Law / Frameworks / NIST Privacy Framework / Communicate-P

NIST Privacy Framework, Communicate-PCM.AW-P7

Impacted individuals and organizations are notified about a privacy breach or event.NIST Privacy Framework, version 1.0, January 2020, CM.AW-P7

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

185
laws
176
places
0
with court rulings behind them
37
not yet in force
4
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Alabama
  • Alaska
  • Albania
  • Algeria
  • Andorra
  • Arizona
  • Arkansas
  • Australia
  • Austria
  • Bangladesh
  • Barbados
  • Belarus
  • Belgium
  • Belize
  • Benin
  • Bermuda
  • Bosnia and Herzegovina
  • Botswana
  • Brazil
  • Brunei Darussalam
  • Bulgaria
  • California
  • Cambodia
  • Cameroon
  • Canada
  • Cayman Islands
  • Chad
  • China
  • Colombia
  • Colorado
  • Connecticut
  • Croatia
  • Cuba
  • Cyprus
  • Czech Republic
  • Delaware
  • Democratic Republic of the Congo
  • Denmark
  • District of Columbia
  • Djibouti
  • Ecuador
  • Egypt
  • El Salvador
  • Estonia
  • Eswatini
  • Ethiopia
  • European Union
  • Finland
  • Florida
  • France
  • Gabon
  • Gambia
  • Georgia
  • Georgia
  • Germany
  • Ghana
  • Greece
  • Guam
  • Hawaii
  • Hungary
  • Iceland
  • Idaho
  • Illinois
  • India
  • Indiana
  • Indonesia
  • Iowa
  • Ireland
  • Israel
  • Italy
  • Jamaica
  • Japan
  • Jordan
  • Kansas
  • Kazakhstan
  • Kentucky
  • Kenya
  • Kiribati
  • Kosovo
  • Latvia
  • Lesotho
  • Liechtenstein
  • Lithuania
  • Louisiana
  • Luxembourg
  • Maine
  • Malaysia
  • Maldives
  • Malta
  • Maryland
  • Massachusetts
  • Mauritius
  • Mexico
  • Michigan
  • Minnesota
  • Mississippi
  • Missouri
  • Moldova
  • Monaco
  • Mongolia
  • Montana
  • Nebraska
  • Netherlands
  • Nevada
  • New Hampshire
  • New Jersey
  • New Mexico
  • New York
  • New Zealand
  • Nicaragua
  • Niger
  • Nigeria
  • North Carolina
  • North Dakota
  • North Macedonia
  • Norway
  • Ohio
  • Oklahoma
  • Oman
  • Oregon
  • Panama
  • Paraguay
  • Pennsylvania
  • Philippines
  • Poland
  • Portugal
  • Puerto Rico
  • Qatar
  • Republic of the Congo
  • Rhode Island
  • Romania
  • Russia
  • Rwanda
  • Samoa
  • San Marino
  • Saudi Arabia
  • Serbia
  • Seychelles
  • Singapore
  • Slovakia
  • Slovenia
  • Somalia
  • South Africa
  • South Carolina
  • South Dakota
  • South Korea
  • Spain
  • Sri Lanka
  • Suriname
  • Sweden
  • Switzerland
  • Syria
  • Taiwan
  • Tanzania
  • Texas
  • Thailand
  • Tonga
  • Turkey
  • Uganda
  • Ukraine
  • United Arab Emirates
  • United Kingdom
  • United States
  • United States Virgin Islands
  • Uruguay
  • Utah
  • Vermont
  • Vietnam
  • Virginia
  • Washington
  • West Virginia
  • Wisconsin
  • Wyoming
  • Zambia
  • Zimbabwe

Breach notification

177 laws, 173 places
PlaceLawWhat it asks, as read here
Alabama Alabama Data Breach Notification Act of 2018 from a date not yet set

Notify the Alabama Attorney General of a breach involving unauthorized acquisition of sensitive personally identifying information that is reasonably likely to cause substantial harm to affected individuals.

Alaska Alaska Personal Information Protection Act, breach notification duty from a date not yet set

Disclose a breach of the security of an information system containing an Alaska resident's personal information to each affected resident in the most expeditious time possible and without unreasonable delay.

Albania Law No. 124/2024, notification of a personal data breach

Notify the Commissioner of a personal data breach as soon as possible and no later than 72 hours of becoming aware of the breach, unless the breach is unlikely to endanger the rights and freedoms of data subjects, and give the Commissioner your reasons for any later notification.

As a processor, notify the controller immediately after becoming aware of any personal data breach.

+2 more
Algeria Loi n° 18-07 relative à la protection des personnes physiques, notification des violations de données

As a service provider, that is any public or private entity offering users the ability to communicate over a computer or telecommunications system, or any entity processing or storing data for that communication service, notify the ANPDP without delay of a personal-data breach occurring on a public electronic communications network.

Notify the affected individual without delay of that same breach where it may harm their private life, unless the ANPDP finds you had already implemented appropriate protective measures.

+3 more
Andorra LQPD, personal data breach notification

Notify the Andorran Data Protection Agency of a personal data breach without undue delay and, where possible, within seventy-two hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.

Justify the reasons for the delay if notifying the Agency after that seventy-two-hour period.

+3 more
Arizona Arizona data breach notification law from a date not yet set

Notify each affected Arizona resident of a breach of system security involving their personal information without unreasonable delay and no later than 45 days after determining the breach occurred.

Notify the Arizona Attorney General, the director of the Arizona Department of Homeland Security, and the three largest nationwide consumer reporting agencies if the breach affects more than 1,000 individuals.

Arkansas Arkansas Personal Information Protection Act, breach notification and security from a date not yet set

Notify each affected Arkansas resident of a breach of security without unreasonable delay.

Notify the Arkansas Attorney General if the breach affects more than 1,000 individuals, at the same time as consumer notice or within 45 days of determining a reasonable likelihood of harm, whichever occurs first.

Australia Privacy Act 1988 (Cth), Notifiable Data Breaches Scheme

Prepare a statement about an eligible data breach and give a copy to the Information Commissioner as soon as practicable after becoming aware of reasonable grounds to believe the breach happened.

Notify the contents of that statement to each individual to whom the relevant information relates, or to each individual at risk, or, if neither is practicable, publish the statement on the entity's website and take reasonable steps to publicise it.

Austria GDPR Articles 33-34, Breach Notification in Austria

Notify the Datenschutzbehorde without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Austria, unless the breach is unlikely to risk their rights and freedoms.

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

Bangladesh Personal Data Protection Act, 2026, breach notification duties

An app that suffers a personal data breach in Bangladesh, including one involving a biometric identifier, must notify the Authority in the form, manner and time a regulation prescribes whenever the breach creates a possibility of significant harm to an affected data principal; no separate statutory duty to notify the affected individual directly was found.

Show the other 167 laws
Barbados Data Protection Act, 2019, personal data breach notification

Notify a personal data breach to the Data Protection Commissioner without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of an individual, and give reasons for the delay if you notify later.

Communicate a personal data breach likely to result in a high risk to the rights and freedoms of individuals to the affected data subject, in clear and plain language, without undue delay and, where feasible, not later than 72 hours after becoming aware of it.

