Law / Frameworks / NIST Privacy Framework / Communicate-P
NIST Privacy Framework, Communicate-PCM.AW-P7
Impacted individuals and organizations are notified about a privacy breach or event.NIST Privacy Framework, version 1.0, January 2020, CM.AW-P7
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 185
- laws
- 176
- places
- 0
- with court rulings behind them
- 37
- not yet in force
- 4
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 4.3 Organizational practices are in place to enable AI testing, identification of...
- NIST AI RMFMANAGE 4.1 Post-deployment AI system monitoring plans are implemented, including mechanisms for...
- NIST AI 600-1GAI-RISK-09 Information Security
- NIST AI 600-1GAI-RISK-04 Data Privacy
- MIT mitigations4.3 Incident Reporting
- MIT mitigations3.6 Incident Response & Recovery
- NIST CSF 2.0ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are...
- NIST CSF 2.0RS.CO-02 Internal and external stakeholders are notified of incidents
A law in force is unmarked; the rest wear their state: not yet in force proposed
Breach notification
177 laws, 173 places| Place | Law | What it asks, as read here |
|---|---|---|
| Alabama Data Breach Notification Act of 2018 from a date not yet set |
Notify the Alabama Attorney General of a breach involving unauthorized acquisition of sensitive personally identifying information that is reasonably likely to cause substantial harm to affected individuals. |
|
| Alaska Personal Information Protection Act, breach notification duty from a date not yet set |
Disclose a breach of the security of an information system containing an Alaska resident's personal information to each affected resident in the most expeditious time possible and without unreasonable delay. |
|
| Law No. 124/2024, notification of a personal data breach |
Notify the Commissioner of a personal data breach as soon as possible and no later than 72 hours of becoming aware of the breach, unless the breach is unlikely to endanger the rights and freedoms of data subjects, and give the Commissioner your reasons for any later notification. As a processor, notify the controller immediately after becoming aware of any personal data breach. +2 more |
|
| Loi n° 18-07 relative à la protection des personnes physiques, notification des violations de données |
As a service provider, that is any public or private entity offering users the ability to communicate over a computer or telecommunications system, or any entity processing or storing data for that communication service, notify the ANPDP without delay of a personal-data breach occurring on a public electronic communications network. Notify the affected individual without delay of that same breach where it may harm their private life, unless the ANPDP finds you had already implemented appropriate protective measures. +3 more |
|
| LQPD, personal data breach notification |
Notify the Andorran Data Protection Agency of a personal data breach without undue delay and, where possible, within seventy-two hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Justify the reasons for the delay if notifying the Agency after that seventy-two-hour period. +3 more |
|
| Arizona data breach notification law from a date not yet set |
Notify each affected Arizona resident of a breach of system security involving their personal information without unreasonable delay and no later than 45 days after determining the breach occurred. Notify the Arizona Attorney General, the director of the Arizona Department of Homeland Security, and the three largest nationwide consumer reporting agencies if the breach affects more than 1,000 individuals. |
|
| Arkansas Personal Information Protection Act, breach notification and security from a date not yet set |
Notify each affected Arkansas resident of a breach of security without unreasonable delay. Notify the Arkansas Attorney General if the breach affects more than 1,000 individuals, at the same time as consumer notice or within 45 days of determining a reasonable likelihood of harm, whichever occurs first. |
|
| Privacy Act 1988 (Cth), Notifiable Data Breaches Scheme |
Prepare a statement about an eligible data breach and give a copy to the Information Commissioner as soon as practicable after becoming aware of reasonable grounds to believe the breach happened. Notify the contents of that statement to each individual to whom the relevant information relates, or to each individual at risk, or, if neither is practicable, publish the statement on the entity's website and take reasonable steps to publicise it. |
|
| GDPR Articles 33-34, Breach Notification in Austria |
Notify the Datenschutzbehorde without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Austria, unless the breach is unlikely to risk their rights and freedoms. Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms. |
|
| Personal Data Protection Act, 2026, breach notification duties |
An app that suffers a personal data breach in Bangladesh, including one involving a biometric identifier, must notify the Authority in the form, manner and time a regulation prescribes whenever the breach creates a possibility of significant harm to an affected data principal; no separate statutory duty to notify the affected individual directly was found. |
Show the other 167 laws
| Data Protection Act, 2019, personal data breach notification |
Notify a personal data breach to the Data Protection Commissioner without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of an individual, and give reasons for the delay if you notify later. Communicate a personal data breach likely to result in a high risk to the rights and freedoms of individuals to the affected data subject, in clear and plain language, without undue delay and, where feasible, not later than 72 hours after becoming aware of it. +2 more |
|
| Law of the Republic of Belarus On Personal Data Protection, notification of personal data protection violations |
Notify the National Center for Personal Data Protection immediately, and in any case no later than three working days after becoming aware of a violation of your personal data protection systems, under Article 16, unless the Center itself provides otherwise. |
|
| GDPR Articles 33-34, Breach Notification |
Notify the GBA/APD within 72 hours of becoming aware of a personal-data breach affecting a person in Belgium, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them. |
|
| Data Protection Act 2021, personal data breach notification from a date not yet set |
Where feasible, notify the Data Protection Commissioner of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to risk a person's rights and freedoms. Where a personal data breach is likely to result in a high risk to a person's rights and freedoms, notify that person without undue delay. |
|
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, notification des ruptures de sécurité |
Notify the Autorité de Protection des Données Personnelles (APDP) and the affected person without delay of any security breach that has affected their personal data. As a processor, warn the controller without delay of any security breach affecting personal data you process on the controller's behalf. +1 more |
|
| Personal Information Protection Act 2016, breach of security notification |
Notify the Privacy Commissioner, then any affected individual, without undue delay of a breach of security that is likely to adversely affect an individual. Describe in the Commissioner notification the nature of the breach, its likely consequences, and the measures taken and to be taken to address it. |
|
| Law on the Protection of Personal Data of Bosnia and Herzegovina, personal data breach notification |
Notify the Agency of a personal data breach without undue delay and, if possible, within 72 hours of becoming aware of the breach, giving the Agency the reasons for the delay where notice comes later. As a processor, notify the controller without undue delay after becoming aware of a personal data breach. +3 more |
|
| Data Protection Act, 2024, personal data breach notification |
Notify the Information and Data Protection Commission of a personal-data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the affected person's rights and freedoms, and give reasons for any later notification. As a data processor, notify the data controller of a personal-data breach without undue delay after becoming aware of it. +1 more |
|
| LGPD, security incident notification |
Notify the ANPD and the affected data subjects of a security incident that may create relevant risk or harm to data subjects, within the reasonable period the ANPD sets by regulation, and state the reasons for the delay when the notice is not immediate. Describe in the notification the nature of the personal data affected, the data subjects involved, the technical and security measures used, the risks related to the incident, and the measures taken or planned to reverse or mitigate its effects. |
|
| Personal Data Protection Order 2025, breach notification |
