Skip to main content
Category: Breach and Risk Assessment

72-Hour Notification

Also known as: 72-Hour Notification Rule, 72-Hour Reporting Requirement
Simply put

A 72-hour notification is a requirement to report a defined event, such as a data breach, to a designated authority within 72 hours of becoming aware of it. The specific meaning, who must report, and what triggers the clock depend entirely on the applicable regime, and the term is also used outside the privacy field in unrelated contexts such as certain U.S. Department of Veterans Affairs emergency care processes. Because the term appears across very different rules, the precise obligation should always be confirmed against the governing instrument.

Formal definition

The phrase '72-hour notification' refers to a category of time-bound reporting obligations that require a specified party to notify a designated recipient within 72 hours of a triggering event. The evidence provided documents two distinct and unrelated uses of the phrase and does not establish a single, unified definition. One use is a U.S. Department of Veterans Affairs process requiring notification of emergency treatment to VA within 72 hours to support care coordination and transfer, governed by VA authorities cited in the evidence (referencing 38 U.S.C. Section 1703, the Veterans Community Care Program). A separate use, per the evidence, frames a 72-hour clock as a service-provider reporting expectation directed at notifying a party (for example, a customer), which the source distinguishes from a downstream customer-notification deadline. The evidence does not provide the article numbers, effective dates for privacy regimes, or the precise scope of any data protection breach-notification statute; practitioners should note that where a 72-hour breach-notification concept exists under regimes such as the EU GDPR or UK GDPR, the identity of the notifying party (typically the controller notifying a supervisory authority), the trigger (awareness), exceptions, and separate obligations to notify affected individuals differ by regime and are not documented in this packet. This entry does not cover cross-border transfer mechanics, penalties, retention rules, or the substantive content required in any notification, none of which are established by the evidence.

Why it matters

The phrase "72-hour notification" is a frequent source of confusion because it appears across entirely unrelated regimes, and practitioners who assume a single meaning risk applying the wrong obligation to the wrong situation. The evidence documents two distinct uses that share nothing but the 72-hour figure: a U.S. Department of Veterans Affairs process for notifying VA of emergency treatment to support care coordination and transfer, and a service-provider reporting expectation directed at notifying a party such as a customer. These are not variations on one rule; they arise from different authorities, involve different notifying parties, and serve different purposes. Confirming which instrument governs is therefore the first and most important step before acting on any "72-hour" claim.

Who it's relevant to

Data protection officers and privacy leads
DPOs and privacy leads should treat the "72-hour" label as ambiguous and confirm the governing instrument before acting. Where a 72-hour breach-notification concept applies under a regime such as the EU GDPR or UK GDPR, the notifying party, trigger, exceptions, and the separate question of notifying affected individuals differ by regime and are not documented in the evidence here. This entry does not supply those statutory details.
Service providers and processors
The evidence describes a use in which a 72-hour clock is a service-provider reporting expectation directed at notifying a party such as a customer. Providers should recognize that this reporting obligation is distinct from any downstream customer-notification deadline the recipient may separately owe, and should confirm the exact terms of their obligation against the applicable contract or instrument.
Veterans Affairs emergency-care and provider stakeholders
For those handling VA emergency treatment, the evidence documents a distinct, non-privacy use in which notification to VA within 72 hours supports coordination of necessary care or transfer, cited under 38 U.S.C. Section 1703 and the Veterans Community Care Program. This process is unrelated to data protection breach notification and should not be conflated with it.
Compliance and incident response teams
Incident response and compliance teams should build their playbooks around the specific governing instrument rather than a generic 72-hour figure, since the label spans unrelated regimes. Given that this entry does not establish the content required in any notification, penalties, retention rules, or cross-border transfer mechanics, teams should source those requirements directly from the applicable authority.

Inside 72-Hour Notification

Notification Trigger
The obligation is generally triggered by a controller becoming aware of a personal data breach, not by the moment the breach itself occurred. Under the EU GDPR and UK GDPR, the clock typically starts when the controller becomes aware, and awareness itself may involve a short period of investigation to establish reasonable certainty that a breach has occurred.
Time Window
Notification to the relevant supervisory authority should generally be made without undue delay and, where feasible, not later than 72 hours after the controller becomes aware of the breach. Where notification is not made within that window, the controller is generally expected to provide reasons for the delay.
Risk-Based Threshold
Under the EU GDPR and UK GDPR, notification to the supervisory authority is generally required unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. This is an assessment obligation resting on the controller and is distinct from the separate question of notifying affected individuals.
Content of the Notification
Notifications typically describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Where full information is not available at once, information may generally be provided in phases without undue further delay.
Controller and Processor Responsibilities
The 72-hour notification obligation to the supervisory authority generally falls on the controller. A processor that becomes aware of a breach is typically required to notify the controller without undue delay, but the processor is not usually the party notifying the supervisory authority. The obligation to notify affected individuals also rests with the controller.

