (1 month) European Union: NIS2 Directive, Reporting Obligations (1 month) Austria: Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Significant-Incident Reporting Obligations (1 month) Belgium: Loi du 26 avril 2024, Significant-Incident Notification Obligations (1 month) Bulgaria: Cybersecurity Act, Incident and Cyber-Threat Reporting Obligations (Zakon za kibersigurnost, ZKS) (1 month) Cyprus: Security of Networks and Information Systems Law, Incident Notification Obligations (1 month) Czech Republic: Cybersecurity Act (Zákon o kybernetické bezpečnosti), Incident Notification (30 days) Germany: BSI-Gesetz (BSIG), Incident Notification (1 month) Denmark: NIS 2-loven, Significant-Incident Reporting and Recipient-Notice Duties (1 month) Estonia: Küberturvalisuse seadus (KüTS), Duty to Notify of a Cyber Incident (1 month) Finland: Kyberturvallisuuslaki, Significant-Incident Reporting Obligations (1 month) France: Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Incident Notification (NIS2) (1 month) Greece: Law 5160/2024, Significant-Incident Reporting Obligations (1 month) Croatia: Zakon o kibernetičkoj sigurnosti and Uredba o kibernetičkoj sigurnosti, Incident and Cyber-Threat Reporting Obligations (30 days) Hungary: Cybersecurity Act, Incident Notification and Cybersecurity Fine (1 month) Ireland: National Cyber Security Bill, Incident Response Powers and Reporting Obligations (1 month) Italy: Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident Notification (1 month) Lithuania: Kibernetinio saugumo įstatymas (Law on Cyber Security), Incident Notification (1 month) Luxembourg: Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Incident Notification (1 month) Latvia: Nacionālās kiberdrošības likums, Incident Notification (1 month) Netherlands: Cyberbeveiligingswet, Significant-Incident Reporting Obligations (1 month) Poland: Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), Zgłaszanie Incydentów Poważnych (1 month) Portugal: Regime Jurídico da Cibersegurança, Significant-Incident Reporting Obligations (30 business days) Romania: Ordonanța de urgență nr. 155/2024, Incident Notification (1 month) Sweden: Cybersäkerhetslag, Incident Notification (1 month) Slovenia: Zakon o informacijski varnosti (ZInfV-1), Significant-Incident Notification Obligations (1 month) Slovakia: Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability Notification (1 month) New York: New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent (30 days) China: National Cybersecurity Incident Reporting Measures (30 days) Micronesia: FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Incident Reporting Clock (30 days) Liechtenstein: Cyber-Sicherheitsgesetz (CSG), Incident Notification (1 month) Montenegro: Law on Information Security, Cyber Threat and Incident Reporting (30 days) Marshall Islands: Cybersecurity Act 2025, Cybersecurity Incident Reporting Obligations (30 days) Spain: Real Decreto-ley 12/2018, Incident Notification Obligation (40 days) 42 39 34 Privacy law El Salvador: Ley para la Protección de Datos Personales, personal data breach notification (2 hours) Idaho: Identity Theft Act, breach of security disclosure duty (24 hours) Jordan: Personal Data Protection Law, breach notification (24 hours) Russia: Federal Law No. 152-FZ, Article 21 Part 3.1, Breach Notification (24 hours) Zambia: Data Protection Act, 2021, notification of a security breach (24 hours) Zimbabwe: Cyber and Data Protection Act, security breach notification (24 hours) Zimbabwe: Cyber and Data Protection Regulations 2024, security breach notification (24 hours) Ecuador: LOPDP, notificación de vulneración de seguridad (2 days) Kenya: Data Protection Act, 2019, personal data breach notification (48 hours) Rwanda: Law relating to the Protection of Personal Data and Privacy, personal data breach notification (48 hours) European Union: GDPR Articles 33-34, Breach Notification (72 hours) Austria: GDPR Articles 33-34, Breach Notification in Austria (72 hours) Belgium: GDPR Articles 33-34, Breach Notification (72 hours) Bulgaria: GDPR Articles 33-34, Breach Notification (72 hours) Cyprus: GDPR Articles 33-34, Breach Notification in Cyprus (72 hours) Czech Republic: GDPR Articles 33-34, Breach Notification (72 hours) Germany: GDPR Articles 33-34, Breach Notification in Germany (72 hours) Denmark: GDPR Articles 33-34, Breach Notification in Denmark (72 hours) Estonia: GDPR Articles 33-34, Breach Notification in Estonia (72 hours) Spain: GDPR Articles 33-34 and LOPDGDD Article 69, Breach Notification (72 hours) Finland: GDPR Articles 33-34, Breach Notification in Finland (72 hours) France: GDPR Articles 33-34, Breach Notification (72 hours) Greece: GDPR Articles 33-34, Breach Notification in Greece (72 hours) Croatia: GDPR Articles 33-34, Breach Notification (72 hours) Hungary: Infotörvény Sections 25/J-25/K, Breach Notification, Inserted by Act XXXVIII of 2018 (72 hours) Ireland: GDPR Articles 33-34, Breach Notification in Ireland (72 hours) Italy: GDPR Articles 33-34, Breach Notification (72 hours) Lithuania: GDPR Articles 33-34, Breach Notification in Lithuania (72 hours) Luxembourg: GDPR Articles 33-34, Breach Notification in Luxembourg (72 hours) Latvia: GDPR Articles 33-34, Breach Notification in Latvia (72 hours) Malta: GDPR Articles 33-34, Breach Notification in Malta (72 hours) Netherlands: GDPR Articles 33-34 and UAVG Article 42, Breach Notification (72 hours) Poland: GDPR Articles 33-34, Breach Notification (72 hours) Portugal: GDPR Articles 33-34, Breach Notification in Portugal (72 hours) Romania: GDPR Articles 33-34, Breach Notification (72 hours) Sweden: GDPR Articles 33-34, Breach Notification (72 hours) Slovenia: GDPR Articles 33-34, Breach Notification (72 hours) Slovakia: GDPR Articles 33-34, Breach Notification (72 hours) United Kingdom: UK GDPR Articles 33-34 and PECR, Breach Notification in the United Kingdom (72 hours) Brunei Darussalam: Personal Data Protection Order 2025, breach notification (3 days) Indonesia: Law on Personal Data Protection, breach notification (72 hours) India: Digital Personal Data Protection Act, 2023, breach notification duties (72 hours) Cambodia: Cambodia's Draft Law on Personal Data Protection, personal data breach notification (72 hours) Singapore: Personal Data Protection Act, data breach notification (3 days) Thailand: Personal Data Protection Act, breach notification (72 hours) Vietnam: Law on Personal Data Protection, breach notification (72 hours) Barbados: Data Protection Act, 2019, personal data breach notification (72 hours) Belize: Data Protection Act 2021, personal data breach notification (72 hours) Ecuador: LOPDP, notificación de vulneración de seguridad (3 days) Jamaica: Data Protection Act, 2020, reporting a contravention or security breach (72 hours) Paraguay: Ley N° 7593/2025, notificación de un incidente de seguridad (72 hours) Suriname: Draft Law on the Protection of Privacy and Personal Data, breach notification (72 hours) Andorra: LQPD, personal data breach notification (72 hours) United Arab Emirates: ADGM Data Protection Regulations, breach notification (72 hours) Albania: Law No. 124/2024, notification of a personal data breach (72 hours) Bosnia and Herzegovina: Law on the Protection of Personal Data of Bosnia and Herzegovina, personal data breach notification (72 hours) Botswana: Data Protection Act, 2024, personal data breach notification (72 hours) Belarus: Law of the Republic of Belarus On Personal Data Protection, notification of personal data protection violations (3 business days) Republic of the Congo: Law No. 29-2019, personal-data breach notification (72 hours) Djibouti: Digital Code, Book I: personal-data breach notification (72 hours) Egypt: Egypt Personal Data Protection Law, Personal Data Infringement notification (72 hours) Ethiopia: Personal Data Protection Proclamation, personal data breach notification (72 hours) Georgia: Law on Personal Data Protection, breach notification (72 hours) Gambia: Personal Data Protection and Privacy Act, 2025, personal data breach notification (72 hours) Iceland: Act No. 90/2018, Breach Notification in Iceland (72 hours) Jordan: Personal Data Protection Law, breach notification (72 hours) Kenya: Data Protection Act, 2019, personal data breach notification (72 hours) Monaco: Loi sur la Protection des Données Personnelles, notification des violations de données (72 hours) Moldova: Moldova Law No. 195/2024, personal data breach notification (72 hours) North Macedonia: Law on Personal Data Protection (LPDP), personal data breach notification (72 hours) Mauritius: Data Protection Act 2017, personal data breach notification (72 hours) Maldives: Maldives Personal Data Protection Bill, personal data breach notification (72 hours) Niger: Loi n° 2022-59, notification des violations de données (72 hours) Nigeria: Nigeria Data Protection Act, 2023, data breach notification (72 hours) Norway: Personal Data Act, Breach Notification in Norway (72 hours) Serbia: Law on Personal Data Protection, personal data breach notification (72 hours) Russia: Federal Law No. 152-FZ, Article 21 Part 3.1, Breach Notification (72 hours) Rwanda: Law relating to the Protection of Personal Data and Privacy, personal data breach notification (72 hours) Seychelles: Data Protection Act, 2023, personal data breach notification (72 hours) San Marino: San Marino Law No. 171, personal data breach notification (72 hours) Somalia: Data Protection Act, 2023, personal data breach notification (72 hours) Syria: Law No. 12 of 2024 on Protection of Electronic Personal Data, personal data breach notification (3 business days) Tonga: Privacy Act 2025, personal information breaches (72 hours) Ukraine: Draft Law No. 8153, personal data breach notification (72 hours) Samoa: National Digital Identification Act 2024, personal data breach notification (72 hours) Kosovo: Law No. 06/L-082 on Protection of Personal Data, personal data breach notification (72 hours) Zimbabwe: Cyber and Data Protection Regulations 2024, security breach notification (72 hours) Iowa: Personal Information Security Breach Protection (5 business days) Ecuador: LOPDP, notificación de vulneración de seguridad (5 days) Algeria: Loi n° 18-07 relative à la protection des personnes physiques, notification des violations de données (5 days) Cayman Islands: Data Protection Act 2021 Revision, personal data breach notification (5 days) Maryland: Maryland Personal Information Protection Act (MPIPA), breach notification (7 days) Kenya: Data Protection (General) Regulations, 2021 (7 days) Puerto Rico: Ley de Información al Ciudadano sobre la Seguridad de Bancos de Información (data breach notification) (10 days) Vermont: Security Breach Notice Act (14 business days) Kenya: Data Protection (General) Regulations, 2021 (14 days) California: California Data Breach Notification Law, as amended by SB 446 (15 days) Florida: Florida Information Protection Act, breach notification (15 days) Zimbabwe: Cyber and Data Protection Regulations 2024, security breach notification (21 days) United States: GLBA Safeguards Rule Breach Notification Amendment (30 days) California: California Data Breach Notification Law, as amended by SB 446 (30 days) Colorado: C.R.S. 6-1-716, Notification of Security Breach (30 days) Florida: Florida Information Protection Act, breach notification (30 days) Maine: Notice of Risk to Personal Data (30 days) New York: Stop Hacks and Improve Electronic Data Security (SHIELD) Act, breach notification duty (30 days) Rhode Island: Identity Theft Protection Act of 2015, notification of breach (30 days) Texas: Identity Theft Enforcement and Protection Act, breach notification (30 days) Washington: Notice of security breaches involving personal information (30 days) Arkansas: Arkansas Personal Information Protection Act, breach notification and security (45 days) Arizona: Arizona data breach notification law (45 days) Indiana: Disclosure of Security Breach Act (45 days) Maryland: Maryland Personal Information Protection Act (MPIPA), breach notification (45 days) New Mexico: Data Breach Notification Act (45 days) Ohio: Security Breach Notification Act (45 days) Rhode Island: Identity Theft Protection Act of 2015, notification of breach (45 days) Vermont: Security Breach Notice Act (45 days) Wisconsin: Notice of unauthorized acquisition of personal information (45 days) United States: HIPAA Breach Notification Rule (60 days) Connecticut: Breach of security re computerized data containing personal information (60 days) Delaware: Computer Security Breaches (60 days) Louisiana: Database Security Breach Notification Law, notice duty (60 days) Oklahoma: Security Breach Notification Act (60 days) South Dakota: Breach of system security, notification statute (60 days) Texas: Identity Theft Enforcement and Protection Act, breach notification (60 days) 77 AI law, high-risk systems European Union: AI Act, Article 73 (reporting of serious incidents) (2 days) European Union: AI Act, Article 73 (reporting of serious incidents) (10 days) European Union: AI Act, Article 73 (reporting of serious incidents) (15 days) AI law, frontier models California: Transparency in Frontier Artificial Intelligence Act (SB 53) (24 hours) Illinois: Artificial Intelligence Safety Measures Act (24 hours) Illinois: Artificial Intelligence Safety Measures Act (72 hours) New York: Responsible AI Safety and Education Act (RAISE Act) (72 hours) California: Transparency in Frontier Artificial Intelligence Act (SB 53) (15 days) 1 h 6 h 24 h 72 h 7 d 14 d 30 d 90 d 72 hours 4 business days 14 days 30 days 90 days
Every clock in the corpus, one mark per instrument, on one time axis. The axis is logarithmic from the first hour to the ninetieth day, because the clocks crowd the first day and thin out over the quarter: 268 marks in four lanes, one per instrument at each of its rungs: 59 in the first day, 136 in the first week, 56 in the first month, 17 in the first quarter. The four bands are the stretches a runbook is written in, each captioned by the stage word most of its clocks carry. Marks are stacked at their rung and drawn as the flag of the place whose law each one is; the families are still told apart by their lane rather than by any ink of ours, and the amber lines are the proposal's rungs. A place inside a country carries a heavier frame than a country does, and a place whose flag the corpus does not hold draws a plain square. Every mark is a link to that instrument's page, and the tables below are the same data in full.

The proposal's notification timeline sets six dated rungs and one recurring duty, quoted here as the proposal writes them (source: the SAFE proposal, read 2026-09-18). Beside each rung are the statutory clocks in this corpus that fall at or inside it: later than the proposal's previous rung, no later than this one. The first rung has no hours, so what sits there is every obligation stated as a standard rather than a number.

The proposal's rung, as writtenWhat it asks a member to doStatutory clocks at or inside it
ASAP (as soon as possible) notify the directly affected organization
Security: "without delay" in 20, "immediately" in 17, "without undue delay" in 16, "promptly" in 5, "as soon as possible" in 2, "as soon as may be" in 1, "without unreasonable delay" in 1, "as soon as it occurs" in 1 of the 75 listed
Privacy: "without undue delay" in 54, "without unreasonable delay" in 37, "immediately" in 16, "without delay" in 14, "as soon as possible" in 11, "as soon as practicable" in 9, "as soon as reasonably possible" in 3, "promptly" in 3, "in the most expedient time possible" in 3, "as soon as reasonably practicable" in 2, "at the time it becomes aware" in 1, "as soon as feasible" in 1, "upon becoming aware" in 1, "from the moment the breach is detected" in 1, "forthwith" in 1, "upon knowing" in 1, "within the shortest time" in 1, "as expeditiously as possible" in 1 of the 167 listed
High-risk AI: "immediately" in 2, "without delay" in 1, "promptly" in 1 of the 3 listed
Frontier-model AI: "without undue delay" in 1 of the 4 listed
72 hours notify customers with credible exposure
1 hour: 2 security provisions
2 hours: 1 security provision, 1 privacy provision
4 hours: 4 security provisions
6 hours: 1 security provision
24 hours: 42 security provisions, 6 privacy provisions, 2 frontier-model AI provisions
36 hours: 1 security provision
48 hours: 3 security provisions, 3 privacy provisions, 1 high-risk AI provision
72 hours: 39 security provisions, 77 privacy provisions, 2 frontier-model AI provisions
4 business days submit a confidential, initial SAFE incident report
4 business days: 1 security provision
14 days issue a broader customer advisory when warranted
5 days: 1 security provision, 4 privacy provisions
7 days: 2 security provisions, 2 privacy provisions
10 days: 1 privacy provision, 1 high-risk AI provision
14 days: 1 security provision, 2 privacy provisions
30 days publish a preliminary factual report, subject to security, legal and investigative constraints, and provide a preliminary control-failure analysis
15 days: 2 security provisions, 2 privacy provisions, 1 high-risk AI provision, 1 frontier-model AI provision
20 days: 1 security provision
21 days: 1 privacy provision
1 month: 34 security provisions, 9 privacy provisions
90 days publish remediation status
40 days: 1 security provision
45 days: 9 privacy provisions
60 days: 7 privacy provisions
Weekly weekly machine-readable updates while material risks remain unresolved recurring, not drawn; the corpus's own progress-report cadences are left off the ladder for the same reason
Every rung as a list Show the ladderHide the ladder
As soon as possible
The proposal (ASAP): notify the directly affected organization
1 hour
2 hours
1 security provision in 1 jurisdiction1 privacy provision in 1 jurisdiction: Ley para la Protección de Datos Personales, personal data breach notification
4 hours
6 hours
24 hoursalso written 1 day
36 hours
48 hoursalso written 2 days
72 hoursalso written 3 days, 3 business daysbusiness days, drawn as calendar days
4 business daysbusiness days, drawn as calendar days
1 security provision in 1 jurisdiction: SEC Cybersecurity Risk Management, Governance, and Incident Disclosure (Regulation S-K Item 106; Form 8-K Item 1.05) The proposal (4 business days): submit a confidential, initial SAFE incident report
5 daysalso written 5 business daysbusiness days, drawn as calendar days
7 days
10 days
14 daysalso written 14 business daysbusiness days, drawn as calendar days
1 security provision in 1 jurisdiction: Cyber Resilience Act, Manufacturer Reporting Obligations2 privacy provisions in 2 jurisdictions: Security Breach Notice Act · Data Protection (General) Regulations, 2021 The proposal (14 days): issue a broader customer advisory when warranted
15 days
20 days
1 security provision in 1 jurisdiction: Real Decreto-ley 12/2018, Incident Notification Obligation
21 days
1 monthalso written 30 days, 30 business daysbusiness days, drawn as calendar days
34 security provisions in 32 jurisdictions: DORA, Article 19 (reporting of major ICT-related incidents), with the time limits of Delegated Regulation (EU) 2025/301 · NIS2 Directive, Reporting Obligations · Cyber Resilience Act, Manufacturer Reporting Obligations · and others9 privacy provisions in 9 jurisdictions: GLBA Safeguards Rule Breach Notification Amendment · California Data Breach Notification Law, as amended by SB 446 · C.R.S. 6-1-716, Notification of Security Breach · and others The proposal (30 days): publish a preliminary factual report, subject to security, legal and investigative constraints, and provide a preliminary control-failure analysis
40 days
1 security provision in 1 jurisdiction: Real Decreto-ley 12/2018, Incident Notification Obligation
45 days
60 days
90 days
The proposal (90 days): publish remediation status
Every rung on one axis. Bar length is the clock on a logarithmic scale, so one hour and ninety days fit one drawing; a teal bar is a statute or regulation the corpus holds, an amber bar is the proposal, and a rung both share draws both. A count is the number of instruments carrying that rung in any stage, as of 2026-09-21. Instrument names link to the corpus page that carries the citation, the status and the source.
What the drawing shows

7 statutory rungs (1 hour, 2 hours, 4 hours, 6 hours, 24 hours, 36 hours, 48 hours) fall before the proposal's first dated rung of 72 hours. The rung most security instruments share is 24 hours (42 instruments in 40 jurisdictions). The rung most privacy instruments share is 72 hours (77 instruments in 77 jurisdictions). No high-risk AI rung is shared by more than one instrument, and the rungs drawn are 48 hours, 10 days, 15 days. The rung most frontier-model AI instruments share is 24 hours (2 instruments in 2 jurisdictions). The longest security rung is 40 days. The longest privacy rung is 60 days. The longest high-risk AI rung is 15 days. The longest frontier-model AI rung is 15 days.

