Get Demo
↑

Breach Notification Deadlines Compared: GDPR, HIPAA, PIPEDA, Law 25, PDPL, CCPA

One matrix of breach notification clocks — GDPR 72h, HIPAA 60 days, PIPEDA, Quebec Law 25, California §1798.82.

Published: September 2026 Compliance · Privacy 8–12 min read

Breach clocks differ by statute. Use this matrix in IR playbooks and SOAR runbooks so counsel and SOC share one source of timing truth.

Related: GDPR breach guide · ThreatHawk.

CCPA note: CCPA/CPRA do not impose a GDPR-style 72-hour supervisory-authority notice. California resident security-breach notice is primarily under Civil Code §1798.82 (most expedient time / without unreasonable delay) — distinct from CCPA consumer rights.

Notification Matrix

Law
Clock / trigger
GDPR Art 33
Notify supervisory authority without undue delay and where feasible within 72 hours of becoming aware
HIPAA (45 CFR 164.400–414)
Individuals without unreasonable delay and no later than 60 calendar days; HHS for 500+ same 60-day clock; <500 annual to HHS
PIPEDA (Canada)
Breach of security safeguards creating real risk of significant harm — notify individuals and OPC as soon as feasible (not a fixed 72h)
Quebec Law 25
Notify Commission d’accès à l’information and affected persons as soon as possible when risk of serious injury (not identical to GDPR 72h)
California §1798.82
Resident breach notice in the most expedient time possible and without unreasonable delay — separate from CCPA rights clocks
Saudi PDPL
Notify competent authority / data subjects per SDAIA implementing rules — confirm current circular for exact timing
UAE PDPL
Notify per Federal Decree-Law 45/2021 implementing regulations — confirm current UAE guidance for exact timing

Playbook Tip

Start the legal assessment clock at confirmed awareness. SIEM detections that shorten time-to-awareness help every regime’s “without delay / as soon as feasible” standard.

Wire Clocks into IR and SOAR

ThreatHawk detections plus CSA incident packages for counsel.

Frequently Asked Questions

Is CCPA a 72-hour SA notice?

No. Use California Civil Code §1798.82 for resident security-breach notice framing; CCPA rights are separate.

Does PIPEDA use 72 hours?

No. Notify as soon as feasible when there is a real risk of significant harm.

Why hedge PDPL hours?

Implementing regulations and circulars evolve — confirm the current SDAIA / UAE authority text before locking playbooks.

Privacy vs security · ThreatHawk · CSA Privacy

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!