+2 more
Belarus Law of the Republic of Belarus On Personal Data Protection, notification of personal data protection violations

Notify the National Center for Personal Data Protection immediately, and in any case no later than three working days after becoming aware of a violation of your personal data protection systems, under Article 16, unless the Center itself provides otherwise.

Belgium GDPR Articles 33-34, Breach Notification

Notify the GBA/APD within 72 hours of becoming aware of a personal-data breach affecting a person in Belgium, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.

Belize Data Protection Act 2021, personal data breach notification from a date not yet set

Where feasible, notify the Data Protection Commissioner of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to risk a person's rights and freedoms.

Where a personal data breach is likely to result in a high risk to a person's rights and freedoms, notify that person without undue delay.

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, notification des ruptures de sécurité

Notify the Autorité de Protection des Données Personnelles (APDP) and the affected person without delay of any security breach that has affected their personal data.

As a processor, warn the controller without delay of any security breach affecting personal data you process on the controller's behalf.

+1 more
Bermuda Personal Information Protection Act 2016, breach of security notification

Notify the Privacy Commissioner, then any affected individual, without undue delay of a breach of security that is likely to adversely affect an individual.

Describe in the Commissioner notification the nature of the breach, its likely consequences, and the measures taken and to be taken to address it.

Bosnia and Herzegovina Law on the Protection of Personal Data of Bosnia and Herzegovina, personal data breach notification

Notify the Agency of a personal data breach without undue delay and, if possible, within 72 hours of becoming aware of the breach, giving the Agency the reasons for the delay where notice comes later.

As a processor, notify the controller without undue delay after becoming aware of a personal data breach.

+3 more
Botswana Data Protection Act, 2024, personal data breach notification

Notify the Information and Data Protection Commission of a personal-data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the affected person's rights and freedoms, and give reasons for any later notification.

As a data processor, notify the data controller of a personal-data breach without undue delay after becoming aware of it.

+1 more
Brazil LGPD, security incident notification

Notify the ANPD and the affected data subjects of a security incident that may create relevant risk or harm to data subjects, within the reasonable period the ANPD sets by regulation, and state the reasons for the delay when the notice is not immediate.

Describe in the notification the nature of the personal data affected, the data subjects involved, the technical and security measures used, the risks related to the incident, and the measures taken or planned to reverse or mitigate its effects.

Brunei Darussalam Personal Data Protection Order 2025, breach notification

Brunei's Personal Data Protection Order 2025 has required, since this duty (Part 7) took effect under Government Gazette No. S 11/2025, an organisation to notify the Authority within 3 days of assessing that a breach is notifiable, meaning it is likely to cause significant harm or is of significant scale, and to notify each affected individual, for a breach involving any personal data including a voiceprint or faceprint.

Bulgaria GDPR Articles 33-34, Breach Notification

Notify KZLD within 72 hours of becoming aware of a personal-data breach affecting a person in Bulgaria, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them, using KZLD's own Bulgarian-language notification template.

California California Data Breach Notification Law, as amended by SB 446

Notify affected California residents of a breach of their unencrypted personal information within 30 calendar days of discovery or notification.

Notify the California Attorney General within 15 days of consumer notification when a breach affects more than 500 California residents.

Cambodia Cambodia's Draft Law on Personal Data Protection, personal data breach notification proposed

If enacted as drafted, a data controller would have to notify the Ministry of Post and Telecommunications immediately, but no later than 72 hours of becoming aware of a personal data breach that may pose a risk to the data subject or another natural person, or give the Ministry valid reasons for any delay.

If enacted as drafted, a data controller would have to notify the affected data subject immediately upon becoming aware of a personal data breach that may pose a high risk to their rights and freedoms, unless the controller had already secured the data, had taken steps removing the high risk, or individual notice would be disproportionately burdensome, in which case a public notice would serve instead.

Canada PIPEDA breach of security safeguards regime

Report any breach of security safeguards involving personal information under the organization's control to the Privacy Commissioner as soon as feasible, if it is reasonable to believe the breach creates a real risk of significant harm to an individual.

Notify each affected individual directly, in a conspicuous form, with enough information to let them understand the significance of the breach and take steps to reduce or mitigate the resulting harm.

Cayman Islands Data Protection Act 2021 Revision, personal data breach notification

Notify the Ombudsman and each affected data subject of a personal data breach without undue delay and no later than five days after becoming aware of it, describing the breach, its consequences, and the measures taken or recommended.

Chad Loi n°007/PR/2015, obligation de notification des violations de données à l'ANSICE

Notify both ANSICE and the affected data subject, without delay, of any security breach affecting that person's personal data.

China Personal Information Protection Law, Data Breach Notification

Upon discovering an actual or possible leak, alteration, or loss of personal information, immediately take remedial measures and notify both the competent personal information protection department and every affected individual, unless the remedial measures can be shown to effectively prevent harm.

Include in any breach notice the categories of information involved, the cause, possible harm, remedial steps taken, what affected individuals can do to protect themselves, and the handler's contact information.

Colombia Ley 1581 de 2012, Security Breach Notification to the Authority

Notify the Superintendencia de Industria y Comercio when a violation of the security codes occurs and creates a risk in the administration of a data subject's personal information; the law fixes no deadline for this notice.

As a data processor, notify the Superintendencia de Industria y Comercio under the same terms when a security code violation creates that risk; neither duty requires telling the affected data subject directly.

Colorado C.R.S. 6-1-716, Notification of Security Breach

If you experience unauthorized acquisition of unencrypted computerized personal information of Colorado residents, notify affected residents without unreasonable delay and within 30 days of determining a breach occurred.

Notify the Colorado Attorney General if 500 or more residents are affected, and nationwide consumer reporting agencies if more than 1,000 are affected.

Connecticut Breach of security re computerized data containing personal information from a date not yet set

Notify each affected Connecticut resident of a breach of security involving personal information without unreasonable delay and no later than 60 days after discovery, unless federal law requires a shorter time.

Croatia GDPR Articles 33-34, Breach Notification

Notify AZOP within 72 hours of becoming aware of a personal-data breach affecting a person in Croatia, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.

Cyprus GDPR Articles 33-34, Breach Notification in Cyprus

Notify the ODPC without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Cyprus, unless the breach is unlikely to risk their rights and freedoms.

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

Czech Republic GDPR Articles 33-34, Breach Notification

Notify UOOU within 72 hours of becoming aware of a personal-data breach affecting a person in the Czech Republic, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.

Delaware Computer Security Breaches from a date not yet set

Notify affected Delaware residents of a breach of security without unreasonable delay and no later than 60 days after determining the breach occurred.

Notify the Delaware Attorney General, by the time you notify residents, if the breach affects more than 500 Delaware residents.

Democratic Republic of the Congo Digital Code, Title III, personal data breach notification

Notify the Data Protection Authority and the affected data subject without delay of any breach affecting personal data, describing the nature of the breach, the categories and approximate number of affected people and records where possible, a contact point, the likely consequences, and the measures taken or proposed to address it.

As a processor, warn the controller without delay of any breach of security affecting personal data you process on the controller's behalf.

+1 more
Denmark GDPR Articles 33-34, Breach Notification in Denmark

Notify Datatilsynet without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Denmark, unless the breach is unlikely to risk their rights and freedoms.

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

District of Columbia Consumer Security Breach Notification

If your business conducts business in the District of Columbia and discovers a breach of the security of a system containing a District resident's personal information, notify each affected resident in the most expedient time possible and without unreasonable delay.