A member on the statutory clocks reports to a regulator before the proposal's own confidential report is due. That is the ordinary shape of the law, and it is the reason the proposal's public report at 30 days may describe an incident already in a regulator's hands, under that regulator's confidentiality and publication rules.

2Security law: incident and vulnerability reporting, by jurisdiction

75 instruments in 63 jurisdictions in the corpus's cybersecurity topic under its incident-reporting family state a reporting deadline, as of 2026-09-21: 55 a numeric clock, and 20 a standard such as "immediately" or "without undue delay" with no number. Most bind the OPERATOR of a service inside the scope of the NIS2 Directive or its national transposition; the CRA binds the MAKER of a product with digital elements, software included. The sentence says which.

4 more instruments in this family state no deadline in their obligation lines and are not listed here; the cybersecurity law section has them.

European Union Show the 3 provisionsHide the 3 provisions
JurisdictionInstrument, and the obligation lines that carry a clock
European Union Cyber Resilience Act, Manufacturer Reporting Obligations (Regulation (EU) 2024/2847, Art. 14)
24 hours72 hours14 daysNotify the CSIRT designated as coordinator for your main establishment and ENISA, through the single reporting platform, of any actively exploited vulnerability you become aware of in your product: an early warning within 24 hours of becoming aware, a vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure becomes available.
24 hours72 hours1 monthNotify the same recipients of any severe incident affecting the security of your product on the same 24-hour early warning and 72-hour incident notification clock, followed by a final report within one month of the incident notification.
Status since 2026-09-11Read from the corpus 2026-09-12
European Union DORA, Article 19 (reporting of major ICT-related incidents), with the time limits of Delegated Regulation (EU) 2025/301 (Regulation (EU) 2022/2554, Article 19)
4 hours24 hoursReport a major ICT-related incident to the competent authority your sector's Union law designates under Article 46, the European Central Bank through your national supervisor if you are a credit institution classified as significant, using the templates referred to in Article 20, and submit an initial notification as early as possible and in any case within four hours of classifying the incident as major, and no later than 24 hours from becoming aware of it.
4 hoursWhere classification as major comes later than that, submit the initial notification within four hours of the classification instead.
72 hoursSubmit an intermediate report within 72 hours of the initial notification, and update it without undue delay whenever the incident's status changes significantly or you recover normal activity.
1 monthSubmit a final report no later than one month after the intermediate report, or your latest updated one, once you know the root cause and the actual impact figures.
without undue delayIf you cannot meet one of those deadlines, tell the competent authority without undue delay and before the deadline lapses, explaining why. A deadline falling on a weekend or bank holiday moves to noon of the next working day, unless you are a credit institution, a central counterparty, a trading venue operator, or an entity your Member State has designated essential or important under the NIS2 Directive, none of which get that extension for an initial notification or intermediate report.
without undue delayNotifying a significant cyber threat under Article 19(2) is voluntary, only where you judge it relevant to the financial system, service users, or your clients. Where a major ICT-related incident affects your clients' financial interests, tell them without undue delay as soon as you become aware of it, describing the incident and the mitigation measures you took, and, for a significant cyber threat, tell a potentially affected client of protection measures it could take, where applicable.
Status since 2025-01-17Read from the corpus 2026-09-20
European Union NIS2 Directive, Reporting Obligations (Directive (EU) 2022/2555, Art. 23)
24 hours72 hours1 monthNotify your CSIRT, or the competent authority where applicable, of any incident with a significant impact on the provision of your services: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report no later than one month after the incident notification.
without undue delayWhere appropriate, notify, without undue delay, the recipients of your services who a significant incident is likely to adversely affect, and communicate to recipients potentially affected by a significant cyber threat any measures or remedies they can take.
Status since 2024-10-18Read from the corpus 2026-09-08
EU member states (the national layer) Show the 31 provisionsHide the 31 provisions
JurisdictionInstrument, and the obligation lines that carry a clock
Austria Netz- und Informationssystemsicherheitsgesetz (NISG), Incident Notification Obligations (NISG, BGBl. I Nr. 111/2018, §§ 19 und 21)
without delayNotify your competent Computer-Notfallteam (CERT), or, absent one, the national CERT or GovCERT, without delay of a security incident affecting the service you provide.
Status since 2018-12-28Read from the corpus 2026-09-14
Austria Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Significant-Incident Reporting Obligations (NISG 2026, BGBl. I Nr. 94/2025, §§ 34 und 35)
24 hoursNotify your competent sector-specific CSIRT, or, absent one, the national CSIRT, of every significant cybersecurity incident: an early warning within 24 hours of becoming aware, stating whether it is suspected to result from unlawful and culpable acts or to have cross-border effects.
72 hoursFollow with a fuller notification within 72 hours of becoming aware, updating the early warning with an initial evaluation of the incident's severity and impact and any indicators of compromise.
1 month72 hoursSubmit an interim report on request, and a final report no later than one month after the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once you have resolved it.
Status from 2026-10-01 [enacted, not yet in effect]Read from the corpus 2026-09-14
Belgium Loi du 26 avril 2024, Significant-Incident Notification Obligations (Loi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information d'intérêt général pour la sécurité publique, Artt. 34-37)
without undue delayNotify the national CSIRT of any significant incident without undue delay, following the arrangements set out in the protocol between the CSIRT and the National Crisis Centre.
24 hoursSubmit an early warning within 24 hours of becoming aware of the significant incident, stating whether it is suspected to result from unlawful or malicious action and whether it may have a cross-border impact.
72 hoursFollow with an incident notification within 72 hours, updating the early warning with an initial assessment of the incident's severity and impact and any available indicators of compromise.
1 monthSubmit an interim report if the national CSIRT or the competent sectoral authority asks for one, and a final report no later than one month after the incident notification, describing the incident in detail, its severity and impact, the likely threat or root cause, the mitigation measures applied and in progress, and any cross-border impact.
Status since 2024-10-18Read from the corpus 2026-09-14
Bulgaria Cybersecurity Act, Incident and Cyber-Threat Reporting Obligations (Zakon za kibersigurnost, ZKS) (Закон за киберсигурност (ЗКС), чл. 23, изм. с § 27 от Закона за изменение и допълнение на ЗКС, обн. ДВ, бр. 17 от 13.02.2026 г. (English: Cybersecurity Act, Art. 23, as substituted by § 27 of the Act Amending and Supplementing the Cybersecurity Act, State Gazette No. 17 of 13 February 2026))
24 hours72 hours24 hours1 month1 monthNotify СЕРИКС of every significant incident on this clock: an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours (24 hours if you are a trust service provider), an interim report on request, and a final report no later than one month after the incident notification (or, if unresolved by then, an interim report followed by a final report within one month of resolution).
72 hoursState in your early warning, where applicable, whether the incident is suspected to result from unlawful or malicious acts and whether it could have a cross-border effect; update that assessment with an initial severity and impact evaluation in your 72-hour notification; and cover in your final report the incident's scope and impact, its likely cause, your mitigation measures, and any cross-border effect.
without undue delayWhere appropriate and without undue delay, notify the recipients of your service of a significant incident likely to adversely affect them and of any measures they can take, and of a significant cyber threat and its nature.
24 hoursExpect СЕРИКС to acknowledge your early warning within 24 hours except where objectively impossible, and to provide initial information and, on request, guidance or further technical support.
Status since 2026-02-17Read from the corpus 2026-09-15
Cyprus Security of Networks and Information Systems Law, Incident Notification Obligations (Art. 35B of the Security of Networks and Information Systems Law of 2020, N. 89(I)/2020, as amended by the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025)
without undue delayNotify the Digital Security Authority without undue delay, and in any event within six (6) hours of becoming aware of a significant incident, with an early warning stating, where applicable, whether the incident is suspected to result from unlawful or malicious acts and whether it may have a cross-border impact.
72 hoursFollow with an incident notification within 72 hours of becoming aware, updating the early warning and giving an initial assessment of the incident's severity and impact, including any indicators of compromise where available.
1 month15 daysSubmit an intermediate report on the Authority's request, and a final report within one month of the incident notification (or, for an incident still ongoing at that point, a progress report every fifteen days, and a final report within fifteen days of restoring the affected network or information system's normal operation).
24 hoursWhere you are a trust service provider, notify within 24 hours rather than 72 for a significant incident affecting the trust services you supply.
without undue delayWhere applicable, notify without undue delay the recipients of your services who may be affected by a significant cyber threat, of any measures or corrective action they can take, and notify them of a significant incident likely to adversely affect their use of the service.
Status since 2025-04-25Read from the corpus 2026-09-16
Czech Republic Cybersecurity Act (Zákon o kybernetické bezpečnosti), Incident Notification (Act No. 264/2025 Coll., Cybersecurity Act, Sections 15-16)
24 hoursIf you are in the higher-obligations regime, notify NÚKIB no later than 24 hours after detecting a qualifying cybersecurity incident, with an initial report giving your identifying details, basic incident data, and whether you believe the incident was caused by an unlawful intervention or could have a cross-border impact.
24 hoursIf you are in the lower-obligations regime, notify the Národní CERT on the same 24-hour clock instead, for a qualifying incident with significant impact on your service's provision.
72 hoursFor an incident with significant impact, follow with a report no later than 72 hours after detection that updates your initial assessment and gives the incident's impact and, where available, indicators of compromise.
30 days72 hours30 daysSubmit an interim report on request, and a final report no later than 30 days after the 72-hour report, or, if the incident is still ongoing at that point, a progress report followed by a final report within 30 days of resolution.
Status since 2025-11-01Read from the corpus 2026-09-14
Germany BSI-Gesetz (BSIG), Incident Notification (BSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), § 32)
24 hoursNotify the BSI's and the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe's joint reporting office without delay, and in any event within 24 hours of becoming aware of a significant security incident, with an early warning stating whether the incident is suspected to be unlawful or malicious or to have cross-border effect.
72 hoursFollow with a full notification within 72 hours of becoming aware, confirming or updating the early warning and giving an initial assessment of the incident's severity and impact and, where available, indicators of compromise.
1 month72 hoursSubmit an intermediate report on the BSI's request, and a final report within one month of the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once you have finished handling it.
Status since 2025-12-06Read from the corpus 2026-09-12
Denmark NIS 2-loven, Significant-Incident Reporting and Recipient-Notice Duties (NIS 2-loven, §§ 12-13, 15)
24 hoursSend an early warning without undue delay, and no later than 24 hours after becoming aware of the significant incident, stating whether it is suspected to result from an unlawful or malicious act and whether it may have a cross-border effect.
72 hoursFollow with a notification, without undue delay and in any case within 72 hours of becoming aware of the incident, updating the early warning with an initial assessment of the incident's severity and impact, including any indicators of compromise where available.
1 month1 monthSubmit an interim report if your CSIRT asks for one, and a final report no later than one month after your notification, describing the incident in detail, its severity and impact, the likely threat or root cause, mitigating measures applied and under way, and any cross-border effects. If the incident is still ongoing at that point, submit a status report instead and the final report within one month of the incident being handled.
72 hours24 hoursIf you are a trust-service provider, send only the 72-hour-shaped notification, without undue delay and no later than 24 hours after becoming aware of the significant incident, rather than the separate two-step early-warning and notification sequence.
without undue delayNotify the recipients of your service, without undue delay, of a significant incident likely to adversely affect the delivery of your service to them, and inform any recipient potentially affected by a significant cyber threat of the measures or countermeasures they can take in response, and of the threat itself where relevant.
Status since 2025-07-01Read from the corpus 2026-09-15
Estonia Küberturvalisuse seadus (KüTS), Duty to Notify of a Cyber Incident (Küberturvalisuse seadus (Cybersecurity Act), RT I, 30.12.2025, 4, §§ 8 and 8-1)
24 hoursSubmit an initial report to RIA without delay and no later than 24 hours after becoming aware of a cyber incident that has, or could reasonably be expected to have, a significant effect on your system's security or your service's continuity, unless you are a security authority.
72 hours24 hoursFollow with an incident report no later than 72 hours after becoming aware of the significant incident, updating the initial report, unless you are a qualified trust service provider, in which case you report in a single stage within 24 hours instead.
1 month1 monthSubmit an interim report if RIA asks for one, and a final report within one month of the incident report, or, if the incident is still unresolved at that point, treat that report as interim and submit a further final report within one month of resolution.
Status since 2026-01-01Read from the corpus 2026-09-15
Spain Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad, Incident Reporting Obligations (Anteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad, text approved by the Consejo de Ministros on 14 January 2025 (transposing Directive (EU) 2022/2555))
as soon as possibleExpect a duty to communicate to the recipients of your service, as soon as possible, a significant cyberthreat that could affect them and any mitigating measures they can take.
Status [proposed]Read from the corpus 2026-09-12
Spain Real Decreto-ley 12/2018, Incident Notification Obligation (Real Decreto-ley 12/2018, de 7 de septiembre, de seguridad de las redes y sistemas de informacion, arts. 19, 21 y 22, developed by Real Decreto 43/2021, de 26 de enero)
without undue delayNotify the competent authority, through your reference CSIRT, without undue delay, of an incident that may have a significant disruptive effect on the provision of your service, whether on your own networks or a third-party provider's.
24 hours48 hours20 days72 hours40 daysFor a CRITICO-severity incident under the national notification instruction, notify immediately, follow up with an interim notification within 24 to 48 hours, and file a final notification within 20 days; for a MUY ALTO-severity incident, notify immediately, follow up within 72 hours, and file a final notification within 40 days; an ALTO-severity incident requires only an immediate initial notification.
Status since 2018-09-09Read from the corpus 2026-09-12
Finland Kyberturvallisuuslaki, Significant-Incident Reporting Obligations (Kyberturvallisuuslaki (124/2025), 11-14 ja 22 §)
without delayNotify your supervisory authority without delay of a significant incident, one that has caused or could cause a serious service disruption or considerable financial loss to you, or that has affected or could affect another person with considerable material or immaterial damage.
24 hours72 hours24 hoursFile an early notification within 24 hours of detecting the significant incident, stating whether it is suspected to result from an unlawful or hostile act and the likelihood of cross-border effects, and a follow-up notification within 72 hours of detection, both clocks running from detection rather than from each other; if you are a trust service provider whose trust services are affected, file your follow-up notification within 24 hours instead of 72.
1 month1 month1 monthProvide an interim report on the authority's request, or within one month of your follow-up notification if the incident is long-running, and a final report within one month of the follow-up notification, or within one month of the incident's resolution if it is still ongoing at that point, describing the incident, its likely root cause, mitigation measures taken, and any cross-border effects.
without delayNotify the recipients of your services without delay of a significant incident likely to adversely affect your service to them, and of a significant cyberthreat that may affect them together with the measures available to counter it.
Status since 2025-04-08Read from the corpus 2026-09-15
France Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Incident Notification (Loi n° 2018-133 du 26 février 2018, Titre Ier, art. 7 et 13)
without delayDeclare to ANSSI, without delay after becoming aware of it, an incident affecting the networks and information systems necessary to provide your service, where the incident has or is likely to have a significant impact on the continuity of the service (an operator of essential services) or on the provision of the service in the European Union (a digital service provider).
Status since 2018-05-10Read from the corpus 2026-09-12
France Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Incident Notification (NIS2) (Article 17, texte adopté n° 78 (2024-2025), Sénat, 12 mars 2025 (notification des incidents))
24 hours72 hours1 month1 month1 monthNotify ANSSI without undue delay of any incident with an important impact on the provision of your services (one causing or liable to cause a severe operational disruption or financial loss for you, or considerable material, physical or non-material damage to another person), on a graduated clock: an initial notification within 24 hours of becoming aware of it, an intermediate notification within 72 hours updating the initial one and giving an initial assessment of severity and impact, a report on ANSSI's request, and a final report within one month (or, for an incident still being handled, a progress report at one month followed by a final report within one month of resolution).
24 hoursWhere you are a trust-service provider or one of the domain-name and registry services Articles 8(4) and 9(3) name, notify within 24 hours rather than 72 for the intermediate notification.
24 hoursExpect ANSSI to respond within 24 hours of your initial notification where possible, and expect the same penalty tiers as this jurisdiction's companion risk-management row.
Status [proposed]Read from the corpus 2026-09-12
Greece Law 5160/2024, Significant-Incident Reporting Obligations (Law 5160/2024 (Ν. 5160/2024), Art. 16)
24 hoursNotify the CSIRT of the National Cybersecurity Authority, without undue delay and in any case within 24 hours of becoming aware of a significant incident, with an early warning stating whether unlawful or malicious action is suspected and whether the incident may have cross-border effects.
72 hoursFollow within 72 hours of becoming aware of the significant incident with an incident notification updating the early warning and adding an initial assessment of its severity and effects.
1 month72 hours1 monthSubmit a final report no later than one month after the 72-hour notification, describing the incident in detail, its severity and effects, the likely threat or root cause, mitigating measures applied, and any cross-border impact; if the incident is still ongoing at that point, submit a progress report instead and the final report within one month of its resolution.
without undue delayWithout undue delay, notify the recipients of your services of a significant incident likely to adversely affect the services they receive, and inform any recipients affected by a significant cyber threat of the threat and of the measures they can take in response.
Status since 2024-11-27Read from the corpus 2026-09-15
Croatia Zakon o kibernetičkoj sigurnosti and Uredba o kibernetičkoj sigurnosti, Incident and Cyber-Threat Reporting Obligations (Zakon o kibernetičkoj sigurnosti, Narodne novine, broj 14/2024, čl. 37.-44.; Uredba o kibernetičkoj sigurnosti, Narodne novine, broj 135/2024, čl. 64.-71. i 85.)
24 hours24 hours72 hours30 days30 daysNotify the competent CSIRT of every significant incident on this clock, set by the Cybersecurity Regulation rather than the Act itself: an early warning without delay and no later than 24 hours after becoming aware of it (24 hours also for a trust service provider's initial notification), an initial notification no later than 72 hours otherwise, an interim report if the CSIRT requests one, and a final report no later than 30 days after your initial notification, or, if the incident is still unresolved at that point, a progress report instead, repeated every 30 days once the incident has run past 60 days, followed by a final report within 30 days of your last progress report.
