Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
Who must be notified after a data breach?
Updated
Supervisory authorities, CSIRTs, affected individuals, customers, law enforcement, payment brands, and insurers are different recipient classes. Each is a legal requirement, a contractual obligation, or best practice only when it applies. This map is not legal advice and does not start a clock.
Recipient-class map, last verified 7 September 2026 against Regulation (EU) 2016/679 Articles 33–34, HIPAA 45 CFR §§164.406–408, PCI DSS v4.0.1 Requirement 12.10.1, Directive (EU) 2022/2555 Article 23, and Form 8-K Item 1.05. It is not legal advice, not YOUR notice list, and not a substitute for counsel.
This is a recipient-class map, not YOUR notice list
Audience: an incident commander, CISO, or counsel who needs a map of every notifiable party class so a required recipient is not missed. This page is not legal advice. It does not start a clock. Reading it does not start a clock. It does not name YOUR recipients. Counsel names the actual authorities, CSIRTs, people, customers, brands, and carriers on YOUR facts.
Recipient classes are not interchangeable. A GDPR Article 33 notice to a supervisory authority is not an Article 34 communication to a data subject, not a NIS2 Article 23 notification to a CSIRT, not a Form 8-K Item 1.05, not a PCI DSS payment-brand notice, and not an insurer claim notice. Filing one never discharges the others. Last verified 7 September 2026. Not legal advice.
- A legal requirement applies only if the cited instrument applies to YOUR facts. Mapping a class is not a determination that you must notify that class.
- A contractual obligation is YOUR contract, DPA, acquiring agreement, or policy — not 'the law'. This page does not interpret YOUR contract or YOUR policy.
- Best practice is regulator guidance or operational practice. It is not a statute. Do not collapse PCI DSS or an insurer panel into 'the law'.
- The who-to-call page on this site is a calling order (commander, counsel, insurer, DFIR). This page is the notification-duty map, not a call tree.
- The regulator-customer-individual page on this site is the three-stream comparison. A dedicated GDPR jurisdiction guide is not on this site yet. Naming them is not a link.
Recipient classes — legal, contractual, or best practice
Work this table with counsel. Each row is a class, not a named addressee. Print it. Last verified 7 September 2026. Not legal advice. Not a complete world list.
| Recipient class | When it is a legal requirement (cite) | When it is contractual | When it is best practice | Do not treat as | Source |
|---|---|---|---|---|---|
| Supervisory authority / regulator | Only if the instrument applies. GDPR Article 33(1): the controller notifies the supervisory authority competent under Article 55 of a personal data breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. HIPAA 45 CFR §164.408: a covered entity notifies the Secretary of HHS of a breach of unsecured PHI — contemporaneously with individual notice if 500 or more individuals (§164.408(b)); annual log if fewer than 500 (§164.408(c)). Form 8-K Item 1.05: a registrant files with the SEC within four business days after determining a material cybersecurity incident. NIS2 Article 23 also names the competent authority as an alternative to the CSIRT — see the CSIRT row. A dedicated GDPR, HIPAA, and SEC cyber-disclosure guide is not on this site yet. | Some DPAs, customer contracts, or government contracts require you to copy a named regulator or to confirm that a statutory filing was made. That is YOUR contract. This page does not interpret it. | Documenting a no-notification decision when the statutory threshold is not met (GDPR Article 33(5) is the documentation example, only if GDPR applies). Not a reason to skip a duty that does apply. | A complete world list of every DPA, attorney general, or sector supervisor. Filing one authority never discharges another. A CISA report is not a GDPR, HIPAA, or Item 1.05 filing. HIPAA §164.406 media notice (more than 500 residents of a State or jurisdiction) is a separate legal requirement when it applies — not a substitute for §164.404 individual notice or for §164.408 Secretary notice. | Regulation (EU) 2016/679 Article 33(1); 45 CFR §164.408 (and §164.406 for media); Form 8-K Item 1.05; 17 CFR 229.106. Last verified 7 September 2026. |
| Sector CSIRT (NIS2 class) | Only if NIS2 as transposed applies and you are an in-scope essential or important entity. Directive (EU) 2022/2555 Article 23(1): notify, without undue delay, the CSIRT or, where applicable, the competent authority of a significant incident. Article 23(4) is the 24-hour early warning / 72-hour incident notification / one-month final-report ladder from becoming aware of the significant incident. CRA Article 14 is a different instrument: the CSIRT designated as coordinator and ENISA, via the Single Reporting Platform — only if CRA applies. A dedicated NIS2 jurisdiction guide is not on this site yet. A dedicated CRA jurisdiction guide is not on this site yet. | Some sector ISACs, customer contracts, or framework clauses ask you to copy a CSIRT. That copy is not a NIS2 Article 23 notification unless counsel says the duty applies. | Voluntary operational sharing with a national CSIRT when no legal duty applies. CISA asks US organizations to report cyber incidents; last verified 7 September 2026, CIRCIA mandatory reporting is not in effect. That ask is not NIS2. | A determination that you are an essential or important entity. A CISA report is not a NIS2 filing. A CRA Article 14 notification is not a NIS2 Article 23 notification. The product's CRA ladder tracks recorded awareness for findings the organization classified as CRA-in-scope; it is not a notice to a CSIRT. | Directive (EU) 2022/2555 Article 23(1) and 23(4). Last verified 7 September 2026. |
