Data Breach Notification Deadlines by Country (2026 Comparison Table)

Independently fact-checkedBy Recording Law Editorial Team36 min read

Independently fact-checked against primary sources (last audited July 23, 2026). · 47 primary sources cited on this page. How we verify our legal content

Data Breach Notification Deadlines by Country (2026 Comparison Table)

Frequently Asked Questions

Is 72 hours the global standard for data breach notification?

No. It is the most-copied figure, originating with the EU's GDPR, but a meaningful share of the countries in this matrix, including Switzerland, South Africa, Canada, New Zealand's own statute, and Chile's data-protection law, set no fixed hour figure at all. Others use different numbers entirely, such as Brazil's 3 business days or Peru's 48 hours.

Why does Chile keep getting quoted as a 72-hour country?

Chile's Cybersecurity Framework Law (21.663) does set a 72-hour clock, but only for cyberattacks against essential services, reported to CSIRT Nacional. Chile's actual data-protection law, 21.719, sets no fixed hour at all for personal-data breaches, only "the most expeditious means possible, without undue delay." Aggregators regularly misattribute the cybersecurity law's number to the data-protection law.

Is the commonly-cited 24-hour German telecom breach rule accurate?

The number is right, the attribution usually is not. Section 169 of Germany's Telecommunications Act (TKG) uses only "unverzuglich," without undue delay, with no numeric figure anywhere in the statute text. The 24-hour clock comes from directly applicable EU law instead: Regulation (EU) No 611/2013, Article 2(2), requires providers of publicly available electronic communications services to notify the competent national authority "no later than 24 hours after the detection of the personal data breach, where feasible." A German telecom provider does face a binding 24-hour deadline, it just is not written in the TKG.

What is the difference between the regulator-notification deadline and the individual-notification deadline?

They are usually two separate clocks with two separate triggers. Under GDPR, for example, the regulator must be notified of any breach that carries some risk within 72 hours, while individuals only need to be notified, with no fixed hour figure, if the breach poses a high risk, a meaningfully higher bar. Many other jurisdictions follow a similar split, and conflating the two legs is the most common error in breach-notification coverage.

Which countries have no legal deadline for breach notification at all?

South Africa, Switzerland, Canada, New Zealand (by statute; a 72-hour figure exists only in non-binding regulator guidance), Morocco, and Ghana all set no fixed hour or day figure in their current law. Hong Kong goes further: breach notification itself is entirely voluntary. Argentina has no legal breach-notification obligation of any kind, only a non-binding regulator recommendation.

Is India's data-protection breach-notification rule in effect right now?

Not yet. The DPDP Act's breach-notification duty, including its 72-hour detailed report to the Data Protection Board, was gazetted 13 Nov 2025 but does not commence until roughly 13 May 2027. What does bind Indian entities today is a separate cybersecurity regime, CERT-In's 6-hour incident-reporting rule under the IT Act, which has been in force since 2022. These are two different regimes and should never be reported as a single "India's breach deadline" figure.

Does Malaysia's 72-hour clock run from when the breach happened or from when it was discovered?

The circular text itself (Pekeliling No. 2/2025, s.4(4)) reads "within 72 hours from the personal data breach," language pointing to occurrence rather than discovery, while s.4(1) separately frames the underlying duty as "as soon as practicable." The Commissioner's own detailed Guideline on this point was not independently verified for this page, so treat the exact clock-start with some caution and confirm current JPDP guidance before relying on it for a live compliance deadline.

Does the United States have one federal data-breach-notification deadline?

No. There is no general federal breach-notification law. All 50 states, DC, and the US territories set their own deadlines, most commonly "without unreasonable delay" with an optional 30-60 day backstop. Federal sectoral rules fill part of the gap for specific industries: HIPAA gives covered entities 60 days for health-data breaches, and the SEC requires public companies to disclose material cybersecurity incidents within 4 business days of determining materiality.

Why do Kuwait and Bahrain not have a published deadline in this matrix?

For Kuwait, reputable secondary sources directly conflict, some cite 24 hours and others 72 hours, for the same regulation, and we could not resolve the conflict against a primary text. For Bahrain, the primary data-protection Law contains no breach-notification article at all; any 72-hour figure lives only in a 2022 Resolution that could not be located as a verifiable primary document. Publishing an invented number in either case would be less accurate than stating the gap honestly.

Updates

Independently fact-checked against the cited primary sources

Initial publication of the 45-plus jurisdiction data breach notification deadline matrix, covering Europe, Asia-Pacific, the Middle East and Africa, and the Americas, sourced entirely from primary statutes, implementing regulations, and regulator guidance, plus a US state-law summary and sector overlays (NIS2, DORA, eIDAS, HIPAA, SEC).