72 hoursNotify the recipients of your service, without delay and no later than 72 hours after you become aware of a significant incident likely to affect them, in a clear and easily verifiable way, and separately notify them of a serious cyber threat and of any protective measures or remedies they can take.
30 daysIf you are newly categorized as an essential or important entity, you have 30 days from the date you receive your Article 19(1) categorization notice before these notification duties bind you.
Status since 2024-11-30Read from the corpus 2026-09-16
Hungary Cybersecurity Act, Incident Notification and Cybersecurity Fine (2024. évi LXIX. törvény, 66. §; 418/2024. (XII. 23.) Korm. rendelet, 42. § és 77. §)
24 hours72 hours1 monthNotify the national cybersecurity incident-handling centre (Nemzeti Kiberbiztonsági Intézet, the NKI) of a cyber threat, near-incident or cybersecurity incident affecting your electronic information system: an initial notification without undue delay and in any case within 24 hours of becoming aware, an event notification within 72 hours that updates that report and assesses the incident's severity and impact, and a final report no later than one month after the event notification.
1 monthSubmit an interim status report if the centre asks for one, and, if the incident is still ongoing when the final report is due, a report on the results achieved so far followed by a final report within one month of the incident's resolution.
Status since 2025-01-01Read from the corpus 2026-09-14
Ireland European Union (NIS) Regulations 2018, Incident Notification (S.I. No. 360/2018, Regs. 18 and 22)
72 hoursNotify the State's CSIRT without delay and in any event not later than 72 hours after becoming aware of an incident with a significant impact on the continuity of your essential service, or a substantial impact on your digital service, including an incident affecting a third-party digital service provider you rely on.
Status since 2018-09-18Read from the corpus 2026-09-12
Ireland National Cyber Security Bill, Incident Response Powers and Reporting Obligations (Head 15, General Scheme, National Cyber Security Bill 2024)
24 hours72 hours1 monthNotify the CSIRT without undue delay of any incident with a significant impact on the provision of your service: an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours, and a final report within one month.
Status [proposed]Read from the corpus 2026-09-12
Italy Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident Notification (D.Lgs. 4 settembre 2024, n. 138, Art. 25)
24 hoursNotify CSIRT Italia without unjustified delay, and in any event within 24 hours of becoming aware of a significant incident, with a pre-notification stating, where possible, whether the incident appears unlawful or malicious and whether it may have a cross-border impact.
72 hoursFollow with a full notification within 72 hours of becoming aware, updating the pre-notification and giving an initial assessment of the incident's severity and impact and, where available, indicators of compromise.
1 month1 monthSubmit an intermediate report on CSIRT Italia's request, and a final report within one month of the notification (or, for an incident still ongoing at that point, a monthly progress report and a final report within one month of the incident's resolution).
24 hoursWhere you are a trust-service provider, notify within 24 hours rather than 72 for an incident affecting the trust services you supply.
24 hoursExpect CSIRT Italia to respond within 24 hours of your pre-notification with an initial assessment and, on request, guidance or technical support on mitigation measures.
Status since 2024-10-16Read from the corpus 2026-09-12
Lithuania Kibernetinio saugumo įstatymas (Law on Cyber Security), Incident Notification (Lietuvos Respublikos kibernetinio saugumo įstatymas Nr. XII-1428, as restated by Įstatymo Nr. XIV-2902 pakeitimo įstatymas of 11 July 2024, in force since 18 October 2024, Art. 18)
24 hoursNotify NKSC of a significant cyber incident without delay and in any event within 24 hours of becoming aware of it.
72 hours72 hours24 hoursFollow within 72 hours of becoming aware with the incident's severity and impact assessment and any evidence of compromise; report a minor incident within 72 hours without a separate 24-hour early warning.
1 monthSubmit a final report within one month of the incident's registration, and an interim report on NKSC's request.
Status since 2024-10-18Read from the corpus 2026-09-14
Luxembourg Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Incident Notification (Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité, Art. 14)
without undue delayNotify the competent authority, without undue delay, of any incident with a significant impact on the provision of your services: treat an incident as significant where it has caused or is capable of causing severe operational disruption or financial loss to you, or considerable material, physical or moral damage to another person.
24 hoursSubmit an early warning within 24 hours of becoming aware of the significant incident, stating whether it is suspected to result from unlawful or malicious acts or could have cross-border effect.
72 hoursFollow with a fuller incident notification within 72 hours of becoming aware, updating the early warning and giving an initial assessment of the incident's severity and impact and, where available, indicators of compromise.
1 month72 hoursSubmit an intermediate report if a CSIRT or the competent authority requests one, and a final report within one month of the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once you have finished handling it.
without undue delayWhere appropriate, notify the recipients of your services, without undue delay, of a significant incident likely to affect the services they receive from you, and of any measures or corrections they can apply in response to a significant cyber threat.
24 hours72 hoursIf you are a qualified trust-service provider, notify significant incidents affecting your trust services within 24 hours of becoming aware, without the 72-hour and later stages that apply to other entities.
Status since 2026-05-10Read from the corpus 2026-09-14
Latvia Nacionālās kiberdrošības likums, Coordinated Vulnerability Disclosure and Remediation (Nacionālās kiberdrošības likums (adopted 20.06.2024, in force 01.09.2024), 39.-40. panti)
5 business daysWhere you discover a vulnerability yourself in another subject's system, know that Article 39 lets you report it to the competent institution within five working days, anonymously if you choose, with your identity kept confidential.
Status since 2024-09-01Read from the corpus 2026-09-15
Latvia Nacionālās kiberdrošības likums, Incident Notification (Nacionālās kiberdrošības likums (adopted 20.06.2024, notification clock applying from 01.07.2025), 34. pants)
immediatelyImmediately take all action necessary to contain a detected cyber incident, immediately inform the competent cyber incident prevention institution (in practice CERT.LV for most private-sector and civilian public-sector subjects), and follow its instructions.
24 hoursFor a significant cyber incident, electronically submit an early warning to the competent institution without delay and no later than within 24 hours of becoming aware of it.
72 hours24 hoursFollow with an initial report within 72 hours of becoming aware (within 24 hours instead, if you are a trust service provider).
1 monthWithin one month of the initial report, submit a final report on the incident's resolution, or, if it is still unresolved at that point, a progress report followed by a final report once you have resolved it; submit an intermediate report if the competent institution requests one.
immediatelyWhere relevant, immediately inform your service recipients, including affected network or system users, of protective measures they can take, and, after coordinating with the competent institution, inform them of the significant incident or threat itself, unless disclosure would create a new significant-incident risk or conflict with national security.
Status since 2025-07-01Read from the corpus 2026-09-15
Netherlands Cyberbeveiligingswet, Significant-Incident Reporting Obligations (Cyberbeveiligingswet, Artt. 25-29)
24 hoursGive your CSIRT and competent authority an early warning without delay, or within 24 hours of becoming aware of a significant incident if immediate reporting is not possible, stating whether the incident is suspected to result from unlawful or malicious action and whether it may have cross-border effects.
72 hoursFollow with a notification, without delay or within 72 hours, updating the early warning with an initial assessment of the incident's severity and effects.
1 month1 monthSubmit a final report no later than one month after your notification, describing the incident in detail, its severity and effects, the likely threat or root cause, mitigating measures applied, and any cross-border effects; if the incident is still ongoing at that point, submit a progress report instead and the final report within one month of resolution.
Status since 2026-08-15Read from the corpus 2026-09-12
Poland Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), Zgłaszanie Incydentów Poważnych (Art. 11 ustawy z dnia 5 lipca 2018 r. o krajowym systemie cyberbezpieczeństwa (Dz.U. 2026 poz. 20), w brzmieniu nadanym ustawą z dnia 23 stycznia 2026 r. (Dz.U. 2026 poz. 252))
24 hoursNotify the competent sectoral CSIRT without delay, and in any event within 24 hours of detecting a significant incident, with an early warning.
72 hours1 month72 hoursFollow with a fuller notification within 72 hours of detection, a periodic report on the CSIRT's request, and a final report no later than one month after the 72-hour notification.
Status from 2027-04-03 [enacted, not yet in effect]Read from the corpus 2026-09-14
Portugal Regime Jurídico da Cibersegurança, Significant-Incident Reporting Obligations (Decreto-Lei n.º 125/2025, de 4 de dezembro, Artigos 40.º a 44.º)
24 hours72 hoursSubmit an initial notification without undue delay and within 24 hours of concluding that a significant incident exists or may exist, and, where necessary, update it within 72 hours with an initial assessment of the incident's severity and impact; if the incident resolves within two hours of detection, submit only the end-of-impact notification below.
24 hoursSubmit a notification that the incident's significant impact has ended, without undue delay and within 24 hours of that impact ending.
30 business daysSubmit a final report within 30 working days of your end-of-impact notification, describing the incident, its impact, the mitigating measures you took and any residual impact still present, and submit an interim report if the competent authority asks for one.
Status since 2026-04-03Read from the corpus 2026-09-15
Romania Ordonanța de urgență nr. 155/2024, Incident Notification (Ordonanța de urgență a Guvernului nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetică a rețelelor și sistemelor informatice din spațiul cibernetic național civil, reportedly approved by Legea nr. 124/2025, art. 15-17)
without undue delayReport to the national cybersecurity-incident-response team, without undue delay, any incident with a significant impact on the provision of your services, through the Platforma națională pentru raportarea incidentelor de securitate cibernetică (PNRISC).
24 hours72 hours1 month72 hoursSubmit an early warning within 24 hours of becoming aware of a significant incident, stating whether it is suspected unlawful, malicious, or cross-border in impact; follow with a fuller incident report within 72 hours giving an initial severity and impact assessment and any known indicators of compromise; submit an interim report if the CSIRT requests one; and submit a final report within one month of the 72-hour report, or a progress report followed by a final report if the incident is still ongoing at that point.
24 hoursIf you are a trust service provider, report an incident affecting your trust services within a flat 24 hours of becoming aware of it, rather than on the graduated clock.
Status since 2024-12-31Read from the corpus 2026-09-15
Sweden Cybersäkerhetslag, Incident Notification (Cybersäkerhetslag (2025:1506), 2 kap. 5-10 §§)
24 hoursInform the authority the government designates (in practice the CSIRT-enhet at Försvarets radioanstalt) of a significant incident as soon as you can, and no later than 24 hours after becoming aware of it.
24 hours72 hoursFollow with a formal incident notification to the same authority as soon as you can; if you provide a trust service, no later than 24 hours after becoming aware, and otherwise no later than 72 hours after becoming aware.
1 month1 monthNo later than one month after your incident notification, submit a final report; if the significant incident is still ongoing at that point, submit a progress report instead and a final report within one month after you have resolved it.
Status since 2026-01-15Read from the corpus 2026-09-15
Slovenia Zakon o informacijski varnosti (ZInfV-1), Significant-Incident Notification Obligations (Zakon o informacijski varnosti (ZInfV-1), Uradni list RS, št. 40/25, čl. 29-30)
24 hoursGive your competent CSIRT group an early warning without delay, at latest within 24 hours of detecting a significant incident, stating whether it is suspected to result from an unlawful or malicious act and whether it may have a cross-border effect.
72 hours1 month72 hours1 monthFollow with a full notification without delay, at latest within 72 hours, updating the early warning with an initial assessment of the incident's severity and impact and any available threat indicators, then an interim report if the CSIRT group asks for one, and a final report at latest one month after the 72-hour notification, or a progress report and a final report within one month of resolution if the incident is still ongoing at that point.
without delayWithout delay, inform the recipients of your services of a significant incident likely to adversely affect them, and communicate to a recipient potentially affected by a significant cyber threat the measures it can take in response.
Status since 2025-06-18Read from the corpus 2026-09-15
Slovakia Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability Notification (Zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplní niektorých zákonov, v znení zákona č. 366/2024 Z. z., § 24 a § 5 ods. 5)
24 hoursReport without undue delay, and no later than 24 hours after becoming aware of it, an early warning of a significant cyber security incident, stating in particular whether it may have been caused by unlawful conduct or may have a cross-border effect.
72 hoursNo later than 72 hours after becoming aware of it, report a notification updating and completing the early warning, in particular an initial assessment of the incident's severity and impact.
1 month72 hoursNo later than one month after the 72-hour notification, report a final report describing the incident, its severity and impact, the threat type or probable root cause, the mitigating measures taken and under way, and any cross-border impact.
30 days30 daysWhere a cross-border-impact incident is still ongoing when the final report is due, report an updated final report within 30 days of restoring normal network and system operation, or, if it remains unresolved at the final-report stage, within 30 days of its eventual resolution.
Status since 2025-01-01Read from the corpus 2026-09-15
United States, federal Show the 4 provisionsHide the 4 provisions
JurisdictionInstrument, and the obligation lines that carry a clock
United States Computer-Security Incident Notification Requirements for Banking Organizations and Their Bank Service Providers (12 CFR Part 53 (OCC); 12 CFR Part 225, Subpart N (Federal Reserve Board); 12 CFR Part 304, Subpart C (FDIC))
36 hoursIf your organization is a banking organization, notify your primary federal banking regulator, the OCC, the Federal Reserve Board, or the FDIC, whichever supervises it, about a notification incident, as soon as possible and no later than 36 hours after your organization determines that a notification incident has occurred. A notification incident is the subset of computer-security incidents that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, your ability to serve customers, a business line, or an operation whose failure would threaten the financial stability of the United States, so a computer-security incident that falls short of that threshold does not by itself start this clock.
as soon as possibleIf your organization is a bank service provider, notify at least one bank-designated point of contact at each affected banking organization customer as soon as possible after your organization determines that it has experienced a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, covered services provided to that banking organization for a period of four hours or more. This duty carries a standard, as soon as possible, rather than a fixed number of hours to notify by, and that disruption threshold is what engages the duty rather than a period to notify within.
Status since 2022-05-01Read from the corpus 2026-09-20
United States Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) (6 U.S.C. 681-681g (CIRCIA))
72 hoursOnce the final rule takes effect, report a covered cyber incident to the Agency not later than 72 hours after your organization reasonably believes that the covered cyber incident has occurred.
24 hoursOnce the final rule takes effect, report a ransom payment to the Agency not later than 24 hours after your organization makes the payment, even where the underlying ransomware attack is not itself a covered cyber incident.
promptlyOnce the final rule takes effect, promptly submit an update to a previously submitted covered cyber incident report whenever substantial new or different information becomes available or a ransom payment is later made, continuing until your organization notifies the Agency that the incident has concluded and been fully mitigated and resolved, and preserve data relevant to the incident or payment under the procedures the final rule establishes.
Status enacted, not yet in effectRead from the corpus 2026-09-20
United States SEC Cybersecurity Risk Management, Governance, and Incident Disclosure (Regulation S-K Item 106; Form 8-K Item 1.05) (17 CFR 229.106; 17 CFR 249.308 (Form 8-K Item 1.05))
4 business daysIf your organization is an SEC reporting company, determine, without unreasonable delay after you discover a cybersecurity incident, whether the incident is material, and if it is, file a Form 8-K under Item 1.05 within four business days after you make that determination.
Status since 2023-12-18Read from the corpus 2026-09-18
United States Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 252.204-7012) (48 CFR 252.204-7012)
72 hoursRapidly report a cyber incident to the Department of Defense within 72 hours of discovering it, at the Department's DIBNet portal (dibnet.dod.mil), using a DoD-approved medium assurance certificate that you must obtain before you need to file a report.
Status since 2015-08-26Read from the corpus 2026-09-20
United States, states Show the 1 provisionHide the 1 provision
JurisdictionInstrument, and the obligation lines that carry a clock
New York New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent (23 NYCRR 500.17)
72 hoursNotify the Superintendent electronically, in the form set forth on the Department's website, as promptly as possible but no later than 72 hours after you determine that a Cybersecurity Incident has occurred at your organization, an affiliate, or a third-party service provider: an event that requires notice to a government or supervisory body, that has a reasonable likelihood of materially harming a material part of your normal operations, or that results in the deployment of ransomware within a material part of your information systems.
promptlyPromptly provide the Superintendent any information requested about a reported incident, and continue updating the Superintendent with material changes or new information previously unavailable; the regulation states no separate numbered clock for either duty.
24 hours30 daysWhere you make an extortion payment in connection with a cybersecurity event, notify the Superintendent of the payment within 24 hours of making it, and within 30 days of the payment provide a written description of why the payment was necessary, the alternatives you considered, and the diligence you performed, including under Office of Foreign Assets Control rules.
Status since 2023-11-01Read from the corpus 2026-09-20
Asia and the Pacific Show the 9 provisionsHide the 9 provisions
JurisdictionInstrument, and the obligation lines that carry a clock
Bangladesh Cyber Security Act, Computer Emergency Response Team, Duty to Report a Cyber Incident (Cyber Security Act, 2026 (Act No. 81 of 2026), s. 9)
without delayWithout delay after a cyber incident occurs, inform the National Computer Emergency Response Team the National Cyber Security Agency maintains; the Act names no fixed number of hours or days for this notification.
Status since 2025-05-21Read from the corpus 2026-09-18
China Data Security Law, Risk Monitoring and Incident Reporting Duty (Data Security Law of the People's Republic of China, Art. 29)
immediatelyOn an actual data-security incident, immediately take disposal measures, promptly notify affected users as provided, and report the incident to the competent authority; the statute states no numeric deadline, only immediacy and promptness.
Status since 2021-09-01Read from the corpus 2026-09-12
China National Cybersecurity Incident Reporting Measures (Measures for the Administration of National Cybersecurity Incident Reporting (Cyberspace Administration of China, issued September 11, 2025), Arts. 2, 4, 5, 8, 9, 12, 14)
1 hourWhere the incident involves critical information infrastructure, report to your sector's protection-work department and to the public security organ within 1 hour of discovering or becoming aware of the incident.
2 hoursWhere you are a department of a central or state organ, or a directly affiliated unit of one, report to your own department's cyberspace affairs unit within 2 hours of discovering or becoming aware of the incident.
4 hoursEvery other network operator must report to the cyberspace administration department of its own province within 4 hours of discovering or becoming aware of the incident.
promptlyWhere your industry carries its own reporting rule, also report as your industry's regulator requires, and report a suspected crime to the public security organ promptly.