If the breach affects 50 or more District residents, also give written notice to the Office of the Attorney General for the District of Columbia, no later than when you notify residents.

+1 more
Djibouti Digital Code, Book I: personal-data breach notification

Notify the Commission Nationale de Protection des Données à Caractère Personnel of a personal-data breach without undue delay and, at the latest, within 72 hours of becoming aware of it, stating the reasons for any delay beyond that window.

Tell the affected individual of the breach without undue delay, in clear and simple terms, where it is likely to result in a high risk to their rights and freedoms.

+2 more
Ecuador LOPDP, notificación de vulneración de seguridad

Notify the Authority and the telecommunications regulator of a personal-data security breach as soon as possible and no later than five days after becoming aware of it.

Notify the affected data subject within 3 days of learning of the risk, where the breach carries a risk to their fundamental rights and individual freedoms.

+3 more
Egypt Egypt Personal Data Protection Law, Personal Data Infringement notification

Notify the Personal Data Protection Center of any personal data breach within 72 hours of discovering it, and notify immediately where the breach concerns national security.

Notify the Data Subject within 3 days of the date you notified the Center, telling them of the infringement and the procedures you have adopted about it.

+1 more
El Salvador Ley para la Protección de Datos Personales, personal data breach notification

Notify the Agencia de Ciberseguridad del Estado, the Fiscalia General de la Republica, and every affected data subject of a personal data breach within seventy two hours of becoming aware of it.

Tell the Agencia de Ciberseguridad del Estado, in clear and simple language, the incident's nature, the personal data compromised, the immediate corrective actions taken, recommendations for the data subject, and where to learn more, and give the affected data subject the incident's nature, the data compromised, the recommendations, and where to learn more.

Estonia GDPR Articles 33-34, Breach Notification in Estonia

Notify the Estonian Data Protection Inspectorate without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Estonia, unless the breach is unlikely to risk their rights and freedoms.

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

Eswatini Data Protection Act, 2022, notification of security compromises

Notify the Eswatini Communications Commission and the affected data subject as soon as reasonably possible after discovering that a data subject's personal information has been accessed or acquired by an unauthorised person, unless the data subject's identity cannot be established.

Take into account the legitimate needs of law enforcement and any measures reasonably necessary to determine the scope of the compromise when timing your notification, but do not use that as a reason to delay beyond what is reasonably possible.

+2 more
Ethiopia Personal Data Protection Proclamation, personal data breach notification

Notify the Authority of a personal data breach within 72 hours of becoming aware of it, giving reasons for any delay.

Communicate a personal data breach to the affected data subject within 72 hours of becoming aware of it, in clear language, describing the likely consequences, the contact point for more information and the measures taken to address it.

+2 more
European Union GDPR Articles 33-34, Breach Notification

Notify the competent supervisory authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting EU personal data, unless the breach is unlikely to risk individuals' rights and freedoms.

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

Finland GDPR Articles 33-34, Breach Notification in Finland

Notify the Data Protection Ombudsman without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Finland, unless the breach is unlikely to risk their rights and freedoms.

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

Florida Florida Information Protection Act, breach notification from a date not yet set

Notify the Florida Department of Legal Affairs of a breach of security affecting 500 or more individuals in Florida as expeditiously as practicable, and no later than 30 days after determining a breach occurred or having reason to believe one occurred.

Notify each affected Florida individual of a breach no later than 30 days after determining a breach occurred, unless you obtain a written 15-day extension for good cause.

France GDPR Articles 33-34, Breach Notification

Notify the CNIL within 72 hours of becoming aware of a personal-data breach affecting a person in France, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.

Gabon Law No. 025/2023, personal-data breach notification

Notify the APDPVP without delay of a personal-data breach, describing its nature, the categories and approximate number of data subjects and records concerned where possible, the data protection officer's or another contact point's details, the likely consequences, and the measures taken or proposed to address it; the law sets no numeric deadline for this notice.

Accompany a notification to the APDPVP with supporting evidence of the breach.

+2 more
Gambia Personal Data Protection and Privacy Act, 2025, personal data breach notification from a date not yet set

Notify the Information Commission of a personal data breach within 72 hours of becoming aware of the breach.

Notify each affected data subject of a personal data breach without undue delay where the breach carries a high risk to their rights.

Georgia Georgia Personal Identity Protection Act, notification of security breach from a date not yet set

Give notice of a breach of the security of a system containing a Georgia resident's personal information in the most expedient time possible and without unreasonable delay.

Notify the information broker or data collector you maintain data for, of any breach you discover, so that party can meet its own notice duty.

+1 more
Georgia Law on Personal Data Protection, breach notification

An app that suffers an incident affecting the personal data of a person in Georgia must notify the State Audit Office within 72 hours of identification, and must notify affected data subjects immediately or without unreasonable delay where there is a high probability of significant damage or a significant threat to their fundamental rights.

Germany GDPR Articles 33-34, Breach Notification in Germany

Notify the competent German data protection authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Germany, unless the breach is unlikely to risk their rights and freedoms.

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

Ghana Data Protection Act, notification of security compromises

Notify the Data Protection Commission and the affected data subject as soon as reasonably practicable after you have reasonable grounds to believe personal data has been accessed or acquired by an unauthorised person.

Give the data subject enough information in the notification to take protective measures against the consequences of the breach, including the identity of the unauthorised person if known, and communicate it by registered mail, electronic mail, the website, media publication, or another manner the Commission directs.

Greece GDPR Articles 33-34, Breach Notification in Greece

Notify the Hellenic Data Protection Authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Greece, unless the breach is unlikely to risk their rights and freedoms.

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

Guam Notification of Breaches of Personal Information

Disclose a breach of the security of your system to any affected Guam resident without unreasonable delay once you know or reasonably believe the breach caused or will cause identity theft or other fraud.

If you hold a Guam resident's computerized personal information for another owner or licensee rather than for yourself, notify that owner or licensee as soon as practicable after discovering a breach.

Hawaii Hawaii Security Breach of Personal Information Act, notice of security breach from a date not yet set

Provide clear and conspicuous notice, without unreasonable delay, to a Hawaii resident affected by a security breach of a system containing their personal information, describing the incident, the type of information exposed, and remedial steps taken.

Notify the State of Hawaii's Office of Consumer Protection and nationwide consumer reporting agencies if the breach requires notifying more than 1,000 persons at one time.

Hungary Infotörvény Sections 25/J-25/K, Breach Notification, Inserted by Act XXXVIII of 2018

Notify NAIH without delay, and no later than 72 hours after becoming aware of it, of a personal-data breach affecting a person in Hungary, per Infotorveny Section 25/J(1).

Iceland Act No. 90/2018, Breach Notification in Iceland

Notify Personuvernd without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Iceland, unless the breach is unlikely to risk their rights and freedoms.

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

Idaho Identity Theft Act, breach of security disclosure duty from a date not yet set

Give notice to each affected Idaho resident as soon as possible, and in the most expedient time possible without unreasonable delay, after discovering a breach of system security involving personal information.

Illinois Personal Information Protection Act, data breach notification

Notify affected Illinois residents of a data breach in the most expedient time possible and without unreasonable delay after discovering unauthorized acquisition of their computerized personal information, which includes unique biometric data used to authenticate an individual.

