Skip to content

Breach and incident notification rules

41 regulations worldwide that deal with breach notification, with every phased deadline and the official source for each.

Upcoming deadlines

October 20261 deadline

  1. Lords report stage scheduled

    House of Lords report stage scheduled (committee stage sat 1, 3 and 7 Sept 2026).

    Takes effectTentativein 32 daysSource

November 20261 deadline

  1. Consent Manager registration rule in force (12 months)

    Rule 4 (registration and obligations of Consent Managers) comes into force one year after publication.

    Transitionin 50 daysSource

December 20263 deadlines

  1. Law in force

    Main obligations apply and the Personal Data Protection Agency begins supervision.

    Takes effectin 2 monthsSource
  2. Children's Online Privacy Code must be registered

    OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.

    Compliance deadlinein 3 monthsSource
  3. Automated decision-making transparency applies

    Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).

    Compliance deadlinein 3 monthsSource

January 20271 deadline

  1. Implementing regulation GR 33/2026 takes effect

    Detailed PDP implementing rules (DPIA, cross-border, children's consent) apply, 6 months after the 16 Jul 2026 enactment.

    Compliance deadlinein 4 monthsSource

April 20272 deadlines

  1. GDPR

    GDPR Procedural Regulation applies

    Harmonised rules for cross-border complaint admissibility, rights to be heard and access to preliminary findings, and investigation timelines apply to DPAs from 2 April 2027 (Regulation (EU) 2025/2518, final article).

    Enforcementin 6 monthsSource
  2. NIS2

    Next biennial entity notification

    Competent authorities notify the Commission and Cooperation Group of the number of essential and important entities, repeated every two years after 17 Apr 2025 (Art 3(5)).

    Reportingin 7 monthsSource

May 20271 deadline

  1. Main data fiduciary obligations apply (18 months)

    Rules 3, 5-16, 22 and 23 (notice, security safeguards, breach notification, retention, children's consent, SDF duties, cross-border) come into force 18 months after publication.

    Compliance deadlinein 8 monthsSource

July 20271 deadline

  1. South Korea PIPA

    Mandatory ISMS-P certification

    ISMS-P certification becomes mandatory for private entities meeting the statutory criteria.

    Compliance deadlinein 9 monthsSource

October 20271 deadline

  1. NIS2

    Commission review of NIS2

    Commission must review the functioning of NIS2 and report to Parliament and Council, then every 36 months (Art 40).

    Reportingin 13 monthsSource

December 20272 deadlines

  1. Proposed postponement of entry into force

    Government bill Boletin 18623-07 (filed 1 Sep 2026, 'suma' urgency) would replace the 24-month vacatio legis in transitional Art 1 with a fixed date of 1 Dec 2027; in first committee stage in the Senate, not law.

    Takes effectTentativein 14 monthsSource
  2. Cyber Resilience Act

    CRA fully applies

    All remaining obligations, including essential cybersecurity requirements, conformity assessment and CE marking, apply (Art 71(2)). Products placed on the market earlier are covered only if substantially modified (Art 69(2)).

    Compliance deadlinein 15 monthsSource

June 20281 deadline

  1. Cyber Resilience Act

    Legacy type-examination certificates expire

    EU type-examination certificates and approval decisions on cybersecurity requirements under other harmonisation legislation remain valid until this date unless they expire earlier (Art 69(1)).

    Sunsetin 21 monthsSource

September 20281 deadline

  1. Cyber Resilience Act

    Report on single reporting platform

    Commission report assessing the single reporting platform's effectiveness (Art 70(2)).

    Reportingin 24 monthsSource

December 20301 deadline

  1. Cyber Resilience Act

    First CRA evaluation

    Commission evaluation and review report, then every four years (Art 70(1)).

    Reportingin 4.2 yearsSource

Past deadlines

September 20262 deadlines

  1. South Korea PIPA

    2026 PIPA amendments take effect

    10%-of-revenue fines, CEO accountability, and notice duties for possible breaches apply.