promptlyWhere an organization or individual provides you network-security or system-operation-and-maintenance services under contract, require that provider by contract to promptly report to you any cybersecurity incident it discovers through monitoring, and to assist your own reporting under these Measures; this is the paragraph that reaches a cloud host, managed-security vendor, or AI operator serving you as its customer.
30 daysWithin 30 days of completing disposal of a relatively major incident or above, submit a summary report covering the incident's cause, your emergency response, the harm caused, accountability, remediation, and lessons learned, through the same channel you used for the original report.
Status since 2025-11-01Read from the corpus 2026-09-20
Indonesia Government Regulation on the Operation of Electronic Systems and Transactions, security-incident reporting duty (Government Regulation No. 71 of 2019 (PP PSTE), Pasal 24(3))
immediatelyReport the incident immediately, at the first opportunity, to law enforcement officials and the relevant Ministry or Agency; the Government Regulation states no numeric clock for this report, only immediacy.
Status since 2019-10-10Read from the corpus 2026-09-16
India CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation (Directions under section 70B(6) of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In (Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, 28 April 2022))
6 hoursReport a listed cyber security incident, including a targeted attack, a data breach, a data leak, unauthorised access to your IT systems, or an attack through a malicious or fake mobile app, to CERT-In within six hours of noticing it or being notified of it, by email, phone, or fax; current reporting formats and channels are published on CERT-In's own website.
Status since 2022-06-27Read from the corpus 2026-09-12
Kyrgyzstan Digital Code, digital resilience incident notification (Digital Code, Law No. 178, Art. 63)
72 hoursNotify the sectoral regulator with jurisdiction over your sector no later than 72 hours after you discover the incident; if you notify later than that, explain the reason for the delay in the notice.
48 hoursIf you process data as a processor for a record owner, notify that record owner of an incident within the period your contract sets, and in any event no later than 48 hours after you discover it.
Status since 2026-02-06Read from the corpus 2026-09-18
South Korea Information and Communications Network Act, Report on Computer Security Incidents (Arts. 48-3 and 48-4 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. (Act No. 20069, Jan. 23, 2024))
immediatelyImmediately report a computer security incident to the Minister of Science and ICT or to the Korea Internet and Security Agency upon discovering it; a report already made for the same incident under another statute satisfies this duty and need not be repeated.
Status since 2022-06-10Read from the corpus 2026-09-12
Uzbekistan Law on Cybersecurity, cybersecurity incident notification duty (Law No. O'RQ-764 (15 April 2022) "On Cybersecurity," Arts. 3, 16, 22-24)
as soon as it occursNotify the State Security Service of any cybersecurity incident or cybercrime affecting your information systems or resources as soon as it occurs; the statute sets no numeric deadline or severity threshold.
Status since 2022-07-17Read from the corpus 2026-09-18
Vietnam Cybersecurity Law, Incident Response and Reporting Duties (Law No. 116/2025/QH15 (Law on Cybersecurity), arts. 40(1)(c), 41(2)-(4))
immediatelyWhen a cybersecurity incident occurs, implement that plan immediately and simultaneously report it to the specialised cybersecurity protection force. The Law states no fixed number of hours for this report, unlike the 24-hour and 72-hour clocks the same enterprise faces under Article 25(2) for a content-takedown or a user-information request, which are a content-moderation duty this row does not carry.
Status since 2026-07-01Read from the corpus 2026-09-16
The Americas outside the United States Show the 1 provisionHide the 1 provision
JurisdictionInstrument, and the obligation lines that carry a clock
Cuba Resolución 105/2021, Reglamento sobre el Modelo de Actuación Nacional para la Respuesta a Incidentes de Ciberseguridad (Resolución 105/2021 of the Ministry of Communications, ‘Reglamento sobre el Modelo de Actuación Nacional para la Respuesta a Incidentes de Ciberseguridad’ (Gaceta Oficial de la República de Cuba, Ordinaria No. 92, GOC-2021-762-O92, 17 de agosto de 2021), arts. 1, 2, 21-23 and resolving clause SEGUNDO)
immediatelyReport a cybersecurity incident immediately to your immediate superior and to the Cuban Computer Incident Response Team (CuCERT), inside the Ministry of Communications' Oficina de Seguridad para las Redes Informáticas (OSRI), using the incident-report form the Reglamento's Annex III sets out.
Status in effectRead from the corpus 2026-09-19
Africa, the Middle East and elsewhere Show the 26 provisionsHide the 26 provisions
JurisdictionInstrument, and the obligation lines that carry a clock
Andorra Llei 22/2022, Incident Handling and Notification Obligation (Llei 22/2022, del 9 de juny, arts. 14 i 15)
72 hours72 hoursNotify the CSIRT-AD, without delay and in any event within 72 hours of becoming aware of it, of any incident that has or may have significant effects on your essential or important service, including information on any cross-border effects; where you cannot yet establish that effect, you may omit it if you send a justificatory report within 72 hours of the notification explaining why.
without undue delayWhere appropriate, notify the recipients of your service, without undue delay, that a significant incident is likely to affect them and what measures or remedies they can take in response.
without delayNotify the competent authority, through the CSIRT-AD and without delay, of a significant cyber threat to your essential or important service that you believe could result in a significant incident, once the threshold for that duty is further specified by regulation.
Status since 2022-06-23Read from the corpus 2026-09-18
Democratic Republic of the Congo Digital Code, Livre II: Trust Service Provider Security-Incident Notification (Code du numérique, Livre II, Titre II, Chapitre III, Ordonnance-loi n° 23/010 du 13 mars 2023 (art. 148 et 149))
4 hoursNotify the Autorité Nationale de Certification Électronique, and where applicable other bodies concerned, within twenty four hours of becoming aware of it, of every breach of security or loss of integrity having a significant impact on the trust service provided or on the personal data it stores.
4 hoursWhere the breach or loss of integrity is liable to harm a user of the service, notify that user as well, within twenty four hours.
Status since 2023-03-13Read from the corpus 2026-09-19
Côte d'Ivoire Mandatory Reporting of Attacks and Intrusions to ARTCI (Décret n°2021-917 du 22 décembre 2021, Arts. 16-17)
immediatelyInform ARTCI immediately of any attack, intrusion or other disruption likely to impede your information system's proper functioning.
Status since 2021-12-22Read from the corpus 2026-09-18
Djibouti Digital Code, Book VII: National Health Data System Security Incident Reporting (Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Septième, Art. 747)
without delayReport a serious information-system security incident to the cybersecurity authority without delay, if you access data in Djibouti's national health data system as a health professional, health establishment, health-insurance financing body, or other body accessing that system.
immediatelyExpect a significant security incident to be separately and immediately transmitted by the national authority in charge of information systems to the State's competent authorities.
Status since 2025-09-18Read from the corpus 2026-09-19
Ethiopia Computer Crime Proclamation, Duty to Report Computer Crime and Illegal Content (Computer Crime Proclamation No. 958/2016, art. 2(13), art. 2(19), art. 17, art. 27, art. 46)
immediatelyImmediately notify the Information Network Security Agency (now the Information Network Security Administration) and report the crime to the police, and take appropriate measures.
Status since 2016-07-07Read from the corpus 2026-09-19
Ethiopia Critical Infrastructure Cybersecurity Proclamation, Cyber Incident Reporting to National CERT (Critical Infrastructure Cybersecurity Proclamation No. 1426/2026, art. 7(14), art. 9(2), art. 22(1)(b)-(c), art. 22(2)-(3), art. 22(5), art. 25(1)(b), art. 25(2)-(4), art. 28)
48 hoursNotify the National Computer Emergency Response Center of a cyber incident within 48 hours of becoming aware of it, using the system the Administration establishes, and implement the mandatory recommendations or directions the Center provides within the time it sets.
48 hoursFailing to notify an incident within 48 hours, or to take appropriate corrective action, is an administrative offense fined from 1,500,000 to 2,000,000 Birr; failing to provide the requested information or cooperation during a cyberattack response is fined from 300,000 to 500,000 Birr; a negligent violation of either is fined at no more than half the stated amount, a first violation causing no damage may be resolved with a written warning instead, and a repeat violation is fined at triple the stated maximum.
48 hoursAn officer, employee, member of the management body, or owner of the critical infrastructure who intentionally fails to notify the Center within 48 hours, or to take appropriate corrective action, is separately subject to imprisonment of up to one year; where that failure interrupts, disrupts, or damages the critical infrastructure's service, compromises its integrity or confidentiality, or harms national security, national interest, public health, life, or the environment, the term rises to rigorous imprisonment of seven to ten years, or three to five years where the aggravated result is caused negligently.
Status from 2027-07-21 [enacted, not yet in effect]Read from the corpus 2026-09-19
Micronesia FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Incident Reporting Clock (§ 412, Subchapter III, C.B. No. 24-14 (Cybersecurity Act 2025), proposed new Chapter 4, Title 21, FSM Code)
24 hours72 hours30 daysNotify the Secretary of Justice and the CERT-FSM of a significant cybersecurity incident affecting your critical information infrastructure or an interconnected system: an early warning within 24 hours of becoming aware of it, a fuller notification within 72 hours, and a final report within 30 days of that notification.
Status [proposed]Read from the corpus 2026-09-19
Ghana Cybersecurity Act, Duty to Report Cybersecurity Incident (Cybersecurity Act, 2020 (Act 1038), ss. 47(2) and 47(5)-(6), and Second Schedule item 47(6))
24 hoursReport a cybersecurity incident to the relevant Sectoral Computer Emergency Response Team, or to the National Computer Emergency Response Team where the institution has no Sectoral team, within twenty-four hours after the incident is detected.
24 hoursFailing to report within the twenty-four-hour window is an administrative penalty of not less than two hundred and fifty penalty units and not more than five thousand penalty units, payable to the Cyber Security Authority.
Status since 2020-12-29Read from the corpus 2026-09-18
Gambia Information and Communications Act, 2009, security of information and communications services (subscriber risk notification) (Information and Communications Act, 2009 (No. 2 of 2009), sec. 140(3)-(6))
promptlyWhere an event affecting or jeopardizing the security of your services occurs and reveals a previously unknown risk, promptly and free of charge inform the affected subscriber of the risk, the measures they may take, and the estimated cost involved.
Status since 2009-05-29Read from the corpus 2026-09-19
Iceland Notification of Serious Incidents and Risk to the National Cybersecurity Incident-Response Team (Log nr. 78/2019, Art. 8)
as soon as may beNotify Iceland's national cybersecurity incident-response team as soon as may be about a serious incident or risk threatening the security of a network or information system; the Act sets no fixed hour-based clock of its own for this notification.
Status since 2020-09-01Read from the corpus 2026-09-15
Jordan Cyber Security Law No. 16 of 2019, Article 8 private-sector incident-reporting and Center-cooperation duty (Cyber Security Law No. (16) of 2019, Article 8(b))
1 hour4 hours1 dayWhere the incident is Critical or High severity, in particular where it touches critical infrastructure, a security or military body, a ministry or government institution, a government-owned or government-invested company, a supply chain feeding those entities, or where it disrupts essential services entirely at a higher-education institution, the Center's own Incident Response and Reporting Policy sets a reporting clock as short as 30 minutes for a Critical-tier incident, rising through roughly 1 hour for High, 4 hours for Medium, and 1 day for Low; an ordinary private company or individual establishment with no such touchpoint is typically classified Medium or Low.
Status in effectRead from the corpus 2026-09-16
Kenya Computer Misuse and Cybercrimes Act, Reporting of Cyber Threat (Computer Misuse and Cybercrimes Act (No. 5 of 2018), s. 40)
24 hoursImmediately inform the National Computer and Cybercrimes Co-ordination Committee, established under section 4 of the Act, of an attack, intrusion, or other disruption to the functioning of another computer system or network, within twenty-four hours of the attack, intrusion, or disruption.
Status since 2018-05-30Read from the corpus 2026-09-14
Kiribati Cybersecurity Act 2026, Duty to Report a Cybersecurity Incident (Cybersecurity Act 2026 (Act No. 7 of 2026), s. 21 (Part VI))
24 hoursWhen you are the subject of a cybersecurity incident or threat of one, gather information about it, assess the risk to your critical infrastructure, customers, suppliers and other stakeholders, take appropriate preventative, mitigating and remedial measures to limit that risk, and report all material information about a significant cybersecurity incident to the National CERT and any relevant Sectoral CERT within 24 hours after you detect it, in the form or manner the CERT prescribes.
Status enacted, not yet in effectRead from the corpus 2026-09-19
Liechtenstein Cyber-Sicherheitsgesetz (CSG), Incident Notification (Cyber-Sicherheitsgesetz (CSG) vom 5. Dezember 2024, LGBl. 2025 Nr. 111, Art. 6)
24 hoursNotify the Stabsstelle Cyber-Sicherheit (Cyber Security Office) without delay, and in any event within 24 hours of becoming aware of a significant security incident, with an early warning stating, where relevant, whether the incident is suspected to result from unlawful or malicious acts or to have cross-border effect.
72 hoursFollow with a full notification within 72 hours of becoming aware, updating the early warning where relevant and giving an initial assessment of the incident's severity and impact and, where available, indicators of compromise.
1 month72 hoursSubmit an intermediate report on the Stabsstelle Cyber-Sicherheit's request, and a final report within one month of the 72-hour notification, describing the incident's severity and impact in detail, the likely threat or root cause, and the mitigation measures taken.
Status since 2025-02-01Read from the corpus 2026-09-15
Morocco Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Incident and Vulnerability Notification Duties (Loi n° 05-20 relative à la cybersécurité, Chapitre II, Section 3, Arts. 27, 30 et 33, promulguée par le Dahir n° 1-20-69 du 4 hija 1441 (25 juillet 2020), Bulletin Officiel n° 6906 du 16 hija 1441 (6 août 2020))
without delayWhen you detect an event that could affect the security of a client's information systems, inform the national cybersecurity authority of it without delay.
Status in effectRead from the corpus 2026-09-17
Montenegro Law on Information Security, Cyber Threat and Incident Reporting (Law on Information Security, Arts. 28 to 37)
24 hoursWhere a cyber threat or incident could significantly affect the continuity of your service, submit an initial notification to the Cybersecurity Agency within 24 hours of becoming aware of it, on the prescribed form (Article 30).
72 hours30 daysFor an incident the Agency rates medium, submit a first report within 72 hours of your initial notification, a further report without delay on any new development, continuing reports every 72 hours while the incident lasts, and a final report within 30 days of resolving it (Article 33).
Status since 2024-12-05Read from the corpus 2026-09-18
Marshall Islands Cybersecurity Act 2025, Cybersecurity Incident Reporting Obligations (Cybersecurity Act 2025, 40 MIRC Ch. 4 § 407 (P.L. 2025-0027))
immediatelyImmediately notify the Director and the CSIRT-MH (the Cyber Security Incident Response Team of the Marshall Islands) of a significant cybersecurity incident affecting your critical information infrastructure, of a significant incident on any interconnected computer system under your control, or of any other incident type the Director specifies by written order.
24 hours72 hours30 days30 days30 daysSubmit an early warning within twenty-four hours of becoming aware of the incident, a fuller notification with an initial severity and impact assessment within seventy-two hours, and a final report within thirty days of that notification, or, for an ongoing incident, a thirty-day progress report followed by a final report within thirty days of the incident's resolution.
Status since 2025-04-21Read from the corpus 2026-09-19
Mozambique Cybersecurity Law, Incident Notification and Responsible Vulnerability Disclosure (Lei n.º 13/2026, arts. 57 a 66)
promptlyIf you operate a data centre or a cloud-computing platform, also notify your own subscribers promptly of an incident, including a data leak, that affects or may affect their content.
Status from 2026-09-29 [enacted, not yet in effect]Read from the corpus 2026-09-18
Nigeria Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, Reporting of Cyber Threats to the National CERT (Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, section 21, Reporting of Cyber Threats)
immediatelyImmediately inform the National Computer Emergency Response Team (CERT) Coordination Center of any attack, intrusion, or other disruption liable to hinder the functioning of another computer system or network.
7 daysReport the incident to the National CERT within 7 days of its occurrence. Failing to do so is itself an offence, punishable by denial of internet services and a mandatory fine of N2,000,000 payable into the National Cyber Security Fund.
Status in effectRead from the corpus 2026-09-17
Serbia Law on Information Security, Incident Reporting Obligations (Zakon o informacionoj bezbednosti ("Sl. glasnik RS", br. 91/2025), čl. 13-14, 24-25)
24 hoursNotify the single incident-reporting system, through the Ministry's or the Office for Information Security's website, of an incident that may significantly disrupt information security, without delay and at the latest within 24 hours of becoming aware of it.
without delayNotify the users of your service, without delay, of an incident that causes or may cause a harmful effect on providing or using your service, together with any measures they can take to reduce or remove the harmful effect.
15 daysSubmit a final report within 15 days after the incident ends, covering its type, cause, duration, scope of impact, any cross-border effect, and the steps you took to remedy it.
Status since 2026-01-01Read from the corpus 2026-09-18
Sierra Leone Cyber Security and Crime Act, 2021, Reporting of Cyber Security Incidents (Cyber Security and Crime Act, 2021 (Act No. 7 of 2021), s. 53 (Reporting Cyber Threats))
immediatelyImmediately inform the National Computer Security Incidence Response Team of an attack, intrusion, or other disruption liable to hinder the functioning of another computer system or network.
7 daysReport the incident to the Team within 7 days of its occurrence even if you already gave the immediate notice section 53(1) requires; failing to do so, without reasonable excuse, is itself an offence distinct from any liability for the disruption reported.
Status since 2021-11-15Read from the corpus 2026-09-19
Tunisia Cybersecurity Incident Reporting and Emergency Response (Décret-loi n° 2023-17 du 11 mars 2023, relatif à la cybersécurité, Arts. 17-20, 24-25)
immediatelyImmediately inform the national contact point or your emergency response center of any cybersecurity incident or attack, and comply with the emergency measures either one orders.
Status since 2023-09-11Read from the corpus 2026-09-18
Tonga Cybersecurity Act 2025, Duty to Report a Cybersecurity Incident (Act 14 of 2025, s. 15)
24 hoursWithin 24 hours of becoming aware of it, report to the Computer Emergency Response Team (CERT) a cybersecurity incident relating to the information systems of your designated critical infrastructure, an incident relating to any information system interconnected with or communicating with those systems, or any other cybersecurity incident or occurrence the Minister CPR has designated as requiring notification.
Status enacted, not yet in effectRead from the corpus 2026-09-19
Turkey Cybersecurity Law, Reporting and Cooperation Duties (Law No. 7545 (12 March 2025), Art. 7)
without delayReport a detected vulnerability or cyber incident in the area of service provided to the Cybersecurity Directorate without delay; the Law's own text sets no numeric reporting clock.
Status since 2025-03-19Read from the corpus 2026-09-14
Ukraine Law on the Basic Principles of Ensuring Cybersecurity, CERT-UA Incident Notification Duty (Закон України "Про основні засади забезпечення кібербезпеки України" № 2163-VIII від 05.10.2017 (редакція від 03.04.2025, підстава - 4070-IX), ст. 6(4)-(5), ст. 9(2))
immediatelyInform CERT-UA immediately (невідкладно, without delay; the statute states no fixed hour clock) of a cybersecurity incident affecting your critical infrastructure object's communication or technological systems.
Status since 2018-05-09Read from the corpus 2026-09-19
Kosovo Law No. 08/L-173 on Cyber Security, Incident Reporting and Enforcement (Law No. 08/L-173 on Cyber Security, Arts. 6, 8 and 24)
24 hoursAs an operator of essential services, notify the Agency for Cyber Security immediately, and no later than 24 hours after becoming aware, of a cyber incident with a significant impact on system security or service continuity, and notify affected persons or the public within a reasonable time where individual notice is impractical.
immediatelyAs a digital service provider, notify the Agency for Cyber Security immediately upon becoming aware of a cyber incident with a significant impact on the digital service you provide.
Status since 2023-03-14Read from the corpus 2026-09-18

