Breach Notification
Breach notification is a legal duty to inform affected individuals, and often regulators, when a security incident exposes their personal or sensitive information. The specific triggers, deadlines, and recipients depend on which law applies and where the affected people are located. It is not a single universal rule but a requirement that appears in several different regulations across sectors and jurisdictions.
Breach notification refers to a set of statutory and regulatory obligations requiring covered organizations to notify affected data subjects, supervisory or enforcement authorities, and in some cases the public or the media, following a qualifying security incident involving protected information. The scope, thresholds, timelines, and content of notice vary by the governing instrument. Under the EU GDPR, a 'personal data breach' is defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, personal data, with distinct obligations for controllers and processors; readers should note the roles and their differing duties are not interchangeable. In the United States, sector-specific rules apply rather than a single federal standard: the HIPAA Breach Notification Rule (45 CFR §§ 164.400-414) obligates covered entities and their business associates to provide notification following a breach of unsecured protected health information; the FTC's Health Breach Notification Rule reaches vendors of personal health records and related entities not covered by HIPAA; and the FCC has updated data breach notification rules applicable to telecommunications carriers regarding breaches of customer PII. Because triggers frequently turn on whether the information was 'unsecured,' on risk assessment, and on data category, applicability is fact-specific. This entry does not cover every state breach notification statute or non-U.S./non-EU regimes, and specific deadlines, penalty provisions, and effective dates should be verified against the current official text of the relevant law, as these rules are periodically amended.
Why it matters
Breach notification obligations convert a security incident into a set of enforceable legal duties, often on tight timelines and with defined recipients. For compliance and legal teams, the consequences of a mishandled notification can extend beyond the underlying incident itself: failure to notify affected individuals or regulators when required, or notifying in a manner that does not meet statutory content and timing requirements, can create independent exposure. This is why breach notification is typically treated not as an afterthought to incident response but as a workflow that must be planned before an incident occurs.
A central challenge is that there is no single universal breach notification standard. The applicable rule depends on which law governs, the category of information involved, and where the affected people are located. Under the EU GDPR, the trigger is a 'personal data breach' — a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, personal data — and the duties differ depending on whether an organization acts as a controller or a processor. In the United States, sector-specific regimes apply instead of one federal rule: the HIPAA Breach Notification Rule reaches covered entities and business associates handling unsecured protected health information, the FTC's Health Breach Notification Rule reaches vendors of personal health records and related entities outside HIPAA's scope, and the FCC has updated rules addressing breaches of telecommunications customer PII.
Because many of these obligations turn on fact-specific questions — whether information was 'unsecured,' the outcome of a risk assessment, and the data category involved — organizations frequently cannot determine their notification duties without first analyzing the specific incident against the specific instruments that apply to them. Overlapping regimes may impose parallel duties for a single event, and this entry does not cover every U.S. state breach notification statute or non-U.S./non-EU regime. Deadlines, penalty provisions, and effective dates should be verified against the current official text, as these rules are periodically amended.
Who it's relevant to
Inside Breach Notification
Common questions
Answers to the questions practitioners most commonly ask about Breach Notification.