Brunei's Personal Data Protection Order 2025 has required, since this duty (Part 7) took effect under Government Gazette No. S 11/2025, an organisation to notify the Authority within 3 days of assessing that a breach is notifiable, meaning it is likely to cause significant harm or is of significant scale, and to notify each affected individual, for a breach involving any personal data including a voiceprint or faceprint. |
|
| GDPR Articles 33-34, Breach Notification |
Notify KZLD within 72 hours of becoming aware of a personal-data breach affecting a person in Bulgaria, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them, using KZLD's own Bulgarian-language notification template. |
|
| California Data Breach Notification Law, as amended by SB 446 |
Notify affected California residents of a breach of their unencrypted personal information within 30 calendar days of discovery or notification. Notify the California Attorney General within 15 days of consumer notification when a breach affects more than 500 California residents. |
|
| Cambodia's Draft Law on Personal Data Protection, personal data breach notification proposed |
If enacted as drafted, a data controller would have to notify the Ministry of Post and Telecommunications immediately, but no later than 72 hours of becoming aware of a personal data breach that may pose a risk to the data subject or another natural person, or give the Ministry valid reasons for any delay. If enacted as drafted, a data controller would have to notify the affected data subject immediately upon becoming aware of a personal data breach that may pose a high risk to their rights and freedoms, unless the controller had already secured the data, had taken steps removing the high risk, or individual notice would be disproportionately burdensome, in which case a public notice would serve instead. |
|
| PIPEDA breach of security safeguards regime |
Report any breach of security safeguards involving personal information under the organization's control to the Privacy Commissioner as soon as feasible, if it is reasonable to believe the breach creates a real risk of significant harm to an individual. Notify each affected individual directly, in a conspicuous form, with enough information to let them understand the significance of the breach and take steps to reduce or mitigate the resulting harm. |
|
| Data Protection Act 2021 Revision, personal data breach notification |
Notify the Ombudsman and each affected data subject of a personal data breach without undue delay and no later than five days after becoming aware of it, describing the breach, its consequences, and the measures taken or recommended. |
|
| Loi n°007/PR/2015, obligation de notification des violations de données à l'ANSICE |
Notify both ANSICE and the affected data subject, without delay, of any security breach affecting that person's personal data. |
|
| Personal Information Protection Law, Data Breach Notification |
Upon discovering an actual or possible leak, alteration, or loss of personal information, immediately take remedial measures and notify both the competent personal information protection department and every affected individual, unless the remedial measures can be shown to effectively prevent harm. Include in any breach notice the categories of information involved, the cause, possible harm, remedial steps taken, what affected individuals can do to protect themselves, and the handler's contact information. |
|
| Ley 1581 de 2012, Security Breach Notification to the Authority |
Notify the Superintendencia de Industria y Comercio when a violation of the security codes occurs and creates a risk in the administration of a data subject's personal information; the law fixes no deadline for this notice. As a data processor, notify the Superintendencia de Industria y Comercio under the same terms when a security code violation creates that risk; neither duty requires telling the affected data subject directly. |
|
| C.R.S. 6-1-716, Notification of Security Breach |
If you experience unauthorized acquisition of unencrypted computerized personal information of Colorado residents, notify affected residents without unreasonable delay and within 30 days of determining a breach occurred. Notify the Colorado Attorney General if 500 or more residents are affected, and nationwide consumer reporting agencies if more than 1,000 are affected. |
|
| Breach of security re computerized data containing personal information from a date not yet set |
Notify each affected Connecticut resident of a breach of security involving personal information without unreasonable delay and no later than 60 days after discovery, unless federal law requires a shorter time. |
|
| GDPR Articles 33-34, Breach Notification |
Notify AZOP within 72 hours of becoming aware of a personal-data breach affecting a person in Croatia, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them. |
|
| GDPR Articles 33-34, Breach Notification in Cyprus |
Notify the ODPC without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Cyprus, unless the breach is unlikely to risk their rights and freedoms. Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms. |
|
| GDPR Articles 33-34, Breach Notification |
Notify UOOU within 72 hours of becoming aware of a personal-data breach affecting a person in the Czech Republic, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them. |
|
| Computer Security Breaches from a date not yet set |
Notify affected Delaware residents of a breach of security without unreasonable delay and no later than 60 days after determining the breach occurred. Notify the Delaware Attorney General, by the time you notify residents, if the breach affects more than 500 Delaware residents. |
|
| Digital Code, Title III, personal data breach notification |
Notify the Data Protection Authority and the affected data subject without delay of any breach affecting personal data, describing the nature of the breach, the categories and approximate number of affected people and records where possible, a contact point, the likely consequences, and the measures taken or proposed to address it. As a processor, warn the controller without delay of any breach of security affecting personal data you process on the controller's behalf. +1 more |
|
| GDPR Articles 33-34, Breach Notification in Denmark |
Notify Datatilsynet without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Denmark, unless the breach is unlikely to risk their rights and freedoms. Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms. |
|
| Consumer Security Breach Notification |
If your business conducts business in the District of Columbia and discovers a breach of the security of a system containing a District resident's personal information, notify each affected resident in the most expedient time possible and without unreasonable delay. If the breach affects 50 or more District residents, also give written notice to the Office of the Attorney General for the District of Columbia, no later than when you notify residents. +1 more |
|
| Digital Code, Book I: personal-data breach notification |
Notify the Commission Nationale de Protection des Données à Caractère Personnel of a personal-data breach without undue delay and, at the latest, within 72 hours of becoming aware of it, stating the reasons for any delay beyond that window. Tell the affected individual of the breach without undue delay, in clear and simple terms, where it is likely to result in a high risk to their rights and freedoms. +2 more |
|
| LOPDP, notificación de vulneración de seguridad |
Notify the Authority and the telecommunications regulator of a personal-data security breach as soon as possible and no later than five days after becoming aware of it. Notify the affected data subject within 3 days of learning of the risk, where the breach carries a risk to their fundamental rights and individual freedoms. +3 more |
|
| Egypt Personal Data Protection Law, Personal Data Infringement notification |
Notify the Personal Data Protection Center of any personal data breach within 72 hours of discovering it, and notify immediately where the breach concerns national security. Notify the Data Subject within 3 days of the date you notified the Center, telling them of the infringement and the procedures you have adopted about it. +1 more |
|
| Ley para la Protección de Datos Personales, personal data breach notification |
Notify the Agencia de Ciberseguridad del Estado, the Fiscalia General de la Republica, and every affected data subject of a personal data breach within seventy two hours of becoming aware of it. Tell the Agencia de Ciberseguridad del Estado, in clear and simple language, the incident's nature, the personal data compromised, the immediate corrective actions taken, recommendations for the data subject, and where to learn more, and give the affected data subject the incident's nature, the data compromised, the recommendations, and where to learn more. |
|
| GDPR Articles 33-34, Breach Notification in Estonia |
Notify the Estonian Data Protection Inspectorate without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Estonia, unless the breach is unlikely to risk their rights and freedoms. Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms. |
|