3Privacy law: personal-data breach notification, by jurisdiction

167 instruments in 162 jurisdictions in the corpus's privacy topic under its breach-notification family state a reporting deadline, as of 2026-09-21: 109 a numeric clock, and 58 a standard such as "immediately" or "without undue delay" with no number. These bind the party that decides why and how personal data is processed, which for an agent is nearly always its OPERATOR, and the clock runs to the supervisory authority and, separately, to the people affected. The GDPR row is stated once for the EU and once for each member state, because each state's authority is the recipient.

13 more instruments in this family state no deadline in their obligation lines and are not listed here; the privacy law section has them.

European Union Show the 1 provisionHide the 1 provision
JurisdictionInstrument, and the obligation lines that carry a clock
European Union GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the competent supervisory authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting EU personal data, unless the breach is unlikely to risk individuals' rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-23
EU member states (the national layer) Show the 27 provisionsHide the 27 provisions
JurisdictionInstrument, and the obligation lines that carry a clock
Austria GDPR Articles 33-34, Breach Notification in Austria (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the Datenschutzbehorde without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Austria, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
Belgium GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the GBA/APD within 72 hours of becoming aware of a personal-data breach affecting a person in Belgium, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
Bulgaria GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify KZLD within 72 hours of becoming aware of a personal-data breach affecting a person in Bulgaria, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them, using KZLD's own Bulgarian-language notification template.
Status since 2018-05-25Read from the corpus 2026-08-24
Cyprus GDPR Articles 33-34, Breach Notification in Cyprus (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the ODPC without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Cyprus, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
Czech Republic GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify UOOU within 72 hours of becoming aware of a personal-data breach affecting a person in the Czech Republic, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
Germany GDPR Articles 33-34, Breach Notification in Germany (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the competent German data protection authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Germany, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
Denmark GDPR Articles 33-34, Breach Notification in Denmark (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify Datatilsynet without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Denmark, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
Estonia GDPR Articles 33-34, Breach Notification in Estonia (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the Estonian Data Protection Inspectorate without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Estonia, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2019-01-15Read from the corpus 2026-08-24
Spain GDPR Articles 33-34 and LOPDGDD Article 69, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34; LOPDGDD, Art. 69, Art. 73(r)-(s))
72 hoursNotify the AEPD within 72 hours of becoming aware of a personal-data breach affecting a person in Spain, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-12-07Read from the corpus 2026-08-24
Finland GDPR Articles 33-34, Breach Notification in Finland (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the Data Protection Ombudsman without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Finland, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2019-01-01Read from the corpus 2026-08-24
France GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the CNIL within 72 hours of becoming aware of a personal-data breach affecting a person in France, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
Greece GDPR Articles 33-34, Breach Notification in Greece (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the Hellenic Data Protection Authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Greece, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
Croatia GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify AZOP within 72 hours of becoming aware of a personal-data breach affecting a person in Croatia, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
Hungary Infotörvény Sections 25/J-25/K, Breach Notification, Inserted by Act XXXVIII of 2018 (2011. evi CXII. torveny, 25/J-25/K. section, as inserted by 2018. evi XXXVIII. torveny 17. section)
72 hoursNotify NAIH without delay, and no later than 72 hours after becoming aware of it, of a personal-data breach affecting a person in Hungary, per Infotorveny Section 25/J(1).
Status since 2019-04-26Read from the corpus 2026-08-24
Ireland GDPR Articles 33-34, Breach Notification in Ireland (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the Data Protection Commission without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Ireland, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
Italy GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the Garante within 72 hours of becoming aware of a personal-data breach affecting a person in Italy, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
Lithuania GDPR Articles 33-34, Breach Notification in Lithuania (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify VDAI without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Lithuania, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
Luxembourg GDPR Articles 33-34, Breach Notification in Luxembourg (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the CNPD without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Luxembourg, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
Latvia GDPR Articles 33-34, Breach Notification in Latvia (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the Data State Inspectorate without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Latvia, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
Malta GDPR Articles 33-34, Breach Notification in Malta (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the IDPC without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Malta, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
Netherlands GDPR Articles 33-34 and UAVG Article 42, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34; UAVG, Art. 42)
72 hoursNotify the AP within 72 hours of becoming aware of a personal-data breach affecting a person in the Netherlands, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them, subject to UAVG Article 42's national exception.
Status since 2018-05-25Read from the corpus 2026-08-24
Poland GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify UODO within 72 hours of becoming aware of a personal-data breach affecting a person in Poland, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
Portugal GDPR Articles 33-34, Breach Notification in Portugal (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the CNPD without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Portugal, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-05-25Read from the corpus 2026-08-24
Romania GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify ANSPDCP within 72 hours of becoming aware of a personal-data breach affecting a person in Romania, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
Sweden GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify IMY within 72 hours of becoming aware of a personal-data breach affecting a person in Sweden, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
Slovenia GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the Slovenian Information Commissioner within 72 hours of becoming aware of a personal-data breach affecting a person in Slovenia, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
Slovakia GDPR Articles 33-34, Breach Notification (Regulation (EU) 2016/679, Arts. 33-34)
72 hoursNotify the Slovak Office for Personal Data Protection within 72 hours of becoming aware of a personal-data breach affecting a person in Slovakia, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Status since 2018-05-25Read from the corpus 2026-08-24
United Kingdom Show the 1 provisionHide the 1 provision
JurisdictionInstrument, and the obligation lines that carry a clock
United Kingdom UK GDPR Articles 33-34 and PECR, Breach Notification in the United Kingdom (UK GDPR, Arts. 33-34; Privacy and Electronic Communications Regulations (PECR), as amended by the Data (Use and Access) Act 2025)
72 hoursNotify the ICO without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in the United Kingdom, unless the breach is unlikely to risk their rights and freedoms.
72 hoursNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms, and if you are a telecoms or ISP-type provider, notify a PECR breach to the ICO within 72 hours.
Status since 2018-05-25Read from the corpus 2026-08-24
United States, federal Show the 2 provisionsHide the 2 provisions
JurisdictionInstrument, and the obligation lines that carry a clock
United States GLBA Safeguards Rule Breach Notification Amendment (16 CFR Section 314.4(j))
30 daysNotify the FTC within 30 days of discovering a security event that has compromised unencrypted customer information for 500 or more consumers.
Status since 2024-05-13Read from the corpus 2026-08-23
United States HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D (Sections 164.400-164.414))
60 daysNotify affected individuals without unreasonable delay and no later than 60 days after discovering a breach of unsecured protected health information.
Status since 2009-09-23Read from the corpus 2026-08-23
United States, states Show the 51 provisionsHide the 51 provisions
JurisdictionInstrument, and the obligation lines that carry a clock
Alaska Alaska Personal Information Protection Act, breach notification duty (Alaska Stat. Secs. 45.48.010-45.48.070)
without unreasonable delayDisclose a breach of the security of an information system containing an Alaska resident's personal information to each affected resident in the most expeditious time possible and without unreasonable delay.
Status enacted, not yet in effectRead from the corpus 2026-08-27
Arkansas Arkansas Personal Information Protection Act, breach notification and security (Ark. Code Ann. secs. 4-110-101 to 4-110-108)
without unreasonable delayNotify each affected Arkansas resident of a breach of security without unreasonable delay.
45 daysNotify the Arkansas Attorney General if the breach affects more than 1,000 individuals, at the same time as consumer notice or within 45 days of determining a reasonable likelihood of harm, whichever occurs first.
Status enacted, not yet in effectRead from the corpus 2026-08-27
Arizona Arizona data breach notification law (A.R.S. secs. 18-551 to 18-552)
45 daysNotify each affected Arizona resident of a breach of system security involving their personal information without unreasonable delay and no later than 45 days after determining the breach occurred.
Status enacted, not yet in effectRead from the corpus 2026-08-27
California California Data Breach Notification Law, as amended by SB 446 (Cal. Civ. Code section 1798.82, as amended by SB 446 (2025, Ch. 319))
30 daysNotify affected California residents of a breach of their unencrypted personal information within 30 calendar days of discovery or notification.
15 daysNotify the California Attorney General within 15 days of consumer notification when a breach affects more than 500 California residents.
Status since 2026-01-01Read from the corpus 2026-08-23
Colorado C.R.S. 6-1-716, Notification of Security Breach (C.R.S. section 6-1-716)
30 daysIf you experience unauthorized acquisition of unencrypted computerized personal information of Colorado residents, notify affected residents without unreasonable delay and within 30 days of determining a breach occurred.
Status since 2018-09-01Read from the corpus 2026-08-23
Connecticut Breach of security re computerized data containing personal information (Conn. Gen. Stat. § 36a-701b)
60 daysNotify each affected Connecticut resident of a breach of security involving personal information without unreasonable delay and no later than 60 days after discovery, unless federal law requires a shorter time.
Status enacted, not yet in effectRead from the corpus 2026-09-02
District of Columbia Consumer Security Breach Notification (D.C. Code §§ 28-3851 to 28-3853 (Title 28, Chapter 38, Subchapter II))
without unreasonable delayIf your business conducts business in the District of Columbia and discovers a breach of the security of a system containing a District resident's personal information, notify each affected resident in the most expedient time possible and without unreasonable delay.
Status since 2007-07-01Read from the corpus 2026-09-06
Delaware Computer Security Breaches (Del. Code Ann. tit. 6, §§ 12B-101 to 12B-104)
60 daysNotify affected Delaware residents of a breach of security without unreasonable delay and no later than 60 days after determining the breach occurred.
Status enacted, not yet in effectRead from the corpus 2026-08-27
Florida Florida Information Protection Act, breach notification (Fla. Stat. § 501.171)
30 daysNotify the Florida Department of Legal Affairs of a breach of security affecting 500 or more individuals in Florida as expeditiously as practicable, and no later than 30 days after determining a breach occurred or having reason to believe one occurred.
30 days15 daysNotify each affected Florida individual of a breach no later than 30 days after determining a breach occurred, unless you obtain a written 15-day extension for good cause.
Status enacted, not yet in effectRead from the corpus 2026-08-27
Georgia Georgia Personal Identity Protection Act, notification of security breach (O.C.G.A. Sec. 10-1-912)
without unreasonable delayGive notice of a breach of the security of a system containing a Georgia resident's personal information in the most expedient time possible and without unreasonable delay.
Status enacted, not yet in effectRead from the corpus 2026-08-27
Guam Notification of Breaches of Personal Information (9 GCA §§ 48.10-48.80)
without unreasonable delayDisclose a breach of the security of your system to any affected Guam resident without unreasonable delay once you know or reasonably believe the breach caused or will cause identity theft or other fraud.
as soon as practicableIf you hold a Guam resident's computerized personal information for another owner or licensee rather than for yourself, notify that owner or licensee as soon as practicable after discovering a breach.
Status in effectRead from the corpus 2026-09-05
Hawaii Hawaii Security Breach of Personal Information Act, notice of security breach (Haw. Rev. Stat. Secs. 487N-1, 487N-2)
without unreasonable delayProvide clear and conspicuous notice, without unreasonable delay, to a Hawaii resident affected by a security breach of a system containing their personal information, describing the incident, the type of information exposed, and remedial steps taken.
Status enacted, not yet in effectRead from the corpus 2026-08-27
Iowa Personal Information Security Breach Protection (Iowa Code § 715C.2)
without unreasonable delayNotify affected Iowa residents of a breach of security in the most expeditious manner possible and without unreasonable delay.
5 business daysNotify the Iowa Attorney General's consumer protection division within five business days of notifying consumers, if the breach requires notifying more than 500 Iowa residents.
Status enacted, not yet in effectRead from the corpus 2026-08-27
Idaho Identity Theft Act, breach of security disclosure duty (Idaho Code § 28-51-105)
as soon as possibleGive notice to each affected Idaho resident as soon as possible, and in the most expedient time possible without unreasonable delay, after discovering a breach of system security involving personal information.
24 hoursIf you are a government agency, also notify the Idaho Attorney General within 24 hours of discovering the breach; this duty does not extend to a private commercial entity.
Status enacted, not yet in effectRead from the corpus 2026-08-28
Illinois Personal Information Protection Act, data breach notification (815 ILCS 530/1 et seq. (P.A. 94-36, eff. 2006-01-01))
without unreasonable delayNotify affected Illinois residents of a data breach in the most expedient time possible and without unreasonable delay after discovering unauthorized acquisition of their computerized personal information, which includes unique biometric data used to authenticate an individual.
Status since 2006-01-01Read from the corpus 2026-08-23
Indiana Disclosure of Security Breach Act (Ind. Code §§ 24-4.9-3-1, 24-4.9-3-3, 24-4.9-4-1, 24-4.9-4-2)
45 daysDisclose a breach to affected Indiana residents without unreasonable delay and no later than 45 days after discovering that the unauthorized acquisition has resulted in or could result in identity deception, identity theft, or fraud.
Status enacted, not yet in effectRead from the corpus 2026-08-27
Kansas Kansas Breach Notification Act, notice of security breach (K.S.A. 50-7a02(a)-(f))
as soon as possibleGive notice to each affected Kansas resident as soon as possible, in the most expedient time possible and without unreasonable delay, if the investigation shows misuse occurred or is reasonably likely. There is no fixed numeric deadline in the statute; do not rely on a 45-day figure some secondary sources describe.
Status enacted, not yet in effectRead from the corpus 2026-08-28
Kansas Student Data Privacy Act, breach notice for student data (K.S.A. 72-6318)
immediatelyImmediately notify the affected Kansas student, or the student's parent or guardian, of a breach or unauthorized disclosure of student data if your entity has access to that data.
Status enacted, not yet in effectRead from the corpus 2026-08-28
Kentucky Notification to affected persons of computer security breach (KRS 365.732)
without unreasonable delayNotify an affected Kentucky resident of a breach involving unencrypted personal information in the most expedient time possible and without unreasonable delay.
Status since 2014-07-15Read from the corpus 2026-08-27
Louisiana Database Security Breach Notification Law, notice duty (La. R.S. 51:3074(C), (E), (I))
60 daysNotify each affected Louisiana resident of a breach involving personal information in the most expedient time possible and without unreasonable delay, no later than 60 days after discovery.
Status since 2006-01-01Read from the corpus 2026-08-28
Massachusetts Security Breach statute, duty to report breach of personal information (Mass. Gen. Laws ch. 93H, § 3)
as soon as practicableNotify the Massachusetts Attorney General, the Director of Consumer Affairs and Business Regulation, and each affected Massachusetts resident as soon as practicable and without unreasonable delay after learning of a breach of security involving personal information.
Status enacted, not yet in effectRead from the corpus 2026-08-28
Maryland Maryland Personal Information Protection Act (MPIPA), breach notification (Md. Code Ann., Com. Law §§ 14-3501, 14-3504 (Title 14, Subtitle 35))
45 daysNotify each affected Maryland individual as soon as reasonably practicable, and no later than 45 days after discovering or being notified of the breach, once you determine a likelihood that personal information has been or will be misused.
7 days45 daysWhere notification is delayed because a law enforcement agency says it would impede an investigation, notify within 7 days after that delay is cleared, or by the original 45-day deadline, whichever is later.
Status enacted, not yet in effectRead from the corpus 2026-09-02
Maine Notice of Risk to Personal Data (10 M.R.S. secs. 1347-1349)
30 daysNotify affected Maine residents of a breach of security as expediently as possible and without unreasonable delay, no more than 30 days after becoming aware of the breach and identifying its scope, absent a law enforcement delay.
Status enacted, not yet in effectRead from the corpus 2026-08-27
Michigan Identity Theft Protection Act, breach of security notice duty (MCL 445.72)
without unreasonable delayGive breach notice without unreasonable delay unless you determine the breach has not caused and is not likely to cause substantial loss, injury, or identity theft to affected Michigan residents.
Status since 2006-07-02Read from the corpus 2026-08-28
Minnesota Minnesota breach notification (Minn. Stat. § 325E.61)
without unreasonable delayDisclose a breach of the security of the system to an affected Minnesota resident in the most expedient time possible and without unreasonable delay. Minnesota sets no fixed numeric-day cap, unlike several peer states.
immediatelyNotify the data owner immediately upon discovering a breach if you maintain, but do not own, the affected data.
Status enacted, not yet in effectRead from the corpus 2026-08-27
Missouri Notice of security breach of personal information (Mo. Rev. Stat. Sec. 407.1500)
without unreasonable delayNotify each affected Missouri consumer of a breach of security involving their personal information without unreasonable delay.
without unreasonable delayNotify the Missouri Attorney General's office and every nationwide consumer reporting agency without unreasonable delay if you provide notice to more than 1,000 consumers at one time.
Status since 2009-08-28Read from the corpus 2026-08-27
Mississippi Breach notification law, notice of security breach (Miss. Code Ann. § 75-24-29(2)-(3))
without unreasonable delayDisclose a breach of security to all affected Mississippi individuals without unreasonable delay, unless your investigation reasonably determines the breach will not likely result in harm.
Status since 2011-07-01Read from the corpus 2026-08-28
Montana Notification of security breach (Mont. Code Ann. § 30-14-1704)
without unreasonable delayNotify affected Montana residents of a breach of security without unreasonable delay, and simultaneously submit an electronic copy of the notification to the Attorney General's consumer protection office.
Status enacted, not yet in effectRead from the corpus 2026-08-27
North Carolina Identity Theft Protection Act, security breach notification (N.C. Gen. Stat. Secs. 75-61, 75-65)
without unreasonable delayNotify each affected North Carolina resident of a security breach involving their personal information without unreasonable delay, consistent with the legitimate needs of law enforcement.
Status enacted, not yet in effectRead from the corpus 2026-09-02
North Dakota Notice of Security Breach for Personal Information (N.D. Cent. Code ch. 51-30)
without unreasonable delayDisclose a breach of the security system to any affected North Dakota resident in the most expedient time possible and without unreasonable delay.
Status enacted, not yet in effectRead from the corpus 2026-08-28
New Hampshire Notice of Security Breach (RSA 359-C:19-21)
as soon as possibleNotify affected New Hampshire residents and the Attorney General's office as soon as possible on determining a security breach of personal information occurred.
Status since 2007-01-01Read from the corpus 2026-09-02
New Jersey New Jersey Identity Theft Prevention Act, breach notification (N.J. Stat. § 56:8-163)
without unreasonable delayDisclose the breach to each affected New Jersey resident in the most expedient time possible and without unreasonable delay. New Jersey sets no fixed numeric-day cap.
Status since 2006-01-01Read from the corpus 2026-08-27
New Mexico Data Breach Notification Act (NMSA 1978 Secs. 57-12C-1 to 57-12C-12)
45 daysNotify each affected New Mexico resident of a security breach involving their personal identifying information in the most expedient time possible and no later than 45 calendar days after discovery.
Status enacted, not yet in effectRead from the corpus 2026-08-28
Nevada Security breach of personal information, notification (NRS 603A.220)
without unreasonable delayDisclose a security breach of personal information to an affected Nevada resident in the most expedient time possible and without unreasonable delay. Nevada sets no fixed numeric deadline.
Status enacted, not yet in effectRead from the corpus 2026-09-02
New York Stop Hacks and Improve Electronic Data Security (SHIELD) Act, breach notification duty (N.Y. Gen. Bus. Law § 899-aa)
30 daysDisclose a breach of the security of your system to each affected New York resident in the most expedient time possible and without unreasonable delay, and no later than 30 days after discovering the breach.
Status since 2019-10-23Read from the corpus 2026-08-27
Ohio Security Breach Notification Act (Ohio Rev. Code Sec. 1349.19)
45 daysNotify an affected Ohio resident of a security breach involving their personal information in the most expedient time possible and no later than 45 days after discovery.
without unreasonable delayNotify every nationwide consumer reporting agency without unreasonable delay if a single breach affects more than 1,000 Ohio residents.
Status since 2007-03-30Read from the corpus 2026-08-29
Oklahoma Security Breach Notification Act (Okla. Stat. tit. 24, Secs. 162-166)
without unreasonable delayProvide notice of a breach of security involving personal information without unreasonable delay.
60 daysNotify the Oklahoma Attorney General within 60 days of consumer notice if the breach affects 500 or more Oklahoma residents (1,000 or more for a breach maintained by a credit bureau).
Status since 2026-01-01Read from the corpus 2026-08-28
Pennsylvania Breach of Personal Information Notification Act (73 P.S. secs. 2302, 2303, 2305, 2308 (Act 94 of 2005))
without unreasonable delayNotify each affected Pennsylvania resident of a breach of system security involving personal information without unreasonable delay.
Status since 2006-06-20Read from the corpus 2026-08-28
Puerto Rico Ley de Información al Ciudadano sobre la Seguridad de Bancos de Información (data breach notification) (Ley Núm. 111 de 7 de septiembre de 2005, según enmendada; 10 L.P.R.A. §§ 4051-4055)
as expeditiously as possibleNotify affected Puerto Rico residents of a security breach of an information bank containing their personal information as expeditiously as possible.
10 daysReport the breach to the Department of Consumer Affairs within ten non-extendable days of detecting it.
Status in effectRead from the corpus 2026-09-05
Rhode Island Identity Theft Protection Act of 2015, notification of breach (R.I. Gen. Laws secs. 11-49.3-4, 11-49.3-5)
45 days30 daysNotify affected Rhode Island residents of a breach posing a significant risk of identity theft within 45 days of confirming the breach, or within 30 days if you are a state or municipal agency.
Status enacted, not yet in effectRead from the corpus 2026-08-27
South Carolina Business data breach of security, notification statute (S.C. Code Ann. sec. 39-1-90)
without unreasonable delayNotify each affected South Carolina resident of a breach of security involving personal identifying information in the most expedient time possible and without unreasonable delay.
Status since 2009-07-01Read from the corpus 2026-09-02
South Dakota Breach of system security, notification statute (SDCL secs. 22-40-19 to 22-40-26 (SL 2018 ch. 135))
60 daysNotify each affected South Dakota resident of a breach of system security not later than 60 days after discovery, absent a law enforcement delay.
Status since 2018-07-01Read from the corpus 2026-08-28
Texas Identity Theft Enforcement and Protection Act, breach notification (Tex. Bus. & Com. Code sec. 521.053, as amended by Tex. SB 768, 88th Legislature (2023))
60 daysNotify each affected Texas resident of a breach of system security involving their sensitive personal information without unreasonable delay and no later than 60 days after determining the breach occurred.
