THREAT-WATCH logo

THREAT‑WATCH

Glossary

Breach Notification

The legal obligation to inform regulators and, in some cases, affected individuals after a qualifying data breach.

Under GDPR, organizations generally must notify their supervisory authority within 72 hours of becoming aware of a breach likely to risk individuals' rights; affected individuals must also be notified if the risk is high. NIS2 imposes its own, often stricter and sector-specific, incident-reporting deadlines (an early warning within 24 hours in many transpositions). Missing these windows is itself a compliance failure, separate from the breach.