| Data Protection Act, 2022, notification of security compromises |
Notify the Eswatini Communications Commission and the affected data subject as soon as reasonably possible after discovering that a data subject's personal information has been accessed or acquired by an unauthorised person, unless the data subject's identity cannot be established. Take into account the legitimate needs of law enforcement and any measures reasonably necessary to determine the scope of the compromise when timing your notification, but do not use that as a reason to delay beyond what is reasonably possible. +2 more |
|
| Personal Data Protection Proclamation, personal data breach notification |
Notify the Authority of a personal data breach within 72 hours of becoming aware of it, giving reasons for any delay. Communicate a personal data breach to the affected data subject within 72 hours of becoming aware of it, in clear language, describing the likely consequences, the contact point for more information and the measures taken to address it. +2 more |
|
| GDPR Articles 33-34, Breach Notification |
Notify the competent supervisory authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting EU personal data, unless the breach is unlikely to risk individuals' rights and freedoms. Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms. |
|
| GDPR Articles 33-34, Breach Notification in Finland |
Notify the Data Protection Ombudsman without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Finland, unless the breach is unlikely to risk their rights and freedoms. Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms. |
|
| Florida Information Protection Act, breach notification from a date not yet set |
Notify the Florida Department of Legal Affairs of a breach of security affecting 500 or more individuals in Florida as expeditiously as practicable, and no later than 30 days after determining a breach occurred or having reason to believe one occurred. Notify each affected Florida individual of a breach no later than 30 days after determining a breach occurred, unless you obtain a written 15-day extension for good cause. |
|
| GDPR Articles 33-34, Breach Notification |
Notify the CNIL within 72 hours of becoming aware of a personal-data breach affecting a person in France, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them. |
|
| Law No. 025/2023, personal-data breach notification |
Notify the APDPVP without delay of a personal-data breach, describing its nature, the categories and approximate number of data subjects and records concerned where possible, the data protection officer's or another contact point's details, the likely consequences, and the measures taken or proposed to address it; the law sets no numeric deadline for this notice. Accompany a notification to the APDPVP with supporting evidence of the breach. +2 more |
|
| Personal Data Protection and Privacy Act, 2025, personal data breach notification from a date not yet set |
Notify the Information Commission of a personal data breach within 72 hours of becoming aware of the breach. Notify each affected data subject of a personal data breach without undue delay where the breach carries a high risk to their rights. |
|
| Georgia Personal Identity Protection Act, notification of security breach from a date not yet set |
Give notice of a breach of the security of a system containing a Georgia resident's personal information in the most expedient time possible and without unreasonable delay. Notify the information broker or data collector you maintain data for, of any breach you discover, so that party can meet its own notice duty. +1 more |
|
| Law on Personal Data Protection, breach notification |
An app that suffers an incident affecting the personal data of a person in Georgia must notify the State Audit Office within 72 hours of identification, and must notify affected data subjects immediately or without unreasonable delay where there is a high probability of significant damage or a significant threat to their fundamental rights. |
|
| GDPR Articles 33-34, Breach Notification in Germany |
Notify the competent German data protection authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Germany, unless the breach is unlikely to risk their rights and freedoms. Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms. |
|
| Data Protection Act, notification of security compromises |
Notify the Data Protection Commission and the affected data subject as soon as reasonably practicable after you have reasonable grounds to believe personal data has been accessed or acquired by an unauthorised person. Give the data subject enough information in the notification to take protective measures against the consequences of the breach, including the identity of the unauthorised person if known, and communicate it by registered mail, electronic mail, the website, media publication, or another manner the Commission directs. |
|
| GDPR Articles 33-34, Breach Notification in Greece |
Notify the Hellenic Data Protection Authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Greece, unless the breach is unlikely to risk their rights and freedoms. Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms. |
|
| Notification of Breaches of Personal Information |
Disclose a breach of the security of your system to any affected Guam resident without unreasonable delay once you know or reasonably believe the breach caused or will cause identity theft or other fraud. If you hold a Guam resident's computerized personal information for another owner or licensee rather than for yourself, notify that owner or licensee as soon as practicable after discovering a breach. |
|
| Hawaii Security Breach of Personal Information Act, notice of security breach from a date not yet set |
Provide clear and conspicuous notice, without unreasonable delay, to a Hawaii resident affected by a security breach of a system containing their personal information, describing the incident, the type of information exposed, and remedial steps taken. Notify the State of Hawaii's Office of Consumer Protection and nationwide consumer reporting agencies if the breach requires notifying more than 1,000 persons at one time. |
|
| Infotörvény Sections 25/J-25/K, Breach Notification, Inserted by Act XXXVIII of 2018 |
Notify NAIH without delay, and no later than 72 hours after becoming aware of it, of a personal-data breach affecting a person in Hungary, per Infotorveny Section 25/J(1). |
|
| Act No. 90/2018, Breach Notification in Iceland |
Notify Personuvernd without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Iceland, unless the breach is unlikely to risk their rights and freedoms. Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms. |
|
| Identity Theft Act, breach of security disclosure duty from a date not yet set |
Give notice to each affected Idaho resident as soon as possible, and in the most expedient time possible without unreasonable delay, after discovering a breach of system security involving personal information. |
|
| Personal Information Protection Act, data breach notification |
Notify affected Illinois residents of a data breach in the most expedient time possible and without unreasonable delay after discovering unauthorized acquisition of their computerized personal information, which includes unique biometric data used to authenticate an individual. Notify the Illinois Attorney General once a single breach affects more than 500 Illinois residents, or more than 250 residents for a State agency. |
|
| Digital Personal Data Protection Act, 2023, breach notification duties from , in 7 months |
India's data-breach notification duty, covering personal data including a biometric identifier, has not yet commenced and is scheduled to take effect . Once in force, an app must notify the Data Protection Board and each affected data principal of a personal data breach without delay, and must supply the Board a detailed follow-up report within 72 hours of becoming aware of the breach. |
|
| Disclosure of Security Breach Act from a date not yet set |
Disclose a breach to affected Indiana residents without unreasonable delay and no later than 45 days after discovering that the unauthorized acquisition has resulted in or could result in identity deception, identity theft, or fraud. Notify the Indiana Attorney General of any breach disclosure, and notify each nationwide consumer reporting agency if the breach affects more than 1,000 Indiana consumers. |
|
| Law on Personal Data Protection, breach notification |
An app that suffers a failure of personal data protection affecting an individual in Indonesia must give written notification within 72 hours to the affected individual and to the supervisory institution, describing the data disclosed and the remedial measures taken. |
|
| Personal Information Security Breach Protection from a date not yet set |
Notify affected Iowa residents of a breach of security in the most expeditious manner possible and without unreasonable delay. Notify the Iowa Attorney General's consumer protection division within five business days of notifying consumers, if the breach requires notifying more than 500 Iowa residents. |
