Data Breach Notification Deadlines by Country (2026 Comparison Table)

Quick answer
There is no worldwide breach-notification deadline. The European Union's GDPR set the benchmark most other laws are compared against: notify the regulator within 72 hours of becoming aware of a breach, and notify affected individuals "without undue delay" only if the breach poses a high risk to their rights.
Many countries copy the 72-hour number for their own regulator-notice leg (South Korea, the Philippines, Indonesia, Saudi Arabia's implementing regulation, Turkey, Kenya, Nigeria, Uruguay, and several UAE free zones). Just as many do not: Switzerland, South Africa, Canada, New Zealand's statute, Chile, Germany's telecom-sector rule, and most Latin American civil-law countries use open-ended language such as "without undue delay," "as soon as feasible," or "as soon as practicable" instead of a fixed hour count.
A handful of jurisdictions have no breach-notification law at all in practical terms right now: Hong Kong (voluntary), Argentina (no legal duty), and India's data-protection-specific duty (enacted but not yet in force). The tables below give the two deadlines separately for every jurisdiction we could verify, and say so plainly wherever a fixed number does not exist.

How to read this table
Every row below is split into two columns on purpose: the deadline to notify the regulator and the deadline to notify affected individuals. These are frequently different clocks, with different triggers, and conflating them is the most common mistake in breach-notification coverage. GDPR is the clearest example: the regulator-notice trigger is any breach that carries some risk, while the individual-notice trigger requires high risk, a meaningfully higher bar, and the individual leg carries no fixed hour figure at all.
"No fixed deadline" is a real, correctly-researched answer, not a gap in this table. Where a jurisdiction's law says "as soon as possible" or "without undue delay" with no accompanying number, we say so rather than borrowing a number from a different country's law or from regulator guidance that was never written into the statute.
We also flag, wherever it matters, whether a deadline lives in the primary statute, in a subordinate regulation, or only in non-binding guidance, and whether a deadline that has been enacted is actually in force yet. Those three distinctions change how much weight a compliance team should put on a number, and most secondary sources collapse them into a single "X hours" headline that erases the distinction entirely.

The GDPR 72-hour anchor, briefly
The EU/EEA baseline comes from the General Data Protection Regulation, Articles 33 and 34. A controller must notify its competent supervisory authority "without undue delay and, where feasible, not later than 72 hours after having become aware" of a breach, unless the breach is unlikely to result in any risk to individuals' rights and freedoms. Notice to the affected individuals themselves is required only where the breach is likely to result in a high risk, and that leg carries no fixed hour figure, only "without undue delay."
That two-tier structure, a lower bar and a fixed clock for the regulator, a higher bar and no fixed clock for individuals, is the design pattern most of the rest of the world either copies or deliberately diverges from. For the full walkthrough of GDPR's own text, exemptions, and enforcement history, see our GDPR 72-hour breach notification rule deep dive.

Europe
The EU/EEA states share one legal text (GDPR), so the real variation in Europe comes from EEA-EFTA states that apply GDPR through separate national incorporation, non-EU states like Switzerland and the UK that have their own post-GDPR statutes, and sector-specific overlays that impose shorter, separate clocks. EU adequacy decisions also shape how breach data can move across these borders in the first place.
| Jurisdiction | Regulator | Deadline to Regulator | Notice to Individuals | Trigger / Threshold | Legal Basis & Status |
|---|---|---|---|---|---|
| EU/EEA (GDPR baseline) | National supervisory authority (one per member state) | 72 hours after becoming aware, "without undue delay and where feasible"; reasons required if later (Art. 33(1)) | "Without undue delay," no fixed hour figure (Art. 34(1)) | Regulator: any risk to rights and freedoms, unless unlikely. Individual: high risk specifically, a higher bar, with encryption/mitigation/disproportionate-effort exemptions (Art. 34(3)) | Primary statute, GDPR Arts. 33/34, in force |
| United Kingdom | ICO (being restructured into the "Information Commission" under the 2025 Data (Use and Access) Act; breach substance unchanged) | Same as GDPR: 72 hours, reasons required if later; phased notification allowed | Same GDPR high-risk trigger, "without undue delay," no fixed hour | Same two-tier GDPR test; ICO can compel individual notice even where the controller judged risk low | Primary, UK GDPR + DPA 2018, in force |
| Switzerland | FDPIC (EDOB / PFPDT) | No fixed hour. Statute text: "so rasch als moglich," as soon as possible (revFADP Art. 24(1)) | Narrower than GDPR. The controller informs the data subject only if necessary for their protection or if the FDPIC demands it (Art. 24(4)); notice can be restricted, delayed, or waived under conditions mirroring Art. 26 | Regulator: breach likely to lead to high risk to personality or fundamental rights. Processors must also notify the controller "as soon as possible" | Primary statute (SR 235.1, Art. 24), in force since 1 Sept 2023. Any 72-hour figure quoted for Switzerland is informal commentary, not the statute |
| Norway | Datatilsynet | Same as GDPR: 72 hours; Datatilsynet's own guidance explicitly allows a phased, incomplete initial notice, with the clock starting once the controller has reasonable certainty a breach occurred | Same GDPR high-risk trigger, "without undue delay" | Same GDPR two-tier test | Primary, GDPR applied directly via EEA incorporation (EEA Joint Committee Decision 154/2018), in force |
| Iceland | Personuvernd | Same as GDPR: 72 hours | Same GDPR high-risk trigger | Same GDPR two-tier test | GDPR applied directly via the same EEA incorporation mechanism as Norway; Act No. 90/2018 |
| Liechtenstein | Datenschutzstelle (DSS) | Same as GDPR: 72 hours | Same GDPR high-risk trigger | Same GDPR two-tier test | GDPR applied directly via the same EEA incorporation mechanism; Datenschutzgesetz in force since 1 Jan 2019 |
| Germany, telecom sector add-on (Sec. 169 TKG) | BNetzA and BfDI, notified separately, alongside the ordinary GDPR Art. 33 route | No numeric figure. The statute text says only "unverzuglich," without undue delay, for both legs | Same "unverzuglich" standard, only if there is serious harm to users' rights/interests | Applies specifically to public telecom providers, implementing the ePrivacy Directive via EU Regulation 611/2013, a separate legal basis from GDPR Art. 33/34 | Primary statute (gesetze-im-internet.de), in force. The commonly-cited "24 hours" is not in the TKG text, it comes from Regulation (EU) 611/2013, Art. 2(2), which applies directly to the same providers and is a genuine binding deadline running alongside this one |

Asia-Pacific
Asia-Pacific splits roughly into three groups: jurisdictions that copy the GDPR-style 72-hour regulator clock (South Korea, the Philippines, Indonesia, Malaysia), jurisdictions with day-based or assessment-based deadlines (Japan, Singapore, Australia), and jurisdictions with no fixed number at all (New Zealand's statute, Hong Kong, current-law Taiwan).