Notify the Illinois Attorney General once a single breach affects more than 500 Illinois residents, or more than 250 residents for a State agency.

India Digital Personal Data Protection Act, 2023, breach notification duties from , in 7 months

India's data-breach notification duty, covering personal data including a biometric identifier, has not yet commenced and is scheduled to take effect . Once in force, an app must notify the Data Protection Board and each affected data principal of a personal data breach without delay, and must supply the Board a detailed follow-up report within 72 hours of becoming aware of the breach.

Indiana Disclosure of Security Breach Act from a date not yet set

Disclose a breach to affected Indiana residents without unreasonable delay and no later than 45 days after discovering that the unauthorized acquisition has resulted in or could result in identity deception, identity theft, or fraud.

Notify the Indiana Attorney General of any breach disclosure, and notify each nationwide consumer reporting agency if the breach affects more than 1,000 Indiana consumers.

Indonesia Law on Personal Data Protection, breach notification

An app that suffers a failure of personal data protection affecting an individual in Indonesia must give written notification within 72 hours to the affected individual and to the supervisory institution, describing the data disclosed and the remedial measures taken.

Iowa Personal Information Security Breach Protection from a date not yet set

Notify affected Iowa residents of a breach of security in the most expeditious manner possible and without unreasonable delay.

Notify the Iowa Attorney General's consumer protection division within five business days of notifying consumers, if the breach requires notifying more than 500 Iowa residents.

Ireland GDPR Articles 33-34, Breach Notification in Ireland

Notify the Data Protection Commission without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Ireland, unless the breach is unlikely to risk their rights and freedoms.

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

Israel Protection of Privacy Law, breach notification duty

An app that suffers a severe security incident affecting the personal data of a person in Israel must immediately notify the Head of the Privacy Protection Authority under the Data Security Regulations' Art. 11(d)(1) duty; the regulations' own text, including any data-subject notification duty, is not set out here and should be confirmed directly before relying on it for full compliance detail.

Italy GDPR Articles 33-34, Breach Notification

Notify the Garante within 72 hours of becoming aware of a personal-data breach affecting a person in Italy, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.

Jamaica Data Protection Act, 2020, reporting a contravention or security breach

Report any security breach in respect of your operations which affects or may affect personal data, and any contravention of the data protection standards, to the Information Commissioner within 72 hours of becoming aware of the breach or contravention, in the prescribed form and manner.

Notify the Information Commissioner without undue delay of any breach of your security measures which affects or may affect personal data.

+2 more
Japan Act on the Protection of Personal Information, breach notification

An app that suffers a leak, loss, or damage of personal data belonging to a person in Japan must report the incident to the Personal Information Protection Commission where it is likely to harm the data subject's rights and interests, following PPC-prescribed procedure and timing.

Jordan Personal Data Protection Law, breach notification

An app that suffers a serious breach of data security or safety that could cause significant harm to an individual in Jordan must notify the affected individuals within 24 hours of discovery and must notify the Unit within 72 hours of discovery with the source, mechanism, and affected individuals; a Controller found grossly negligent or engaged in misconduct in a breach is liable to compensate the affected Data Subject.

Kansas Kansas Breach Notification Act, notice of security breach from a date not yet set

Give notice to each affected Kansas resident as soon as possible, in the most expedient time possible and without unreasonable delay, if the investigation shows misuse occurred or is reasonably likely. There is no fixed numeric deadline in the statute; do not rely on a 45-day figure some secondary sources describe.

Notify each nationwide consumer reporting agency if more than 1,000 Kansas consumers are affected by one breach.

Kansas Student Data Privacy Act, breach notice for student data from a date not yet set

Immediately notify the affected Kansas student, or the student's parent or guardian, of a breach or unauthorized disclosure of student data if your entity has access to that data.

Kazakhstan Law on Personal Data and Their Protection, breach notification

An app that suffers a personal data security breach involving Kazakhstani data subjects must notify the competent authority from the moment the breach is detected. The Law sets no numeric deadline for that notice and, on the text read, imposes no separate duty to notify the affected individuals themselves.

Kentucky Notification to affected persons of computer security breach

Notify an affected Kentucky resident of a breach involving unencrypted personal information in the most expedient time possible and without unreasonable delay.

Notify each nationwide consumer reporting agency if more than 1,000 persons are affected at one time.

Kenya Data Protection Act, 2019, personal data breach notification

Notify the Data Commissioner within seventy-two hours of becoming aware of a personal data breach that carries a real risk of harm, giving reasons if you notify later.

As a data processor, notify the data controller within forty-eight hours of becoming aware of a breach.

+1 more
Kiribati Data Protection Act 2025, personal data breaches from a date not yet set

On commencement, notify the Digital Transformation Office of a personal data breach that has resulted in, or is likely to result in, significant harm to affected data subjects, as soon as practicable after becoming aware of the breach.

On commencement, notify each affected data subject of that same harmful personal data breach as soon as practicable after becoming aware of the breach, or by public notification through widely used media where direct notification is not feasible or would involve disproportionate effort or expense.

+2 more
Kosovo Law No. 06/L-082 on Protection of Personal Data, personal data breach notification

Notify the Agency for Information and Privacy of a personal data breach without delay and, where feasible, no later than seventy-two hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.

Give reasons for the delay if notifying the Agency after that seventy-two-hour period.

+3 more
Latvia GDPR Articles 33-34, Breach Notification in Latvia

Notify the Data State Inspectorate without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Latvia, unless the breach is unlikely to risk their rights and freedoms.

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

Lesotho Data Protection Act, 2011, notification of security compromises

Notify the Data Protection Commission and the affected data subject as soon as reasonably possible after discovering that a data subject's personal information has been accessed or acquired by an unauthorised person, unless the data subject's identity cannot be established.

Take into account the legitimate needs of law enforcement and any measures reasonably necessary to determine the scope of the compromise when timing your notification, but do not use that as a reason to delay beyond what is reasonably possible.

+2 more
Liechtenstein DSG Breach Notification in Liechtenstein

Notify the Datenschutzstelle without undue delay after becoming aware of a personal data breach affecting a person in Liechtenstein that presents a risk to their rights and freedoms, under the DSG.

Notify affected individuals where a breach presents a high risk to their rights and freedoms.

Lithuania GDPR Articles 33-34, Breach Notification in Lithuania

Notify VDAI without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Lithuania, unless the breach is unlikely to risk their rights and freedoms.

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

Louisiana Database Security Breach Notification Law, notice duty

Notify each affected Louisiana resident of a breach involving personal information in the most expedient time possible and without unreasonable delay, no later than 60 days after discovery.

If you delay notice, give the Attorney General written reasons for the delay.

Luxembourg GDPR Articles 33-34, Breach Notification in Luxembourg

Notify the CNPD without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Luxembourg, unless the breach is unlikely to risk their rights and freedoms.

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

Maine Notice of Risk to Personal Data from a date not yet set

Notify affected Maine residents of a breach of security as expediently as possible and without unreasonable delay, no more than 30 days after becoming aware of the breach and identifying its scope, absent a law enforcement delay.

Notify the appropriate Department of Professional and Financial Regulation regulator, or the Attorney General if you are not regulated by that department.

