Compliance

Breach Notification Deadline Calculator

Work out every notification deadline that follows a personal data breach across GDPR, NIS2, DORA, HIPAA, SEC and other regimes, counted in hours, business days or calendar days from the moment you specify.

Last reviewed by the Radiatus Cloud team

The timeline appears here.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

Awareness, not confirmation, starts the clock

The GDPR gives 72 hours from the point the controller becomes aware of a personal data breach, and the guidance is clear that awareness means having a reasonable degree of certainty that a security incident has led to personal data being compromised, not having finished the investigation. An organisation that waits for forensics to conclude before starting the count has usually already missed the deadline. Article 33 anticipates this by permitting notification in phases, which is why an incomplete notification inside 72 hours is the correct move rather than a late complete one.

One incident, several clocks

A single incident frequently triggers obligations under more than one regime at once, and those regimes do not share a counting rule or a starting point. NIS2 requires an early warning within 24 hours and a fuller notification within 72. DORA requires an initial report shortly after the incident is classified as major. The SEC counts four business days from the determination that an incident is material, which is a different event again. Tracking these on one timeline is the only way to see which one binds first.

Hours means hours, including weekends

The 72-hour period under the GDPR runs continuously. It does not pause overnight, at weekends or over public holidays, so a breach discovered late on a Friday has a deadline early on Monday. Regimes that count in business days behave differently and can produce a later deadline from an earlier discovery. This tool shows both the wall-clock deadline and the hours remaining, because the difference between the two counting styles is where most missed notifications originate.

Related tools

Frequently Asked Questions

When does the 72-hour GDPR clock start?

From awareness, meaning a reasonable degree of certainty that a security incident has compromised personal data. It does not wait for the investigation to conclude, and Article 33 expressly allows notification in phases for that reason.

Does the 72-hour period pause at weekends?

No. It runs continuously, so a breach discovered late on a Friday has a deadline early on Monday. Regimes counted in business days behave differently.

What if I do not have all the facts within 72 hours?

Notify anyway with what you have. Article 33(4) allows information to be provided in phases, and an incomplete notification on time is treated very differently from a complete one that is late.

When must individuals be told rather than just the regulator?

Under the GDPR when the breach is likely to result in a high risk to the rights and freedoms of individuals, and then without undue delay. Encryption that renders the data unintelligible is one of the recognised reasons this may not be required.

Is this legal advice?

No. It applies published counting rules to the moment you enter. Whether an incident is notifiable at all, and which regimes apply to your organisation, are legal questions this tool cannot answer.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Enter the date and time you became aware, then select the regimes that apply.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.