|
| GDPR Articles 33-34, Breach Notification in Ireland |
Notify the Data Protection Commission without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Ireland, unless the breach is unlikely to risk their rights and freedoms. Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms. |
|
| Protection of Privacy Law, breach notification duty |
An app that suffers a severe security incident affecting the personal data of a person in Israel must immediately notify the Head of the Privacy Protection Authority under the Data Security Regulations' Art. 11(d)(1) duty; the regulations' own text, including any data-subject notification duty, is not set out here and should be confirmed directly before relying on it for full compliance detail. |
|
| GDPR Articles 33-34, Breach Notification |
Notify the Garante within 72 hours of becoming aware of a personal-data breach affecting a person in Italy, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them. |
|
| Data Protection Act, 2020, reporting a contravention or security breach |
Report any security breach in respect of your operations which affects or may affect personal data, and any contravention of the data protection standards, to the Information Commissioner within 72 hours of becoming aware of the breach or contravention, in the prescribed form and manner. Notify the Information Commissioner without undue delay of any breach of your security measures which affects or may affect personal data. +2 more |
|
| Act on the Protection of Personal Information, breach notification |
An app that suffers a leak, loss, or damage of personal data belonging to a person in Japan must report the incident to the Personal Information Protection Commission where it is likely to harm the data subject's rights and interests, following PPC-prescribed procedure and timing. |
|
| Personal Data Protection Law, breach notification |
An app that suffers a serious breach of data security or safety that could cause significant harm to an individual in Jordan must notify the affected individuals within 24 hours of discovery and must notify the Unit within 72 hours of discovery with the source, mechanism, and affected individuals; a Controller found grossly negligent or engaged in misconduct in a breach is liable to compensate the affected Data Subject. |
|
| Kansas Breach Notification Act, notice of security breach from a date not yet set |
Give notice to each affected Kansas resident as soon as possible, in the most expedient time possible and without unreasonable delay, if the investigation shows misuse occurred or is reasonably likely. There is no fixed numeric deadline in the statute; do not rely on a 45-day figure some secondary sources describe. Notify each nationwide consumer reporting agency if more than 1,000 Kansas consumers are affected by one breach. |
|
| Student Data Privacy Act, breach notice for student data from a date not yet set |
Immediately notify the affected Kansas student, or the student's parent or guardian, of a breach or unauthorized disclosure of student data if your entity has access to that data. |
|
| Law on Personal Data and Their Protection, breach notification |
An app that suffers a personal data security breach involving Kazakhstani data subjects must notify the competent authority from the moment the breach is detected. The Law sets no numeric deadline for that notice and, on the text read, imposes no separate duty to notify the affected individuals themselves. |
|
| Notification to affected persons of computer security breach |
Notify an affected Kentucky resident of a breach involving unencrypted personal information in the most expedient time possible and without unreasonable delay. Notify each nationwide consumer reporting agency if more than 1,000 persons are affected at one time. |
|
| Data Protection Act, 2019, personal data breach notification |
Notify the Data Commissioner within seventy-two hours of becoming aware of a personal data breach that carries a real risk of harm, giving reasons if you notify later. As a data processor, notify the data controller within forty-eight hours of becoming aware of a breach. +1 more |
|
| Data Protection Act 2025, personal data breaches from a date not yet set |
On commencement, notify the Digital Transformation Office of a personal data breach that has resulted in, or is likely to result in, significant harm to affected data subjects, as soon as practicable after becoming aware of the breach. On commencement, notify each affected data subject of that same harmful personal data breach as soon as practicable after becoming aware of the breach, or by public notification through widely used media where direct notification is not feasible or would involve disproportionate effort or expense. +2 more |
|
| Law No. 06/L-082 on Protection of Personal Data, personal data breach notification |
Notify the Agency for Information and Privacy of a personal data breach without delay and, where feasible, no later than seventy-two hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Give reasons for the delay if notifying the Agency after that seventy-two-hour period. +3 more |
|
| GDPR Articles 33-34, Breach Notification in Latvia |
Notify the Data State Inspectorate without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Latvia, unless the breach is unlikely to risk their rights and freedoms. Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms. |
|
| Data Protection Act, 2011, notification of security compromises |
Notify the Data Protection Commission and the affected data subject as soon as reasonably possible after discovering that a data subject's personal information has been accessed or acquired by an unauthorised person, unless the data subject's identity cannot be established. Take into account the legitimate needs of law enforcement and any measures reasonably necessary to determine the scope of the compromise when timing your notification, but do not use that as a reason to delay beyond what is reasonably possible. +2 more |
|
| DSG Breach Notification in Liechtenstein |
Notify the Datenschutzstelle without undue delay after becoming aware of a personal data breach affecting a person in Liechtenstein that presents a risk to their rights and freedoms, under the DSG. Notify affected individuals where a breach presents a high risk to their rights and freedoms. |
|
| GDPR Articles 33-34, Breach Notification in Lithuania |
Notify VDAI without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Lithuania, unless the breach is unlikely to risk their rights and freedoms. Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms. |
|
| Database Security Breach Notification Law, notice duty |
Notify each affected Louisiana resident of a breach involving personal information in the most expedient time possible and without unreasonable delay, no later than 60 days after discovery. If you delay notice, give the Attorney General written reasons for the delay. |
|
| GDPR Articles 33-34, Breach Notification in Luxembourg |
Notify the CNPD without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Luxembourg, unless the breach is unlikely to risk their rights and freedoms. Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms. |
|
| Notice of Risk to Personal Data from a date not yet set |
Notify affected Maine residents of a breach of security as expediently as possible and without unreasonable delay, no more than 30 days after becoming aware of the breach and identifying its scope, absent a law enforcement delay. Notify the appropriate Department of Professional and Financial Regulation regulator, or the Attorney General if you are not regulated by that department. |
|
| Personal Data Protection Act, data protection officer and breach notification |
An app that controls or processes the personal data of individuals in Malaysia must appoint a Data Protection Officer, and a data controller who reasonably believes a personal data breach has occurred must notify the Commissioner as soon as practicable, and must notify affected data subjects without unnecessary delay where the breach causes or is likely to cause significant harm. |
|
| Maldives Personal Data Protection Bill, personal data breach notification proposed |
If enacted as drafted, a Controller would have to notify the Data Protection Authority within 72 hours of coming to know of, or reasonably believing in, a personal data breach involving special categories of personal data or data that could enable identity theft or fraud. If enacted as drafted, the same section would require the affected data subjects to be told, on the same seventy-two-hour period and on the same trigger. |
|
| GDPR Articles 33-34, Breach Notification in Malta |
Notify the IDPC without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Malta, unless the breach is unlikely to risk their rights and freedoms. Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms. |
|
| Maryland Personal Information Protection Act (MPIPA), breach notification from a date not yet set |