Malaysia Personal Data Protection Act, data protection officer and breach notification

An app that controls or processes the personal data of individuals in Malaysia must appoint a Data Protection Officer, and a data controller who reasonably believes a personal data breach has occurred must notify the Commissioner as soon as practicable, and must notify affected data subjects without unnecessary delay where the breach causes or is likely to cause significant harm.

Maldives Maldives Personal Data Protection Bill, personal data breach notification proposed

If enacted as drafted, a Controller would have to notify the Data Protection Authority within 72 hours of coming to know of, or reasonably believing in, a personal data breach involving special categories of personal data or data that could enable identity theft or fraud.

If enacted as drafted, the same section would require the affected data subjects to be told, on the same seventy-two-hour period and on the same trigger.

Malta GDPR Articles 33-34, Breach Notification in Malta

Notify the IDPC without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Malta, unless the breach is unlikely to risk their rights and freedoms.

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

Maryland Maryland Personal Information Protection Act (MPIPA), breach notification from a date not yet set

Notify each affected Maryland individual as soon as reasonably practicable, and no later than 45 days after discovering or being notified of the breach, once you determine a likelihood that personal information has been or will be misused.

Where notification is delayed because a law enforcement agency says it would impede an investigation, notify within 7 days after that delay is cleared, or by the original 45-day deadline, whichever is later.

Massachusetts Security Breach statute, duty to report breach of personal information from a date not yet set

Notify the Massachusetts Attorney General, the Director of Consumer Affairs and Business Regulation, and each affected Massachusetts resident as soon as practicable and without unreasonable delay after learning of a breach of security involving personal information.

Mauritius Data Protection Act 2017, personal data breach notification

Notify the Data Protection Commissioner without undue delay, and where feasible within 72 hours, of becoming aware of a personal data breach, giving reasons if notification is later.

Communicate a personal data breach to the affected data subject without undue delay where it is likely to result in a high risk to their rights and freedoms, unless an exception in section 26(3) applies.

Mexico Ley Federal de Protección de Datos Personales en Posesión de los Particulares, security-breach notice

Notify the affected data subject immediately of the breach, occurring at any stage of processing personal data, that significantly affects their patrimonial or moral rights.

Michigan Identity Theft Protection Act, breach of security notice duty

Give breach notice without unreasonable delay unless you determine the breach has not caused and is not likely to cause substantial loss, injury, or identity theft to affected Michigan residents.

Minnesota Minnesota breach notification from a date not yet set

Disclose a breach of the security of the system to an affected Minnesota resident in the most expedient time possible and without unreasonable delay. Minnesota sets no fixed numeric-day cap, unlike several peer states.

Notify the data owner immediately upon discovering a breach if you maintain, but do not own, the affected data.

Mississippi Breach notification law, notice of security breach

Disclose a breach of security to all affected Mississippi individuals without unreasonable delay, unless your investigation reasonably determines the breach will not likely result in harm.

Missouri Notice of security breach of personal information

Notify each affected Missouri consumer of a breach of security involving their personal information without unreasonable delay.

Notify the Missouri Attorney General's office and every nationwide consumer reporting agency without unreasonable delay if you provide notice to more than 1,000 consumers at one time.

Moldova Moldova Law No. 195/2024, personal data breach notification

Notify the National Centre for Personal Data Protection without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Moldova, unless the breach is unlikely to risk their rights and freedoms.

Communicate the breach to the affected data subject without undue delay where it is likely to result in a high risk to their rights and freedoms, in clear and plain language.

+2 more
Monaco Loi sur la Protection des Données Personnelles, notification des violations de données

Notify the Authority of a personal data breach as soon as possible and, where feasible, within 72 hours of becoming aware of the breach, unless it is unlikely to create a risk to the rights and freedoms of the persons concerned, and give the reasons for the delay when you notify later than that.

Communicate a personal data breach to the affected person as soon as possible, in clear language, when it is likely to create a high risk to their rights and freedoms.

+2 more
Mongolia Law on Protection of Personal Data, breach notification

An app that suffers a security breach of, or cyberattack on, an information system holding Mongolian personal data must submit a notification to the state digital-development and communications body, which must act on it in the shortest possible time. Whether the Act sets its own numeric deadline for the app's initial notification is not confirmed.

Montana Notification of security breach from a date not yet set

Notify affected Montana residents of a breach of security without unreasonable delay, and simultaneously submit an electronic copy of the notification to the Attorney General's consumer protection office.

Nebraska Nebraska Financial Data Protection and Consumer Notification of Data Security Breach Act from a date not yet set

Notify the Nebraska Attorney General no later than when you notify the affected resident, if notice to the resident is required.

Netherlands GDPR Articles 33-34 and UAVG Article 42, Breach Notification

Notify the AP within 72 hours of becoming aware of a personal-data breach affecting a person in the Netherlands, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them, subject to UAVG Article 42's national exception.

Nevada Security breach of personal information, notification from a date not yet set

Disclose a security breach of personal information to an affected Nevada resident in the most expedient time possible and without unreasonable delay. Nevada sets no fixed numeric deadline.

Notify each nationwide consumer reporting agency if you notify more than 1,000 persons of the breach at one time.

New Hampshire Notice of Security Breach

Notify affected New Hampshire residents and the Attorney General's office as soon as possible on determining a security breach of personal information occurred.

Notify consumer reporting agencies once notice is required for more than 1,000 residents.

New Jersey New Jersey Identity Theft Prevention Act, breach notification

Report a breach of security involving computerized personal records to the New Jersey Division of State Police before notifying the affected customer.

Disclose the breach to each affected New Jersey resident in the most expedient time possible and without unreasonable delay. New Jersey sets no fixed numeric-day cap.

New Mexico Data Breach Notification Act from a date not yet set

Notify each affected New Mexico resident of a security breach involving their personal identifying information in the most expedient time possible and no later than 45 calendar days after discovery.

Notify the New Mexico Attorney General's office and major consumer reporting agencies if the breach affects more than 1,000 New Mexico residents.

New York Stop Hacks and Improve Electronic Data Security (SHIELD) Act, breach notification duty

Disclose a breach of the security of your system to each affected New York resident in the most expedient time possible and without unreasonable delay, and no later than 30 days after discovering the breach.

Notify the New York Attorney General, the Department of State, and the Division of State Police of the breach, and notify each nationwide consumer reporting agency if you are notifying more than 5,000 New York residents at once.

New Zealand Privacy Act 2020, Notifiable Privacy Breaches

Notify the Privacy Commissioner as soon as practicable after becoming aware that a notifiable privacy breach, one reasonably believed to have caused or be likely to cause serious harm, has occurred.

Notify each affected individual, or give public notice if individual notice is not reasonably practicable, as soon as practicable after becoming aware of a notifiable privacy breach, unless a statutory exception or permitted delay applies.

Nicaragua Ley No. 787, Ley de Protección de Datos Personales, security incident notice

Where the personal data affected belong to a member of the National Police or the Army of Nicaragua, and the security measures the law requires fail or are not observed, immediately inform the affected institution of the breach.

Niger Loi n° 2022-59, notification des violations de données

Notify the HAPDP of a personal data breach without delay after becoming aware of it, and justify to the HAPDP any notification made outside that timeframe.

Notify the affected person of a personal data breach as soon as possible when it is likely to create a high risk to their rights and freedoms; you need not notify the person where it is reasonable to believe the breach creates no such risk.

