The 72-Hour Clock: What It Actually Means

When does the count actually start

Many organizations assume the 72 hours start once the security team finishes assessing the incident and fully understands its scope. The actual rule is different: the clock starts at the moment of detection itself, whether the assessment is finished or still underway.

What the notice has to include

The categories of data affected, the type of personal data, and the number of people affected, actual or approximate. There’s no need to wait for a perfectly precise final figure, but the figure does need to come from real knowledge rather than a random guess.

The difference between a ready organization and one that isn’t has nothing to do with knowing the law. It’s whether the tools exist to produce that number in hours instead of days.

See where your own data actually stands → free scan