Breach and incident notification rules
41 regulations worldwide that deal with breach notification, with every phased deadline and the official source for each.
41 regulations
Add to calendar
- UK Cyber Security and Resilience Bill
United Kingdom
ProposedCybersecurityBreach notificationNext: Oct 26, 2026 Lords report stage scheduled
- India DPDP Act
India
EnactedPrivacyChildrenNext: Nov 13, 2026 Consent Manager registration rule in force (12 months)
- EnactedPrivacyBreach notification
Next: Dec 1, 2026 Law in force
- Australia Privacy Act
Australia
AmendedPrivacyChildrenNext: Dec 10, 2026 Children's Online Privacy Code must be registered
- Indonesia PDP Law
Indonesia
AmendedPrivacyBreach notificationNext: Jan 16, 2027 Implementing regulation GR 33/2026 takes effect
- GDPR
European Union
AmendedPrivacyBreach notificationNext: Apr 2, 2027 GDPR Procedural Regulation applies
- NIS2
European Union
AmendedCybersecurityBreach notificationNext: Apr 17, 2027 Next biennial entity notification
- South Korea PIPA
South Korea
AmendedPrivacyBreach notificationNext: Jul 1, 2027 Mandatory ISMS-P certification
- Cyber Resilience Act
European Union
EnactedCybersecurityBreach notificationNext: Dec 11, 2027 CRA fully applies
- In forceCybersecurityBreach notification
Effective Nov 30, 2024
- Brazil LGPD
Brazil
In forcePrivacyBreach notificationEffective Sep 18, 2020
- Canada Bill C-36 (PPCDA)
Canada
ProposedPrivacyBreach notification - Canada Bill C-8 / CCSPA
Canada
EnactedCybersecurityBreach notification - CIRCIA
United States (Federal)
EnactedCybersecurityBreach notification - Digital Omnibus (data/GDPR)
European Union
ProposedPrivacyData access and sharing - DORA
European Union
In forceCybersecurityFinancialEffective Jan 16, 2023
- ePrivacy Directive (cookie law)
European Union
AmendedPrivacyBreach notificationEffective Jul 31, 2002
- FCC CPNI Breach Rule
United States (Federal)
AmendedPrivacyBreach notificationEffective Mar 13, 2024
- FTC Health Breach Notification Rule
United States (Federal)
AmendedHealth dataPrivacyEffective Sep 24, 2009
- GLBA Safeguards Rule
United States (Federal)
AmendedFinancialCybersecurityEffective May 23, 2003
- HIPAA
United States (Federal)
AmendedPrivacyHealth dataEffective Apr 14, 2003
- In forceCybersecurityBreach notification
Effective Jan 1, 2026
- AmendedPrivacyBreach notification
Effective Aug 14, 2025
- Japan APPI
Japan
AmendedPrivacyChildrenEffective Apr 1, 2005
- In forcePrivacyBreach notification
Effective Nov 25, 2019
- Malaysia PDPA
Malaysia
AmendedPrivacyBreach notificationEffective Nov 15, 2013
- New Zealand Privacy Act
New Zealand
AmendedPrivacyBreach notificationEffective Dec 1, 2020
- Nigeria NDPA
Nigeria
AmendedPrivacyBreach notificationEffective Jun 12, 2023
- AmendedCybersecurityBreach notification
Effective Mar 1, 2017
- PIPEDA
Canada
In forcePrivacyBreach notificationEffective Jan 1, 2001
- Quebec Law 25
Quebec, Canada
In forcePrivacyBreach notificationEffective Sep 22, 2022
- Saudi PDPL
Saudi Arabia
In forcePrivacyData residencyEffective Sep 14, 2023
- SEC Cyber Disclosure Rules
United States (Federal)
In forceCybersecurityBreach notificationEffective Sep 5, 2023
- SEC Regulation S-P
United States (Federal)
AmendedFinancialPrivacyEffective Aug 2, 2024
- Singapore PDPA
Singapore
In forcePrivacyBreach notificationEffective Jul 2, 2014
- South Africa POPIA
South Africa
In forcePrivacyBreach notificationEffective Jul 1, 2020
- Swiss revised FADP (nFADP)
Switzerland
In forcePrivacyBreach notificationEffective Sep 1, 2023
- Thailand PDPA
Thailand
In forcePrivacyBreach notificationEffective Jun 1, 2022
- UAE PDPL
United Arab Emirates
In forcePrivacyBreach notificationEffective Jan 2, 2022
- UK GDPR
United Kingdom
AmendedPrivacyBreach notificationEffective May 25, 2018
- Vietnam PDPL
Vietnam
In forcePrivacyData residencyEffective Jan 1, 2026
Upcoming deadlines
October 20261 deadline
Lords report stage scheduled
House of Lords report stage scheduled (committee stage sat 1, 3 and 7 Sept 2026).
November 20261 deadline
Consent Manager registration rule in force (12 months)
Rule 4 (registration and obligations of Consent Managers) comes into force one year after publication.
December 20263 deadlines
Law in force
Main obligations apply and the Personal Data Protection Agency begins supervision.
Children's Online Privacy Code must be registered
OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.
Automated decision-making transparency applies
Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).
January 20271 deadline
Implementing regulation GR 33/2026 takes effect
Detailed PDP implementing rules (DPIA, cross-border, children's consent) apply, 6 months after the 16 Jul 2026 enactment.
April 20272 deadlines
May 20271 deadline
Main data fiduciary obligations apply (18 months)
Rules 3, 5-16, 22 and 23 (notice, security safeguards, breach notification, retention, children's consent, SDF duties, cross-border) come into force 18 months after publication.
July 20271 deadline
Mandatory ISMS-P certification
ISMS-P certification becomes mandatory for private entities meeting the statutory criteria.
October 20271 deadline
December 20272 deadlines
Proposed postponement of entry into force
Government bill Boletin 18623-07 (filed 1 Sep 2026, 'suma' urgency) would replace the 24-month vacatio legis in transitional Art 1 with a fixed date of 1 Dec 2027; in first committee stage in the Senate, not law.
- Cyber Resilience ActEuropean Union
CRA fully applies
All remaining obligations, including essential cybersecurity requirements, conformity assessment and CE marking, apply (Art 71(2)). Products placed on the market earlier are covered only if substantially modified (Art 69(2)).
June 20281 deadline
- Cyber Resilience ActEuropean Union
Legacy type-examination certificates expire
EU type-examination certificates and approval decisions on cybersecurity requirements under other harmonisation legislation remain valid until this date unless they expire earlier (Art 69(1)).
September 20281 deadline
- Cyber Resilience ActEuropean Union
Report on single reporting platform
Commission report assessing the single reporting platform's effectiveness (Art 70(2)).
December 20301 deadline
- Cyber Resilience ActEuropean Union
First CRA evaluation
Commission evaluation and review report, then every four years (Art 70(1)).
Past deadlines
September 20262 deadlines
2026 PIPA amendments take effect
10%-of-revenue fines, CEO accountability, and notice duties for possible breaches apply.
- Cyber Resilience ActEuropean Union
Vulnerability and incident reporting obligations apply
Art 14: manufacturers must report actively exploited vulnerabilities and severe incidents (24-hour early warning, 72-hour notification) via the single reporting platform. Also covers products placed on the market before 11 Dec 2027 (Art 69(3)).
July 20261 deadline
2026 APPI amendment act promulgated
Amendment enacted by the Diet on 10 July 2026 and promulgated; main provisions take effect by cabinet order within two years of promulgation.
June 20265 deadlines
Passes House of Commons
Report stage and third reading completed in the Commons after carry-over into the new session.
Royal Assent
Bill C-8 receives Royal Assent (S.C. 2026, c. 9); Telecommunications Act amendments take effect.
Bill C-36 tabled (first reading)
Government introduces the PPCDA in the House of Commons.
- Cyber Resilience ActEuropean Union
Conformity assessment body provisions apply
Chapter IV (Arts 35-51, notification of conformity assessment bodies) applies (Art 71(2)).
