Chapter 26

External Notification and Regulatory Obligations

Regulatory notification frameworks, breach notification timelines, individual notification requirements, and what to say — and not say — in each type of notification.

Scenario

Day 5 of a breach investigation. Legal confirms: the exfiltrated data included personal health information for approximately 12,000 patients. HIPAA requires notification to HHS within 60 days and to affected individuals without "unreasonable delay." Your organization is also subject to California's CCPA, which has its own notification requirements, and the GDPR because some patients were EU residents who used your telehealth service. Three different regulatory frameworks, three different deadlines, and two different definitions of "personal data." This chapter explains how to manage multiple parallel notification obligations without missing a deadline.

Notification Framework Matrix

FrameworkTriggerDeadline from discoveryRequired content
GDPR (EU/EEA)Personal data breach likely to result in risk to individuals72 hours to supervisory authority; without undue delay to individuals (if high risk)Nature of breach, categories of data, approx. number of individuals, likely consequences, measures taken
HIPAA (US healthcare)Breach of unsecured PHI affecting 500+ in a state60 days: HHS + affected individuals + media. Under 500: annual HHS log, 60 day individual notice.Description, types of PHI involved, who may have accessed it, steps individuals should take, contact information
CCPA/CPRA (California)Unauthorized access to specific categories of CA resident personal info"In the most expedient time possible" — no specific clock, but 45-day safe harbor for AGBreach description, type of information, timeframe, description of the business response
NY SHIELD ActPrivate information of NY residents accessed without authorization"In the most expedient time possible and without unreasonable delay"Similar to state AG notification; written notice to affected NY residents
SEC Rule (US public companies)Material cybersecurity incident4 business days after determining materialityForm 8-K Item 1.05: nature, scope, timing, material impact

GDPR Notification Process

GDPR's 72-hour clock starts from the moment the organization becomes "aware" of the breach — typically when the security team informs the DPO or legal counsel, not when the breach occurred.

  GDPR Notification Workflow
  ═══════════════════════════════════════════════════════════════════

  Hour 0: Security team confirms breach affecting EU personal data
          → Notify DPO (Data Protection Officer) immediately
          → DPO + Legal: is this a "notifiable" breach?
            (does it risk rights and freedoms of individuals?)

  Hour 0-48: Investigation continues
          → Document what data, how many individuals, what impact
          → Prepare Article 33 notification draft

  Hour 72 DEADLINE: Notify lead supervisory authority (DPA)
          → If you miss the 72 hours: notify with explanation of delay
            (fines increase significantly for unjustified late notification)

  Article 33 notification must contain:
    ├── Nature of the breach
    ├── Categories and approximate number of data subjects
    ├── Categories and approximate number of records
    ├── Name and contact details of DPO
    ├── Likely consequences of the breach
    └── Measures taken or proposed to address the breach

  If high risk to individuals: ALSO notify affected individuals
  (Article 34 — without undue delay)

Individual Notification Content

Individual breach notifications must be clear, accurate, and actionable. They must not cause unnecessary alarm, but they cannot minimize the risk either. Every word is potentially exhibit A in a class action.

  Individual Notification Letter Structure
  ═══════════════════════════════════════════════════════════════════

  1. What happened
     Plain language, factual, no jargon.
     "On [date], we discovered that an unauthorized person gained
     access to [system] and may have obtained information about
     [your/our] [account holders/patients]."

  2. What information was involved
     Specific data types affected: "name, address, and Social Security
     number" — not vague categories. If you know, say it. If you don't
     know for certain, say "may have included."

  3. What we are doing
     Concrete steps already taken: containment, investigation, patches.
     Concrete steps being taken: monitoring, credit monitoring offer, etc.

  4. What you can do
     Specific, actionable steps: fraud alert, credit freeze, change
     passwords for accounts that used the same password. Contact
     information for credit bureaus.

  5. Contact information
     A dedicated breach response email/phone number with extended hours.
     Not the general customer service line — a line staffed specifically
     for this incident with trained agents.

  6. Free credit monitoring offer (common practice for SSN breaches)
     Credit monitoring enrollment code and provider contact.
     Required by some state laws; best practice for SSN/financial data breaches.

Managing Multiple Simultaneous Notification Obligations

DayAction
Day 1 (breach confirmed)Notify DPO, General Counsel, CISO. Engage outside counsel with regulatory practice in all relevant jurisdictions.
Day 1-2Outside counsel determines which regulations apply and confirms timelines. Begin draft of each required notification.
Day 3 (72 hours — GDPR)File Article 33 notice with lead supervisory DPA. May be preliminary — GDPR allows updating the notification as investigation continues.
Day 4 (material determination — SEC)If material: file 8-K within 4 business days of materiality determination (not of discovery).
Day 30-45State AG notifications (varies by state). Individual notification letters sent.
Day 60 (HIPAA)HHS OCR notification filed (Breach Reporting Tool at hhs.gov). Individual notifications must also be sent by this date.

Q & A

Q: You're still investigating whether EU residents' data was affected. The 72-hour GDPR clock is running. Do you notify before you've confirmed the EU resident scope?

Yes — GDPR explicitly accounts for investigations that aren't complete at 72 hours. Article 33(4) allows notification in phases: file the initial notification with what you know, note that the investigation is ongoing, and update the supervisory authority as more information becomes available. The notification can state: "The number of EU data subjects affected is currently under investigation. We will provide an update within [X] days." Failing to notify within 72 hours because the investigation isn't complete is a far greater regulatory risk than filing a preliminary notification that acknowledges the limitation. The supervisory authority would rather receive an incomplete notification on time than a complete one late. Document the timeline of your awareness and the evolving scope determination — this is your defense if the initial notification understates the scope.

Q: Your organization has no EU operations and no EU customers — but the attacker was located in the EU. Does GDPR apply?

No — GDPR's Article 3 applies based on the location of the data subjects (EU/EEA residents whose personal data was processed), not the location of the attacker. If your organization doesn't process personal data of EU/EEA residents, GDPR doesn't apply to this incident regardless of where the attacker is located. Double-check: (1) Do you have any EU employees? (2) Do any of your customers, patients, or users include EU/EEA residents? (3) Do you have a subsidiary, office, or web service targeting EU residents? If yes to any of these, GDPR may apply. If genuinely no, document that determination in writing with outside counsel's sign-off — a "we determined GDPR does not apply because [reasons]" memo protects you more than silence if the DPA later inquires.