+1 more
Nigeria Nigeria Data Protection Act, 2023, data breach notification

Notify the Commission of a personal data breach likely to result in a risk to individuals' rights and freedoms within 72 hours of becoming aware of it, describing the nature of the breach and, where feasible, the categories and approximate numbers of data subjects and records concerned.

Notify affected data subjects immediately after becoming aware of a breach likely to result in a high risk to their rights and freedoms.

+2 more
North Carolina Identity Theft Protection Act, security breach notification from a date not yet set

Notify each affected North Carolina resident of a security breach involving their personal information without unreasonable delay, consistent with the legitimate needs of law enforcement.

Notify the Consumer Protection Division of the North Carolina Attorney General's Office of every breach requiring notice to any affected person, not only breaches above the 1,000-person threshold.

North Dakota Notice of Security Breach for Personal Information from a date not yet set

Disclose a breach of the security system to any affected North Dakota resident in the most expedient time possible and without unreasonable delay.

Disclose the breach to the North Dakota Attorney General by mail or electronic mail if it exceeds 250 individuals.

North Macedonia Law on Personal Data Protection (LPDP), personal data breach notification

Once Chapter IV takes effect, notify the Agency of a personal data breach within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons, and give reasons for any delay beyond that period.

Once Chapter IV takes effect, communicate a personal data breach to the affected data subject without undue delay wherever the breach is likely to result in a high risk to their rights and freedoms, unless an exception such as prior encryption, later mitigation, or disproportionate effort applies.

Norway Personal Data Act, Breach Notification in Norway

Notify Datatilsynet without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Norway, unless the breach is unlikely to risk their rights and freedoms.

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

Ohio Security Breach Notification Act

Notify an affected Ohio resident of a security breach involving their personal information in the most expedient time possible and no later than 45 days after discovery.

Notify every nationwide consumer reporting agency without unreasonable delay if a single breach affects more than 1,000 Ohio residents.

Oklahoma Security Breach Notification Act

Provide notice of a breach of security involving personal information without unreasonable delay.

Notify the Oklahoma Attorney General within 60 days of consumer notice if the breach affects 500 or more Oklahoma residents (1,000 or more for a breach maintained by a credit bureau).

Oman Personal Data Protection Law, breach notification

An app that suffers a breach leading to the destruction, alteration, disclosure, access, or illegal processing of an individual's personal data in Oman must notify the Ministry and the affected Data Subject, following the procedure the Executive Regulations set; no specific notification timeline is confirmed at primary source.

Oregon Notice of breach of security from a date not yet set

Notify each affected Oregon consumer of a breach of security, including one you learn of through a vendor, and notify the Oregon Attorney General as well once more than 250 Oregon consumers are notified.

Panama Ley 81 de 2019, personal data breach notification

Notify the affected data subject as soon as possible after learning that their personal data was stolen without authorization or that its security was otherwise compromised. This Law sets no fixed number of hours or days for that notice and no duty to notify ANTAI of the breach.

As an operator of a public communications network, tell affected data subjects about a particular breach of your network's security and the measures you are taking, again with no fixed period stated.

Paraguay Ley N° 7593/2025, notificación de un incidente de seguridad from , in 14 months

Notify the National Data Protection Agency, and the affected person where relevant, of a security incident within 72 hours of becoming aware of it.

Pennsylvania Breach of Personal Information Notification Act

Notify each affected Pennsylvania resident of a breach of system security involving personal information without unreasonable delay.

Notify each nationwide consumer reporting agency if you notify more than 500 persons of a breach at one time.

Philippines Data Privacy Act of 2012, breach notification

An app that reasonably believes sensitive personal information or identity-fraud-enabling information of an individual in the Philippines has been acquired by an unauthorized person, in a way likely to cause serious harm, must promptly notify the National Privacy Commission and the affected individuals.

Poland GDPR Articles 33-34, Breach Notification

Notify UODO within 72 hours of becoming aware of a personal-data breach affecting a person in Poland, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.

Portugal GDPR Articles 33-34, Breach Notification in Portugal

Notify the CNPD without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Portugal, unless the breach is unlikely to risk their rights and freedoms.

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

Puerto Rico Ley de Información al Ciudadano sobre la Seguridad de Bancos de Información (data breach notification)

Notify affected Puerto Rico residents of a security breach of an information bank containing their personal information as expeditiously as possible.

Report the breach to the Department of Consumer Affairs within ten non-extendable days of detecting it.

+2 more
Qatar Personal Data Privacy Protection Law, breach notification

An app that is a Processor handling the personal data of an individual in Qatar, including a voiceprint or faceprint, must forthwith notify its Controller of any breach or risk of one, and a Controller must inform the affected individual and the Competent Department where a breach of security precautions may cause serious damage to the data or the individual's privacy; the PDPPL states no fixed notification timeline.

Québec Confidentiality incident notification and register

Where the incident presents a risk of serious injury, judged by the sensitivity of the information, the anticipated consequences and the likelihood of injurious use, promptly notify the Commission d’accès à l’information and each person whose personal information is concerned.

Republic of the Congo Law No. 29-2019, personal-data breach notification

Notify the national commission of a personal-data breach without undue delay and, where possible, within 72 hours of becoming aware of it, unless the breach is not likely to create a risk to the rights and freedoms of natural persons.

Communicate the breach to the affected data subject without undue delay, in clear and simple terms, where it is likely to create a high risk to their rights and freedoms.

+2 more
Rhode Island Identity Theft Protection Act of 2015, notification of breach from a date not yet set

Notify affected Rhode Island residents of a breach posing a significant risk of identity theft within 45 days of confirming the breach, or within 30 days if you are a state or municipal agency.

Notify the Attorney General and consumer reporting agencies once more than 500 Rhode Island residents are affected, without delaying notice to residents.

Romania GDPR Articles 33-34, Breach Notification

Notify ANSPDCP within 72 hours of becoming aware of a personal-data breach affecting a person in Romania, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.

Russia Federal Law No. 152-FZ, Article 21 Part 3.1, Breach Notification

Notify Roskomnadzor within 24 hours of detecting an unlawful or accidental transfer, provision, distribution, or access to personal data of a person in Russia, and file a full follow-up report within 72 hours.

Rwanda Law relating to the Protection of Personal Data and Privacy, personal data breach notification

Notify the supervisory authority of the breach within 48 hours of becoming aware of it.

As a data processor, notify the data controller of the breach within 48 hours of becoming aware of it.

+2 more
Samoa National Digital Identification Act 2024, personal data breach notification

As a relying party or data processor in the National Digital Identification System, notify the Registrar General of a personal data breach within 72 hours of becoming aware of it, describing the categories and approximate number of records concerned.

Where a personal data breach is likely to result in a high risk to a registered person's rights, ensure the Registrar General can communicate the breach to that person without undue delay, in plain language, with advice on mitigating measures.

San Marino San Marino Law No. 171, personal data breach notification

Notify the Data Protection Authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in San Marino, under Article 34.

Communicate the breach to the affected data subject without undue delay where it is likely to result in a high risk to their rights and freedoms, in clear and plain language.