30 daysNotify the Texas Attorney General as soon as practicable and no later than 30 days after determining the breach occurred, if the breach affects 250 or more Texas residents.
Status since 2009-04-01Read from the corpus 2026-08-23
Utah Protection of Personal Information Act (Utah Code 13-44-101 et seq.)
promptlyIf unencrypted Utah-resident data combining a name with a Social Security number, a driver license or state ID number, or a financial account or card number with its access code is breached, investigate promptly in good faith and notify each affected Utah resident without unreasonable delay.
Status since 2024-05-01Read from the corpus 2026-08-23
Virginia Breach of personal information notification (Va. Code Ann. § 18.2-186.6)
without unreasonable delayNotify the Virginia Office of the Attorney General and each affected Virginia resident of a breach of system security involving personal information without unreasonable delay after discovery.
Status enacted, not yet in effectRead from the corpus 2026-09-02
U.S. Virgin Islands Disclosure of Breach of Security (Identity Theft and Privacy Protection) (14 V.I.C. §§ 2208-2209)
without unreasonable delayNotify an affected Virgin Islands resident without unreasonable delay after discovering that unencrypted personal information (a name combined with a Social Security number, driver's license number, or financial account number with its access code) was acquired without authorization.
Status in effectRead from the corpus 2026-09-05
Vermont Security Breach Notice Act (9 V.S.A. sec. 2435)
45 daysNotify an affected Vermont consumer of a security breach in the most expedient time possible and without unreasonable delay, and no later than 45 days after discovery.
14 business daysNotify the Attorney General or the Department of Financial Regulation, as applicable, with a preliminary description of the breach within 14 business days of discovery.
Status since 2007-01-01Read from the corpus 2026-08-27
Washington Notice of security breaches involving personal information (RCW 19.255, as amended by HB 1071 (2019 c 241); originally enacted 2005 c 368)
30 daysNotify affected Washington residents of a breach of unsecured personal information, including biometric identifiers, in the most expedient time possible and no more than 30 calendar days after discovery.
Status since 2020-03-01Read from the corpus 2026-09-02
Wisconsin Notice of unauthorized acquisition of personal information (Wis. Stat. sec. 134.98)
45 daysMake reasonable efforts to notify each affected Wisconsin individual of an unauthorized acquisition of their personal information within a reasonable time, not to exceed 45 days after learning of it.
Status enacted, not yet in effectRead from the corpus 2026-08-28
West Virginia Breach of Security of Consumer Information (W. Va. Code secs. 46A-2A-101 to 46A-2A-105)
without unreasonable delayNotify each affected West Virginia resident of a breach of security involving personal information without unreasonable delay.
Status enacted, not yet in effectRead from the corpus 2026-08-28
Wyoming Breach of the security of a computerized data system, notification duty (Wyo. Stat. Ann. secs. 40-12-501 to 40-12-511)
as soon as possibleGive notice as soon as possible to each affected Wyoming resident once your investigation determines misuse of their personal identifying information has occurred or is reasonably likely.
Status enacted, not yet in effectRead from the corpus 2026-08-28
Asia and the Pacific Show the 14 provisionsHide the 14 provisions
JurisdictionInstrument, and the obligation lines that carry a clock
Australia Privacy Act 1988 (Cth), Notifiable Data Breaches Scheme (Privacy Act 1988 (Cth), Part IIIC, ss. 26WE, 26WK, 26WL)
as soon as practicablePrepare a statement about an eligible data breach and give a copy to the Information Commissioner as soon as practicable after becoming aware of reasonable grounds to believe the breach happened.
Status since 2018-02-22Read from the corpus 2026-09-06
Brunei Darussalam Personal Data Protection Order 2025, breach notification (Personal Data Protection Order, 2025 (S 1/2025), Part 7 (ss.25-29))
3 daysBrunei's Personal Data Protection Order 2025 has required, since this duty (Part 7) took effect 1 January 2026 under Government Gazette No. S 11/2025, an organisation to notify the Authority within 3 days of assessing that a breach is notifiable, meaning it is likely to cause significant harm or is of significant scale, and to notify each affected individual, for a breach involving any personal data including a voiceprint or faceprint.
Status since 2026-01-01Read from the corpus 2026-08-29
China Personal Information Protection Law, Data Breach Notification (PIPL Art. 57)
immediatelyUpon discovering an actual or possible leak, alteration, or loss of personal information, immediately take remedial measures and notify both the competent personal information protection department and every affected individual, unless the remedial measures can be shown to effectively prevent harm.
Status since 2021-11-01Read from the corpus 2026-08-23
Indonesia Law on Personal Data Protection, breach notification (Law No. 27 of 2022 on Personal Data Protection, Article 46)
72 hoursAn app that suffers a failure of personal data protection affecting an individual in Indonesia must give written notification within 72 hours to the affected individual and to the supervisory institution, describing the data disclosed and the remedial measures taken.
Status since 2022-10-17Read from the corpus 2026-08-29
India Digital Personal Data Protection Act, 2023, breach notification duties (Digital Personal Data Protection Act, 2023 (DPDPA), No. 22 of 2023, breach notification, s.8(6))
72 hoursIndia's data-breach notification duty, covering personal data including a biometric identifier, has not yet commenced and is scheduled to take effect 13 May 2027. Once in force, an app must notify the Data Protection Board and each affected data principal of a personal data breach without delay, and must supply the Board a detailed follow-up report within 72 hours of becoming aware of the breach.
Status from 2027-05-13 [enacted, not yet in effect]Read from the corpus 2026-08-29
Cambodia Cambodia's Draft Law on Personal Data Protection, personal data breach notification (Draft Law on Personal Data Protection, articles 21-22 (personal data breach notification))
72 hoursIf enacted as drafted, a data controller would have to notify the Ministry of Post and Telecommunications immediately, but no later than 72 hours of becoming aware of a personal data breach that may pose a risk to the data subject or another natural person, or give the Ministry valid reasons for any delay.
immediatelyIf enacted as drafted, a data controller would have to notify the affected data subject immediately upon becoming aware of a personal data breach that may pose a high risk to their rights and freedoms, unless the controller had already secured the data, had taken steps removing the high risk, or individual notice would be disproportionately burdensome, in which case a public notice would serve instead.
Status [proposed]Read from the corpus 2026-09-19
South Korea Personal Information Protection Act, breach notification duties (Act No. 10465 (as amended by Act No. 19234, 2023), Art. 34; Enforcement Decree Arts. 39-40)
without delayAn app that suffers a leak, theft, or unauthorized disclosure of Korean personal data must notify affected data subjects without delay, and must report the breach to the PIPC without delay if it affects 1,000 or more people, involves sensitive information such as a biometric identifier, or resulted from illegal external access.
Status since 2023-09-15Read from the corpus 2026-08-23
Kazakhstan Law on Personal Data and Their Protection, breach notification (Law No. 94-V (21 May 2013), Art. 25(2))
from the moment the breach is detectedAn app that suffers a personal data security breach involving Kazakhstani data subjects must notify the competent authority from the moment the breach is detected. The Law sets no numeric deadline for that notice and, on the text read, imposes no separate duty to notify the affected individuals themselves.
Status since 2024-07-01Read from the corpus 2026-08-29
Malaysia Personal Data Protection Act, data protection officer and breach notification (Act 709 (Malaysia) ss.12A-12B, as inserted by Act A1727 s.6, in force 2025-06-01)
as soon as practicableAn app that controls or processes the personal data of individuals in Malaysia must appoint a Data Protection Officer, and a data controller who reasonably believes a personal data breach has occurred must notify the Commissioner as soon as practicable, and must notify affected data subjects without unnecessary delay where the breach causes or is likely to cause significant harm.
Status since 2025-06-01Read from the corpus 2026-08-29
New Zealand Privacy Act 2020, Notifiable Privacy Breaches (Privacy Act 2020 (NZ), No 31, ss. 112-118)
as soon as practicableNotify the Privacy Commissioner as soon as practicable after becoming aware that a notifiable privacy breach, one reasonably believed to have caused or be likely to cause serious harm, has occurred.
as soon as practicableNotify each affected individual, or give public notice if individual notice is not reasonably practicable, as soon as practicable after becoming aware of a notifiable privacy breach, unless a statutory exception or permitted delay applies.
Status since 2020-12-01Read from the corpus 2026-09-06
Philippines Data Privacy Act of 2012, breach notification (Republic Act No. 10173 (2012), Section 20(f))
promptlyAn app that reasonably believes sensitive personal information or identity-fraud-enabling information of an individual in the Philippines has been acquired by an unauthorized person, in a way likely to cause serious harm, must promptly notify the National Privacy Commission and the affected individuals.
Status since 2012-08-15Read from the corpus 2026-08-29
Singapore Personal Data Protection Act, data breach notification (Personal Data Protection Act 2012, Part 6A, ss.26A-26E, as added by Act 40 of 2020)
3 daysAn app that experiences a data breach affecting an individual's personal data in Singapore must assess whether the breach is likely to cause significant harm or is of significant scale, and if so must notify the PDPC as soon as practicable and in any case within 3 calendar days of that assessment, and must also notify each affected individual unless a statutory exception applies.
Status since 2021-02-01Read from the corpus 2026-08-29
Thailand Personal Data Protection Act, breach notification (Personal Data Protection Act B.E. 2562 (2019), Section 37(4))
72 hoursAn app that experiences a personal data breach affecting an individual in Thailand must notify the Personal Data Protection Committee's Office without delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to pose a risk to the affected individuals; where the breach is likely to cause high risk, the app must also notify each affected individual without delay.
Status since 2022-06-01Read from the corpus 2026-08-29
Vietnam Law on Personal Data Protection, breach notification (Law No. 91/2025/QH15, Article 23)
72 hoursAn app that detects a violation of Vietnam's personal data protection rules likely to cause harm to national defense and security, social order, or an individual's life, health, honor, dignity, or property must notify the agency in charge of personal data protection within 72 hours.
Status since 2026-01-01Read from the corpus 2026-08-29
The Americas outside the United States Show the 12 provisionsHide the 12 provisions
JurisdictionInstrument, and the obligation lines that carry a clock
Barbados Data Protection Act, 2019, personal data breach notification (Data Protection Act, 2019, ss. 63-64 (personal data breach notification))
72 hoursNotify a personal data breach to the Data Protection Commissioner without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of an individual, and give reasons for the delay if you notify later.
72 hoursCommunicate a personal data breach likely to result in a high risk to the rights and freedoms of individuals to the affected data subject, in clear and plain language, without undue delay and, where feasible, not later than 72 hours after becoming aware of it.
without undue delayAs a data processor, notify the data controller without undue delay after becoming aware of a personal data breach.
Status since 2021-03-26Read from the corpus 2026-09-19
Belize Data Protection Act 2021, personal data breach notification (Data Protection Act, 2021 (Act No. 45 of 2021), ss. 60-62)
72 hoursWhere feasible, notify the Data Protection Commissioner of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to risk a person's rights and freedoms.
without undue delayWhere a personal data breach is likely to result in a high risk to a person's rights and freedoms, notify that person without undue delay.
Status enacted, not yet in effectRead from the corpus 2026-09-05
Canada PIPEDA breach of security safeguards regime (S.C. 2000, c. 5, ss. 10.1-10.3)
as soon as feasibleReport any breach of security safeguards involving personal information under the organization's control to the Privacy Commissioner as soon as feasible, if it is reasonable to believe the breach creates a real risk of significant harm to an individual.
Status since 2018-11-01Read from the corpus 2026-09-02
Ecuador LOPDP, notificación de vulneración de seguridad (LOPDP, arts. 43 y 46 (notificacion de vulneracion de seguridad))
5 daysNotify the Authority and the telecommunications regulator of a personal-data security breach as soon as possible and no later than five days after becoming aware of it.
3 daysNotify the affected data subject within 3 days of learning of the risk, where the breach carries a risk to their fundamental rights and individual freedoms.
2 daysAs a processor, notify the controller of any personal-data security breach as soon as possible and within 2 days of learning of it.
5 daysGive the reasons for the delay where your notification to the Authority is later than the five days article 43 allows.
Status since 2021-05-26Read from the corpus 2026-09-19
Jamaica Data Protection Act, 2020, reporting a contravention or security breach (Data Protection Act, 2020 (Act 7 of 2020), ss. 21(2)-(5), 30(1)(b), (4)-(5))
72 hoursReport any security breach in respect of your operations which affects or may affect personal data, and any contravention of the data protection standards, to the Information Commissioner within 72 hours of becoming aware of the breach or contravention, in the prescribed form and manner.
without undue delayNotify the Information Commissioner without undue delay of any breach of your security measures which affects or may affect personal data.
upon becoming awareNotify each data subject whose personal data is affected by the breach, upon becoming aware of the breach or having reason to become aware of it, of the nature of the breach, of the measures taken or proposed to address it, and of your data protection officer's contact information, in the form, manner and time prescribed.
Status in effectRead from the corpus 2026-09-19
Mexico Ley Federal de Protección de Datos Personales en Posesión de los Particulares, security-breach notice (LFPDPPP, art. 19 (security-breach notice))
immediatelyNotify the affected data subject immediately of the breach, occurring at any stage of processing personal data, that significantly affects their patrimonial or moral rights.
Status since 2025-03-21Read from the corpus 2026-09-19
Nicaragua Ley No. 787, Ley de Protección de Datos Personales, security incident notice (Ley No. 787, art. 11 (security incident notice to the affected institution))
immediatelyWhere the personal data affected belong to a member of the National Police or the Army of Nicaragua, and the security measures the law requires fail or are not observed, immediately inform the affected institution of the breach.
Status since 2012-03-29Read from the corpus 2026-09-19
Panama Ley 81 de 2019, personal data breach notification (Ley 81 de 2019, arts. 2(5) and 26 (duty to notify security breaches))
as soon as possibleNotify the affected data subject as soon as possible after learning that their personal data was stolen without authorization or that its security was otherwise compromised. This Law sets no fixed number of hours or days for that notice and no duty to notify ANTAI of the breach.
Status since 2021-03-29Read from the corpus 2026-09-19
Paraguay Ley N° 7593/2025, notificación de un incidente de seguridad (Ley 7593/2025, art. 17 (notificacion de un incidente de seguridad))
72 hoursNotify the National Data Protection Agency, and the affected person where relevant, of a security incident within 72 hours of becoming aware of it.
Status from 2027-11-27 [enacted, not yet in effect]Read from the corpus 2026-09-19
Suriname Draft Law on the Protection of Privacy and Personal Data, breach notification (Art. 20 Wet Bescherming Privacy en Persoonsgegevens)
72 hours72 hoursNotify the Commissioner for Personal Data Protection of a breach relating to personal data without delay, and no later than 72 hours after becoming aware of the breach, unless the breach is unlikely to pose a risk to individuals' rights and freedoms; if you do not notify within 72 hours, state the reasons for the delay.
without unreasonable delayAs a processor, inform the controller without unreasonable delay after becoming aware of a breach relating to personal data.
Status [proposed]Read from the corpus 2026-09-19
El Salvador Ley para la Protección de Datos Personales, personal data breach notification (Decreto Legislativo No. 144, art. 25 (personal data breach notification))
2 hoursNotify the Agencia de Ciberseguridad del Estado, the Fiscalia General de la Republica, and every affected data subject of a personal data breach within seventy two hours of becoming aware of it.
Status since 2024-11-23Read from the corpus 2026-09-19
Uruguay Ley N° 19.670, personal data breach notification (Ley N° 19.670, de 15 de octubre de 2018, art. 38, reglamentado por Decreto N° 64/020, de 2020 (notificación de vulneración de seguridad))
immediatelyNotify the affected data subjects immediately and in detail on becoming aware of the breach, describing the measures adopted to address it.
immediatelyNotify the Unidad Reguladora y de Control de Datos Personales immediately and in detail on becoming aware of the breach, coordinating your response with the national cybersecurity incident response center (CERTuy).
Status since 2019-01-01Read from the corpus 2026-09-19
Africa, the Middle East and elsewhere Show the 59 provisionsHide the 59 provisions
JurisdictionInstrument, and the obligation lines that carry a clock
Andorra LQPD, personal data breach notification (Llei 29/2021, arts. 36-37 (personal data breach notification))
72 hoursNotify the Andorran Data Protection Agency of a personal data breach without undue delay and, where possible, within seventy-two hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
72 hoursJustify the reasons for the delay if notifying the Agency after that seventy-two-hour period.
without delayAs a data processor, notify the data controller without delay of a personal data breach you become aware of.
without undue delayCommunicate a personal data breach to the affected data subject without undue delay where the breach is likely to result in a high risk to their rights and freedoms, unless an Article 37(3) exception applies.
without undue delayDescribe in the Agency notification the nature of the breach, the categories and approximate number of data subjects and records affected where possible, a contact point, the likely consequences, and the measures taken or proposed, supplying information in phases without undue delay where it cannot all be given at once.
Status since 2022-05-17Read from the corpus 2026-09-19
United Arab Emirates ADGM Data Protection Regulations, breach notification (ADGM Data Protection Regulations 2021, personal data breach notification provisions)
72 hoursAn app that is a controller or processor established in or targeting the ADGM free zone and that suffers a personal data breach must notify the Commissioner of Data Protection without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to pose a risk to individuals' rights.
Status since 2021-02-14Read from the corpus 2026-08-29
United Arab Emirates Federal Decree-Law on the Protection of Personal Data, breach notification (Federal Decree-Law No. 45 of 2021, Art. 9)
at the time it becomes awareAn app that suffers a breach affecting the personal data of an individual in the onshore UAE must notify the Bureau at the time it becomes aware of the breach; the Decree-Law defers the specific notification window to Executive Regulations whose text could not be confirmed at primary source, so an app should not assume a specific hour count without checking current regulator guidance.
Status since 2022-01-02Read from the corpus 2026-08-29
Albania Law No. 124/2024, notification of a personal data breach (Law No. 124/2024, Art. 29 (notification of a personal data breach))
72 hoursNotify the Commissioner of a personal data breach as soon as possible and no later than 72 hours of becoming aware of the breach, unless the breach is unlikely to endanger the rights and freedoms of data subjects, and give the Commissioner your reasons for any later notification.
immediatelyAs a processor, notify the controller immediately after becoming aware of any personal data breach.
as soon as possibleDescribe in the notification to the Commissioner the nature of the breach, including where possible the categories and approximate number of data subjects and personal data records concerned, the data protection officer's or other contact point's details, the likely consequences, and the measures taken or proposed, supplying anything you cannot give at once as soon as possible afterward.
Status since 2025-01-31Read from the corpus 2026-09-19
Bosnia and Herzegovina Law on the Protection of Personal Data of Bosnia and Herzegovina, personal data breach notification (Law on the Protection of Personal Data, arts. 35-36, 86-87 (personal data breach notification))
72 hoursNotify the Agency of a personal data breach without undue delay and, if possible, within 72 hours of becoming aware of the breach, giving the Agency the reasons for the delay where notice comes later.
without undue delayAs a processor, notify the controller without undue delay after becoming aware of a personal data breach.
without delayNotify the affected person of a personal data breach without delay, in writing and in clear language, wherever the breach is likely to result in a high risk to that person's rights and freedoms, unless the data were rendered unintelligible, the high risk can no longer materialize, or notice would take disproportionate effort and a public notice reaches the person as effectively.
72 hoursAs a competent authority processing personal data for a criminal-law purpose, notify the Agency of a breach within the same 72-hour window and the affected person without delay under the same high-risk test, and pass the breach information to the data controller of another country without undue delay wherever the breached data were transmitted by or to it.
Status since 2025-10-04Read from the corpus 2026-09-19
Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, notification des ruptures de sécurité (Loi n°2017-20 du 20 avril 2018, Livre V, art. 427 (notification des ruptures de sécurité))
without delayNotify the Autorité de Protection des Données Personnelles (APDP) and the affected person without delay of any security breach that has affected their personal data.
without delayAs a processor, warn the controller without delay of any security breach affecting personal data you process on the controller's behalf.
Status since 2018-04-20Read from the corpus 2026-09-19
Bermuda Personal Information Protection Act 2016, breach of security notification (Personal Information Protection Act 2016 (Bermuda), 2016:43, s. 14 (breach of security))
without undue delayNotify the Privacy Commissioner, then any affected individual, without undue delay of a breach of security that is likely to adversely affect an individual.
Status in effectRead from the corpus 2026-09-07
Botswana Data Protection Act, 2024, personal data breach notification (Data Protection Act, 2024 (Act No. 18 of 2024), ss. 63-64)
72 hoursNotify the Information and Data Protection Commission of a personal-data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the affected person's rights and freedoms, and give reasons for any later notification.
without undue delayAs a data processor, notify the data controller of a personal-data breach without undue delay after becoming aware of it.
without undue delayCommunicate a high-risk personal-data breach to the affected data subject without undue delay.
Status since 2025-01-14Read from the corpus 2026-09-19
Belarus Law of the Republic of Belarus On Personal Data Protection, notification of personal data protection violations (Law No. 99-Z, art. 16.1 (notification of personal data protection violations))
3 business daysNotify the National Center for Personal Data Protection immediately, and in any case no later than three working days after becoming aware of a violation of your personal data protection systems, under Article 16, unless the Center itself provides otherwise.
Status since 2021-11-15Read from the corpus 2026-09-19
Democratic Republic of the Congo Digital Code, Title III, personal data breach notification (Code du numérique, Titre III, art. 244 (violation de données à caractère personnel))
without delayNotify the Data Protection Authority and the affected data subject without delay of any breach affecting personal data, describing the nature of the breach, the categories and approximate number of affected people and records where possible, a contact point, the likely consequences, and the measures taken or proposed to address it.
without delayAs a processor, warn the controller without delay of any breach of security affecting personal data you process on the controller's behalf.
Status since 2023-03-13Read from the corpus 2026-09-19
Republic of the Congo Law No. 29-2019, personal-data breach notification (Loi n° 29-2019, articles 74 à 78 (violation de données à caractère personnel))
72 hoursNotify the national commission of a personal-data breach without undue delay and, where possible, within 72 hours of becoming aware of it, unless the breach is not likely to create a risk to the rights and freedoms of natural persons.
without undue delayCommunicate the breach to the affected data subject without undue delay, in clear and simple terms, where it is likely to create a high risk to their rights and freedoms.
without undue delayAs a processor, notify the controller of any personal-data breach without undue delay after becoming aware of it.
Status in effectRead from the corpus 2026-09-19
Switzerland FADP Article 24, Breach Notification in Switzerland (Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 24)
as soon as possibleNotify the FDPIC as soon as possible once you become aware of a data security breach likely to result in a high risk to a Swiss data subject's personality or fundamental rights.
Status since 2023-09-01Read from the corpus 2026-08-24
Djibouti Digital Code, Book I: personal-data breach notification (Code Numérique, Livre Premier, Arts. 14 et 15 (notification des atteintes à la sécurité))
72 hoursNotify the Commission Nationale de Protection des Données à Caractère Personnel of a personal-data breach without undue delay and, at the latest, within 72 hours of becoming aware of it, stating the reasons for any delay beyond that window.
without undue delayTell the affected individual of the breach without undue delay, in clear and simple terms, where it is likely to result in a high risk to their rights and freedoms.
without undue delayAs a processor, notify the controller of a personal-data breach without undue delay after becoming aware of it.
