Breach Notification Clock · free

When must you notify after a breach?

Pick the jurisdictions you operate in and an incident time. This shows each regime's notification clock, who to notify, and a computed deadline where the clock is fixed. During a real incident, minutes matter — know the clocks before you're in one.

European UnionGDPR Art. 33/34
Aug 17, 2026, 6:43 PM

72 hours to the DPA; to individuals “without undue delay” if high risk

Notify: Supervisory authority (DPA); affected individuals if high risk

GDPR Articles 33 & 34

United States (public cos.)SEC Form 8-K Item 1.05
Aug 20, 2026, 6:43 PM

4 business days after determining the incident is material

Notify: SEC (public filing)

SEC Cybersecurity Disclosure Rules (2023), 8-K Item 1.05

Practise managing a breach

Not legal advice. These are simplified summaries of complex regulations with many conditions, thresholds, and exceptions. The clock trigger (e.g. “awareness” vs “materiality determination”) is often contested. Always confirm exact obligations with qualified legal counsel.

Breach Notification Deadline Calculator — GDPR, SEC & more (free) · PlayCISO