Data Breach Notification Deadline Calculator
From the minute you learn of a breach: who to tell, by when, and what to include.
Every deadline
The deadlines appear here once you enter when you became aware.
Notes
An estimate, not legal advice: whether a law applies and whether an incident must be reported are legal questions. The deadlines are outer limits — most of these laws ask you to report without delay.
For general information only, not legal advice. Templates are generic starting points — have a qualified lawyer review anything you rely on.
About the Data Breach Notification Deadline Calculator
When a personal data breach or cyber incident is discovered, several clocks start at once — and the shortest is six hours. Enter the date, time and time zone at which you became aware, tick the laws that may apply, and the calculator lists every reporting deadline as an exact moment, soonest first, with a live countdown, the authority to tell and a checklist of what the report must contain.
It covers India’s CERT-In Directions (6 hours) and DPDP Rules, rule 7 (the Board without delay, and a detailed report within 72 hours), the GDPR and UK GDPR (72 hours to the supervisory authority; people without undue delay when the risk is high), the EU’s NIS2 Directive (24-hour early warning, 72-hour notification, final report a month later), the US HIPAA Breach Notification Rule (60 calendar days) and SEC Form 8-K Item 1.05 (four business days after deciding the incident is material). Times are shown in any time zone, daylight-saving changes included, and the deadlines can go into your calendar with reminders. Nothing you enter leaves your browser.
How to use it
- Enter the date and time you became aware of the incident and the time zone of that clock — or press Now. Awareness is when you noticed it or were told about it; HIPAA counts a breach as discovered when it was known, or would have been known with reasonable diligence.
- Tick the laws that may apply to you and answer their questions: a trust service provider under NIS2, how many people a HIPAA breach affects, the date a US public company decided the incident was material.
- Read the deadlines, soonest first. Each card shows who to tell, the exact time in your zone and the authority’s own, the time left, and the rule behind it. Choose another zone under Show times in to see the same deadlines on another office’s clock.
- Work through What to include in each card while you prepare the report, then Copy summary for your incident log or Add to calendar (.ics) to set reminders before every deadline.
Examples
Became aware Monday 14 June 2027, 09:30 IST
CERT-In by 15:30 IST the same day; the DPDP detailed report to the Board and a GDPR notification (if EU residents are affected) by Thursday 17 June, 09:30 IST; NIS2 early warning by 15 June, 09:30 IST if it applies.
Discovered 5 October 2026 · 500 or more · more than 500 residents of one State
Individuals, prominent media outlets and HHS by Friday 4 December 2026 — 60 calendar days after discovery, and sooner if possible.
Materiality determined on Thursday, November 19, 2026
Form 8-K Item 1.05 due Wednesday, November 25, 2026 by 5:30 p.m. Eastern time — four business days (Thanksgiving, November 26, is not one).
Common uses
- An incident response lead setting up the reporting timeline in the first hour of a breach.
- A DPO or privacy lawyer checking which authority is told first, and by when, across India, the EU, the UK and the US.
- Preparing a tabletop exercise or an incident response plan with realistic deadlines and report contents.
- Putting every reporting deadline into the team calendar with reminders.
The deadlines, law by law
- CERT-In (India). Service providers, intermediaries, data centres, body corporates and government organisations report the incidents listed in Annexure I of the Directions — data breaches and leaks, ransomware, unauthorised access, attacks on servers and many more — within 6 hours of noticing them or being told. CERT-In’s FAQ 30 names the incidents held to the 6 hours — data breaches and data leaks among them — and lets you send what you know first, with the rest to follow.
- DPDP Rules, rule 7 (India). A Data Fiduciary tells each affected person and the Data Protection Board without delay, then sends the Board a detailed report within 72 hours of becoming aware, or a longer period the Board allows on a written request. Rule 7 applies eighteen months after the Rules were published (rule 1(4)); the calculator shows whether it applies on the date you enter.
- GDPR and UK GDPR. The controller notifies the supervisory authority (the ICO in the UK) without undue delay and, where feasible, within 72 hours, unless the breach is unlikely to result in a risk to people; a later notification must explain the delay. People are told without undue delay when the risk to them is high (Art. 34). A processor tells the controller without undue delay.
- NIS2 (EU). Essential and important entities send the CSIRT or competent authority an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours (24 hours for trust service providers), intermediate reports on request, and a final report within one month of the notification — as transposed by each Member State.
- HIPAA (US). Covered entities notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery; the media too when more than 500 residents of a State or jurisdiction are affected; HHS at the same time for 500 or more, or within 60 days after the end of the calendar year for fewer. A business associate tells the covered entity within 60 days.
- SEC Form 8-K Item 1.05 (US). A registrant files within four business days after determining that a cybersecurity incident is material, and must make that determination without unreasonable delay after discovery. The calculator skips weekends and federal holidays, and shows 5:30 p.m. Eastern time — EDGAR filings made after it count as filed the next business day.
How the clock is counted
Hour-based deadlines run in real elapsed hours from the moment you became aware, so a 72-hour deadline that crosses a daylight-saving change still ends 72 hours later — the wall-clock time can shift by an hour. Calendar-day deadlines (HIPAA) end at midnight at the end of the last day in your time zone. NIS2’s final report runs one calendar month from the incident notification: enter when you sent it, or the calculator counts from the latest moment it could have been sent. None of the hour-based deadlines stops for weekends or holidays.
Sources
- CERT-In Directions under section 70B(6) of the IT Act, CERT-In FAQs and the incident reporting form
- Digital Personal Data Protection Rules, 2025 — rules 1 and 7; DPDP Act, 2023 — s.8(6)
- GDPR — Arts. 33, 34; EDPB guidelines on personal data breach notification; ICO: report a personal data breach
- NIS2 Directive (EU) 2022/2555 — Art. 23
- 45 CFR Part 164, Subpart D — §§164.404–164.412
- SEC Form 8-K — General Instruction B.1 and Item 1.05; Regulation S-T Rule 13
Limitations
- An estimate, not legal advice. Whether a law applies, whether an incident is a reportable breach and who the competent authority is are legal questions — the calculator shows the deadlines if they apply.
- Sector and national rules are not covered: banking, insurance and securities regulators (for example RBI, SEBI and IRDAI in India, or DORA for EU financial entities), US state breach laws, and each Member State’s NIS2 transposition may add other or shorter deadlines.
- The deadlines are the outer limits. GDPR, DPDP and HIPAA all ask for notice without (undue) delay, and the clock does not wait for the investigation to finish.
- The SEC business-day count skips weekends and federal holidays; it cannot know a day the SEC closes unexpectedly.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.
Frequently asked questions
When does the 72-hour GDPR clock start?
When the controller becomes aware of the personal data breach (Art. 33(1)) — in the EDPB’s words, when it has “a reasonable degree of certainty that a security incident has occurred that has led to personal data being compromised” — not when the breach happened or when the investigation ends. The same 72 hours apply to the ICO under the UK GDPR.
Is the CERT-In deadline really 6 hours?
Yes: the CERT-In Directions under s.70B(6) of the IT Act require the incidents in their Annexure I to be reported within 6 hours of noticing them or being brought to notice of them. CERT-In’s FAQ says you may report what is available within that time and send further information later.
Does the DPDP 72-hour report already apply?
Rule 7 of the DPDP Rules 2025 comes into force eighteen months after the Rules were published (rule 1(4)). Enter the date you became aware: the calculator marks the DPDP deadlines as not yet in force for earlier dates, and shows them for planning.
Do weekends or holidays extend these deadlines?
Not for the hour-based ones — 6, 24 and 72 hours run continuously. HIPAA counts calendar days, weekends included. Only the SEC Form 8-K deadline is counted in business days.
What if I cannot give all the details in time?
Report on time with what you know. GDPR allows information in phases (Art. 33(4)), NIS2 builds in an early warning and a later final report, CERT-In accepts the available information first, and Form 8-K can be amended within four business days once missing information is determined.
Is anything I type sent anywhere?
No. The times, choices and checklist ticks stay in your browser; the summary and the calendar file are created on your device.