Smaller entities must comply
Smaller covered institutions (24 months after Federal Register publication) must comply with the amended Regulation S-P.
May 20261 deadline
IPP 3A indirect-collection notification applies
Agencies collecting personal information from third parties must take reasonable steps to notify individuals, subject to exceptions.
April 20261 deadline
Annual compliance notification
Annual certification or acknowledgment covering calendar year 2025 due.
March 20261 deadline
2026 PIPA amendment promulgated (Act No. 21445)
Amendment raising fines to 10% of revenue and adding CEO accountability promulgated.
February 20262 deadlines
Notice of Privacy Practices updates (Part 2 alignment)
Covered entities must update Notices of Privacy Practices under 45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) changes; this NPP piece survived the Purl vacatur.
January 20264 deadlines
PDPL and Decree 356/2025 take effect
Personal data protection obligations, DPIA/TIA filing and penalty framework apply; Decree 13/2023 replaced.
PCICSO comes into operation
Commissioner's Office is established and designation of CIOs begins; obligations apply to designated operators.
Ransomware reporting moves to compliance phase
The education-first phase (30 May-31 Dec 2025) ends; Home Affairs moves to a compliance and education approach for missed reports.
December 20251 deadline
Larger entities must comply
Larger covered institutions (18 months after Federal Register publication) must have incident response programs, 30-day customer notification, and service-provider oversight in place.
November 20255 deadlines
DPDP Rules published; Board and procedural rules in force
Rules 1, 2 and 17-21 (Data Protection Board constitution and functioning) take effect on publication in the Official Gazette.
Introduced (Commons first reading)
Bill introduced in the House of Commons.
Universal MFA and asset inventory
500.12 multi-factor authentication for all users and 500.13(a) asset inventory requirements apply.
September 20252 deadlines
Privacy Amendment Act 2025 technical changes commence
Technical amendments commence the day after Royal Assent (23 Sep 2025).
GAID 2025 takes effect
General Application and Implementation Directive becomes effective, replacing the NDPR 2019 and NDPR Implementation Framework.
August 20252 deadlines
Deadline to adopt ANPD standard contractual clauses
Agents relying on contractual clauses for international transfers must incorporate the ANPD-approved SCCs into their contracts within 12 months of publication.
Amendment 13 in force
Amended Privacy Protection Law, PPA enforcement powers and statutory damages take effect.
July 20251 deadline
June 20253 deadlines
Bill C-8 introduced
First reading in the House of Commons.
Statutory tort for serious invasions of privacy commences
Individuals can sue for serious invasions of privacy (Schedule 2), 6 months after Royal Assent.
PDPA amendments phase 3
Mandatory DPO appointment, data breach notification, and data portability take effect.
May 20252 deadlines
Ransomware payment reporting starts
Reporting business entities must report ransomware/cyber-extortion payments to ASD within 72 hours of payment.
Vulnerability scans, access privileges, malware controls, Class A monitoring
500.5(a)(2) automated scans, 500.7 access privilege restrictions, 500.14(a)(2) malicious code protection, and 500.14(b) Class A endpoint detection and centralized logging apply.
April 20253 deadlines
- DORAEuropean Union
First registers of information submitted to the ESAs
Competent authorities had to submit financial entities' registers of ICT third-party contractual arrangements (reference date 31 Mar 2025) to the ESAs by 30 Apr 2025. National authorities set earlier deadlines for entities.
PDPA amendments phase 2
'Data controller' terminology, biometric data as sensitive data, higher penalties, Security Principle for processors, and removal of the cross-border whitelist take effect.
March 20251 deadline
January 20253 deadlines
- NIS2European Union
Digital infrastructure entities submit registration data
DNS providers, TLD registries, domain registration services, cloud, data centre, CDN, managed (security) service providers, marketplaces, search engines and social networks had to submit registration details to competent authorities (Art 27(2)).
PDPA amendments phase 1
Miscellaneous provisions commence (e.g. electronic service of notices).