When must you notify after a breach?
Pick the jurisdictions you operate in and an incident time. This shows each regime's notification clock, who to notify, and a computed deadline where the clock is fixed. During a real incident, minutes matter — know the clocks before you're in one.
72 hours to the DPA; to individuals “without undue delay” if high risk
Notify: Supervisory authority (DPA); affected individuals if high risk
GDPR Articles 33 & 34
4 business days after determining the incident is material
Notify: SEC (public filing)
SEC Cybersecurity Disclosure Rules (2023), 8-K Item 1.05
Not legal advice. These are simplified summaries of complex regulations with many conditions, thresholds, and exceptions. The clock trigger (e.g. “awareness” vs “materiality determination”) is often contested. Always confirm exact obligations with qualified legal counsel.