Governance & Operations

What is Data Breach Notification?

Data breach notification is the legal obligation to inform regulators and affected individuals when personal data is exposed, stolen, or destroyed — within 72 hours to supervisory authorities under GDPR, and under breach statutes in all 50 US states.

Under GDPR, a 'personal data breach' is any security incident leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data — broader than hacking, covering lost laptops, misdirected emails, and ransomware. Article 33 requires controllers to notify the supervisory authority without undue delay and where feasible within 72 hours of becoming aware, unless the breach is unlikely to risk individuals' rights; late notifications must explain the delay. Article 34 adds direct notice to affected individuals when the risk is high, and processors must inform their controllers without undue delay.

In the US, breach notification is the one privacy obligation with truly national coverage: every state has a breach statute, each with its own definitions of covered data, thresholds, deadlines, and attorney-general notice rules. California adds a unique enforcement layer — the CCPA's private right of action lets consumers claim $100 to $750 per consumer per incident, without proving actual damages, when unencrypted personal information is breached because of unreasonable security. Sector rules (HIPAA, GLBA, the SEC's disclosure requirements for public companies) stack on top.

The 72-hour clock makes preparation the whole game. It starts at awareness, and three days is not enough time to discover what data you hold, which systems were touched, and who is affected — unless a data map and an incident-response plan already exist. Mature programs pre-stage the decision framework: severity assessment, notification triggers per jurisdiction, regulator contacts, template notices, and forensic and legal counsel on call.

Documentation is mandatory even when notification is not: GDPR requires an internal record of every breach, including the reasoning for not notifying — a record regulators review when the next incident surfaces.

Why it matters for eCommerce

eCommerce breaches are as likely to originate in a vendor as in your own systems — a compromised app, a skimmed checkout script, a marketing platform incident. Your notification duties do not shrink because a processor was the entry point, and their obligation is to tell you, promptly. Keep breach-notice commitments in every DPA, know each state's rules where your customers live, and rehearse the 72-hour drill before it is real.

Frequently asked questions

When does the GDPR 72-hour clock start?
When the controller becomes 'aware' — has a reasonable degree of certainty a breach occurred — not when the incident began. Investigating within an incident-response process is expected, but awareness cannot be indefinitely deferred, and the notification can be supplemented in phases.
Do all breaches have to be reported?
No. GDPR requires regulator notification unless the breach is unlikely to risk individuals, and individual notice only for high risk. US state laws have their own thresholds, often keyed to specific data types. Every breach must be internally documented regardless.
What are the penalties for breach mishandling in California?
The CCPA gives consumers a private right of action for breaches of unencrypted personal information due to unreasonable security: statutory damages of $100-$750 per consumer per incident, no proof of harm required — which turns a million-record breach into automatic nine-figure exposure on paper.

Related terms

Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.

Run a free scan

← Back to all glossary terms