Common questions

Answers to the questions practitioners most commonly ask about 72-Hour Notification.

Does the 72-hour clock always start the moment a security incident occurs?
No. Under the EU GDPR the timeframe is generally tied to when the controller becomes aware of a personal data breach, not to the moment the incident technically began or when it is fully investigated. Awareness typically means having a reasonable degree of certainty that a personal data breach has occurred. Detection, initial triage, and confirmation can all affect when awareness is established, so the start point is a factual and legal judgment rather than the raw incident timestamp. Note that the specifics of what constitutes awareness can be contested and may be scrutinized by a supervisory authority.
Does every personal data breach have to be reported to the supervisory authority within 72 hours?
Not necessarily. Under the EU GDPR, notification to the supervisory authority is generally not required where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. This is a risk-based assessment made by the controller, and that assessment should itself be documented. Separately, communication to affected data subjects is generally triggered by a higher threshold of high risk and follows its own timing expectations. Treatment differs across regimes, so the 72-hour framing specifically reflects the EU and UK GDPR and should not be assumed to apply identically under the CCPA and CPRA, HIPAA, or other frameworks.
What should we do if we cannot gather all breach details within 72 hours?
The EU GDPR generally allows notification in phases where all information is not available at once. A controller can typically make an initial notification within the timeframe and provide further details as they become available, and where notification is not made within 72 hours it is generally expected to be accompanied by reasons for the delay. This entry does not cover the precise content requirements of a notification or the exact procedural expectations of any particular supervisory authority, which should be confirmed against the applicable regime and guidance.
Who within the organization is responsible for making the notification?
The obligation to notify the supervisory authority generally rests with the data controller. A data processor that becomes aware of a personal data breach is generally required to notify the controller, typically without undue delay, but the processor does not usually notify the supervisory authority directly on its own behalf for the controller's processing. Contractual arrangements between controller and processor commonly specify timing and content of processor-to-controller notifications, and organizations should be able to demonstrate these responsibilities through documented evidence rather than stated intent alone.
How does the 72-hour obligation interact with our internal detection and escalation processes?
Because the timeframe is generally measured from the controller's awareness, organizations typically need detection, escalation, and decision-making processes that can establish awareness quickly and route the matter to those who assess reportability. This is where information security and governance overlap: security controls support detection and containment, while governance defines ownership, escalation paths, and accountability. This entry does not prescribe specific tooling or a particular incident response methodology; those depend on context and implementation.
What evidence should we retain to demonstrate we handled the timeframe appropriately?
Under the accountability expectations of the EU GDPR, controllers are generally expected to document breaches, including the facts, effects, and remedial action taken, in a manner that allows a supervisory authority to verify compliance. This typically includes records of when and how awareness was established, the risk assessment supporting any decision to notify or not, and the timing of any notification. Demonstrable evidence is generally required rather than a stated assertion of compliance. This entry does not address specific retention periods for such records, which fall outside its scope.

Common misconceptions

The 72-hour clock starts when the breach happens.
In most cases under the EU GDPR and UK GDPR, the clock starts when the controller becomes aware of the breach, which may follow a brief period of investigation to establish reasonable certainty, rather than at the moment the incident technically occurred.
Every personal data breach must be reported to the supervisory authority within 72 hours.
Notification to the supervisory authority is generally required unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Separately, notifying affected individuals is typically only required where the breach is likely to result in a high risk, so the two obligations have different thresholds and should not be conflated.
The 72-hour rule is a universal standard that applies the same way everywhere.
This specific 72-hour framing derives from the EU GDPR and is mirrored in the UK GDPR. Other regimes, such as the CCPA and CPRA in California or HIPAA in the US healthcare context, address breach notification differently, with their own triggers, timelines, and recipients. Treatment varies by jurisdiction and instrument.

Best practices

Establish a documented incident response process that defines the point at which the organization is considered to have become aware of a breach, so the 72-hour window is measured consistently and defensibly.
Maintain clear contractual and operational arrangements requiring processors to notify the controller without undue delay, recognizing that the controller generally bears the obligation to notify the supervisory authority.
Apply and document a risk-based assessment for each breach to determine whether supervisory authority notification is required and whether the higher threshold for notifying affected individuals is met, keeping the two determinations separate.
Prepare notification templates covering the nature of the breach, affected categories and approximate numbers, likely consequences, and remedial measures, and plan for phased reporting where full information is not immediately available.
Record reasons for any delay beyond 72 hours, since the framework generally expects a reasoned explanation where the window is not met.
Retain demonstrable evidence of breach assessments, decisions, and notifications, as accountability under these frameworks generally requires documented proof rather than stated intent. This entry does not cover cross-border transfer mechanics, retention rules, or enforcement penalties.