Sources and References

  1. GDPR Article 33 — Notification of a personal data breach to the supervisory authority(gdpr-info.eu)
  2. GDPR Article 34 — Communication of a personal data breach to the data subject(gdpr-info.eu)
  3. ICO — Personal data breaches: a guide(ico.org.uk).gov
  4. Switzerland revFADP (SR 235.1), Article 24 — Meldung von Verletzungen der Datensicherheit(fedlex.admin.ch).gov
  5. Datatilsynet — Meld avvik til Datatilsynet (breach reporting guidance)(datatilsynet.no).gov
  6. EFTA EEA-Lex — GDPR incorporation into the EEA Agreement (JCD 154/2018)(efta.int)
  7. Germany — Telekommunikationsgesetz (TKG) § 169(gesetze-im-internet.de).gov
  8. BfDI — Das Verfahren nach § 169 TKG(bfdi.bund.de).gov
  9. CNIL — Notifications d'incidents de sécurité aux autorités de régulation(cnil.fr).gov
  10. EUR-Lex — Directive (EU) 2022/2555 (NIS2)(eur-lex.europa.eu).gov
  11. EUR-Lex — Commission Delegated Regulation (EU) 2025/301 (DORA incident-reporting RTS)(eur-lex.europa.eu).gov
  12. EUR-Lex — Regulation (EU) 910/2014 (eIDAS), Article 19(eur-lex.europa.eu).gov
  13. Japan PPC — Data breach reporting obligation overview(ppc.go.jp).gov
  14. China — Cyberspace Administration of China, Network Data Security Management Regulations(cac.gov.cn).gov
  15. China PIPL Article 57 (translation)(personalinformationprotectionlaw.com)
  16. Singapore — Personal Data Protection Act 2012(sso.agc.gov.sg).gov
  17. Malaysia — Pekeliling Pesuruhjaya Perlindungan Data Peribadi Bilangan 2 Tahun 2025 (Data Breach Notification Circular)(pdp.gov.my).gov
  18. Philippines NPC Circular 16-03 — Personal Data Breach Management(privacy.gov.ph).gov
  19. Indonesia — UU No. 27 Tahun 2022 tentang Pelindungan Data Pribadi, Pasal 46(jdih.komdigi.go.id).gov
  20. Australia OAIC — Notifiable Data Breach scheme, Part 4(oaic.gov.au).gov
  21. New Zealand OPC — Breach Management guidance(privacy.org.nz).gov
  22. Hong Kong PCPD — Guidance Note on Data Breach Handling and Notification(pcpd.org.hk).gov
  23. Taiwan — Personal Data Protection Act, Article 12(law.moj.gov.tw).gov
  24. Vietnam Decree No. 13/2023/ND-CP on Personal Data Protection, Article 23(finalsite.net)
  25. Internet Freedom Foundation — statement on DPDP Rules 2025 notification and commencement schedule(internetfreedom.in)
  26. Saudi Arabia — Personal Data Protection Law, Article 20(sdaia.gov.sa).gov
  27. Saudi Arabia — PDPL Implementing Regulation, Article 24(sdaia.gov.sa).gov
  28. UAE Federal Decree-Law No. 45 of 2021 (PDPL), Article 9(uaepdpl.com)
  29. DIFC Data Protection Law No. 5 of 2020, Articles 41–42(assets.difc.com).gov
  30. ADGM Data Protection Regulations 2021, Articles 32–33(assets.adgm.com).gov
  31. Qatar Law No. 13 of 2016, Article 14(almeezan.qa).gov
  32. Bahrain Personal Data Protection Law No. 30 of 2018 (full text)(pdp.gov.bh).gov
  33. Oman — Personal Data Protection Law, Official Gazette text(mtcit.gov.om).gov
  34. Turkey KVKK — Board Decision No. 2019/10 on personal data breach notification(kvkk.gov.tr).gov
  35. Nigeria NDPC — Data Protection Act Guidance, March 2025(ndpc.gov.ng).gov
  36. Kenya Law — Data Protection Act, 2019, Section 43(kenyalaw.org).gov
  37. Ghana — Data Protection Act, 2012 (Act 843)(nita.gov.gh).gov
  38. Tanzania — Personal Data Protection Act, 2022(pdpc.go.tz).gov
  39. Canada — Personal Information Protection and Electronic Documents Act, s.10.1(laws-lois.justice.gc.ca).gov
  40. Quebec — Act respecting the protection of personal information in the private sector, s.3.5(legisquebec.gouv.qc.ca).gov
  41. ANPD — Comunicado de Incidente de Segurança (breach notification requirement)(gov.br).gov
  42. Mexico — Ley Federal de Protección de Datos Personales en Posesión de los Particulares(diputados.gob.mx).gov
  43. Mexico — Diario Oficial de la Federación, regulator transition decree, 20 March 2025(dof.gob.mx).gov
  44. Argentina — Law 25.326 (Ley de Protección de los Datos Personales), full text(oas.org)
  45. Uruguay — Decreto 64/020, Articles 3–4(impo.com.uy).gov
  46. Chile — Ley 21.719, Artículo 14 sexies (official BCN text)(bcn.cl).gov
  47. Chile — Ley 21.663 (Cybersecurity Framework Law), Artículo 9(bcn.cl).gov
  48. Colombia SIC — Cumplimiento de la obligación del reporte de incidentes de seguridad(sic.gov.co).gov
  49. Peru — D.S. 016-2024-JUS, Artículo 34(lpderecho.pe)
  50. Costa Rica — Decreto Ejecutivo 37554-JP, Artículos 38–39(mopt.go.cr).gov
  51. Panama — Decreto Ejecutivo 285 de 2021, Artículo 37(sijusa.com)
  52. Ecuador — Ley Orgánica de Protección de Datos Personales, Artículos 43 y 46(cpccs.gob.ec).gov
  53. eCFR — HIPAA Breach Notification Rule, 45 CFR § 164.404(ecfr.gov).gov
  54. SEC — Press Release 2023-139, Cybersecurity Incident Disclosure (Item 1.05 Form 8-K)(sec.gov).gov
  55. FTC — Safeguards Rule notification requirement now in effect(ftc.gov).gov
  56. Washington RCW 19.255.010 — Notice of security breaches(app.leg.wa.gov).gov
  57. Florida Statute § 501.171 — Security of confidential personal information(flsenate.gov).gov
Share: