GDPR set the tone for regulatory action — and the AI fine pushback to come

This three-day notification rule is law in six jurisdictions — EU, UK, Thailand, Kenya, Nigeria, and South Korea — and influential elsewhere. For example, the US CIRCIA rule for critical infrastructure, which is pending final rule publication this month, is due to apply the 72-hour standard.

By comparison, HIPAA gives US healthcare organisations 60 days as a breach notification deadline. The SEC gives public companies four business days but only after they’ve internally determined a breach is “material,” which adds its own delay.

Although the breach notification regulations established by GDPR have been a success, issues with the enforcement of rules remain.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *