Compliance Glossary

What is Breach Notification?

Definition

Breach notification is the legal requirement for organizations to inform regulatory authorities and affected individuals when a security incident results in unauthorized access to protected data. Notification timelines and requirements vary significantly by framework and jurisdiction.

In Depth

Breach notification requirements exist across most compliance frameworks but differ significantly in their specifics. Under GDPR, data controllers must notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach that poses a risk to individuals' rights and freedoms; if the risk is high, affected individuals must also be notified without undue delay. HIPAA requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured PHI, with HHS Secretary and media notification required for breaches affecting 500 or more individuals. SOC 2 does not have a prescriptive notification timeline but requires that incident response procedures include communication protocols. A robust breach notification process includes predefined templates for regulatory and individual notifications, a decision tree for assessing notification obligations across jurisdictions, legal review procedures, and communication channel selection. Organizations operating across multiple frameworks must map their notification obligations to ensure the strictest timeline is met.

Related Frameworks

Generate compliance docs with PoliWriter

Stop reading about compliance and start achieving it. PoliWriter generates audit-ready policies customized to your organization in hours.

Get Started Free