Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Category: Incident & Breach Response

72-Hour Notification Requirement

Also known as: 72-Hour Rule, 72-Hour Breach Notification, 72-Hour Incident Reporting Requirement
Simply put

The 72-hour notification requirement is a rule found in several different laws and regulations that generally requires an organization to report a qualifying data breach or cyber incident to a designated authority within 72 hours. The exact trigger, recipient, and content of the report depend on which specific regime applies, so the same phrase can mean different things across sectors and jurisdictions. It is not a single universal standard, and organizations must identify which particular obligation governs their situation.

Formal definition

"72-Hour Notification Requirement" is an informal umbrella label for a group of distinct legal and regulatory obligations, each imposing a maximum 72-hour window to notify a specified body following a qualifying event. Under the EU GDPR, a controller must generally notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach that meets the applicable threshold (with certain exceptions and separate rules for processors and for communicating to data subjects). Distinct U.S. regimes use a comparable window but differ in trigger, scope, and recipient: NCUA rules require federally insured credit unions to notify the NCUA as soon as possible and no later than 72 hours after a reportable cyber incident (per the evidence, from September 1, 2023); CIRCIA-related provisions concern reporting significant cyber incidents affecting critical infrastructure to CISA; and Department of Defense contractor obligations require reporting a cyber incident to the DoD within 72 hours with a preliminary assessment. These regimes are not interchangeable — they differ in what counts as a qualifying event, who must report, to whom, and what information is required, and some (such as CIRCIA implementation) reflect evolving rulemaking. Readers should verify the precise trigger, timing calculation, and content requirements against the current authoritative text of the specific applicable law or regulation, as these provisions are periodically amended and their enforcement practice may diverge from the statutory or regulatory text.

Why it matters

The phrase "72-hour notification requirement" appears across multiple unrelated legal regimes, and treating it as a single universal rule is a common and consequential error. The same 72-hour window governs personal data breaches under the EU GDPR, reportable cyber incidents at federally insured credit unions under NCUA rules, cyber incidents affecting critical infrastructure under CIRCIA-related provisions reported to CISA, and cyber incidents affecting certain Department of Defense contractors. Each regime defines a different qualifying event, a different reporting entity, and a different recipient authority. An organization that satisfies one obligation has not necessarily satisfied another, and some organizations may fall under more than one at once.

The practical stakes are high because the clock is short and the triggers are technical. Determining when the 72-hour window begins — for example, when a controller "becomes aware" of a personal data breach under the GDPR, versus when a credit union identifies a reportable cyber incident under NCUA rules — requires a factual and often time-sensitive judgment made under pressure. Misidentifying which regime applies, or miscalculating the start of the window, can lead to late or misdirected reports.

Because these obligations differ in scope and are, in some cases, still the subject of evolving rulemaking (CIRCIA implementation being a notable example), organizations should map their specific exposure in advance rather than during an incident. This entry describes the general shape of these requirements; it does not substitute for the current authoritative text of any specific law or regulation, and application to a particular situation requires professional judgment.

Who it's relevant to

Data protection officers and privacy teams (EU GDPR)
Organizations acting as controllers of personal data subject to the GDPR must be prepared to notify the competent supervisory authority within 72 hours of becoming aware of a qualifying personal data breach. These teams need clear internal processes for detecting breaches, assessing the applicable threshold, and identifying the point at which awareness — and therefore the 72-hour window — begins. Note that separate rules apply to processors and to notifying affected individuals; the details should be confirmed against the current GDPR text.
Credit union compliance and security staff (NCUA)
Federally insured credit unions are subject to NCUA rules requiring notification to the NCUA as soon as possible and no later than 72 hours after a reportable cyber incident, effective from September 1, 2023. Compliance and information security personnel should confirm what constitutes a reportable cyber incident under the NCUA framework, as it differs from the GDPR's personal data breach trigger and from other U.S. regimes.
Critical infrastructure operators (CIRCIA / CISA reporting)
Entities in sectors treated as critical infrastructure may be subject to CIRCIA-related provisions requiring notification to CISA within 72 hours of a significant cyber incident. Because CIRCIA implementation reflects evolving rulemaking, affected operators should track the current status of these requirements rather than rely on earlier proposals, and verify the applicable trigger, timing, and content obligations against authoritative sources.
Defense contractors and their compliance functions (DoD)
Contractors subject to Department of Defense cyber incident reporting obligations must report a cyber incident to the DoD within 72 hours, generally including a preliminary assessment with as much detail as available. These teams should distinguish this obligation from other 72-hour regimes, since the qualifying event, recipient, and required report content differ.
Legal counsel and incident response leads across regimes
Counsel and incident response leads coordinating multi-jurisdictional or multi-sector organizations must recognize that a single incident may trigger more than one 72-hour obligation, each with a distinct trigger, recipient, and content requirement. Mapping applicable regimes in advance and confirming each against its current authoritative text supports timely and correctly directed reporting; application to specific facts requires professional judgment.