Notify each affected Maryland individual as soon as reasonably practicable, and no later than 45 days after discovering or being notified of the breach, once you determine a likelihood that personal information has been or will be misused. Where notification is delayed because a law enforcement agency says it would impede an investigation, notify within 7 days after that delay is cleared, or by the original 45-day deadline, whichever is later. |
|
| Security Breach statute, duty to report breach of personal information from a date not yet set |
Notify the Massachusetts Attorney General, the Director of Consumer Affairs and Business Regulation, and each affected Massachusetts resident as soon as practicable and without unreasonable delay after learning of a breach of security involving personal information. |
|
| Data Protection Act 2017, personal data breach notification |
Notify the Data Protection Commissioner without undue delay, and where feasible within 72 hours, of becoming aware of a personal data breach, giving reasons if notification is later. Communicate a personal data breach to the affected data subject without undue delay where it is likely to result in a high risk to their rights and freedoms, unless an exception in section 26(3) applies. |
|
| Ley Federal de Protección de Datos Personales en Posesión de los Particulares, security-breach notice |
Notify the affected data subject immediately of the breach, occurring at any stage of processing personal data, that significantly affects their patrimonial or moral rights. |
|
| Identity Theft Protection Act, breach of security notice duty |
Give breach notice without unreasonable delay unless you determine the breach has not caused and is not likely to cause substantial loss, injury, or identity theft to affected Michigan residents. |
|
| Minnesota breach notification from a date not yet set |
Disclose a breach of the security of the system to an affected Minnesota resident in the most expedient time possible and without unreasonable delay. Minnesota sets no fixed numeric-day cap, unlike several peer states. Notify the data owner immediately upon discovering a breach if you maintain, but do not own, the affected data. |
|
| Breach notification law, notice of security breach |
Disclose a breach of security to all affected Mississippi individuals without unreasonable delay, unless your investigation reasonably determines the breach will not likely result in harm. |
|
| Notice of security breach of personal information |
Notify each affected Missouri consumer of a breach of security involving their personal information without unreasonable delay. Notify the Missouri Attorney General's office and every nationwide consumer reporting agency without unreasonable delay if you provide notice to more than 1,000 consumers at one time. |
|
| Moldova Law No. 195/2024, personal data breach notification |
Notify the National Centre for Personal Data Protection without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Moldova, unless the breach is unlikely to risk their rights and freedoms. Communicate the breach to the affected data subject without undue delay where it is likely to result in a high risk to their rights and freedoms, in clear and plain language. +2 more |
|
| Loi sur la Protection des Données Personnelles, notification des violations de données |
Notify the Authority of a personal data breach as soon as possible and, where feasible, within 72 hours of becoming aware of the breach, unless it is unlikely to create a risk to the rights and freedoms of the persons concerned, and give the reasons for the delay when you notify later than that. Communicate a personal data breach to the affected person as soon as possible, in clear language, when it is likely to create a high risk to their rights and freedoms. +2 more |
|
| Law on Protection of Personal Data, breach notification |
An app that suffers a security breach of, or cyberattack on, an information system holding Mongolian personal data must submit a notification to the state digital-development and communications body, which must act on it in the shortest possible time. Whether the Act sets its own numeric deadline for the app's initial notification is not confirmed. |
|
| Notification of security breach from a date not yet set |
Notify affected Montana residents of a breach of security without unreasonable delay, and simultaneously submit an electronic copy of the notification to the Attorney General's consumer protection office. |
|
| Nebraska Financial Data Protection and Consumer Notification of Data Security Breach Act from a date not yet set |
Notify the Nebraska Attorney General no later than when you notify the affected resident, if notice to the resident is required. |
|
| GDPR Articles 33-34 and UAVG Article 42, Breach Notification |
Notify the AP within 72 hours of becoming aware of a personal-data breach affecting a person in the Netherlands, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them, subject to UAVG Article 42's national exception. |
|
| Security breach of personal information, notification from a date not yet set |
Disclose a security breach of personal information to an affected Nevada resident in the most expedient time possible and without unreasonable delay. Nevada sets no fixed numeric deadline. Notify each nationwide consumer reporting agency if you notify more than 1,000 persons of the breach at one time. |
|
| Notice of Security Breach |
Notify affected New Hampshire residents and the Attorney General's office as soon as possible on determining a security breach of personal information occurred. Notify consumer reporting agencies once notice is required for more than 1,000 residents. |
|
| New Jersey Identity Theft Prevention Act, breach notification |
Report a breach of security involving computerized personal records to the New Jersey Division of State Police before notifying the affected customer. Disclose the breach to each affected New Jersey resident in the most expedient time possible and without unreasonable delay. New Jersey sets no fixed numeric-day cap. |
|
| Data Breach Notification Act from a date not yet set |
Notify each affected New Mexico resident of a security breach involving their personal identifying information in the most expedient time possible and no later than 45 calendar days after discovery. Notify the New Mexico Attorney General's office and major consumer reporting agencies if the breach affects more than 1,000 New Mexico residents. |
|
| Stop Hacks and Improve Electronic Data Security (SHIELD) Act, breach notification duty |
Disclose a breach of the security of your system to each affected New York resident in the most expedient time possible and without unreasonable delay, and no later than 30 days after discovering the breach. Notify the New York Attorney General, the Department of State, and the Division of State Police of the breach, and notify each nationwide consumer reporting agency if you are notifying more than 5,000 New York residents at once. |
|
| Privacy Act 2020, Notifiable Privacy Breaches |
Notify the Privacy Commissioner as soon as practicable after becoming aware that a notifiable privacy breach, one reasonably believed to have caused or be likely to cause serious harm, has occurred. Notify each affected individual, or give public notice if individual notice is not reasonably practicable, as soon as practicable after becoming aware of a notifiable privacy breach, unless a statutory exception or permitted delay applies. |
|
| Ley No. 787, Ley de Protección de Datos Personales, security incident notice |
Where the personal data affected belong to a member of the National Police or the Army of Nicaragua, and the security measures the law requires fail or are not observed, immediately inform the affected institution of the breach. |
|
| Loi n° 2022-59, notification des violations de données |
Notify the HAPDP of a personal data breach without delay after becoming aware of it, and justify to the HAPDP any notification made outside that timeframe. Notify the affected person of a personal data breach as soon as possible when it is likely to create a high risk to their rights and freedoms; you need not notify the person where it is reasonable to believe the breach creates no such risk. +1 more |
|
| Nigeria Data Protection Act, 2023, data breach notification |
Notify the Commission of a personal data breach likely to result in a risk to individuals' rights and freedoms within 72 hours of becoming aware of it, describing the nature of the breach and, where feasible, the categories and approximate numbers of data subjects and records concerned. Notify affected data subjects immediately after becoming aware of a breach likely to result in a high risk to their rights and freedoms. +2 more |
|
| Identity Theft Protection Act, security breach notification from a date not yet set |
Notify each affected North Carolina resident of a security breach involving their personal information without unreasonable delay, consistent with the legitimate needs of law enforcement. Notify the Consumer Protection Division of the North Carolina Attorney General's Office of every breach requiring notice to any affected person, not only breaches above the 1,000-person threshold. |
|
