Regulator Notification
Regulator notification is the formal process of informing a supervisory authority or regulator when a qualifying event, such as a data breach or security incident, occurs. Different laws and regulators set their own rules for when the obligation is triggered and how quickly the notification must be made. It is generally a separate step from notifying affected individuals or the public.
Regulator notification refers to the obligation of a regulated entity to formally report a qualifying event, typically a data breach or computer security incident, to the relevant supervisory authority within a prescribed timeframe. Triggers, deadlines, submission mechanisms, and content requirements vary by regime and are not interchangeable: for example, Regulation S-P has been described as requiring notification within 30 days of awareness, while certain U.S. banking regulators have adopted a 36-hour notification requirement for banking organizations, and sector-specific regulators such as FINRA operate dedicated electronic filing systems (FINRA Gateway) for member-firm submissions. The obligation falls on the regulated entity accountable under the applicable instrument; in a controller-processor context under data protection law, a processor generally notifies the controller rather than the regulator directly, though this evidence does not detail those allocations. This entry does not cover cross-border transfer mechanics, retention rules, enforcement penalties, the distinct obligation to notify affected data subjects or the public, or jurisdiction-specific content and timing requirements beyond the examples cited; practitioners should confirm the precise trigger, deadline, and format against the governing instrument, as the point at which the notification clock starts (for example, awareness) is regime-dependent.
Why it matters
Regulator notification is often where the operational reality of an incident response plan is tested against the clock. Different regimes start counting from different moments and impose materially different deadlines, so an organization that treats all notification obligations as equivalent risks missing the tightest one. For example, Regulation S-P has been described as requiring notification within 30 days of awareness, while certain U.S. banking regulators have adopted a 36-hour notification requirement for banking organizations. Because the trigger point, such as when the entity becomes aware of a qualifying event, is regime-dependent, mapping each applicable deadline in advance is generally the difference between a defensible response and a late filing.
The obligation also matters because it is distinct from, and usually additional to, notifying affected individuals or the public. Reporting to a supervisory authority does not discharge any separate duty owed to data subjects, and conflating the two can leave one obligation unmet. Regulator notification is a formal, accountable act: the regulated entity accountable under the governing instrument bears responsibility for making the filing correctly, on time, and through the prescribed channel.
Getting the mechanics right is not merely procedural. In a controller-processor context under data protection law, a processor generally notifies the controller rather than the regulator directly, so allocating who files what, to whom, and by when is a governance question that must be settled before an incident occurs. Practitioners should confirm the precise trigger, deadline, and format against the applicable law or regulator's rules rather than assuming a single universal standard applies.
Who it's relevant to
Inside Regulator Notification
Common questions
Answers to the questions practitioners most commonly ask about Regulator Notification.