Back to Resources
Regulatory Notification Checklist: visual preview
Checklist

Regulatory Notification Checklist

Breach Disclosure Deadlines & Compliance Requirements

Overview

After a breach, you are racing multiple clocks at once. Different regulations have different deadlines, different authorities expecting different information, and different consequences for missing them. This checklist consolidates the notification requirements across major regulatory frameworks so your incident response team knows exactly who to notify, when, and with what information. Print it, pin it to your war room wall, and reference it every time an incident crosses the reportable threshold.

Notification Deadlines by Framework

FrameworkDeadlineNotifyKey requirements
GDPR72 hours from awarenessSupervisory authority + data subjects (if high risk)Nature of breach, categories of data, approximate number of records, DPO contact
HIPAA60 days from discoveryHHS OCR + individuals, media if 500+ per stateDescription of breach, types of PHI, steps taken, contact for questions
SEC (8-K)4 business days from materiality determinationSEC via Form 8-KMaterial impact, nature and scope, status of remediation
CCPA/CPRAWithout unreasonable delayCalifornia AG (if 500+ residents) + affected individualsCategories of data, timeline, remedial actions, contact info
NY SHIELD ActWithout unreasonable delayNY AG + affected residentsTypes of data, timeline, protective measures offered
PCI DSSImmediately upon discoveryAcquiring bank and card brandsCompromise scope, potentially affected card numbers, forensic investigation plan

Pre-Incident Preparation Steps

  • Map all applicable regulations to your organization based on customer locations and data types
  • Build a regulatory contact database with authority names, submission portals, and email addresses
  • Pre-draft notification templates for each major framework
  • Identify outside counsel with breach notification expertise across jurisdictions
  • Establish a cross-functional notification team: legal, privacy, communications, and IR
  • Conduct a tabletop exercise focused specifically on multi-jurisdiction notification scenarios

During-Incident Notification Workflow

Start the notification clock the moment the incident meets the "awareness" or "discovery" threshold under each applicable law. Immediately convene the notification team and outside counsel. Determine which jurisdictions apply based on affected individuals. Draft authority notifications first since many regulations require authority notification before or concurrent with individual notification. Log every notification sent with timestamps, recipients, and content. Assign a single person to own deadline tracking across all jurisdictions.

Post-Notification Obligations

  • File supplemental notifications if the investigation reveals additional affected individuals or data types
  • Respond to regulatory inquiries within requested timelines
  • Preserve all notification records for at least five years
  • Monitor for follow-up enforcement actions or investigations
  • Update breach notification procedures based on lessons learned
  • Track customer inquiries and complaint volumes for regulatory reporting

Common Pitfalls

The most frequent mistake is not starting the clock early enough. If your team suspects a breach on Monday but does not confirm it until Friday, most regulators will argue the clock started Monday. Other common pitfalls include failing to account for state-level laws that have shorter timelines than federal ones, sending incomplete notifications that require costly supplementals, and not coordinating timing between authority and individual notifications. build the muscle memory before you need it by running notification-focused tabletop exercises at least once a year.

Frequently asked questions