External Notification and Regulatory Obligations
Regulatory notification frameworks, breach notification timelines, individual notification requirements, and what to say — and not say — in each type of notification.
Day 5 of a breach investigation. Legal confirms: the exfiltrated data included personal health information for approximately 12,000 patients. HIPAA requires notification to HHS within 60 days and to affected individuals without "unreasonable delay." Your organization is also subject to California's CCPA, which has its own notification requirements, and the GDPR because some patients were EU residents who used your telehealth service. Three different regulatory frameworks, three different deadlines, and two different definitions of "personal data." This chapter explains how to manage multiple parallel notification obligations without missing a deadline.
Notification Framework Matrix
| Framework | Trigger | Deadline from discovery | Required content |
|---|---|---|---|
| GDPR (EU/EEA) | Personal data breach likely to result in risk to individuals | 72 hours to supervisory authority; without undue delay to individuals (if high risk) | Nature of breach, categories of data, approx. number of individuals, likely consequences, measures taken |
| HIPAA (US healthcare) | Breach of unsecured PHI affecting 500+ in a state | 60 days: HHS + affected individuals + media. Under 500: annual HHS log, 60 day individual notice. | Description, types of PHI involved, who may have accessed it, steps individuals should take, contact information |
| CCPA/CPRA (California) | Unauthorized access to specific categories of CA resident personal info | "In the most expedient time possible" — no specific clock, but 45-day safe harbor for AG | Breach description, type of information, timeframe, description of the business response |
| NY SHIELD Act | Private information of NY residents accessed without authorization | "In the most expedient time possible and without unreasonable delay" | Similar to state AG notification; written notice to affected NY residents |
| SEC Rule (US public companies) | Material cybersecurity incident | 4 business days after determining materiality | Form 8-K Item 1.05: nature, scope, timing, material impact |
GDPR Notification Process
GDPR's 72-hour clock starts from the moment the organization becomes "aware" of the breach — typically when the security team informs the DPO or legal counsel, not when the breach occurred.
GDPR Notification Workflow
═══════════════════════════════════════════════════════════════════
Hour 0: Security team confirms breach affecting EU personal data
→ Notify DPO (Data Protection Officer) immediately
→ DPO + Legal: is this a "notifiable" breach?
(does it risk rights and freedoms of individuals?)
Hour 0-48: Investigation continues
→ Document what data, how many individuals, what impact
→ Prepare Article 33 notification draft
Hour 72 DEADLINE: Notify lead supervisory authority (DPA)
→ If you miss the 72 hours: notify with explanation of delay
(fines increase significantly for unjustified late notification)
Article 33 notification must contain:
├── Nature of the breach
├── Categories and approximate number of data subjects
├── Categories and approximate number of records
├── Name and contact details of DPO
├── Likely consequences of the breach
└── Measures taken or proposed to address the breach
If high risk to individuals: ALSO notify affected individuals
(Article 34 — without undue delay)
Individual Notification Content
Individual breach notifications must be clear, accurate, and actionable. They must not cause unnecessary alarm, but they cannot minimize the risk either. Every word is potentially exhibit A in a class action.
Individual Notification Letter Structure
═══════════════════════════════════════════════════════════════════
1. What happened
Plain language, factual, no jargon.
"On [date], we discovered that an unauthorized person gained
access to [system] and may have obtained information about
[your/our] [account holders/patients]."
2. What information was involved
Specific data types affected: "name, address, and Social Security
number" — not vague categories. If you know, say it. If you don't
know for certain, say "may have included."
3. What we are doing
Concrete steps already taken: containment, investigation, patches.
Concrete steps being taken: monitoring, credit monitoring offer, etc.
4. What you can do
Specific, actionable steps: fraud alert, credit freeze, change
passwords for accounts that used the same password. Contact
information for credit bureaus.
5. Contact information
A dedicated breach response email/phone number with extended hours.
Not the general customer service line — a line staffed specifically
for this incident with trained agents.
6. Free credit monitoring offer (common practice for SSN breaches)
Credit monitoring enrollment code and provider contact.
Required by some state laws; best practice for SSN/financial data breaches.
Managing Multiple Simultaneous Notification Obligations
| Day | Action |
|---|---|
| Day 1 (breach confirmed) | Notify DPO, General Counsel, CISO. Engage outside counsel with regulatory practice in all relevant jurisdictions. |
| Day 1-2 | Outside counsel determines which regulations apply and confirms timelines. Begin draft of each required notification. |
| Day 3 (72 hours — GDPR) | File Article 33 notice with lead supervisory DPA. May be preliminary — GDPR allows updating the notification as investigation continues. |
| Day 4 (material determination — SEC) | If material: file 8-K within 4 business days of materiality determination (not of discovery). |
| Day 30-45 | State AG notifications (varies by state). Individual notification letters sent. |
| Day 60 (HIPAA) | HHS OCR notification filed (Breach Reporting Tool at hhs.gov). Individual notifications must also be sent by this date. |
Q & A
Q: You're still investigating whether EU residents' data was affected. The 72-hour GDPR clock is running. Do you notify before you've confirmed the EU resident scope?
Yes — GDPR explicitly accounts for investigations that aren't complete at 72 hours. Article 33(4) allows notification in phases: file the initial notification with what you know, note that the investigation is ongoing, and update the supervisory authority as more information becomes available. The notification can state: "The number of EU data subjects affected is currently under investigation. We will provide an update within [X] days." Failing to notify within 72 hours because the investigation isn't complete is a far greater regulatory risk than filing a preliminary notification that acknowledges the limitation. The supervisory authority would rather receive an incomplete notification on time than a complete one late. Document the timeline of your awareness and the evolving scope determination — this is your defense if the initial notification understates the scope.
Q: Your organization has no EU operations and no EU customers — but the attacker was located in the EU. Does GDPR apply?
No — GDPR's Article 3 applies based on the location of the data subjects (EU/EEA residents whose personal data was processed), not the location of the attacker. If your organization doesn't process personal data of EU/EEA residents, GDPR doesn't apply to this incident regardless of where the attacker is located. Double-check: (1) Do you have any EU employees? (2) Do any of your customers, patients, or users include EU/EEA residents? (3) Do you have a subsidiary, office, or web service targeting EU residents? If yes to any of these, GDPR may apply. If genuinely no, document that determination in writing with outside counsel's sign-off — a "we determined GDPR does not apply because [reasons]" memo protects you more than silence if the DPA later inquires.