Breach Notification
Breach notification is the practice of informing affected individuals, and often regulators, when their personal or sensitive data has been exposed, lost, or accessed without authorization. Various laws set out who must send these notices, how quickly, and to whom. The goal is to make sure people are told promptly so they can take steps to protect themselves.
Breach notification refers to the legal and procedural obligations, imposed under a range of regulatory frameworks, to notify affected data subjects and, where required, supervisory authorities following a security incident involving personal or otherwise protected data. The specific triggers, timelines, thresholds, and required recipients vary by governing regime: under the GDPR, a personal data breach is defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, personal data; HIPAA's Breach Notification Rule requires covered entities to notify patients when unsecured protected health information (PHI) is impermissibly used or disclosed; the FTC's Health Breach Notification Rule applies to certain businesses and nonprofits not covered by HIPAA; and sector-specific rules, such as the FCC's data breach notification rules for carriers handling consumer PII, impose their own requirements. Because obligations differ by jurisdiction, sector, and data type, organizations should determine which regime or regimes apply to a given incident and validate requirements against the current text of the applicable rule.
Why it matters
Breach notification obligations turn a security incident from a private technical event into a matter of legal and public accountability. When personal or protected data is exposed, lost, or accessed without authorization, affected individuals often cannot take protective steps unless they are told. Timely notification is intended to give people the opportunity to monitor accounts, change credentials, watch for fraud, or otherwise mitigate harm, while giving regulators visibility into incidents affecting the populations they oversee.
For organizations that handle payment or personal data, breach notification is one of the most consequential compliance areas because the applicable rules differ substantially by jurisdiction, sector, and data type. The GDPR defines a personal data breach broadly as a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, personal data. HIPAA's Breach Notification Rule addresses unsecured protected health information held by covered entities, the FTC's Health Breach Notification Rule reaches certain businesses and nonprofits not covered by HIPAA, and rules such as the FCC's data breach notification requirements govern carriers handling consumer PII. A single incident may implicate more than one of these regimes at once.
Because triggers, timelines, thresholds, and required recipients vary across these frameworks, misreading which rule applies can lead either to unnecessary disclosure or to a failure to notify when required. Organizations should determine which regime or regimes govern a given incident and validate the specific obligations against the current published text of the applicable rule, rather than assuming a uniform standard. Note that PCI DSS is a separate framework focused on protecting cardholder data; it is not itself a breach notification law, and payment card breach reporting to card brands is governed separately by network and brand rules.
Who it's relevant to
Inside Breach Notification
Common questions
Answers to the questions practitioners most commonly ask about Breach Notification.