Close-up of Scrabble tiles spelling 'data breach' on a blurred background

Photo by Markus Winkler on Pexels

A 72-hour breach deadline usually starts when an organization becomes aware that a personal-data breach has occurred, not when investigators finish measuring the damage. Under the EU General Data Protection Regulation, the organization must notify the relevant supervisory authority within 72 hours where feasible, unless the breach is unlikely to put people’s rights and freedoms at risk.

That distinction changes the first three days of incident response. Teams cannot wait for perfect certainty. They need enough verified information to decide whether notification applies, submit what they know, and explain what remains under investigation.

Hours 0 to 6: Establish what happened and preserve the evidence

The first alert may look ordinary: unusual account activity, an exposed storage bucket, a stolen laptop, or a support ticket reporting data visible to the wrong customer. The immediate job is to contain the incident without destroying the evidence needed to understand it.

Someone must record when the organization first became aware of a credible personal-data breach. That timestamp matters because the legal clock may depend on awareness, while internal teams may be tempted to use a later milestone such as executive confirmation or completion of forensic analysis.

During these first hours, responders should preserve logs, restrict affected credentials, isolate compromised systems where appropriate, and establish a written incident record. They should also identify the decision-makers across security, legal, privacy, communications, customer support, and senior management.

The hardest early question is deceptively simple: do the available facts show a personal-data breach, or merely suspicious activity? The answer can change as evidence arrives. Documenting why the team reached each conclusion is therefore as important as recording the conclusion itself.

Hours 6 to 24: Define the affected data and the likely risk

By this stage, the investigation needs to move beyond “a system was accessed.” The team should determine which records were involved, whose data they contained, and whether an unauthorized party could read, copy, alter, or delete them.

Useful questions include:

  • Which systems, databases, accounts, and backups are affected?
  • What categories of personal data were involved?
  • Were credentials, financial details, health information, identity documents, or children’s data exposed?
  • How many people may be affected?
  • Was the data encrypted, and could the attacker access the keys?
  • Is there evidence of extraction, publication, misuse, or attempted resale?
  • Which countries and legal entities are involved?

Exact answers may remain unavailable. Record ranges and confidence levels instead of turning estimates into facts.

Legal and privacy teams should begin the notification assessment while technical work continues. Waiting for forensics to “finish” creates a false sequence. The two tracks need to run together, with investigators feeding confirmed findings into a decision record.

Jurisdiction also matters. The GDPR’s 72-hour rule is widely cited, but other regimes use different triggers, deadlines, definitions, and recipients. Some require notice to regulators, affected individuals, customers, insurers, law enforcement, or contractual partners. A company operating across borders may face several clocks at once.

Hours 24 to 48: Make the notification decision with incomplete information

The second day is where weak preparation becomes visible. Contact lists are stale. Nobody owns the regulator account. The data inventory names a database but not the customers inside it. A processor has acknowledged the incident but has not supplied usable logs.

This is also the point when internal incentives can distort the response. Technical teams may want more evidence. Executives may fear reputational damage. Communications staff may want language that sounds reassuring. None of those concerns changes the deadline.

The notification decision should rest on the applicable legal threshold and the evidence available at that time. If the organization decides notification is unnecessary, it should document the facts, risk analysis, assumptions, and responsible approvers. If notification is required, drafting should begin before every field can be completed.

Under the GDPR, an initial notification can be supplemented in phases when all information cannot be provided at once. That makes an honest preliminary filing safer than delaying solely to produce a polished final account. The notice should distinguish confirmed facts from estimates and open questions.

This is the same discipline needed during a difficult production incident: preserve the difference between what the logs show and what the team suspects. The 2 A.M. Alert Packet explains why collecting that evidence before an emergency reduces confusion when decisions become time-sensitive.

Hours 48 to 72: File, communicate, and keep investigating

The final day should focus on approval and delivery, not first-draft discovery. Confirm the correct authority, submission method, filing entity, and contact person. Check that the notice covers the nature of the breach, likely consequences, affected people and records where known, and measures taken or proposed.

Do not fill gaps with confident language. State what remains unknown, why it is unknown, and when the next update is expected. If filing occurs after the deadline, record and explain the reasons for delay.

Regulator notification and communication to affected people are separate decisions. Under the GDPR, informing individuals generally depends on whether the breach is likely to create a high risk to their rights and freedoms. Other laws may apply different standards. Customer contracts may impose additional duties even where a statutory notice is unnecessary.

Once the filing is sent, preserve the submission receipt and the exact version delivered. Continue the investigation, update authorities when material facts change, and prepare support teams for questions they can answer without speculation.

The practical preparation happens before hour zero. Run a timed exercise, assign one person to own the clock, pre-authorize alternates, verify regulator access, map systems to data categories, and keep a notification template ready. At hour 71, the most valuable document is the one the team tested months earlier.

Comments

No comments yet.