| Jurisdiction | Regulator | Deadline to Regulator | Notice to Individuals | Trigger / Threshold | Legal Basis & Status |
|---|---|---|---|---|---|
| Japan | Personal Information Protection Commission (PPC) | Two-stage: a preliminary report "without delay" (PPC guidance describes roughly 3-5 days in practice), then a final report within 30 days (60 days if the breach may involve an unlawful or improper purpose, such as a cyberattack) | Required "without delay," no fixed hour or day count in the rule itself | Any of: sensitive personal data involved, risk of property damage, likely improper/unlawful purpose, or more than 1,000 individuals affected | Primary, PPC guidance under the amended APPI, in force. See our Japan APPI vs. GDPR comparison for the wider framework |
| South Korea | Personal Information Protection Commission (PIPC) | 72 hours of becoming aware, when the leak involves 1,000 or more individuals, sensitive/unique-ID data, or a confirmed illegal intrusion | 72 hours as well, and this leg applies even for a single affected individual, a lower threshold than the regulator trigger | 1,000+ individuals for the regulator-notice trigger; any scale for individual notice | Corroborated across multiple compliance sources (PIPA Art. 34); treat the exact hour figure as law-firm-corroborated pending a direct statute re-check. See our South Korea PIPA overview |
| China | Cyberspace Administration of China (CAC), plus sector regulators for critical infrastructure | PIPL Art. 57 itself says "immediately" ("li ji"), no fixed hour. Layered cybersecurity regulations impose numeric clocks for critical-information-infrastructure operators and "significant" incidents: 1 hour for a brief report, 24 hours for a detailed report | PIPL Art. 57: notify affected individuals and the regulator "immediately" when leakage, tampering, or loss occurs or may occur | No numeric threshold in PIPL Art. 57 itself; the 1-hour/24-hour clocks attach specifically to "significant" or "particularly major" incidents involving large-scale data or national-security risk | PIPL primary confirmed; the 1-hour/24-hour cybersecurity-incident clocks are corroborated by multiple law firms but not independently re-opened at CAC's own text this pass. See our China data privacy laws overview |
| Singapore | Personal Data Protection Commission (PDPC) | As soon as practicable, and no later than 3 calendar days after completing the required breach assessment | Required when the significant-harm threshold is met, tied to the same assessment, no separate fixed clock | Notifiable if likely to result in significant harm (PDPA Second Schedule: NRIC, financial account, health, login credentials, etc.) or involves 500 or more individuals, regardless of harm | General PDPA framework primary-verified; the specific "3 calendar days" figure is compliance-guide sourced. See our Singapore data privacy laws overview |
| Malaysia | Personal Data Protection Commissioner (JPDP) | 72 hours from the breach, per Circular No. 2/2025 s.4(4) (the Commissioner's own website mislabels this circular "1/2025," but the document itself is numbered 2/2025) | 7 days after the controller notifies the Commissioner, not 7 days from the breach itself (s.5(2)) | Any of five alternative triggers under s.4(3): physical injury/financial loss, unlawful-purpose misuse, sensitive data, identity-fraud-enabling data, or "significant scale" (more than 1,000 affected data subjects, s.3(1)(e)). Significant scale is one of five triggers, not a floor | Primary, circular text read directly, effective 1 June 2025. See our Malaysia data privacy laws overview |
| Philippines | National Privacy Commission (NPC) | 72 hours upon knowledge or reasonable belief that a breach occurred; full written report due within 5 days | 72 hours as well, the same clock, running in parallel, not staggered after the regulator notice | Sensitive personal information or identity-fraud-enabling data, acquired by an unauthorized person, with real risk of serious harm. A separate 100-individual figure governs urgency within the 72-hour window (no delay permitted), it is not itself the trigger for the duty | Primary, NPC Circular 16-03 ss. 17-18, read directly, in force. See our Philippines data privacy laws overview |
| Indonesia | Ministry of Communication and Digital Affairs (Komdigi, acting ad interim; no independent authority is operational yet) | 3 x 24 hours (72 hours), per UU PDP Pasal 46(1) | Same 72-hour clock, to both the regulator and the data subject simultaneously | Any "kegagalan Pelindungan Data Pribadi" (personal data protection failure); no numeric minimum in the article | Primary statute text, read directly, in force. See our Indonesia data privacy laws overview |
| Thailand | Personal Data Protection Committee (PDPC) | "Without undue delay," and within 72 hours where feasible, unless the controller's own risk assessment finds no risk to rights and freedoms | Required only where the breach is likely to pose a high risk, a higher bar than the regulator-notice trigger | Regulator-notice default is broad (risk-based opt-out only); individual notice requires "high risk" specifically | PDPA Sec. 37(4), corroborated by regulatory-tracking sources, primary text of the specific clause not re-opened this pass. See our Thailand data privacy laws overview |
| Australia | Office of the Australian Information Commissioner (OAIC) | No fixed hour clock. Up to 30 calendar days is the statutory ceiling to assess a suspected eligible data breach; once confirmed, notify "as soon as practicable" | "As soon as practicable" after the statement is given to OAIC, no separate fixed clock | "Eligible data breach": unauthorized access, disclosure, or loss likely to result in serious harm, judged by a reasonable-person standard, where remedial action cannot prevent the harm | Primary, Privacy Act 1988 ss 26WH/26WK/26WL, read directly, in force |
| New Zealand | Office of the Privacy Commissioner (OPC) | Statute (Privacy Act 2020) says "as soon as practicable," no fixed number. OPC's own guidance operationalizes this as within roughly 72 hours, but OPC explicitly frames that figure as "a guide only," not a statutory deadline | "As soon as reasonably practicable," no fixed count for this leg either | "Notifiable privacy breach": one that has caused or is likely to cause serious harm (physical, financial, psychological, employment, or safety harm) | Primary statute (Privacy Act 2020 Part 6), in force; non-notification is an offence carrying a fine up to NZ$10,000 |
| Hong Kong | Privacy Commissioner for Personal Data (PCPD) | Voluntary. No legal deadline exists. The PDPO does not mandate breach notification at all; PCPD's non-binding 2023 guidance recommends notifying "as soon as practicable" | Voluntary, the same non-binding recommendation | Not a legal threshold; PCPD's recommended (not required) trigger is real risk of significant harm | No breach-notification statute exists. This is the one jurisdiction in this matrix where "no deadline" is correct because notification itself is not mandatory |