Status since 2025-09-18Read from the corpus 2026-09-19
Algeria Loi n° 18-07 relative à la protection des personnes physiques, notification des violations de données (Loi n° 18-07 du 10 juin 2018, art. 43, telle que modifiée et complétée par la loi n° 25-11 du 24 juillet 2025, arts. 45 bis 8 et 45 bis 10)
without delayAs a service provider, that is any public or private entity offering users the ability to communicate over a computer or telecommunications system, or any entity processing or storing data for that communication service, notify the ANPDP without delay of a personal-data breach occurring on a public electronic communications network.
without delayNotify the affected individual without delay of that same breach where it may harm their private life, unless the ANPDP finds you had already implemented appropriate protective measures.
5 daysIf you are the judicial authority, a body legally empowered to investigate offences, a judicial auxiliary or the prison administration processing personal data under Title V bis for the prevention or detection of offences, investigations, inquiries, criminal prosecutions or the execution of sentences, notify the ANPDP of a personal-data breach within five days of becoming aware of it, stating the reason for the delay if the notification is made later.
Status since 2023-08-11Read from the corpus 2026-09-19
Egypt Egypt Personal Data Protection Law, Personal Data Infringement notification (Law No. 151 of 2020, Article 7 (Personal Data Infringement notification))
72 hoursNotify the Personal Data Protection Center of any personal data breach within 72 hours of discovering it, and notify immediately where the breach concerns national security.
3 daysNotify the Data Subject within 3 days of the date you notified the Center, telling them of the infringement and the procedures you have adopted about it.
Status since 2020-10-16Read from the corpus 2026-09-19
Ethiopia Personal Data Protection Proclamation, personal data breach notification (Proclamation No. 1321/2024, arts. 43-44 (personal data breach notification))
72 hoursNotify the Authority of a personal data breach within 72 hours of becoming aware of it, giving reasons for any delay.
72 hoursCommunicate a personal data breach to the affected data subject within 72 hours of becoming aware of it, in clear language, describing the likely consequences, the contact point for more information and the measures taken to address it.
without undue delayAs a data processor, notify the data controller without undue delay after becoming aware of a personal data breach.
Status since 2024-07-24Read from the corpus 2026-09-19
Gabon Law No. 025/2023, personal-data breach notification (Loi n°025/2023, articles 142 à 147 (violation de données à caractère personnel))
without delayNotify the APDPVP without delay of a personal-data breach, describing its nature, the categories and approximate number of data subjects and records concerned where possible, the data protection officer's or another contact point's details, the likely consequences, and the measures taken or proposed to address it; the law sets no numeric deadline for this notice.
without delayAs a processor, notify the controller without delay of a personal-data breach as soon as you become aware of it.
as soon as possibleWhere a breach is likely to create a high risk to a person's rights and freedoms, inform the affected person as soon as possible, in clear and simple terms, giving at least the same information given to the APDPVP.
Status since 2023-07-15Read from the corpus 2026-09-19
Georgia Law on Personal Data Protection, breach notification (Law of Georgia on Personal Data Protection, Law No. 3144-XI, Arts. 29-30, as amended by Law No. 1289 (17 December 2025))
72 hoursAn app that suffers an incident affecting the personal data of a person in Georgia must notify the State Audit Office within 72 hours of identification, and must notify affected data subjects immediately or without unreasonable delay where there is a high probability of significant damage or a significant threat to their fundamental rights.
Status since 2024-03-01Read from the corpus 2026-08-29
Ghana Data Protection Act, notification of security compromises (Data Protection Act, 2012 (Act 843), s. 31 (notification of security compromises))
as soon as reasonably practicableNotify the Data Protection Commission and the affected data subject as soon as reasonably practicable after you have reasonable grounds to believe personal data has been accessed or acquired by an unauthorised person.
Status in effectRead from the corpus 2026-09-19
Gambia Personal Data Protection and Privacy Act, 2025, personal data breach notification (Personal Data Protection and Privacy Act, 2025, breach notification)
72 hoursNotify the Information Commission of a personal data breach within 72 hours of becoming aware of the breach.
without undue delayNotify each affected data subject of a personal data breach without undue delay where the breach carries a high risk to their rights.
Status enacted, not yet in effectRead from the corpus 2026-09-19
Israel Protection of Privacy Law, breach notification duty (Privacy Protection Regulations (Data Security), 5777-2017, Art. 11(d)(1); Protection of Privacy Law, 5741-1981, monetary sanctions schedule item (21))
immediatelyAn app that suffers a severe security incident affecting the personal data of a person in Israel must immediately notify the Head of the Privacy Protection Authority under the Data Security Regulations' Art. 11(d)(1) duty; the regulations' own text, including any data-subject notification duty, is not set out here and should be confirmed directly before relying on it for full compliance detail.
Status since 2018-05-08Read from the corpus 2026-08-29
Iceland Act No. 90/2018, Breach Notification in Iceland (Log nr. 90/2018 (breach notification provisions))
72 hoursNotify Personuvernd without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Iceland, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-07-15Read from the corpus 2026-08-24
Jordan Personal Data Protection Law, breach notification (Law No. 24 of 2023, Art. 20)
24 hours72 hoursAn app that suffers a serious breach of data security or safety that could cause significant harm to an individual in Jordan must notify the affected individuals within 24 hours of discovery and must notify the Unit within 72 hours of discovery with the source, mechanism, and affected individuals; a Controller found grossly negligent or engaged in misconduct in a breach is liable to compensate the affected Data Subject.
Status since 2024-03-17Read from the corpus 2026-08-29
Kenya Data Protection (General) Regulations, 2021 (Data Protection (General) Regulations, 2021 (Legal Notice No. 263 of 2021), regs. 7, 10, 37, 49-50)
7 days14 daysNotify a data subject in writing within seven days of declining a rectification request, or within fourteen days of declining a restriction request, giving reasons.
Status since 2022-01-14Read from the corpus 2026-09-04
Kenya Data Protection Act, 2019, personal data breach notification (Data Protection Act, 2019 (No. 24 of 2019), s. 43 (notification and communication of breach))
72 hoursNotify the Data Commissioner within seventy-two hours of becoming aware of a personal data breach that carries a real risk of harm, giving reasons if you notify later.
48 hoursAs a data processor, notify the data controller within forty-eight hours of becoming aware of a breach.
Status since 2019-11-25Read from the corpus 2026-09-04
Kiribati Data Protection Act 2025, personal data breaches (Data Protection Act 2025, ss. 19-20 (personal data breaches))
as soon as practicableOn commencement, notify the Digital Transformation Office of a personal data breach that has resulted in, or is likely to result in, significant harm to affected data subjects, as soon as practicable after becoming aware of the breach.
as soon as practicableOn commencement, notify each affected data subject of that same harmful personal data breach as soon as practicable after becoming aware of the breach, or by public notification through widely used media where direct notification is not feasible or would involve disproportionate effort or expense.
as soon as practicableOn commencement, as a person processing personal data on another person's behalf, inform that other person as soon as practicable after becoming aware of any personal data breach, regardless of whether it meets the significant-harm threshold for notifying the Office and data subjects.
Status enacted, not yet in effectRead from the corpus 2026-09-19
Cayman Islands Data Protection Act 2021 Revision, personal data breach notification (Data Protection Act (2021 Revision), s. 16 (personal data breaches))
5 daysNotify the Ombudsman and each affected data subject of a personal data breach without undue delay and no later than five days after becoming aware of it, describing the breach, its consequences, and the measures taken or recommended.
Status since 2019-09-30Read from the corpus 2026-09-07
Liechtenstein DSG Breach Notification in Liechtenstein (DSG, LGBl. 2018 Nr. 272, breach notification provisions)
without undue delayNotify the Datenschutzstelle without undue delay after becoming aware of a personal data breach affecting a person in Liechtenstein that presents a risk to their rights and freedoms, under the DSG.
Status since 2019-01-01Read from the corpus 2026-08-24
Lesotho Data Protection Act, 2011, notification of security compromises (Data Protection Act, 2011, s. 23 (notification of security compromises))
as soon as reasonably possibleNotify the Data Protection Commission and the affected data subject as soon as reasonably possible after discovering that a data subject's personal information has been accessed or acquired by an unauthorised person, unless the data subject's identity cannot be established.
Status since 2012-02-22Read from the corpus 2026-09-19
Monaco Loi sur la Protection des Données Personnelles, notification des violations de données (Loi n. 1.565 du 3 decembre 2024, art. 32 (personal data breach notification))
72 hoursNotify the Authority of a personal data breach as soon as possible and, where feasible, within 72 hours of becoming aware of the breach, unless it is unlikely to create a risk to the rights and freedoms of the persons concerned, and give the reasons for the delay when you notify later than that.
as soon as possibleCommunicate a personal data breach to the affected person as soon as possible, in clear language, when it is likely to create a high risk to their rights and freedoms.
Status since 2024-12-13Read from the corpus 2026-09-19
Moldova Moldova Law No. 195/2024, personal data breach notification (Legea Nr. 195 din 25 iulie 2024, articolele 33-34 (notificarea incalcarii securitatii datelor))
72 hoursNotify the National Centre for Personal Data Protection without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Moldova, unless the breach is unlikely to risk their rights and freedoms.
without undue delayCommunicate the breach to the affected data subject without undue delay where it is likely to result in a high risk to their rights and freedoms, in clear and plain language.
without undue delayAs a processor, notify the controller without undue delay after becoming aware of a personal data breach.
Status since 2026-08-23Read from the corpus 2026-09-19
North Macedonia Law on Personal Data Protection (LPDP), personal data breach notification (Zakon za zastita na licnite podatoci, arts. 37-38 (personal data breach notification))
72 hoursOnce Chapter IV takes effect, notify the Agency of a personal data breach within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons, and give reasons for any delay beyond that period.
without undue delayOnce Chapter IV takes effect, communicate a personal data breach to the affected data subject without undue delay wherever the breach is likely to result in a high risk to their rights and freedoms, unless an exception such as prior encryption, later mitigation, or disproportionate effort applies.
Status since 2021-08-24Read from the corpus 2026-09-19
Mauritius Data Protection Act 2017, personal data breach notification (Data Protection Act 2017 (Act No. 20 of 2017), ss. 25-26 (notification and communication of personal data breach))
72 hoursNotify the Data Protection Commissioner without undue delay, and where feasible within 72 hours, of becoming aware of a personal data breach, giving reasons if notification is later.
without undue delayCommunicate a personal data breach to the affected data subject without undue delay where it is likely to result in a high risk to their rights and freedoms, unless an exception in section 26(3) applies.
Status since 2018-01-15Read from the corpus 2026-09-05
Maldives Maldives Personal Data Protection Bill, personal data breach notification (Personal Data Protection Bill, section 34 (personal data breach notification))
72 hoursIf enacted as drafted, a Controller would have to notify the Data Protection Authority within 72 hours of coming to know of, or reasonably believing in, a personal data breach involving special categories of personal data or data that could enable identity theft or fraud.
Status [proposed]Read from the corpus 2026-09-19
Niger Loi n° 2022-59, notification des violations de données (Loi n° 2022-59, arts. 83 et 86 (notification des violations de données à caractère personnel))
without delayNotify the HAPDP of a personal data breach without delay after becoming aware of it, and justify to the HAPDP any notification made outside that timeframe.
as soon as possibleNotify the affected person of a personal data breach as soon as possible when it is likely to create a high risk to their rights and freedoms; you need not notify the person where it is reasonable to believe the breach creates no such risk.
72 hoursAs a data processor, notify the controller of a personal data breach as soon as possible and no later than 72 hours after becoming aware of it.
Status in effectRead from the corpus 2026-09-19
Nigeria Nigeria Data Protection Act, 2023, data breach notification (Nigeria Data Protection Act, 2023, data breach notification (s. 40; GAID 2025, art. 33))
72 hoursNotify the Commission of a personal data breach likely to result in a risk to individuals' rights and freedoms within 72 hours of becoming aware of it, describing the nature of the breach and, where feasible, the categories and approximate numbers of data subjects and records concerned.
immediatelyNotify affected data subjects immediately after becoming aware of a breach likely to result in a high risk to their rights and freedoms.
Status since 2023-06-12Read from the corpus 2026-09-19
Norway Personal Data Act, Breach Notification in Norway (personopplysningsloven LOV-2018-06-15-38, breach notification provisions)
72 hoursNotify Datatilsynet without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Norway, unless the breach is unlikely to risk their rights and freedoms.
without undue delayNotify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Status since 2018-07-20Read from the corpus 2026-08-24
Qatar Personal Data Privacy Protection Law, breach notification (Law No. 13 of 2016, Arts. 13-14)
forthwithAn app that is a Processor handling the personal data of an individual in Qatar, including a voiceprint or faceprint, must forthwith notify its Controller of any breach or risk of one, and a Controller must inform the affected individual and the Competent Department where a breach of security precautions may cause serious damage to the data or the individual's privacy; the PDPPL states no fixed notification timeline.
Status since 2017-01-01Read from the corpus 2026-08-29
Serbia Law on Personal Data Protection, personal data breach notification (Law on Personal Data Protection, arts. 52-53 (personal data breach notification), Official Gazette RS No. 87/2018)
72 hours72 hoursNotify the Commissioner of a breach that may create risk to a person's rights and freedoms without undue delay, and within 72 hours of becoming aware of the breach where that is possible; give reasons for any delay beyond 72 hours.
without undue delayAs a processor, notify the controller without undue delay after becoming aware of a breach.
without undue delayNotify the affected person of a breach without undue delay, in clear language, whenever the breach may create high risk to their rights and freedoms.
Status since 2019-08-21Read from the corpus 2026-09-19
Russia Federal Law No. 152-FZ, Article 21 Part 3.1, Breach Notification (Federal Law No. 152-FZ, Art. 21, part 3.1, added by Federal Law No. 266-FZ (in force 1 September 2022))
24 hours72 hoursNotify Roskomnadzor within 24 hours of detecting an unlawful or accidental transfer, provision, distribution, or access to personal data of a person in Russia, and file a full follow-up report within 72 hours.
Status since 2022-09-01Read from the corpus 2026-08-24
Rwanda Law relating to the Protection of Personal Data and Privacy, personal data breach notification (Law N° 58/2021, arts. 43-45 (personal data breach notification))
48 hoursNotify the supervisory authority of the breach within 48 hours of becoming aware of it.
48 hoursAs a data processor, notify the data controller of the breach within 48 hours of becoming aware of it.
72 hoursSubmit a full report on the breach to the supervisory authority within 72 hours, describing its nature, the contact point for more information, the measures taken to address it, and your proposal and timeline for communicating it to affected data subjects.
Status since 2021-10-15Read from the corpus 2026-09-19
Saudi Arabia Personal Data Protection Law, breach notification (Royal Decree No. M/19, Art. 20)
upon knowingAn app that suffers a breach, damage, or illegal access affecting the personal data of an individual in Saudi Arabia must notify the Competent Authority upon knowing of the breach, and must separately notify the Data Subject where the breach would cause damage to their data or prejudice their rights and interests, following the Implementing Regulations' procedure.
Status since 2023-09-14Read from the corpus 2026-08-29
Seychelles Data Protection Act, 2023, personal data breach notification (Data Protection Act, 2023 (Act 24 of 2023), ss. 43-44 (notification and communication of a personal data breach))
72 hoursNotify the Information Commission of a personal data breach no later than 72 hours after becoming aware of it, giving reasons for any later notification.
promptlyPromptly inform the affected data subjects where a breach is likely to affect a significant number of individuals and their rights and freedoms.
Status since 2023-12-22Read from the corpus 2026-09-06
San Marino San Marino Law No. 171, personal data breach notification (Legge 21 dicembre 2018 n. 171, articoli 34-35 (violazione dei dati personali))
72 hoursNotify the Data Protection Authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in San Marino, under Article 34.
without undue delayCommunicate the breach to the affected data subject without undue delay where it is likely to result in a high risk to their rights and freedoms, in clear and plain language.
without undue delayAs a processor, notify the controller without undue delay after becoming aware of a personal data breach.
Status since 2018-12-21Read from the corpus 2026-09-19
Somalia Data Protection Act, 2023, personal data breach notification (Data Protection Act, Law No. 005 of 2023, arts. 25-27 (data breach notifications))
72 hoursNotify the Data Protection Authority of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals within 72 hours after becoming aware of it.
without undue delayCommunicate a breach likely to result in a high risk to a data subject to each affected data subject without undue delay, in plain and clear language, or through widely used media where direct communication would take disproportionate effort or expense.
Status in effectRead from the corpus 2026-09-19
Syria Law No. 12 of 2024 on Protection of Electronic Personal Data, personal data breach notification (Law No. 12 of 2024, art. 8 (personal data breach notification))
immediatelyNotify the Authority immediately on becoming aware of the breach, and expect the Authority to immediately notify the competent authorities where the breach concerns national security matters.
3 business daysTell the affected data subject what measures have been taken within three working days of the date you notified the Authority of the breach.
Status from 2025-01-01 [enacted, not yet in effect]Read from the corpus 2026-09-19
Eswatini Data Protection Act, 2022, notification of security compromises (Data Protection Act, 2022, s. 17 (notification of security compromises))
as soon as reasonably possibleNotify the Eswatini Communications Commission and the affected data subject as soon as reasonably possible after discovering that a data subject's personal information has been accessed or acquired by an unauthorised person, unless the data subject's identity cannot be established.
Status since 2022-03-04Read from the corpus 2026-09-19
Chad Loi n°007/PR/2015, obligation de notification des violations de données à l'ANSICE (Loi n°007/PR/2015 du 10 février 2015, art. 61)
without delayNotify both ANSICE and the affected data subject, without delay, of any security breach affecting that person's personal data.
Status since 2015-02-10Read from the corpus 2026-09-07
Tonga Privacy Act 2025, personal information breaches (Privacy Act 2025, s. 37 (personal information breaches))
72 hoursNotify the Privacy Commission within 72 hours of becoming aware of a personal information breach that is likely to result in a risk to the rights and freedoms of individuals, describing its nature and, where possible, the categories and approximate numbers of data subjects and records concerned.
72 hoursAs a data processor, notify the data controller or the data processor that engaged you within 72 hours of becoming aware of a personal information breach, and answer their information requests without undue delay.
without undue delayCommunicate a breach likely to result in a high risk to a data subject to that person without undue delay, in plain and clear language, with advice on how to mitigate the effects, or through widely used media where direct communication would take disproportionate effort or expense.
Status enacted, not yet in effectRead from the corpus 2026-09-19
Turkey Personal Data Protection Law (KVKK), breach notification (Law No. 6698, Art. 12(5))
within the shortest timeAn app that suffers unlawful acquisition of personal data belonging to a person in Turkey must notify the affected data subject and the Board within the shortest time; KVKK sets no fixed numeric deadline in its own text.
Status since 2016-04-07Read from the corpus 2026-08-29
Tanzania Personal Data Protection Act, 2022, security and breach notification (Personal Data Protection Act, 2022 (Act No. 11 of 2022), s. 27 (security of personal data))
without undue delayNotify the Personal Data Protection Commission without undue delay of any security breach affecting personal data you process.
Status since 2023-05-01Read from the corpus 2026-09-06
Ukraine Draft Law No. 8153, personal data breach notification (Draft Law No. 8153, 72 hour breach notification to the National Commission)
72 hoursOnce enacted, notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it.
Status [proposed]Read from the corpus 2026-09-19
Uganda Data Protection and Privacy Act, 2019, breach notification (Data Protection and Privacy Act, 2019, s. 23 (breach notification))
immediatelyNotify the National Information Technology Authority immediately after you believe personal data has been accessed or acquired by an unauthorised person, describing the access or acquisition and the remedial action taken.
Status since 2019-05-03Read from the corpus 2026-09-19
Samoa National Digital Identification Act 2024, personal data breach notification (National Digital Identification Act 2024, No. 3 (Samoa), ss. 47-50 (personal data breach notification))
72 hoursAs a relying party or data processor in the National Digital Identification System, notify the Registrar General of a personal data breach within 72 hours of becoming aware of it, describing the categories and approximate number of records concerned.
without undue delayWhere a personal data breach is likely to result in a high risk to a registered person's rights, ensure the Registrar General can communicate the breach to that person without undue delay, in plain language, with advice on mitigating measures.
Status since 2024-02-05Read from the corpus 2026-09-07
Kosovo Law No. 06/L-082 on Protection of Personal Data, personal data breach notification (Law No. 06/L-082 on Protection of Personal Data, arts. 33-34 (personal data breach notification))
72 hoursNotify the Agency for Information and Privacy of a personal data breach without delay and, where feasible, no later than seventy-two hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
72 hoursGive reasons for the delay if notifying the Agency after that seventy-two-hour period.
without undue delayAs a data processor, notify the data controller without undue delay after becoming aware of a personal data breach.
without undue delayCommunicate a personal data breach to the affected data subject without undue delay where the breach is likely to result in a high risk to their rights and freedoms, unless an Article 34(3) exception applies.
Status since 2019-03-12Read from the corpus 2026-09-19
South Africa Protection of Personal Information Act, notification of security compromises (POPIA, s. 22 (notification of security compromises))
as soon as reasonably possibleNotify the Information Regulator of a security compromise as soon as reasonably possible after discovering that personal information has been accessed or acquired by an unauthorised person; the Act sets no fixed hour or day limit, only this standard.
as soon as reasonably possibleNotify the affected data subject of the same security compromise as soon as reasonably possible after discovery, in writing, unless a law-enforcement body or the Regulator determines that notifying would impede a criminal investigation, or the data subject's identity cannot be established.
immediatelyAs an operator, notify the responsible party immediately once you have reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.
Status since 2020-07-01Read from the corpus 2026-09-19
Zambia Data Protection Act, 2021, notification of a security breach (Data Protection Act, 2021, s. 49 (notification of a security breach))
24 hoursNotify the Data Protection Commissioner within 24 hours of the breach occurring: section 49(1) runs the period from the security breach itself, not from the moment you learn of it.
as soon as practicableNotify the affected data subject as soon as practicable of any security breach affecting their personal data.
as soon as practicableAs a data processor, notify the data controller as soon as practicable of any security breach affecting personal data you process on its behalf.
Status since 2021-04-01Read from the corpus 2026-09-19
Zimbabwe Cyber and Data Protection Act, security breach notification (Cyber and Data Protection Act, No. 5 of 2021, s. 19 (security breach notification))
24 hoursNotify the Data Protection Authority within 24 hours of discovering a security breach affecting personal data you process.
Status since 2022-03-11Read from the corpus 2026-09-19
Zimbabwe Cyber and Data Protection Regulations 2024, security breach notification (Statutory Instrument 155 of 2024, regulation 17 (security breach notification))
24 hoursReport a personal data breach to the Authority within 24 hours of becoming aware of it, on Form DP3 in the Fourth Schedule.
72 hoursInform the affected data subjects within 72 hours of the breach where it is likely to result in a high risk of adversely affecting individuals' rights and freedoms.
21 daysFinish the data breach investigation and submit your report within 21 days from the date of notification.
Status since 2024-09-13Read from the corpus 2026-09-19

4AI law, high-risk systems: serious-incident reporting, by jurisdiction

3 instruments in 3 jurisdictions in the corpus's AI topic under its risk-obligations family state a reporting deadline, as of 2026-09-21: 1 a numeric clock, and 2 a standard such as "immediately" or "without undue delay" with no number. The duty here turns on a high-risk classification, and it binds the MAKER of the system, with a separate and shorter duty on the OPERATOR that identifies the incident first. Only the AI Act states its periods in the duty itself. The rest of this family states no reporting deadline: bills, vetoed acts and framework laws that leave the period to an implementing act or to a legislature that has not passed them, and duties on a high-risk system that are not about reporting an incident at all.

32 more instruments in this family state no deadline in their obligation lines and are not listed here; the AI law section has them.

European Union Show the 1 provisionHide the 1 provision
JurisdictionInstrument, and the obligation lines that carry a clock
European Union AI Act, Article 73 (reporting of serious incidents) (Regulation (EU) 2024/1689, Article 73)
15 daysReport a serious incident not later than 15 days after you become aware of it, or immediately once you establish a causal link between your AI system and the incident, or the reasonable likelihood of one, whichever is sooner.
2 daysReport immediately, and not later than 2 days after becoming aware of it, a widespread infringement or a serious incident causing a serious and irreversible disruption to the management or operation of critical infrastructure.
10 daysReport a serious incident involving the death of a person not later than 10 days after becoming aware of it, and immediately once you establish, or suspect, a causal link between your AI system and the incident.
immediatelyIf you are a deployer of a high-risk AI system and identify a serious incident, immediately inform first the provider, then the importer or distributor, and the relevant market surveillance authority; if you cannot reach the provider, report the incident yourself under the same rules that bind a provider.
without delayAfter reporting a serious incident, without delay investigate it, including a risk assessment and corrective action, and cooperate with the competent authorities; do not alter the AI system in a way that could affect the investigation before telling the authorities.
Status since 2026-08-02Read from the corpus 2026-09-18
Asia and the Pacific Show the 2 provisionsHide the 2 provisions
JurisdictionInstrument, and the obligation lines that carry a clock
Kyrgyzstan Digital Code, Chapter 23: AI system design and risk-management obligations (Digital Code, Law No. 178 (18 June 2025), in force 6 February 2026, Chapter 23, Arts. 191-196)
immediatelyA user of such a heightened-risk system must operate it per its instructions, keep the data it processes relevant, maintain effective human oversight and resourcing, immediately suspend use and notify the owner once it has grounds to believe use as instructed could cause harm to a protected interest, keep operating logs, and comply with a regulator's suspension order or a final court order to stop using the system.
Status since 2026-02-06Read from the corpus 2026-09-20
Vietnam Law on Artificial Intelligence, incident management and reporting obligation (Law No. 134/2025/QH15, art. 12)
promptlyIf a serious incident occurs in your AI system and you are its deployer or user, record the incident, notify it promptly, and coordinate with the other parties during the remediation process.
Status since 2026-03-01Read from the corpus 2026-09-20

5AI law, frontier models: safety-incident reporting, by jurisdiction

4 instruments in 4 jurisdictions in the corpus's AI topic under its governance family state a reporting deadline, as of 2026-09-21: 3 a numeric clock, and 1 a standard such as "immediately" or "without undue delay" with no number. These do not turn on a high-risk classification. They bind the MAKER of a frontier model, reached by a compute or capability threshold, and the report goes to a state agency rather than to a market surveillance authority: California's Office of Emergency Services, New York's Attorney General. Both of those are in force. This family is named for governance rather than for incidents, so a rung is drawn here only where the sentence names the event that starts it: an audit remediation report and a content-complaint status update are periods in this family, neither is started by an incident, and neither is listed.

38 more instruments in this family state no deadline in their obligation lines and are not listed here; the AI law section has them.

European Union Show the 1 provisionHide the 1 provision
JurisdictionInstrument, and the obligation lines that carry a clock
European Union AI Act, Article 55 (obligations for providers of general-purpose AI models with systemic risk) (Regulation (EU) 2024/1689, Article 55)
without undue delayKeep track of, document, and report to the AI Office, and as appropriate to national competent authorities, without undue delay, relevant information about serious incidents involving your model and any corrective measures you have taken or plan to take. The Regulation states no fixed number of days for this report and no explicit moment its clock starts from, only that it must be made without undue delay.
Status since 2025-08-02Read from the corpus 2026-09-20
United States, states Show the 3 provisionsHide the 3 provisions
JurisdictionInstrument, and the obligation lines that carry a clock
California Transparency in Frontier Artificial Intelligence Act (SB 53) (Cal. Bus. and Prof. Code Sections 22757.10 to 22757.16)
15 days24 hoursReport a critical safety incident to the Office of Emergency Services within 15 days of discovering it, or within 24 hours if it poses an imminent risk of death or serious injury
Status since 2026-01-01Read from the corpus 2026-09-08
Illinois Artificial Intelligence Safety Measures Act (P.A. 104-0538 (SB 315, 104th Gen. Assembly), enacting a new Act and amending 5 ILCS 140/7.5 and 740 ILCS 174/15)
72 hoursReport a critical safety incident to the Agency, the Illinois Emergency Management Agency and Office of Homeland Security, and to the Attorney General within 72 hours of learning facts sufficient to establish a reasonable belief that a critical safety incident has occurred.
24 hoursWithin 24 hours of discovering that a critical safety incident poses an imminent risk of death or serious physical injury, disclose it to an appropriate authority, including a law enforcement or public safety agency with jurisdiction over it.
Status from 2027-01-01 [enacted, not yet in effect]Read from the corpus 2026-09-20
New York Responsible AI Safety and Education Act (RAISE Act) (N.Y. Gen. Bus. Law art. 44-B (§§ 1420-1425), ch. 699 of 2025)
72 hoursDisclose each safety incident affecting a frontier model to the Attorney General within 72 hours of learning of it.
Status since 2026-03-19Read from the corpus 2026-09-15
What it means for an agent

Every clock here runs from a moment the reporting party has to establish and evidence: awareness, detection, a materiality finding, a corrective measure. An AGENT that keeps the record of what it did, when, and on whose instruction gives its OPERATOR the thing every report on this page is built from, and the The 6 parties document says which party that is in each arrangement.