| Notice of Security Breach for Personal Information from a date not yet set |
Disclose a breach of the security system to any affected North Dakota resident in the most expedient time possible and without unreasonable delay. Disclose the breach to the North Dakota Attorney General by mail or electronic mail if it exceeds 250 individuals. |
|
| Law on Personal Data Protection (LPDP), personal data breach notification |
Once Chapter IV takes effect, notify the Agency of a personal data breach within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons, and give reasons for any delay beyond that period. Once Chapter IV takes effect, communicate a personal data breach to the affected data subject without undue delay wherever the breach is likely to result in a high risk to their rights and freedoms, unless an exception such as prior encryption, later mitigation, or disproportionate effort applies. |
|
| Personal Data Act, Breach Notification in Norway |
Notify Datatilsynet without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Norway, unless the breach is unlikely to risk their rights and freedoms. Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms. |
|
| Security Breach Notification Act |
Notify an affected Ohio resident of a security breach involving their personal information in the most expedient time possible and no later than 45 days after discovery. Notify every nationwide consumer reporting agency without unreasonable delay if a single breach affects more than 1,000 Ohio residents. |
|
| Security Breach Notification Act |
Provide notice of a breach of security involving personal information without unreasonable delay. Notify the Oklahoma Attorney General within 60 days of consumer notice if the breach affects 500 or more Oklahoma residents (1,000 or more for a breach maintained by a credit bureau). |
|
| Personal Data Protection Law, breach notification |
An app that suffers a breach leading to the destruction, alteration, disclosure, access, or illegal processing of an individual's personal data in Oman must notify the Ministry and the affected Data Subject, following the procedure the Executive Regulations set; no specific notification timeline is confirmed at primary source. |
|
| Notice of breach of security from a date not yet set |
Notify each affected Oregon consumer of a breach of security, including one you learn of through a vendor, and notify the Oregon Attorney General as well once more than 250 Oregon consumers are notified. |
|
| Ley 81 de 2019, personal data breach notification |
Notify the affected data subject as soon as possible after learning that their personal data was stolen without authorization or that its security was otherwise compromised. This Law sets no fixed number of hours or days for that notice and no duty to notify ANTAI of the breach. As an operator of a public communications network, tell affected data subjects about a particular breach of your network's security and the measures you are taking, again with no fixed period stated. |
|
| Ley N° 7593/2025, notificación de un incidente de seguridad from , in 14 months |
Notify the National Data Protection Agency, and the affected person where relevant, of a security incident within 72 hours of becoming aware of it. |
|
| Breach of Personal Information Notification Act |
Notify each affected Pennsylvania resident of a breach of system security involving personal information without unreasonable delay. Notify each nationwide consumer reporting agency if you notify more than 500 persons of a breach at one time. |
|
| Data Privacy Act of 2012, breach notification |
An app that reasonably believes sensitive personal information or identity-fraud-enabling information of an individual in the Philippines has been acquired by an unauthorized person, in a way likely to cause serious harm, must promptly notify the National Privacy Commission and the affected individuals. |
|
| GDPR Articles 33-34, Breach Notification |
Notify UODO within 72 hours of becoming aware of a personal-data breach affecting a person in Poland, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them. |
|
| GDPR Articles 33-34, Breach Notification in Portugal |
Notify the CNPD without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Portugal, unless the breach is unlikely to risk their rights and freedoms. Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms. |
|
| Ley de Información al Ciudadano sobre la Seguridad de Bancos de Información (data breach notification) |
Notify affected Puerto Rico residents of a security breach of an information bank containing their personal information as expeditiously as possible. Report the breach to the Department of Consumer Affairs within ten non-extendable days of detecting it. +2 more |
|
| Personal Data Privacy Protection Law, breach notification |
An app that is a Processor handling the personal data of an individual in Qatar, including a voiceprint or faceprint, must forthwith notify its Controller of any breach or risk of one, and a Controller must inform the affected individual and the Competent Department where a breach of security precautions may cause serious damage to the data or the individual's privacy; the PDPPL states no fixed notification timeline. |
|
| Québec | Confidentiality incident notification and register |
Where the incident presents a risk of serious injury, judged by the sensitivity of the information, the anticipated consequences and the likelihood of injurious use, promptly notify the Commission d’accès à l’information and each person whose personal information is concerned. |
| Law No. 29-2019, personal-data breach notification |
Notify the national commission of a personal-data breach without undue delay and, where possible, within 72 hours of becoming aware of it, unless the breach is not likely to create a risk to the rights and freedoms of natural persons. Communicate the breach to the affected data subject without undue delay, in clear and simple terms, where it is likely to create a high risk to their rights and freedoms. +2 more |
|
| Identity Theft Protection Act of 2015, notification of breach from a date not yet set |
Notify affected Rhode Island residents of a breach posing a significant risk of identity theft within 45 days of confirming the breach, or within 30 days if you are a state or municipal agency. Notify the Attorney General and consumer reporting agencies once more than 500 Rhode Island residents are affected, without delaying notice to residents. |
|
| GDPR Articles 33-34, Breach Notification |
Notify ANSPDCP within 72 hours of becoming aware of a personal-data breach affecting a person in Romania, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them. |
|
| Federal Law No. 152-FZ, Article 21 Part 3.1, Breach Notification |
Notify Roskomnadzor within 24 hours of detecting an unlawful or accidental transfer, provision, distribution, or access to personal data of a person in Russia, and file a full follow-up report within 72 hours. |
|
| Law relating to the Protection of Personal Data and Privacy, personal data breach notification |
Notify the supervisory authority of the breach within 48 hours of becoming aware of it. As a data processor, notify the data controller of the breach within 48 hours of becoming aware of it. +2 more |
|
| National Digital Identification Act 2024, personal data breach notification |
As a relying party or data processor in the National Digital Identification System, notify the Registrar General of a personal data breach within 72 hours of becoming aware of it, describing the categories and approximate number of records concerned. Where a personal data breach is likely to result in a high risk to a registered person's rights, ensure the Registrar General can communicate the breach to that person without undue delay, in plain language, with advice on mitigating measures. |
|
| San Marino Law No. 171, personal data breach notification |
Notify the Data Protection Authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in San Marino, under Article 34. Communicate the breach to the affected data subject without undue delay where it is likely to result in a high risk to their rights and freedoms, in clear and plain language. +2 more |
|
| Personal Data Protection Law, breach notification |
An app that suffers a breach, damage, or illegal access affecting the personal data of an individual in Saudi Arabia must notify the Competent Authority upon knowing of the breach, and must separately notify the Data Subject where the breach would cause damage to their data or prejudice their rights and interests, following the Implementing Regulations' procedure. |
|
| Law on Personal Data Protection, personal data breach notification |
Notify the Commissioner of a breach that may create risk to a person's rights and freedoms without undue delay, and within 72 hours of becoming aware of the breach where that is possible; give reasons for any delay beyond 72 hours. As a processor, notify the controller without undue delay after becoming aware of a breach. +2 more |
|
| Data Protection Act, 2023, personal data breach notification |