| Taiwan | Currently no dedicated breach-notification authority under the operative law; a Personal Data Protection Commission (PDPC) has been created but its breach-notification powers are not yet active | Current law: no authority-notification deadline exists at all. PDPA Art. 12 only requires notifying the data subject, "in an appropriate manner," no fixed clock. A December 2025 amendment (enacted, not in force) will add a 72-hour authority-notice duty once subsidiary regulations are finalized and a commencement order is issued | Current law: "appropriate manner," no fixed clock. The pending amendment will also add a 72-hour data-subject clock, running in parallel with the new regulator clock | Current law: no numeric threshold. Pending amendment: thresholds still in draft, not yet published | Current PDPA Art. 12, in force; the widely-cited "72 hours" describes the not-yet-in-force amendment |
| Vietnam | Ministry of Public Security (the personal data protection authority; notifications go to it or via the National Information Portal for Personal Data Protection) | 72 hours from detecting the violation, now under the Law on Personal Data Protection No. 91/2025/QH15 (Art. 27) and Decree 356/2025/ND-CP (Art. 28). Decree 13/2023/ND-CP, the instrument nearly every tracker still cites for Vietnam, ceased to have effect on 1 January 2026 | 72 hours to affected data subjects where the breach involves location data or biometric data (Decree 356/2025/ND-CP Art. 29(1)(a)), and a separate 72-hour duty for leaked sensitive data in finance, banking and credit-information activities (Art. 8(3)). Outside those categories the law still sets no general individual-notice clock | A violation of the personal data protection rules that may harm national defence, security, public order, or a data subject's life, health, honour, dignity or property; no numeric minimum | Primary, Decree 356/2025/ND-CP read directly, in force 1 January 2026. Any "Vietnam = Decree 13/2023" citation, including in most compliance trackers, is now out of date |
| India | Two separate regimes that must not be conflated: CERT-In (cybersecurity, IT Act s.70B), in force now; and the Data Protection Board under the DPDP Act 2023, not yet in force for breach notification | CERT-In: 6 hours of noting or being notified of any of 20 listed cyber-incident categories, no size threshold, currently binding. DPDP Rule 7: "without delay" plus a 72-hour detailed report to the Board. enacted, but this rule does not commence until roughly 13 May 2027 | DPDP (once in force): "without delay" to affected Data Principals, no separate day count. CERT-In has no individual-notification limb at all | CERT-In: any of 20 incident categories, no minimum size. DPDP (once in force): no materiality threshold, every breach must be notified regardless of scale | CERT-In Direction 20(3)/2022, in force since 28 June 2022 (this is the regime that actually binds Indian entities today). DPDP Rules 2025, gazetted 13 Nov 2025, breach-notification provisions delayed roughly 18 months |
Middle East and Africa
This region has the widest gap between what compliance blogs report and what the underlying legal instrument actually says. Several "72-hour" figures here live only in guidance or a sub-statutory regulation, not the primary law, and at least two jurisdictions (South Africa, Morocco) deliberately set no numeric deadline at all.
| Jurisdiction | Regulator | Deadline to Regulator | Notice to Individuals | Trigger / Threshold | Legal Basis & Status |
|---|---|---|---|---|---|
| Saudi Arabia | SDAIA (the "Competent Authority" named in the Regulation) | 72 hours, but this figure lives in the Implementing Regulation (Art. 24(1)), not the Law itself. The PDPL's own Art. 20 defers entirely to the Regulations and states no number | "Without undue delay" (Implementing Regulation Art. 24(5)), no fixed hour count | Incident that "potentially causes harm" to the data or conflicts with the data subject's rights or interests, a risk-based trigger, not a headcount trigger | Primary, both the PDPL and the Implementing Regulation read directly. See our Saudi Arabia data privacy laws overview |
| UAE, Federal (PDPL) | UAE Data Office | Federal Decree-Law No. 45/2021 Art. 9(1) sets no deadline at all. It requires notice to the Bureau "at the time it becomes aware" of a breach, but leaves the actual period to "the measures and requirements set by the Executive Regulations," which have never been issued. The 72-hour figure quoted everywhere is UAE Data Office operational guidance, not statute text | No deadline either. Art. 9(2) leaves the notification period to affected individuals entirely to "the Executive Regulations," which have never been issued | Risk to the privacy, confidentiality, or security of the data subject's data, no bright-line threshold defined | Statute confirmed; the 72-hour figure is compliance-guide sourced, not codified. See our UAE PDPL vs. GDPR comparison |
| UAE, DIFC | Commissioner of Data Protection (DIFC) | No fixed hour or day deadline anywhere in the DP Law 2020. Art. 41(1): "as soon as practicable in the circumstances" | Same standard, "as soon as practicable," escalating to "promptly" only if there is immediate risk of damage (Art. 42(1)) | Any breach compromising confidentiality, security, or privacy for regulator notice; "likely to result in a high risk" for individual notice | Primary, Articles 41-42 read directly, in force |
| UAE, ADGM | Office of Data Protection (Commissioner of Data Protection, ADGM) | 72 hours, "without undue delay and, where feasible, not later than 72 hours" (Data Protection Regulations 2021, Art. 32(1)); reasons required if later | "Without undue delay" where likely to result in high risk, no fixed hour count, with GDPR-style safe-harbor exemptions (Art. 33(3)) | High risk to the rights of natural persons, a GDPR-style formulation | Primary, Articles 32-33 read directly, in force |
| Qatar | Compliance and Data Protection Department (CDP), under the NCSA | Law No. 13 of 2016, Art. 14, sets no numeric deadline, only "if such breach would result in serious damage." A 72-hour figure appears in sub-statutory CDP/NCSA Guidelines, not the Law | Same "serious damage" trigger applies to both legs under the Law; the Guidelines apply the same 72-hour figure to both | "Serious damage to personal data or privacy," undefined, self-assessed by the controller | The structural finding (deadline lives in guidance, not the Law) is corroborated by multiple sources; the 72-hour figure itself was not confirmed by a direct primary read of the Guidelines |
| Bahrain | Personal Data Protection Authority (PDPA) | The primary Law No. 30 of 2018 contains no breach-notification article at all, confirmed by reading all 60 articles directly. Any 72-hour figure for Bahrain lives only in Resolution No. 43 of 2022, a sub-statutory instrument that could not be located as an openly fetchable primary document | Same gap: no individual-notice clause in the primary Law | N/A in the primary Law | Primary Law read in full, confirms the gap. We are not publishing a specific hour figure for Bahrain because the instrument that would supply it could not be verified |
| Kuwait | Communications and Information Technology Regulatory Authority (CITRA) | We are not publishing a specific number. Secondary sources conflict between 24 hours and 72 hours, both attributed to Regulation No. 26 of 2024, Art. 4(15), and neither was confirmed by a direct primary read | Same conflict, unresolved | Not clearly stated in available sourcing | Scope-limited: covers only CITRA-licensed telecom/IT providers, not an economy-wide law like every other row in this table |
| Oman | Ministry of Transport, Communications and Information Technology (MTCIT), Personal Data Protection Department | 72 hours from becoming aware of a breach that threatens data-subject rights, per the 2024 Executive Regulation to Royal Decree 6/2022 | Same trigger applies to individual notice; no separate day count found | Breach that "may lead to destruction, alteration, disclosure, or unauthorised access" and threatens data-subject rights, no numeric bright line | Secondary-sourced; the primary Gazette PDF was located but not text-extractable |
| Israel | Privacy Protection Authority (PPA) | No fixed hour or day figure. The Protection of Privacy Regulations (Data Security), 5777-2017 require "immediate" report of a "Severe Security Incident." The PPA hardened its posture in September 2022, moving away from an informal 24-72 hour grace window toward demanding truly immediate notice | Not a default statutory duty. The PPA can separately direct a controller to notify affected individuals on a case-by-case basis | "Severe Security Incident," defined by the database's security tier | Secondary-sourced (did not reach a gov.il primary text); the 2022 policy hardening is the key, under-reported nuance most aggregators still miss, they say "24-72 hours" for Israel |
| Turkey | KVKK (Personal Data Protection Board) | 72 hours, "without delay and not later than 72 hours after having become aware," per Board Decision No. 2019/10, read directly. Reasons required if missed | "Shortest reasonable period of time," direct contact preferred, or public announcement if direct contact is not feasible | Unlawful access to personal data (Law No. 6698 Art. 12(5)); the unlawful-access trigger itself is the threshold | Primary, Board Decision read directly, in force. Highest-confidence row in this table |
| Egypt | Personal Data Protection Center (PDPC) | 72 hours to the PDPC, per Executive Regulations issued 1 Nov 2025 under Law No. 151/2020. A one-year grace period runs to 31 October 2026, so full enforcement is not yet live | 3 working days from the PDPC notification, a second, separate clock | Applies broadly to any personal data breach or violation, with immediate notice for national-security-implicated breaches | Secondary-sourced (law-firm alerts, primary regulation text not located this pass); the grace-period timing is the important flag for anyone publishing before 31 Oct 2026 |
| Morocco | CNDP (Commission Nationale de controle de la protection des Donnees a caractere Personnel) | No mandatory numeric deadline exists. Law 09-08's core mechanism is a prior declaration/authorization regime for processing, not a post-breach notice duty with a clock | Not established by the statute | N/A, no statutory breach-notice regime | Corroborated by multiple independent sources; safe to present as a genuine no-deadline jurisdiction, alongside South Africa and Ghana |
| Tunisia | INPDP | Unsettled. The operative statute is the 2004 Organic Act No. 2004-63, which predates GDPR-style breach regimes and likely contains no such clause. A 2025 reform bill is pending, not yet enacted. It is unclear which instrument any cited "72 hours" figure actually describes | Same ambiguity | Same ambiguity | Not confirmed by a primary read of the 2004 text; do not treat 72 hours as settled current Tunisian law |
| Nigeria | Nigeria Data Protection Commission (NDPC) | 72 hours of becoming aware, per the Nigeria Data Protection Act 2023, Section 40(2); phased disclosure allowed if full information is not yet available | "Without undue delay" where there is high risk of fraud, identity theft, or exposure of sensitive data | High risk to rights and freedoms, assessed via the nature of the breach and probability of secondary harm | Strong, consistent secondary corroboration including the regulator's own guidance document; not independently re-opened as primary text this pass |
| Kenya | Office of the Data Protection Commissioner (ODPC) | 72 hours of becoming aware, per the Data Protection Act 2019, Section 43(1)(a), read directly. Late notice must explain the delay | "In writing within a reasonably practical period," no fixed hour or day count, with a safe-harbor exception where appropriate security safeguards like encryption were already in place | Not numeric, but not automatic either: s.43(1) needs unauthorised access or acquisition plus a real risk of harm to the data subject, and reg. 37 of the Data Protection (General) Regulations 2021 defines when that real risk is taken to exist (full name or ID number combined with Second Schedule data such as salary, card or bank-account numbers; or an account identifier combined with a password, security code or biometric) | Primary, Kenya Law's official statute portal read directly, in force |
| South Africa | Information Regulator | No fixed hour or day deadline. POPIA Section 22(1): notification "as soon as reasonably possible," considering law-enforcement needs and the time needed to determine scope and restore system integrity | Same "as soon as reasonably possible" standard applies to both the Regulator and the data subject, POPIA does not split these into separate clocks | "Reasonable grounds to believe" personal information was accessed or acquired by an unauthorized person, a belief-based trigger, not a severity threshold | Near-unanimous corroboration across every source checked; deliberately present this as a no-fixed-deadline row, do not assign 72 hours to South Africa |
| Ghana | Data Protection Commission | No fixed hour or day deadline under the current Data Protection Act, 2012 (Act 843). A pending amendment bill would add a mandatory 72-hour window, not yet in force | Same "reasonable grounds" trigger, no fixed clock | "Reasonable grounds to believe" unauthorized access or acquisition occurred | The substantive finding (no numeric deadline today, a 72-hour bill pending) is corroborated by multiple sources; the exact section citation was not independently confirmed |
| Tanzania | Personal Data Protection Commission (PDPC) | No fixed hour or day deadline in the Act itself. Personal Data Protection Act 2022, Section 27(5): notify "without undue delay." Numeric detail may sit in the 2023 breach-specific regulations, which were not opened this pass | Not detailed in available sourcing, flagged as a gap rather than confirmed either way | Any incident resulting in unauthorized access, disclosure, loss, or compromise of personal data, no severity bar identified | Corroborated by international-firm trackers; the 2023 regulations may contain a numeric clock the Act itself lacks, treat this as unresolved, not settled |
The Americas
Latin America's civil-law data-protection statutes mostly use open-ended language for the primary law, with fixed numeric clocks appearing in implementing regulations, decrees, or resolutions, a level below the law itself. Two structural outliers, Argentina (no legal duty) and Chile (a genuine two-law misattribution), are the region's most-quoted mistakes.