+2 more
Saudi Arabia Personal Data Protection Law, breach notification

An app that suffers a breach, damage, or illegal access affecting the personal data of an individual in Saudi Arabia must notify the Competent Authority upon knowing of the breach, and must separately notify the Data Subject where the breach would cause damage to their data or prejudice their rights and interests, following the Implementing Regulations' procedure.

Serbia Law on Personal Data Protection, personal data breach notification

Notify the Commissioner of a breach that may create risk to a person's rights and freedoms without undue delay, and within 72 hours of becoming aware of the breach where that is possible; give reasons for any delay beyond 72 hours.

As a processor, notify the controller without undue delay after becoming aware of a breach.

+2 more
Seychelles Data Protection Act, 2023, personal data breach notification

Notify the Information Commission of a personal data breach no later than 72 hours after becoming aware of it, giving reasons for any later notification.

Promptly inform the affected data subjects where a breach is likely to affect a significant number of individuals and their rights and freedoms.

Singapore Personal Data Protection Act, data breach notification

An app that experiences a data breach affecting an individual's personal data in Singapore must assess whether the breach is likely to cause significant harm or is of significant scale, and if so must notify the PDPC as soon as practicable and in any case within 3 calendar days of that assessment, and must also notify each affected individual unless a statutory exception applies.

Slovakia GDPR Articles 33-34, Breach Notification

Notify the Slovak Office for Personal Data Protection within 72 hours of becoming aware of a personal-data breach affecting a person in Slovakia, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.

Slovenia GDPR Articles 33-34, Breach Notification

Notify the Slovenian Information Commissioner within 72 hours of becoming aware of a personal-data breach affecting a person in Slovenia, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.

Somalia Data Protection Act, 2023, personal data breach notification

Notify the Data Protection Authority of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals within 72 hours after becoming aware of it.

Where you extend that deadline for the legitimate needs of law enforcement or to determine the scope of the breach, tell the Authority the grounds for the extension, with supporting evidence, before the original deadline expires.

+2 more
South Africa Protection of Personal Information Act, notification of security compromises

Notify the Information Regulator of a security compromise as soon as reasonably possible after discovering that personal information has been accessed or acquired by an unauthorised person; the Act sets no fixed hour or day limit, only this standard.

Notify the affected data subject of the same security compromise as soon as reasonably possible after discovery, in writing, unless a law-enforcement body or the Regulator determines that notifying would impede a criminal investigation, or the data subject's identity cannot be established.

+2 more
South Carolina Business data breach of security, notification statute

Notify each affected South Carolina resident of a breach of security involving personal identifying information in the most expedient time possible and without unreasonable delay.

Notify the Consumer Protection Division of the Department of Consumer Affairs and all nationwide consumer reporting agencies if you notify more than 1,000 persons of a breach at one time.

South Dakota Breach of system security, notification statute

Notify each affected South Dakota resident of a breach of system security not later than 60 days after discovery, absent a law enforcement delay.

Notify the South Dakota Attorney General by mail or electronic mail if a breach affects 250 or more South Dakota residents. This threshold is 250, not 250,000.

South Korea Personal Information Protection Act, breach notification duties

An app that suffers a leak, theft, or unauthorized disclosure of Korean personal data must notify affected data subjects without delay, and must report the breach to the PIPC without delay if it affects 1,000 or more people, involves sensitive information such as a biometric identifier, or resulted from illegal external access.

Spain GDPR Articles 33-34 and LOPDGDD Article 69, Breach Notification

Notify the AEPD within 72 hours of becoming aware of a personal-data breach affecting a person in Spain, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.

Sri Lanka Personal Data Protection Act, breach notification duties

An app that suffers a personal data breach in Sri Lanka, including one involving a biometric identifier, must notify the Data Protection Authority in the form, manner, and time a rule made under the Act determines; whether and when the affected individual must also be told is set by a rule not yet located.

Suriname Draft Law on the Protection of Privacy and Personal Data, breach notification proposed

Notify the Commissioner for Personal Data Protection of a breach relating to personal data without delay, and no later than 72 hours after becoming aware of the breach, unless the breach is unlikely to pose a risk to individuals' rights and freedoms; if you do not notify within 72 hours, state the reasons for the delay.

Include in that notice, at minimum, the nature of the breach, the categories and approximate number of data subjects and records affected, your data protection officer's or another contact point's details, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.

+2 more
Sweden GDPR Articles 33-34, Breach Notification

Notify IMY within 72 hours of becoming aware of a personal-data breach affecting a person in Sweden, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.

Switzerland FADP Article 24, Breach Notification in Switzerland

Notify the FDPIC as soon as possible once you become aware of a data security breach likely to result in a high risk to a Swiss data subject's personality or fundamental rights.

Notify the affected individual only where necessary to protect them or where the FDPIC orders it; there is no fixed statutory hour count as there is under GDPR.

Syria Law No. 12 of 2024 on Protection of Electronic Personal Data, personal data breach notification

Notify the Authority immediately on becoming aware of the breach, and expect the Authority to immediately notify the competent authorities where the breach concerns national security matters.

Within seventy two hours of becoming aware of the breach, give the Authority a description of its nature, form and causes, the approximate number of records, persons and categories affected, the data protection officer's contact details, the breach's likely effects, the measures taken or proposed to address it, and documentation of the breach and the corrective action taken.

+1 more
Tanzania Personal Data Protection Act, 2022, security and breach notification

Notify the Personal Data Protection Commission without undue delay of any security breach affecting personal data you process.

Texas Identity Theft Enforcement and Protection Act, breach notification

Notify each affected Texas resident of a breach of system security involving their sensitive personal information without unreasonable delay and no later than 60 days after determining the breach occurred.

Notify the Texas Attorney General as soon as practicable and no later than 30 days after determining the breach occurred, if the breach affects 250 or more Texas residents.

+1 more
Thailand Personal Data Protection Act, breach notification

An app that experiences a personal data breach affecting an individual in Thailand must notify the Personal Data Protection Committee's Office without delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to pose a risk to the affected individuals; where the breach is likely to cause high risk, the app must also notify each affected individual without delay.

Tonga Privacy Act 2025, personal information breaches from a date not yet set

Notify the Privacy Commission within 72 hours of becoming aware of a personal information breach that is likely to result in a risk to the rights and freedoms of individuals, describing its nature and, where possible, the categories and approximate numbers of data subjects and records concerned.

As a data processor, notify the data controller or the data processor that engaged you within 72 hours of becoming aware of a personal information breach, and answer their information requests without undue delay.

+1 more
Turkey Personal Data Protection Law (KVKK), breach notification

An app that suffers unlawful acquisition of personal data belonging to a person in Turkey must notify the affected data subject and the Board within the shortest time; KVKK sets no fixed numeric deadline in its own text.

Uganda Data Protection and Privacy Act, 2019, breach notification

Notify the National Information Technology Authority immediately after you believe personal data has been accessed or acquired by an unauthorised person, describing the access or acquisition and the remedial action taken.

Wait for the Authority to determine whether you must also notify the affected data subject of the breach; the Act sets no separate deadline for that notice.

+2 more
Ukraine Draft Law No. 8153, personal data breach notification proposed

Once enacted, notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it.

Once enacted, include in that notification the nature of the breach, the number of affected individuals, the data types involved, the likely consequences, and the remedial measures taken.