Notify the Information Commission of a personal data breach no later than 72 hours after becoming aware of it, giving reasons for any later notification. Promptly inform the affected data subjects where a breach is likely to affect a significant number of individuals and their rights and freedoms. |
|
| Personal Data Protection Act, data breach notification |
An app that experiences a data breach affecting an individual's personal data in Singapore must assess whether the breach is likely to cause significant harm or is of significant scale, and if so must notify the PDPC as soon as practicable and in any case within 3 calendar days of that assessment, and must also notify each affected individual unless a statutory exception applies. |
|
| GDPR Articles 33-34, Breach Notification |
Notify the Slovak Office for Personal Data Protection within 72 hours of becoming aware of a personal-data breach affecting a person in Slovakia, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them. |
|
| GDPR Articles 33-34, Breach Notification |
Notify the Slovenian Information Commissioner within 72 hours of becoming aware of a personal-data breach affecting a person in Slovenia, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them. |
|
| Data Protection Act, 2023, personal data breach notification |
Notify the Data Protection Authority of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals within 72 hours after becoming aware of it. Where you extend that deadline for the legitimate needs of law enforcement or to determine the scope of the breach, tell the Authority the grounds for the extension, with supporting evidence, before the original deadline expires. +2 more |
|
| Protection of Personal Information Act, notification of security compromises |
Notify the Information Regulator of a security compromise as soon as reasonably possible after discovering that personal information has been accessed or acquired by an unauthorised person; the Act sets no fixed hour or day limit, only this standard. Notify the affected data subject of the same security compromise as soon as reasonably possible after discovery, in writing, unless a law-enforcement body or the Regulator determines that notifying would impede a criminal investigation, or the data subject's identity cannot be established. +2 more |
|
| Business data breach of security, notification statute |
Notify each affected South Carolina resident of a breach of security involving personal identifying information in the most expedient time possible and without unreasonable delay. Notify the Consumer Protection Division of the Department of Consumer Affairs and all nationwide consumer reporting agencies if you notify more than 1,000 persons of a breach at one time. |
|
| Breach of system security, notification statute |
Notify each affected South Dakota resident of a breach of system security not later than 60 days after discovery, absent a law enforcement delay. Notify the South Dakota Attorney General by mail or electronic mail if a breach affects 250 or more South Dakota residents. This threshold is 250, not 250,000. |
|
| Personal Information Protection Act, breach notification duties |
An app that suffers a leak, theft, or unauthorized disclosure of Korean personal data must notify affected data subjects without delay, and must report the breach to the PIPC without delay if it affects 1,000 or more people, involves sensitive information such as a biometric identifier, or resulted from illegal external access. |
|
| GDPR Articles 33-34 and LOPDGDD Article 69, Breach Notification |
Notify the AEPD within 72 hours of becoming aware of a personal-data breach affecting a person in Spain, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them. |
|
| Personal Data Protection Act, breach notification duties |
An app that suffers a personal data breach in Sri Lanka, including one involving a biometric identifier, must notify the Data Protection Authority in the form, manner, and time a rule made under the Act determines; whether and when the affected individual must also be told is set by a rule not yet located. |
|
| Draft Law on the Protection of Privacy and Personal Data, breach notification proposed |
Notify the Commissioner for Personal Data Protection of a breach relating to personal data without delay, and no later than 72 hours after becoming aware of the breach, unless the breach is unlikely to pose a risk to individuals' rights and freedoms; if you do not notify within 72 hours, state the reasons for the delay. Include in that notice, at minimum, the nature of the breach, the categories and approximate number of data subjects and records affected, your data protection officer's or another contact point's details, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. +2 more |
|
| GDPR Articles 33-34, Breach Notification |
Notify IMY within 72 hours of becoming aware of a personal-data breach affecting a person in Sweden, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them. |
|
| FADP Article 24, Breach Notification in Switzerland |
Notify the FDPIC as soon as possible once you become aware of a data security breach likely to result in a high risk to a Swiss data subject's personality or fundamental rights. Notify the affected individual only where necessary to protect them or where the FDPIC orders it; there is no fixed statutory hour count as there is under GDPR. |
|
| Law No. 12 of 2024 on Protection of Electronic Personal Data, personal data breach notification |
Notify the Authority immediately on becoming aware of the breach, and expect the Authority to immediately notify the competent authorities where the breach concerns national security matters. Within seventy two hours of becoming aware of the breach, give the Authority a description of its nature, form and causes, the approximate number of records, persons and categories affected, the data protection officer's contact details, the breach's likely effects, the measures taken or proposed to address it, and documentation of the breach and the corrective action taken. +1 more |
|
| Personal Data Protection Act, 2022, security and breach notification |
Notify the Personal Data Protection Commission without undue delay of any security breach affecting personal data you process. |
|
| Identity Theft Enforcement and Protection Act, breach notification |
Notify each affected Texas resident of a breach of system security involving their sensitive personal information without unreasonable delay and no later than 60 days after determining the breach occurred. Notify the Texas Attorney General as soon as practicable and no later than 30 days after determining the breach occurred, if the breach affects 250 or more Texas residents. +1 more |
|
| Personal Data Protection Act, breach notification |
An app that experiences a personal data breach affecting an individual in Thailand must notify the Personal Data Protection Committee's Office without delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to pose a risk to the affected individuals; where the breach is likely to cause high risk, the app must also notify each affected individual without delay. |
|
| Privacy Act 2025, personal information breaches from a date not yet set |
Notify the Privacy Commission within 72 hours of becoming aware of a personal information breach that is likely to result in a risk to the rights and freedoms of individuals, describing its nature and, where possible, the categories and approximate numbers of data subjects and records concerned. As a data processor, notify the data controller or the data processor that engaged you within 72 hours of becoming aware of a personal information breach, and answer their information requests without undue delay. +1 more |
|
| Personal Data Protection Law (KVKK), breach notification |
An app that suffers unlawful acquisition of personal data belonging to a person in Turkey must notify the affected data subject and the Board within the shortest time; KVKK sets no fixed numeric deadline in its own text. |
|
| Data Protection and Privacy Act, 2019, breach notification |
Notify the National Information Technology Authority immediately after you believe personal data has been accessed or acquired by an unauthorised person, describing the access or acquisition and the remedial action taken. Wait for the Authority to determine whether you must also notify the affected data subject of the breach; the Act sets no separate deadline for that notice. +2 more |
|
| Draft Law No. 8153, personal data breach notification proposed |
Once enacted, notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it. Once enacted, include in that notification the nature of the breach, the number of affected individuals, the data types involved, the likely consequences, and the remedial measures taken. |
|
| ADGM Data Protection Regulations, breach notification |
An app that is a controller or processor established in or targeting the ADGM free zone and that suffers a personal data breach must notify the Commissioner of Data Protection without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to pose a risk to individuals' rights. |
|
| Federal Decree-Law on the Protection of Personal Data, breach notification |