Inside 72-Hour Notification Requirement

Trigger event
The obligation generally begins when a controller becomes aware of a personal data breach, not from the moment the breach itself occurs. 'Awareness' typically means having a reasonable degree of certainty that a security incident affecting personal data has taken place. The precise threshold is fact-specific and should be assessed against the applicable legal text and supervisory guidance.
Time window
Under the EU GDPR, a notifiable breach must generally be reported to the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after the controller becomes aware of it. Where notification is delayed beyond this window, it must generally be accompanied by reasons for the delay.
Notification threshold
Not every breach requires notification. Under the GDPR, notification to the supervisory authority is generally required unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. This risk-based assessment must be documented regardless of whether notification ultimately proceeds.
Recipient of notification
The 72-hour obligation described here concerns notification to the relevant supervisory authority. Notification to affected data subjects is a separate obligation with a different trigger, generally arising where the breach is likely to result in a high risk to individuals, and is not governed by the same 72-hour deadline.
Content of the notification
A notification generally describes the nature of the breach, including where possible the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Where all information is not available at once, it may be provided in phases without undue further delay.
Controller and processor roles
The 72-hour deadline for notifying the supervisory authority generally rests with the controller. A processor that becomes aware of a breach is generally required to notify the controller without undue delay, but is not itself subject to the 72-hour authority-notification clock in the same way.
Documentation duty
The controller is generally expected to document the facts of any personal data breach, its effects, and the remedial action taken, whether or not it meets the notification threshold. This record supports demonstrating accountability to the supervisory authority.

Common questions

Answers to the questions practitioners most commonly ask about 72-Hour Notification Requirement.

Does the 72-hour clock start when a breach occurs?
No. Under the GDPR, the timeframe generally runs from when the controller becomes aware of a personal data breach, not from the moment the breach occurred or began. Awareness typically means having a reasonable degree of certainty that a security incident has compromised personal data. Determining the precise point of awareness can be fact-specific, and organizations should assess it against the current text of the regulation and relevant supervisory authority guidance, which may evolve.
Is a 72-hour notification deadline a universal rule that applies to every organization worldwide?
No. The 72-hour figure is most commonly associated with the GDPR's requirement to notify the competent supervisory authority, which applies to controllers within its territorial and extraterritorial scope. Other jurisdictions, sectors, and frameworks set different notification timeframes, triggers, and recipients, and some use standards such as 'without undue delay' or specify different periods. This entry does not cover every regime, and requirements differ across the EU, the United States, the United Kingdom, and elsewhere. Verify the applicable obligation for your specific jurisdiction and sector against the current authoritative text.
Who is responsible for making the notification when a processor is involved?
The obligation to notify the supervisory authority generally falls on the controller. A processor that becomes aware of a breach is typically required to notify the controller without undue delay, but the processor does not usually notify the authority directly on its own behalf. The controller then assesses whether and how to notify. Roles should be clarified in the controller-processor arrangement, and application to particular circumstances requires professional judgment.
What should be done if all required details are not available within the timeframe?
Where information is not yet available, the GDPR generally permits information to be provided in phases without undue further delay, rather than delaying the initial notification until every detail is known. Organizations commonly document what is known, what is still under investigation, and follow up as facts develop. The precise content expected and the acceptability of phased reporting should be verified against the current regulation text and relevant supervisory authority guidance.
Does every breach require notification within the deadline?
Not necessarily. Under the GDPR, notification to the supervisory authority is generally required unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. A separate assessment applies to whether affected individuals must also be informed, which is typically triggered by a higher risk threshold. These are risk-based determinations that are fact-specific, and the assessment should be documented and evaluated against the current legal standard.
How can an organization prepare to meet a short notification timeframe in practice?
Common preparatory measures include maintaining an incident response and breach handling procedure, defining internal escalation paths and decision-making roles, keeping a breach register or log, and clarifying notification responsibilities in agreements with processors and other parties. These are operational practices rather than requirements defined in the regulation itself. Whether specific measures are appropriate depends on the organization's risk profile, size, and processing activities, and they should be tailored using professional judgment.

Common misconceptions

The 72-hour clock starts when the breach occurs.
Under the GDPR, the period generally runs from when the controller becomes aware of the breach, which may be later than the moment the breach itself happened. Establishing the point of awareness is a fact-specific determination.
Every data breach must be reported within 72 hours.
Notification to the supervisory authority is generally required only where the breach is likely to result in a risk to individuals' rights and freedoms. Breaches assessed as unlikely to pose such risk may not require notification, though the assessment should still be documented.
The 72-hour requirement is a universal global rule.
The 72-hour framing described here is characteristic of the EU GDPR, and equivalent provisions apply in the UK regime derived from it. Other jurisdictions and sectors impose different timelines, triggers, and recipients. Notifying affected individuals is also a distinct obligation that does not follow the same 72-hour deadline. Readers should verify the specific rules that apply to their situation.

Best practices

Establish an internal incident-response procedure that defines who assesses awareness, how the point of awareness is recorded, and how the notification window is tracked from that moment.
Document the risk assessment for every breach, including those you decide are unlikely to require notification, so you can demonstrate accountability to the supervisory authority.
Prepare notification templates and a phased-reporting approach in advance so that partial information can be submitted within the window and supplemented without undue further delay.
Clarify controller and processor responsibilities in contracts, including the processor's obligation to notify the controller without undue delay and the information it must provide.
Map which supervisory authority or authorities are competent for your operations, and note that individual-notification and multi-jurisdictional obligations may run on separate tracks.
Verify current timelines, thresholds, and procedures against the latest authoritative text and supervisory guidance for each applicable jurisdiction, and involve qualified professionals for application to specific incidents.
Promotional banner for the Penetration Report Template Kit