
THREAT‑WATCH
Glossary
Breach Notification
The legal obligation to inform regulators and, in some cases, affected individuals after a qualifying data breach.
Under GDPR, organizations generally must notify their supervisory authority within 72 hours of becoming aware of a breach likely to risk individuals' rights; affected individuals must also be notified if the risk is high. NIS2 imposes its own, often stricter and sector-specific, incident-reporting deadlines (an early warning within 24 hours in many transpositions). Missing these windows is itself a compliance failure, separate from the breach.