    Takes effect13 days agoSource
  2. Cyber Resilience Act

    Vulnerability and incident reporting obligations apply

    Art 14: manufacturers must report actively exploited vulnerabilities and severe incidents (24-hour early warning, 72-hour notification) via the single reporting platform. Also covers products placed on the market before 11 Dec 2027 (Art 69(3)).

    Reporting13 days agoSource

July 20261 deadline

  1. 2026 APPI amendment act promulgated

    Amendment enacted by the Diet on 10 July 2026 and promulgated; main provisions take effect by cabinet order within two years of promulgation.

    Transition2 months agoSource

June 20265 deadlines

  1. Passes House of Commons

    Report stage and third reading completed in the Commons after carry-over into the new session.

    Takes effect3 months agoSource
  2. Royal Assent

    Bill C-8 receives Royal Assent (S.C. 2026, c. 9); Telecommunications Act amendments take effect.

    Takes effect3 months agoSource
  3. Bill C-36 tabled (first reading)

    Government introduces the PPCDA in the House of Commons.

    Takes effect3 months agoSource
  4. Cyber Resilience Act

    Conformity assessment body provisions apply

    Chapter IV (Arts 35-51, notification of conformity assessment bodies) applies (Art 71(2)).

    Takes effect3 months agoSource
  5. SEC Regulation S-P

    Smaller entities must comply

    Smaller covered institutions (24 months after Federal Register publication) must comply with the amended Regulation S-P.

    Compliance deadline4 months agoSource

May 20261 deadline

  1. IPP 3A indirect-collection notification applies

    Agencies collecting personal information from third parties must take reasonable steps to notify individuals, subject to exceptions.

    Compliance deadline5 months agoSource

April 20261 deadline

  1. Annual compliance notification

    Annual certification or acknowledgment covering calendar year 2025 due.

    Reporting5 months agoSource

March 20261 deadline

  1. South Korea PIPA

    2026 PIPA amendment promulgated (Act No. 21445)

    Amendment raising fines to 10% of revenue and adding CEO accountability promulgated.

    Transition7 months agoSource

February 20262 deadlines

  1. HIPAA

    Notice of Privacy Practices updates (Part 2 alignment)

    Covered entities must update Notices of Privacy Practices under 45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) changes; this NPP piece survived the Purl vacatur.

    Compliance deadline7 months agoSource
  2. UK GDPR

    DUAA amendments to UK GDPR commence

    Main Data (Use and Access) Act 2025 Part 5 amendments (recognised legitimate interests, ADM, DSAR, transfers, cookies, PECR fines) apply.

    Takes effect8 months agoSource

January 20264 deadlines

  1. PDPL and Decree 356/2025 take effect

    Personal data protection obligations, DPIA/TIA filing and penalty framework apply; Decree 13/2023 replaced.

    Takes effect9 months agoSource
  2. PCICSO comes into operation

    Commissioner's Office is established and designation of CIOs begins; obligations apply to designated operators.

    Takes effect9 months agoSource
  3. GDPR

    GDPR Procedural Regulation enters into force

    Regulation (EU) 2025/2518, published in the OJ on 12 December 2025, enters into force on the twentieth day after publication.

    Transition9 months agoSource
  4. Ransomware reporting moves to compliance phase

    The education-first phase (30 May-31 Dec 2025) ends; Home Affairs moves to a compliance and education approach for missed reports.

    Enforcement9 months agoSource

December 20251 deadline

  1. SEC Regulation S-P

    Larger entities must comply

    Larger covered institutions (18 months after Federal Register publication) must have incident response programs, 30-day customer notification, and service-provider oversight in place.

    Compliance deadline10 months agoSource

November 20255 deadlines

  1. GDPR

    GDPR Procedural Regulation adopted

    Regulation (EU) 2025/2518 laying down additional procedural rules for cross-border GDPR enforcement signed by Parliament and Council.

    Transition10 months agoSource
  2. DORA

    First critical ICT third-party providers designated

    The ESAs published the first list of 19 critical ICT third-party providers (including AWS, Google Cloud and Microsoft), which now come under direct EU oversight.

    Enforcement10 months agoSource
  3. DPDP Rules published; Board and procedural rules in force

    Rules 1, 2 and 17-21 (Data Protection Board constitution and functioning) take effect on publication in the Official Gazette.

