Different clocks, different starting points
Notice deadlines come from many sources: state breach laws, sector rules for health and financial data, securities disclosure rules for public companies, regulators' own requirements, and contracts with business customers. Some are measured in hours, others in a set number of days, and some require notice only without unreasonable delay. New York now sets an outer limit on notice to individuals in addition to its general promptness standard, and its financial regulator expects to hear from supervised companies very soon after an incident is identified. Public companies must disclose a material cybersecurity incident within a short window after determining that it is material.
When the clock starts
Whether a deadline begins at discovery, at a determination that an incident occurred, or at a determination that personal information was affected changes the math considerably, and the laws do not agree with one another. Waiting to finish the investigation before deciding anything is a common mistake, because some deadlines keep running while the facts are still developing. Under many statutes law enforcement can ask for notice to be delayed when it would interfere with an investigation, but the request should be documented, and the delay usually ends when the reason does. Data breach response time is therefore partly a documentation exercise, recording when each fact was learned.
Mapping the deadlines
When a company calls us during an incident, one of the first things we produce is a list of notice obligations that may apply and the earliest date each could fall due, based on what is known so far. That list is revisited as the investigation develops, since a new data type or a newly identified group of affected people can add obligations. An early, brief notice to a regulator with supplemental information to follow is sometimes possible. The goal is to meet each obligation on time without committing to facts that later change.