Breach notification and incident notification are different tests
Personal data breach reporting and cyber incident reporting are separate obligations with separate thresholds, deadlines and recipients.
An event can trigger one, both or neither. Organisations frequently have a process for one and assume it covers the other. Knowing which regimes apply to you, and what each one actually requires, is preparation work that cannot be done under time pressure.
More on Regulation and law
- Regulatory scope is a security architecture questionThe rope follows the wire
- Incident reporting deadlines change response prioritiesThe clock starts with the incident
- DORA makes ICT third-party resilience a contractual and oversight responsibility for regulated financial entitiesThe work moves, the answering stays
- Under NIS2, an organisation's sector, size and role can determine whether cybersecurity risk-management and reporting duties applyThree flaps, one outcome
- Legal privilege does not make incident facts disappearIt seals the advice, not the facts
- Regulation can make suppliers part of your compliance systemTheir controls, on your sheet