| Jurisdiction | Regulator | Deadline to Regulator | Notice to Individuals | Trigger / Threshold | Legal Basis & Status |
|---|---|---|---|---|---|
| Canada, federal (PIPEDA) | Office of the Privacy Commissioner of Canada (OPC) | "As soon as feasible after the organization determines that the breach has occurred," no fixed number of days (s.10.1(2)) | Same standard, same clause, "as soon as feasible" (s.10.1(6)) | "Real risk of significant harm" (RROSH): sensitivity of the information plus probability of misuse (s.10.1(8)) | Primary statute (s.10.1), read directly, in force |
| Quebec (Law 25) | Commission d'acces a l'information (CAI) | No fixed statutory hour or day figure. Section 3.5: "must promptly notify" the CAI once there is a risk of serious injury. The widely-cited 72 hours is CAI/industry guidance, not the Act's own text | Individuals must also be notified under the same clause, though the statute repeats no adverb for that leg; the CAI can order notice if the enterprise does not give it | "Risk of serious injury" from the confidentiality incident | Primary statute (s.3.5), read directly on legisquebec.gouv.qc.ca, in force |
| Brazil (LGPD) | Autoridade Nacional de Protecao de Dados (ANPD) | 3 business days from when the controller becomes aware the incident compromised personal data (doubled to 6 for small-sized agents), per ANPD Resolution CD/ANPD No. 15/2024 | Same 3-business-day clock, same resolution | Controller must assess whether the incident may cause relevant risk or harm to data subjects, a judgment call, not every incident is reportable | Primary, ANPD's own site read directly, in force |
| Mexico (new LFPDPPP) | Secretaria Anticorrupcion y Buen Gobierno (SABG), which replaced INAI after INAI was abolished 21 March 2025 | "De forma inmediata" (immediately), no numeric-day figure in the statute; implementing procedure for notifying SABG itself is left to future regulations | "Immediate" notice once the breach significantly affects the data subject's property or moral rights | Breach must "significantly affect" the data subject's property or moral rights | Primary statute text and the regulator-swap decree both read directly, in force |
| Argentina (Law 25.326) | Agencia de Acceso a la Informacion Publica (AAIP) | No general legal obligation to notify a breach exists under Argentine law, only sectoral exceptions. The AAIP recommends, non-bindingly, notifying within 72 hours | Same, no binding deadline; the AAIP's recommendation covers individuals too, also non-binding | N/A, this is the key differentiator versus the rest of the Americas | Primary text of Law 25.326 confirms no breach-notification article exists; only a general Art. 9 security duty. See our Argentina data privacy laws overview |
| Uruguay | Unidad Reguladora y de Control de Datos Personales (URCDP) | 72 hours of becoming aware of the vulnerability (Decree 64/020, Art. 4). A separate, unrelated 24-hour figure in Art. 3 is the deadline to begin mitigation procedures, not to notify anyone, a frequent point of confusion | No fixed hour figure, "once confirmed... in clear and simple language," owed only where there is significant impact on rights | High risk to the rights of data subjects | Primary, Decree 64/020 Art. 4 read directly, in force. See our Uruguay data privacy laws overview |
| Chile (Law 21.719) | New Agencia de Proteccion de Datos Personales (APDP), effective 1 December 2026 | No fixed hour. Article 14 sexies: report "by the most expeditious means possible and without undue delay," full stop. This is the page's headline correction: the 72-hour (and 3-hour, and 15-day) figures widely quoted for Chile belong to a different law, the Cybersecurity Framework Law (21.663), Art. 9, which covers cyberattacks against essential services reported to CSIRT Nacional, not personal-data breaches | Required only for sensitive data, minors under 14, or financial/credit data, same "expeditious, without undue delay" standard, no fixed hour | Reasonable risk to the rights and freedoms of data subjects, for the data-protection law's own trigger | Both laws read directly in full. Data-protection Law 21.719 is not yet in force (effective 1 Dec 2026); the Cybersecurity Framework Law 21.663 is separately in force now for essential-services operators |
| Colombia | Superintendencia de Industria y Comercio (SIC) | 15 business days from the moment the incident is detected and brought to the attention of the person or area responsible | No separate statutory individual-notice deadline located; Colombia's regime is regulator-notice-centric | Any event aimed at violating security codes, or unauthorized/fraudulent alteration, loss, consultation, use, or access to personal data | Primary, SIC's own published concept quoting the rule verbatim, in force |
| Peru | Autoridad Nacional de Proteccion de Datos Personales | 48 hours maximum after becoming aware, per D.S. 016-2024-JUS, Art. 34, in force since 30 March 2025 | 48 hours as well, the same figure for both legs, not two different clocks as some secondary sources guessed | Exposure of large data volumes, potential effect on a large number of people, sensitive data involved, or evident harm to other rights | Primary, regulation Art. 34 read directly, in force |
| Costa Rica | Agencia de Proteccion de Datos de los Habitantes (PRODHAB) | Art. 39 requires the same notice content to go to both the data subject and PRODHAB, no separate regulator-specific clock is carved out | 5 business days from when the vulnerability occurred, framed as the data-subject-facing deadline (Art. 38) | "Irregularity" in treatment or storage, loss, destruction, or extortion of data resulting from a security vulnerability | Primary, Decreto 37554-JP Arts. 38-39 read directly, in force |
| Panama | Autoridad Nacional de Transparencia y Acceso a la Informacion (ANTAI) | "De inmediato" (immediately), the general rule for both ANTAI and affected individuals, with no separate numeric backstop for ANTAI specifically | The general "immediately" rule, plus a 72-hour outer bound specifically governing the format and content of the individual-facing notice | Damage, loss, alteration, destruction, unauthorized access, or illicit use of personal data representing a risk to data protection | Primary, Decreto Ejecutivo 285 de 2021, Art. 37, read directly, in force |
| Ecuador | Superintendencia de Proteccion de Datos Personales, plus ARCOTEL | 5 days ("término de cinco (5) días", so business days) after having constancy of the breach (LOPDP Art. 43), not 3 days as some secondary sources invert it. Processor-to-controller notice is a separate 2-business-day clock, and notice is excused where the breach is unlikely to pose a risk to rights and freedoms | 3 days ("término de tres días", also business days) from learning of the risk (LOPDP Art. 46), the shorter of the two legs, again the opposite ordering from what several aggregators report. Art. 46 excuses individual notice where effective technical measures were already applied or where the controller shows the risk will not occur, and permits a public announcement where direct notice would take disproportionate effort | Any vulneracion affecting confidentiality, availability, or integrity of personal data | Primary, LOPDP Arts. 43 and 46 read directly, in force |
| Jamaica | Office of the Information Commissioner (OIC) | 72 hours of becoming aware, and the clock cannot be paused to first confirm personal data was actually affected, the obligation arises once the breach could potentially affect personal data | 72 hours as well, per converging secondary sources | Any security breach affecting or potentially affecting personal data | Secondary-sourced (primary PDF not text-extractable this pass); a cited criminal penalty of up to 7 years' imprisonment for non-reporting was not independently confirmed and should be treated as unverified |
Common misconceptions
"Chile is 72 hours." No. Chile's data-protection law, 21.719, sets no fixed hour at all for breach notification, only "the most expeditious means possible, without undue delay." The 72-hour figure that gets attached to Chile everywhere actually belongs to a separate statute, the Cybersecurity Framework Law (21.663), which governs cyberattacks against essential services reported to a different regulator, CSIRT Nacional, not general personal-data breaches. Treating these as the same law is the single most-repeated Chile error.
"Germany's telecom rule is 24 hours." Half right, and the wrong half is the sourcing, not the number. Section 169 of the Telecommunications Act (TKG) uses only "unverzuglich," without undue delay, with no numeric figure anywhere in the statute text, so a provider that reads only the TKG will not find 24 hours there. But the 24 hours is real and binding: Regulation (EU) No 611/2013, Article 2(2), applies directly in every member state, Germany included, to providers of publicly available electronic communications services, and requires notice to the competent national authority "no later than 24 hours after the detection of the personal data breach, where feasible." The error is attributing the figure to the TKG, not the figure itself.
"Ecuador is 72 hours to the regulator, 3 days to individuals" or "3 days to the regulator." Both common phrasings get it backwards or conflate the legs. Ecuador's LOPDP sets 5 business days to the Superintendencia and ARCOTEL (Art. 43), and a shorter 3-business-day clock to the individual (Art. 46), the opposite of the regulator-then-individual ordering most breach laws use.
"Everyone uses 72 hours." No. A meaningful share of the jurisdictions in this matrix set no fixed hour figure at all for at least one leg: South Africa, Switzerland, Canada, New Zealand's own statute (the 72 hours you'll see cited is Privacy Commissioner guidance, not the Act), Morocco, Ghana, DIFC, Israel, and Chile's data-protection law all use open-ended standards like "as soon as reasonably possible" or "without undue delay" instead.
Guidance is not statute. The UAE's federal 72-hour figure is Data Office operational guidance; the Executive Regulations that would codify a number were never formally issued. New Zealand's 72 hours is the Privacy Commissioner's own guide, explicitly labeled "a guide only." Quebec's 72 hours is CAI/industry shorthand for a statute that actually just says "promptly."
Enacted is not in force. Taiwan's 72-hour authority-notice clock exists only in a December 2025 amendment awaiting subsidiary regulations and a commencement order; today's operative Taiwanese law has no authority-notice deadline whatsoever. India's DPDP breach-notification duty is enacted but does not commence until roughly 13 May 2027. Egypt's Executive Regulations took effect 1 November 2025 but carry a one-year grace period to 31 October 2026.
Hong Kong has no legal deadline, because it has no legal requirement. Breach notification in Hong Kong is entirely voluntary under the PDPO; the Privacy Commissioner's guidance recommending prompt notice is non-binding.
Argentina has no breach-notification obligation at all. Law 25.326 contains a general security duty but no breach-notice article. The AAIP's 72-hour recommendation is exactly that, a recommendation, not a legal requirement.
Kuwait: no number should be published. Reputable secondary sources directly conflict between 24 hours and 72 hours for the same regulation (Regulation No. 26 of 2024, Art. 4(15)), and the regulation is scope-limited to CITRA-licensed telecom and IT providers, not an economy-wide law.
Sector overlays: rules that stack on top of the general law
Several regimes impose their own, often shorter, breach or incident clocks on specific sectors, layered on top of (not instead of) the general data-protection deadline that already applies.
- NIS2 Directive (EU 2022/2555), Art. 23. applies to "essential" and "important" entities: critical infrastructure, digital infrastructure, healthcare, energy, and similar sectors, not general controllers. A three-stage cascade: an early warning within 24 hours, a full incident notification within 72 hours, and a final report within one month.
- DORA (EU 2022/2554), Art. 20 and its implementing technical standards. applies to the financial sector: banks, insurers, investment firms, and critical ICT third-party providers. Confirmed directly from the Regulatory Technical Standards: an initial report within 4 hours of classifying an incident as major (and in any case within 24 hours of becoming aware), an intermediate report within 72 hours, and a final report within one month.
- eIDAS Regulation (EU 910/2014), Art. 19(2). trust service providers (e-signature, e-seal, website-authentication providers) must notify their national supervisory body within 24 hours, separate from the 72-hour GDPR route, and this duty also applies in the UK via its retained eIDAS regime.
- EU ePrivacy sector regulation (611/2013). public electronic-communications providers across the EU notify their national telecoms regulator within 24 hours where feasible, the EU-wide rule underneath Germany's TKG example above.
- HIPAA (US health data), 45 CFR Sec. 164.404. covered entities must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery. Breaches affecting 500 or more individuals also require notifying HHS and, in many cases, prominent local media, on the same 60-day clock; smaller breaches are logged and reported to HHS annually.
- SEC, Item 1.05 of Form 8-K (US public companies). discloses a material cybersecurity incident within 4 business days of determining materiality, not from discovery of the incident itself. The clock starts at the materiality determination, which itself must be made "without unreasonable delay."
- CERT versus DPA divergence, the sharpest example anywhere in this matrix: India. CERT-In's 6-hour cybersecurity-incident rule is live and binding today. The DPDP Act's data-protection-specific breach duty, with its own "without delay" plus 72-hour Board report, is enacted but does not commence until roughly 13 May 2027. An Indian company facing a breach right now is bound by the 6-hour CERT-In clock, not by any DPDP number, no matter how often "India's breach deadline" gets reported as 72 hours.
United States: state-by-state summary
There is no single federal data-breach-notification law in the US. All 50 states, DC, and the US territories have their own statutes, and the site maintains a full page for each at /us-laws/data-privacy-laws/{state}-data-privacy-laws/data-breach-notification/. This section summarizes the pattern rather than repeating 51 rows.
The most common standard is not a fixed number. Most states use a "without unreasonable delay" or "most expedient time possible" standard, sometimes paired with an outer-bound backstop number.
Where states do set a numeric outer bound, it clusters in the 30-45-60 day range. Washington requires notice within 30 calendar days (RCW 19.255.010), and Florida sets the same 30-day figure with one 15-day extension available for good cause, making the practical ceiling 45 days. Colorado also uses 30 days, with a lower 500-resident threshold for AG notice and a separate 1,000-resident threshold for notifying nationwide consumer-reporting agencies.
Texas is the outlier worth naming specifically, because it does not fit the pattern most aggregators assume. Texas gives individuals 60 days to be notified, but requires notice to the Texas Attorney General within a much shorter 30 days when 250 or more Texas residents are affected, the AG clock, not the consumer clock, is the short one.
AG or regulator notification thresholds most commonly trigger at 500 residents (Florida, Washington, and many others) or 1,000 residents (used both as an independent AG-notice trigger in some states and as a separate consumer-reporting-agency trigger in Colorado).
Federal sectoral rules fill some of the gap where no general federal law exists: HIPAA's 60-day rule for health data and the SEC's 4-business-day rule for public companies (both detailed above), plus the FTC Safeguards Rule, which requires non-banking financial institutions to notify the FTC, not consumers, within 30 days of discovering a breach affecting 500 or more consumers' unencrypted information. That FTC rule is regulator-facing only; consumer notice still depends on the applicable state law.
Practical compliance guidance
Identify both legs separately, for every jurisdiction where you operate. A breach-response plan that tracks only "the deadline" for a country, rather than the regulator deadline and the individual deadline as two distinct clocks with two distinct triggers, will misfire the moment those two clocks diverge, which is the norm, not the exception, across this matrix.
Start every jurisdiction's clock from "becoming aware," not from "confirmed." Most of the statutes above measure from when the controller became aware of, or had reasonable grounds to believe, a breach occurred, not from when the investigation concluded. Waiting for full certainty before starting the clock is one of the more common ways organizations blow a 72-hour deadline.
Check whether the number you are relying on is in the primary statute, a subordinate regulation, or guidance, and whether it has actually commenced. This matrix flags every instance where those three things diverge: Chile, Germany, the UAE, New Zealand, Quebec, Taiwan, India, and Egypt all have at least one commonly-cited figure that turns out to be guidance, a different law, or not yet in force.
Where a jurisdiction sets no fixed number, "as soon as possible" is still an enforceable standard, not an invitation to delay. Regulators in no-fixed-deadline jurisdictions, Switzerland's FDPIC and South Africa's Information Regulator among them, actively evaluate whether the delay itself was reasonable given the facts, even without a bright-line hour count to measure against.
Multinational breaches trigger the shortest applicable clock across every affected jurisdiction simultaneously. A breach touching EU, Indian, and US data subjects at once is bound by GDPR's 72 hours, CERT-In's 6 hours, and whichever US state and sector rules apply, concurrently, not sequentially. Build the response plan around the shortest clock in the mix, not the average.
Frequently Asked Questions
Is 72 hours the global standard for data breach notification?
No. It is the most-copied figure, originating with the EU's GDPR, but a meaningful share of the countries in this matrix, including Switzerland, South Africa, Canada, New Zealand's own statute, and Chile's data-protection law, set no fixed hour figure at all. Others use different numbers entirely, such as Brazil's 3 business days or Peru's 48 hours.
Why does Chile keep getting quoted as a 72-hour country?
Chile's Cybersecurity Framework Law (21.663) does set a 72-hour clock, but only for cyberattacks against essential services, reported to CSIRT Nacional. Chile's actual data-protection law, 21.719, sets no fixed hour at all for personal-data breaches, only "the most expeditious means possible, without undue delay." Aggregators regularly misattribute the cybersecurity law's number to the data-protection law.
Is the commonly-cited 24-hour German telecom breach rule accurate?
The number is right, the attribution usually is not. Section 169 of Germany's Telecommunications Act (TKG) uses only "unverzuglich," without undue delay, with no numeric figure anywhere in the statute text. The 24-hour clock comes from directly applicable EU law instead: Regulation (EU) No 611/2013, Article 2(2), requires providers of publicly available electronic communications services to notify the competent national authority "no later than 24 hours after the detection of the personal data breach, where feasible." A German telecom provider does face a binding 24-hour deadline, it just is not written in the TKG.
What is the difference between the regulator-notification deadline and the individual-notification deadline?
They are usually two separate clocks with two separate triggers. Under GDPR, for example, the regulator must be notified of any breach that carries some risk within 72 hours, while individuals only need to be notified, with no fixed hour figure, if the breach poses a high risk, a meaningfully higher bar. Many other jurisdictions follow a similar split, and conflating the two legs is the most common error in breach-notification coverage.
Which countries have no legal deadline for breach notification at all?
South Africa, Switzerland, Canada, New Zealand (by statute; a 72-hour figure exists only in non-binding regulator guidance), Morocco, and Ghana all set no fixed hour or day figure in their current law. Hong Kong goes further: breach notification itself is entirely voluntary. Argentina has no legal breach-notification obligation of any kind, only a non-binding regulator recommendation.
Is India's data-protection breach-notification rule in effect right now?
Not yet. The DPDP Act's breach-notification duty, including its 72-hour detailed report to the Data Protection Board, was gazetted 13 Nov 2025 but does not commence until roughly 13 May 2027. What does bind Indian entities today is a separate cybersecurity regime, CERT-In's 6-hour incident-reporting rule under the IT Act, which has been in force since 2022. These are two different regimes and should never be reported as a single "India's breach deadline" figure.
Does Malaysia's 72-hour clock run from when the breach happened or from when it was discovered?
The circular text itself (Pekeliling No. 2/2025, s.4(4)) reads "within 72 hours from the personal data breach," language pointing to occurrence rather than discovery, while s.4(1) separately frames the underlying duty as "as soon as practicable." The Commissioner's own detailed Guideline on this point was not independently verified for this page, so treat the exact clock-start with some caution and confirm current JPDP guidance before relying on it for a live compliance deadline.
Does the United States have one federal data-breach-notification deadline?
No. There is no general federal breach-notification law. All 50 states, DC, and the US territories set their own deadlines, most commonly "without unreasonable delay" with an optional 30-60 day backstop. Federal sectoral rules fill part of the gap for specific industries: HIPAA gives covered entities 60 days for health-data breaches, and the SEC requires public companies to disclose material cybersecurity incidents within 4 business days of determining materiality.
Why do Kuwait and Bahrain not have a published deadline in this matrix?
For Kuwait, reputable secondary sources directly conflict, some cite 24 hours and others 72 hours, for the same regulation, and we could not resolve the conflict against a primary text. For Bahrain, the primary data-protection Law contains no breach-notification article at all; any 72-hour figure lives only in a 2022 Resolution that could not be located as a verifiable primary document. Publishing an invented number in either case would be less accurate than stating the gap honestly.
