Skip to main content
Should You Notify Victims Before Closing Your Investigation?Breach & Risk Assessment
5 min readFor Privacy Officers

Should You Notify Victims Before Closing Your Investigation?

When France's tax authority disclosed a breach affecting roughly 600,000 individuals and businesses, it faced a challenging decision: notifying victims while the investigation was still underway. The General Directorate of Public Finances (DGFiP) sent emails and postal notices, warning that stolen data could enable convincing phishing attacks, even as it continued examining whether additional datasets had been compromised.

This raises a question every privacy officer will face: Do you notify affected individuals as soon as you confirm exposure, or wait until your forensic review is complete?

The answer depends on three factors: the nature of the exposed data, your regulatory timeline, and the immediate risk to individuals.

Key Factors That Affect Your Choice

Data sensitivity and misuse potential
Tax identification numbers, household composition, and message contents, like those exposed in the DGFiP breach, create immediate fraud risk. If stolen credentials can be misused quickly, early notification lets victims take protective action before attackers do.

Regulatory notification deadlines
Under GDPR Article 34, you must notify individuals "without undue delay" when a breach is likely to result in a high risk to their rights and freedoms. The 72-hour notification to your Supervisory Authority under Article 33 runs in parallel but doesn't pause the individual notification clock. If you're still investigating on day 70, you've likely missed your window for lawful delay.

Completeness of your forensic picture
You won't have perfect information at the 72-hour mark. The question is whether waiting will materially change what you tell victims or just delay action they should already be taking.

Path A: Notify During the Investigation

Choose this path when:

  • The exposed data enables immediate harm (credentials, financial account details, authentication factors, or communications that reveal sensitive personal circumstances)
  • You've confirmed unauthorized access to a defined dataset, even if you're still quantifying secondary exposures
  • Your Technical and Organisational Measures didn't include controls that would prevent misuse (for example, the data wasn't encrypted, and you can't remotely invalidate the exposed credentials)
  • You're approaching the end of your 72-hour supervisory notification window and don't have grounds under Article 34(3) to delay individual notification

What this looks like in practice:
DGFiP notified affected taxpayers with specific guidance: the authority will never ask for PINs or identity documents via phone, text, or email, and will only request such material through its secure portal. This gives victims a clear decision rule for evaluating suspicious contacts. The notification acknowledged that the investigation into the Vacant Successions Portal vulnerability was ongoing but didn't let that uncertainty delay warnings about the confirmed tax data exposure.

Implementation steps:

  1. Draft a notification that describes the confirmed exposure without speculating about datasets still under review.
  2. Provide concrete protective actions: password resets, MFA enrollment, fraud alert placement with credit bureaus, or, as DGFiP did, authentication rules victims can use to identify imposters.
  3. Commit to a follow-up timeline if your investigation reveals additional exposure.
  4. Document your decision rationale in your Breach Register, linking it to Article 34's "high risk" threshold and the specific harms you're trying to prevent.

Path B: Complete Forensics Before Notification

Choose this path when:

  • The exposed data has limited immediate misuse potential (publicly available information, aggregated statistics, or data that requires additional context to weaponize)
  • You have strong Technical and Organisational Measures that contain the damage (encryption with keys the attacker didn't obtain, immediate credential invalidation, or access controls that limit what the attacker could reach)
  • Your preliminary review suggests multiple affected datasets, and notifying in waves would create more confusion than a single comprehensive disclosure
  • You can complete forensics within a timeline that still satisfies "without undue delay" under Article 34, typically no more than a few weeks from initial discovery

What this looks like in practice:
Consider a scenario where attackers accessed a database containing hashed email addresses and subscription preferences for a marketing platform. The hashes weren't salted, so reversal is possible but time-consuming. The exposed preferences don't reveal sensitive personal circumstances. Here, spending five additional days to confirm whether the attacker also reached a linked CRM system changes what victims need to do, and justifies the delay.

Implementation steps:

  1. Set an internal deadline that accounts for both forensic needs and regulatory timelines (if you discover the breach on Monday, your supervisory notification is due by Thursday morning, and your individual notification decision should be made by the following Monday at the latest).
  2. Prioritize forensic questions that affect victim guidance: Did the attacker get credentials that are still valid? Was encrypted data exposed alongside its keys? Can you prove the attacker didn't access adjacent systems?
  3. Prepare notification materials in parallel with forensics so you're ready to send within hours of completing your review.
  4. If you approach your deadline without answers, default to Path A, notify based on confirmed exposure and commit to updates.

When Neither Path Fits: The Staged Notification

If you're managing a complex breach with clearly separable victim populations, as DGFiP was, with individual taxpayers, businesses, and property records, you can notify in stages. The requirement is that each affected individual receives notification "without undue delay" from the point you confirm their data was exposed. You can't delay notifying Group A just because you're still investigating Group B, unless the two investigations are so intertwined that notifying Group A would compromise forensics for Group B.

DGFiP disclosed the tax data breach and began victim notification while still investigating the Vacant Successions Portal vulnerability. This is defensible because the two incidents involved separate systems and the PSV investigation hadn't yet confirmed personal data exposure.

Summary Matrix

Factor Notify During Investigation Complete Forensics First
Data type Credentials, financial details, communications, authentication factors Publicly available data, aggregated statistics, low-sensitivity metadata
Misuse timeline Immediate (phishing, credential stuffing, fraud within days) Delayed (requires additional context or technical effort to weaponize)
Containment measures None, or ineffective after exfiltration Strong (encryption held, credentials invalidated, access revoked)
Forensic complexity Single clear dataset, or multiple datasets with independent victim populations Interconnected systems where premature notification could compromise investigation
Regulatory clock Approaching 72-hour supervisory notification or "without undue delay" threshold Sufficient time remains to complete review within lawful timeline
Victim action Clear protective steps available now Protective guidance depends on investigation outcome

The DGFiP breach shows that "without undue delay" doesn't mean "with perfect information." When stolen tax identification numbers and message contents create immediate fraud risk, waiting for forensic certainty trades victim protection for investigative completeness. Your Breach Register should document that tradeoff explicitly because your Supervisory Authority will ask why you made it.

You Might Also Like