An app that suffers a breach affecting the personal data of an individual in the onshore UAE must notify the Bureau at the time it becomes aware of the breach; the Decree-Law defers the specific notification window to Executive Regulations whose text could not be confirmed at primary source, so an app should not assume a specific hour count without checking current regulator guidance. |
|
| UK GDPR Articles 33-34 and PECR, Breach Notification in the United Kingdom |
Notify the ICO without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in the United Kingdom, unless the breach is unlikely to risk their rights and freedoms. Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms, and if you are a telecoms or ISP-type provider, notify a PECR breach to the ICO within 72 hours. |
|
| GLBA Safeguards Rule Breach Notification Amendment |
Notify the FTC within 30 days of discovering a security event that has compromised unencrypted customer information for 500 or more consumers. |
|
| HIPAA Breach Notification Rule |
Notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach of unsecured protected health information. Notify HHS, and for a breach affecting more than 500 residents of a state, prominent media outlets serving that state. |
|
| Disclosure of Breach of Security (Identity Theft and Privacy Protection) |
Notify an affected Virgin Islands resident without unreasonable delay after discovering that unencrypted personal information (a name combined with a Social Security number, driver's license number, or financial account number with its access code) was acquired without authorization. Where direct notice is impractical because of cost, the number of residents affected, or insufficient contact information, give substitute notice by email, a conspicuous website posting, and notice to major territory-wide media. |
|
| Ley N° 19.670, personal data breach notification |
Notify the affected data subjects immediately and in detail on becoming aware of the breach, describing the measures adopted to address it. Notify the Unidad Reguladora y de Control de Datos Personales immediately and in detail on becoming aware of the breach, coordinating your response with the national cybersecurity incident response center (CERTuy). |
|
| Protection of Personal Information Act |
If unencrypted Utah-resident data combining a name with a Social Security number, a driver license or state ID number, or a financial account or card number with its access code is breached, investigate promptly in good faith and notify each affected Utah resident without unreasonable delay. Notify the Utah Attorney General and the Utah Cyber Center if the breach affects 500 or more Utah residents, and notify nationwide consumer reporting agencies if it affects 1,000 or more. |
|
| Security Breach Notice Act |
Notify an affected Vermont consumer of a security breach in the most expedient time possible and without unreasonable delay, and no later than 45 days after discovery. Notify the Attorney General or the Department of Financial Regulation, as applicable, with a preliminary description of the breach within 14 business days of discovery. |
|
| Law on Personal Data Protection, breach notification |
An app that detects a violation of Vietnam's personal data protection rules likely to cause harm to national defense and security, social order, or an individual's life, health, honor, dignity, or property must notify the agency in charge of personal data protection within 72 hours. |
|
| Breach of personal information notification from a date not yet set |
Notify the Virginia Office of the Attorney General and each affected Virginia resident of a breach of system security involving personal information without unreasonable delay after discovery. |
|
| Notice of security breaches involving personal information |
Notify affected Washington residents of a breach of unsecured personal information, including biometric identifiers, in the most expedient time possible and no more than 30 calendar days after discovery. Notify the Washington Attorney General of any breach affecting more than 500 Washington residents. |
|
| Breach of Security of Consumer Information from a date not yet set |
Notify each affected West Virginia resident of a breach of security involving personal information without unreasonable delay. Notify each nationwide consumer reporting agency if you are required to notify more than 1,000 persons of a breach. |
|
| Notice of unauthorized acquisition of personal information from a date not yet set |
Make reasonable efforts to notify each affected Wisconsin individual of an unauthorized acquisition of their personal information within a reasonable time, not to exceed 45 days after learning of it. Notify consumer reporting agencies if a single incident requires notifying 1,000 or more individuals. |
|
| Breach of the security of a computerized data system, notification duty from a date not yet set |
Give notice as soon as possible to each affected Wyoming resident once your investigation determines misuse of their personal identifying information has occurred or is reasonably likely. |
|
| Data Protection Act, 2021, notification of a security breach |
Notify the Data Protection Commissioner within 24 hours of the breach occurring: section 49(1) runs the period from the security breach itself, not from the moment you learn of it. Notify the affected data subject as soon as practicable of any security breach affecting their personal data. +2 more |
|
| Cyber and Data Protection Act, security breach notification |
Notify the Data Protection Authority within 24 hours of discovering a security breach affecting personal data you process. Treat every security breach affecting the data you process as notifiable under section 19: the Act sets no risk threshold below which the duty falls away. |
|
| Cyber and Data Protection Regulations 2024, security breach notification |
Report a personal data breach to the Authority within 24 hours of becoming aware of it, on Form DP3 in the Fourth Schedule. Inform the affected data subjects within 72 hours of the breach where it is likely to result in a high risk of adversely affecting individuals' rights and freedoms. +1 more |
Comprehensive regime
5 laws, 5 places| Place | Law | What it asks, as read here |
|---|---|---|
| Loi n°2024/017 du 23 décembre 2024 relative à la protection des données à caractère personnel au Cameroun from a date not yet set |
Notify the data protection authority of a personal-data breach without delay, and inform an affected person where their rights are threatened; submit an annual security report to the authority. |
|
| Ley 149/2022, De Protección de Datos Personales, general regime |
Notify the competent authority of cybersecurity incidents affecting personal data held in a registry, file, archive, or database under your custody. |
|
| Protection of Personal Information Act 4 of 2013 (POPIA) |
Where an operator processes personal information on your behalf, bind it by written contract to the same security measures, and require it to notify you immediately if it has reasonable grounds to believe the information was accessed or acquired by an unauthorised person. |
|
| Personal Data Protection Act (個人資料保護法) |
Notify an affected individual when personal data held has been stolen, altered, damaged, lost, or leaked, and report the incident to the Personal Data Protection Commission where the circumstances fall within the reporting scope the Commission has specified. |
|
| Ley N° 18.331, Personal Data Protection and Habeas Data Law, as amended |
If you operate a public communications network or offer an electronic communications service, secure the network and the service, and tell subscribers about any particular risk of a security breach and the measures to take. |
Data subject rights
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Personal Data Protection Law, data subject rights |
An app must let an individual in Jordan object to processing or profiling of their data that is unnecessary, excessive, discriminatory, or unlawful for its stated purpose, must let them obtain erasure or concealment of their data and a portable copy transferable to another controller, and must notify them of any data breach affecting the security or integrity of their data. |
|
| Personal Data Protection Law, data subject rights |
An app must let an individual in Oman revoke their consent, request amendment or blocking of their data, obtain a copy of it, transfer it to another controller, request its erasure (unless national archiving requires otherwise), and must notify them of any breach or infringement of their personal data and the actions taken in response; these rights apply to a voiceprint, faceprint, or other biometric identifier like any other personal data. |
Cross border transfer
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Resolución 58/2022 (MINCOM), security and localization rules for personal data in electronic form |
Notify the competent authorities of cybersecurity incidents affecting personal data in electronic form under your custody. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.