    Takes effect10 months agoSource
  4. Introduced (Commons first reading)

    Bill introduced in the House of Commons.

    Takes effect10 months agoSource
  5. Universal MFA and asset inventory

    500.12 multi-factor authentication for all users and 500.13(a) asset inventory requirements apply.

    Compliance deadline11 months agoSource

September 20252 deadlines

  1. Privacy Amendment Act 2025 technical changes commence

    Technical amendments commence the day after Royal Assent (23 Sep 2025).

    Takes effect12 months agoSource
  2. GAID 2025 takes effect

    General Application and Implementation Directive becomes effective, replacing the NDPR 2019 and NDPR Implementation Framework.

    Takes effect12 months agoSource

August 20252 deadlines

  1. Deadline to adopt ANPD standard contractual clauses

    Agents relying on contractual clauses for international transfers must incorporate the ANPD-approved SCCs into their contracts within 12 months of publication.

    Compliance deadline13 months agoSource
  2. Amendment 13 in force

    Amended Privacy Protection Law, PPA enforcement powers and statutory damages take effect.

    Takes effect13 months agoSource

July 20251 deadline

  1. DORA

    TLPT regulatory technical standards enter into force

    Commission Delegated Regulation (EU) 2025/1190 (published 18 June 2025) sets criteria for which financial entities must run threat-led penetration testing, plus methodology and tester requirements.

    Takes effect15 months agoSource

June 20253 deadlines

  1. Bill C-8 introduced

    First reading in the House of Commons.

    Transition15 months agoSource
  2. Statutory tort for serious invasions of privacy commences

    Individuals can sue for serious invasions of privacy (Schedule 2), 6 months after Royal Assent.

    Takes effect15 months agoSource
  3. PDPA amendments phase 3

    Mandatory DPO appointment, data breach notification, and data portability take effect.

    Compliance deadline16 months agoSource

May 20252 deadlines

  1. Ransomware payment reporting starts

    Reporting business entities must report ransomware/cyber-extortion payments to ASD within 72 hours of payment.

    Takes effect16 months agoSource
  2. Vulnerability scans, access privileges, malware controls, Class A monitoring

    500.5(a)(2) automated scans, 500.7 access privilege restrictions, 500.14(a)(2) malicious code protection, and 500.14(b) Class A endpoint detection and centralized logging apply.

    Compliance deadline17 months agoSource

April 20253 deadlines

  1. DORA

    First registers of information submitted to the ESAs

    Competent authorities had to submit financial entities' registers of ICT third-party contractual arrangements (reference date 31 Mar 2025) to the ESAs by 30 Apr 2025. National authorities set earlier deadlines for entities.

    Reporting17 months agoSource
  2. NIS2

    Member States establish entity lists

    Member States had to establish lists of essential and important entities and notify the Commission of entity numbers (Art 3(3) and (5)). Repeated every two years.

    Reporting17 months agoSource
  3. PDPA amendments phase 2

    'Data controller' terminology, biometric data as sensitive data, higher penalties, Security Principle for processors, and removal of the cross-border whitelist take effect.

    Takes effect18 months agoSource

March 20251 deadline

  1. HIPAA

    Security Rule NPRM comment period closed

    Comments closed on the proposed HIPAA Security Rule update (90 FR 898); OCR has not issued a final rule.

    Transition19 months agoSource

January 20253 deadlines

  1. NIS2

    Digital infrastructure entities submit registration data

    DNS providers, TLD registries, domain registration services, cloud, data centre, CDN, managed (security) service providers, marketplaces, search engines and social networks had to submit registration details to competent authorities (Art 27(2)).

    Reporting20 months agoSource
  2. DORA

    DORA applies

    All DORA obligations (ICT risk management, incident reporting, testing, third-party risk, register of information) apply from 17 Jan 2025 (Art 64).

    Takes effect20 months agoSource
  3. PDPA amendments phase 1

    Miscellaneous provisions commence (e.g. electronic service of notices).

    Takes effect21 months agoSource

When the rules change: new data, privacy and AI laws and deadlines, the next morning.