Updates
Initial publication of the 45-plus jurisdiction data breach notification deadline matrix, covering Europe, Asia-Pacific, the Middle East and Africa, and the Americas, sourced entirely from primary statutes, implementing regulations, and regulator guidance, plus a US state-law summary and sector overlays (NIS2, DORA, eIDAS, HIPAA, SEC).
Sources and References
- GDPR Article 33 — Notification of a personal data breach to the supervisory authority(gdpr-info.eu)
- GDPR Article 34 — Communication of a personal data breach to the data subject(gdpr-info.eu)
- ICO — Personal data breaches: a guide(ico.org.uk).gov
- Switzerland revFADP (SR 235.1), Article 24 — Meldung von Verletzungen der Datensicherheit(fedlex.admin.ch).gov
- Datatilsynet — Meld avvik til Datatilsynet (breach reporting guidance)(datatilsynet.no).gov
- EFTA EEA-Lex — GDPR incorporation into the EEA Agreement (JCD 154/2018)(efta.int)
- Germany — Telekommunikationsgesetz (TKG) § 169(gesetze-im-internet.de).gov
- BfDI — Das Verfahren nach § 169 TKG(bfdi.bund.de).gov
- CNIL — Notifications d'incidents de sécurité aux autorités de régulation(cnil.fr).gov
- EUR-Lex — Directive (EU) 2022/2555 (NIS2)(eur-lex.europa.eu).gov
- EUR-Lex — Commission Delegated Regulation (EU) 2025/301 (DORA incident-reporting RTS)(eur-lex.europa.eu).gov
- EUR-Lex — Regulation (EU) 910/2014 (eIDAS), Article 19(eur-lex.europa.eu).gov
- Japan PPC — Data breach reporting obligation overview(ppc.go.jp).gov
- China — Cyberspace Administration of China, Network Data Security Management Regulations(cac.gov.cn).gov
- China PIPL Article 57 (translation)(personalinformationprotectionlaw.com)
- Singapore — Personal Data Protection Act 2012(sso.agc.gov.sg).gov
- Malaysia — Pekeliling Pesuruhjaya Perlindungan Data Peribadi Bilangan 2 Tahun 2025 (Data Breach Notification Circular)(pdp.gov.my).gov
- Philippines NPC Circular 16-03 — Personal Data Breach Management(privacy.gov.ph).gov
- Indonesia — UU No. 27 Tahun 2022 tentang Pelindungan Data Pribadi, Pasal 46(jdih.komdigi.go.id).gov
- Australia OAIC — Notifiable Data Breach scheme, Part 4(oaic.gov.au).gov
- New Zealand OPC — Breach Management guidance(privacy.org.nz).gov
- Hong Kong PCPD — Guidance Note on Data Breach Handling and Notification(pcpd.org.hk).gov
- Taiwan — Personal Data Protection Act, Article 12(law.moj.gov.tw).gov
- Vietnam Decree No. 13/2023/ND-CP on Personal Data Protection, Article 23(finalsite.net)
- Internet Freedom Foundation — statement on DPDP Rules 2025 notification and commencement schedule(internetfreedom.in)
- Saudi Arabia — Personal Data Protection Law, Article 20(sdaia.gov.sa).gov
- Saudi Arabia — PDPL Implementing Regulation, Article 24(sdaia.gov.sa).gov
- UAE Federal Decree-Law No. 45 of 2021 (PDPL), Article 9(uaepdpl.com)
- DIFC Data Protection Law No. 5 of 2020, Articles 41–42(assets.difc.com).gov
- ADGM Data Protection Regulations 2021, Articles 32–33(assets.adgm.com).gov
- Qatar Law No. 13 of 2016, Article 14(almeezan.qa).gov
- Bahrain Personal Data Protection Law No. 30 of 2018 (full text)(pdp.gov.bh).gov
- Oman — Personal Data Protection Law, Official Gazette text(mtcit.gov.om).gov
- Turkey KVKK — Board Decision No. 2019/10 on personal data breach notification(kvkk.gov.tr).gov
- Nigeria NDPC — Data Protection Act Guidance, March 2025(ndpc.gov.ng).gov
- Kenya Law — Data Protection Act, 2019, Section 43(kenyalaw.org).gov
- Ghana — Data Protection Act, 2012 (Act 843)(nita.gov.gh).gov
- Tanzania — Personal Data Protection Act, 2022(pdpc.go.tz).gov
- Canada — Personal Information Protection and Electronic Documents Act, s.10.1(laws-lois.justice.gc.ca).gov
- Quebec — Act respecting the protection of personal information in the private sector, s.3.5(legisquebec.gouv.qc.ca).gov
- ANPD — Comunicado de Incidente de Segurança (breach notification requirement)(gov.br).gov
- Mexico — Ley Federal de Protección de Datos Personales en Posesión de los Particulares(diputados.gob.mx).gov
- Mexico — Diario Oficial de la Federación, regulator transition decree, 20 March 2025(dof.gob.mx).gov
- Argentina — Law 25.326 (Ley de Protección de los Datos Personales), full text(oas.org)
- Uruguay — Decreto 64/020, Articles 3–4(impo.com.uy).gov
- Chile — Ley 21.719, Artículo 14 sexies (official BCN text)(bcn.cl).gov
- Chile — Ley 21.663 (Cybersecurity Framework Law), Artículo 9(bcn.cl).gov
- Colombia SIC — Cumplimiento de la obligación del reporte de incidentes de seguridad(sic.gov.co).gov
- Peru — D.S. 016-2024-JUS, Artículo 34(lpderecho.pe)
- Costa Rica — Decreto Ejecutivo 37554-JP, Artículos 38–39(mopt.go.cr).gov
- Panama — Decreto Ejecutivo 285 de 2021, Artículo 37(sijusa.com)
- Ecuador — Ley Orgánica de Protección de Datos Personales, Artículos 43 y 46(cpccs.gob.ec).gov
- eCFR — HIPAA Breach Notification Rule, 45 CFR § 164.404(ecfr.gov).gov
- SEC — Press Release 2023-139, Cybersecurity Incident Disclosure (Item 1.05 Form 8-K)(sec.gov).gov
- FTC — Safeguards Rule notification requirement now in effect(ftc.gov).gov
- Washington RCW 19.255.010 — Notice of security breaches(app.leg.wa.gov).gov
- Florida Statute § 501.171 — Security of confidential personal information(flsenate.gov).gov