United Arab Emirates ADGM Data Protection Regulations, breach notification

An app that is a controller or processor established in or targeting the ADGM free zone and that suffers a personal data breach must notify the Commissioner of Data Protection without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to pose a risk to individuals' rights.

United Arab Emirates Federal Decree-Law on the Protection of Personal Data, breach notification

An app that suffers a breach affecting the personal data of an individual in the onshore UAE must notify the Bureau at the time it becomes aware of the breach; the Decree-Law defers the specific notification window to Executive Regulations whose text could not be confirmed at primary source, so an app should not assume a specific hour count without checking current regulator guidance.

United Kingdom UK GDPR Articles 33-34 and PECR, Breach Notification in the United Kingdom

Notify the ICO without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in the United Kingdom, unless the breach is unlikely to risk their rights and freedoms.

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms, and if you are a telecoms or ISP-type provider, notify a PECR breach to the ICO within 72 hours.

United States GLBA Safeguards Rule Breach Notification Amendment

Notify the FTC within 30 days of discovering a security event that has compromised unencrypted customer information for 500 or more consumers.

United States HIPAA Breach Notification Rule

Notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach of unsecured protected health information.

Notify HHS, and for a breach affecting more than 500 residents of a state, prominent media outlets serving that state.

United States Virgin Islands Disclosure of Breach of Security (Identity Theft and Privacy Protection)

Notify an affected Virgin Islands resident without unreasonable delay after discovering that unencrypted personal information (a name combined with a Social Security number, driver's license number, or financial account number with its access code) was acquired without authorization.

Where direct notice is impractical because of cost, the number of residents affected, or insufficient contact information, give substitute notice by email, a conspicuous website posting, and notice to major territory-wide media.

Uruguay Ley N° 19.670, personal data breach notification

Notify the affected data subjects immediately and in detail on becoming aware of the breach, describing the measures adopted to address it.

Notify the Unidad Reguladora y de Control de Datos Personales immediately and in detail on becoming aware of the breach, coordinating your response with the national cybersecurity incident response center (CERTuy).

Utah Protection of Personal Information Act

If unencrypted Utah-resident data combining a name with a Social Security number, a driver license or state ID number, or a financial account or card number with its access code is breached, investigate promptly in good faith and notify each affected Utah resident without unreasonable delay.

Notify the Utah Attorney General and the Utah Cyber Center if the breach affects 500 or more Utah residents, and notify nationwide consumer reporting agencies if it affects 1,000 or more.

Vermont Security Breach Notice Act

Notify an affected Vermont consumer of a security breach in the most expedient time possible and without unreasonable delay, and no later than 45 days after discovery.

Notify the Attorney General or the Department of Financial Regulation, as applicable, with a preliminary description of the breach within 14 business days of discovery.

Vietnam Law on Personal Data Protection, breach notification

An app that detects a violation of Vietnam's personal data protection rules likely to cause harm to national defense and security, social order, or an individual's life, health, honor, dignity, or property must notify the agency in charge of personal data protection within 72 hours.

Virginia Breach of personal information notification from a date not yet set

Notify the Virginia Office of the Attorney General and each affected Virginia resident of a breach of system security involving personal information without unreasonable delay after discovery.

Washington Notice of security breaches involving personal information

Notify affected Washington residents of a breach of unsecured personal information, including biometric identifiers, in the most expedient time possible and no more than 30 calendar days after discovery.

Notify the Washington Attorney General of any breach affecting more than 500 Washington residents.

West Virginia Breach of Security of Consumer Information from a date not yet set

Notify each affected West Virginia resident of a breach of security involving personal information without unreasonable delay.

Notify each nationwide consumer reporting agency if you are required to notify more than 1,000 persons of a breach.

Wisconsin Notice of unauthorized acquisition of personal information from a date not yet set

Make reasonable efforts to notify each affected Wisconsin individual of an unauthorized acquisition of their personal information within a reasonable time, not to exceed 45 days after learning of it.

Notify consumer reporting agencies if a single incident requires notifying 1,000 or more individuals.

Wyoming Breach of the security of a computerized data system, notification duty from a date not yet set

Give notice as soon as possible to each affected Wyoming resident once your investigation determines misuse of their personal identifying information has occurred or is reasonably likely.

Zambia Data Protection Act, 2021, notification of a security breach

Notify the Data Protection Commissioner within 24 hours of the breach occurring: section 49(1) runs the period from the security breach itself, not from the moment you learn of it.

Notify the affected data subject as soon as practicable of any security breach affecting their personal data.

+2 more
Zimbabwe Cyber and Data Protection Act, security breach notification

Notify the Data Protection Authority within 24 hours of discovering a security breach affecting personal data you process.

Treat every security breach affecting the data you process as notifiable under section 19: the Act sets no risk threshold below which the duty falls away.

Zimbabwe Cyber and Data Protection Regulations 2024, security breach notification

Report a personal data breach to the Authority within 24 hours of becoming aware of it, on Form DP3 in the Fourth Schedule.

Inform the affected data subjects within 72 hours of the breach where it is likely to result in a high risk of adversely affecting individuals' rights and freedoms.

+1 more

Comprehensive regime

5 laws, 5 places
PlaceLawWhat it asks, as read here
Cameroon Loi n°2024/017 du 23 décembre 2024 relative à la protection des données à caractère personnel au Cameroun from a date not yet set

Notify the data protection authority of a personal-data breach without delay, and inform an affected person where their rights are threatened; submit an annual security report to the authority.

Cuba Ley 149/2022, De Protección de Datos Personales, general regime

Notify the competent authority of cybersecurity incidents affecting personal data held in a registry, file, archive, or database under your custody.

South Africa Protection of Personal Information Act 4 of 2013 (POPIA)

Where an operator processes personal information on your behalf, bind it by written contract to the same security measures, and require it to notify you immediately if it has reasonable grounds to believe the information was accessed or acquired by an unauthorised person.

Taiwan Personal Data Protection Act (個人資料保護法)

Notify an affected individual when personal data held has been stolen, altered, damaged, lost, or leaked, and report the incident to the Personal Data Protection Commission where the circumstances fall within the reporting scope the Commission has specified.

Uruguay Ley N° 18.331, Personal Data Protection and Habeas Data Law, as amended

If you operate a public communications network or offer an electronic communications service, secure the network and the service, and tell subscribers about any particular risk of a security breach and the measures to take.

Data subject rights

2 laws, 2 places
PlaceLawWhat it asks, as read here
Jordan Personal Data Protection Law, data subject rights

An app must let an individual in Jordan object to processing or profiling of their data that is unnecessary, excessive, discriminatory, or unlawful for its stated purpose, must let them obtain erasure or concealment of their data and a portable copy transferable to another controller, and must notify them of any data breach affecting the security or integrity of their data.

Oman Personal Data Protection Law, data subject rights

An app must let an individual in Oman revoke their consent, request amendment or blocking of their data, obtain a copy of it, transfer it to another controller, request its erasure (unless national archiving requires otherwise), and must notify them of any breach or infringement of their personal data and the actions taken in response; these rights apply to a voiceprint, faceprint, or other biometric identifier like any other personal data.

Cross border transfer

1 law, 1 place
PlaceLawWhat it asks, as read here
Cuba Resolución 58/2022 (MINCOM), security and localization rules for personal data in electronic form

Notify the competent authorities of cybersecurity incidents affecting personal data in electronic form under your custody.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.