| Affected individuals | Only if the instrument applies. GDPR Article 34(1): when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller communicates it to the data subject without undue delay, unless an Article 34(3) exemption applies. HIPAA 45 CFR §164.404: a covered entity notifies each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed as a result of the breach — without unreasonable delay and in no case later than 60 calendar days after discovery, except as provided in §164.412. HIPAA §164.406 adds prominent media outlets when more than 500 residents of a State or jurisdiction are involved — additional to, not instead of, individual notice. A dedicated GDPR and HIPAA jurisdiction guide is not on this site yet. | Some customer contracts require you to notify the customer's users, or to use the customer's wording. Some cyber policies cover a notification vendor. Those are YOUR contract and YOUR policy. This page does not interpret them. | The FTC Data Breach Response guide tells businesses to notify affected parties when the facts require it. That is US regulator guidance for businesses, not a statute. The legal duties are in the statutes it points at. | A substitute for supervisory-authority notice. Article 34 is not Article 33. HIPAA individual notice is not Secretary notice and not media notice. This page does not convert 'without undue delay' into an hour count where the article does not give one. | Regulation (EU) 2016/679 Article 34; 45 CFR §§164.404 and 164.406. Last verified 7 September 2026. |
| Customers / controllers (processor Article 33(2) class) | Only if the instrument applies. GDPR Article 33(2): the processor shall notify the controller without undue delay after becoming aware of a personal data breach — a different duty from the controller's Article 33(1) authority notice. HIPAA 45 CFR §164.410: a business associate notifies the covered entity of a breach of unsecured PHI. NIS2 Article 23(1): where appropriate, essential and important entities notify, without undue delay, the recipients of their services of significant incidents that are likely to adversely affect the provision of those services. The regulator-customer-individual page on this site is the three-stream comparison. | DPAs, MSAs, and incident-notice SLAs often set a shorter clock, a named mailbox, and a content list. Read YOUR contract. This page does not interpret it. Missing a contractual notice is a contract question, not automatically a GDPR Article 33(1) miss. | Telling a customer you are investigating, when counsel agrees it will not tip an actor, waive a privilege argument, or contradict a legal hold — before a statutory threshold is met. That is practice, not a rule that you must. | A GDPR Article 33(1) supervisory-authority filing, a NIS2 CSIRT notification, or a HIPAA Secretary notice. Questionnaires on this product are customer security questions drafted from recorded posture — not a notification channel and not a customer notice. | Regulation (EU) 2016/679 Article 33(2); 45 CFR §164.410; Directive (EU) 2022/2555 Article 23(1). Last verified 7 September 2026. |
| Law enforcement | Not a notification duty under GDPR Articles 33–34, HIPAA §§164.406–408, NIS2 Article 23, PCI DSS v4.0.1, or Form 8-K Item 1.05. HIPAA §164.412 is a delay of required notices if law enforcement says they would impede an investigation — not a duty to call law enforcement. Immediate physical danger is 911 / local emergency services. Some sector, national-security, or jurisdiction-specific rules can require a police or prosecutor report; counsel maps YOUR facts. This page does not. | Some government contracts, critical-infrastructure agreements, or cyber policies require cooperation with law enforcement or notice that a report was made. That is YOUR contract or YOUR policy. This page does not interpret it. | The FTC Data Breach Response guide tells businesses to consider notifying law enforcement, to call local police, and if local police are not equipped for an information compromise, to contact the local FBI or U.S. Secret Service field office. FBI IC3 is the internet-crime complaint path. NIST SP 800-61r2: contact law enforcement through designated individuals. Those are guidance and operational practice, not a statute. | A GDPR, HIPAA, NIS2, PCI, or Item 1.05 filing. A CISA or IC3 report is voluntary sharing for most operators today (last verified 7 September 2026: the CIRCIA final rule is not in effect). Sharing with law enforcement is not a determination that a legal notification duty has started. | FTC, Data Breach Response: A Guide for Business (regulator guidance). NIST SP 800-61r2 (guidance, not a statute). 45 CFR §164.412 (delay, not a notify-LE duty). Last verified 7 September 2026. |
| Payment brands (PCI DSS is a standard, not a statute) | PCI DSS v4.0.1 is a payment-card industry standard, not a statute. Do not label Requirement 12.10.1 as 'the law'. Whether you must comply is typically a condition of accepting cards, via card-brand operating regulations and your acquirer agreement — counsel and your acquirer map that. This page does not. | PCI DSS v4.0.1 Requirement 12.10.1: the incident-response plan includes, at a minimum, notification of payment brands and acquirers. Card-brand compromise procedures (each brand's own document) and the acquirer contract typically make that notice a condition of the relationship. This page does not rank payment brands, does not restate each brand's hours, and does not interpret YOUR acquiring agreement. The PCI DSS v4.0.1 full text is published by PCI SSC in its Document Library (licence terms apply); this page does not reproduce it. | Having the brand and acquirer contacts in the IRP before an incident — that is the 12.10.1 plan element, so the notice can be made when the plan is activated. | A statute. A GDPR Article 33 notice, a HIPAA Secretary notice, a NIS2 CSIRT notification, or an Item 1.05. Do not collapse the PCI panel into 'the law'. | PCI DSS v4.0.1 Requirement 12.10.1 (PCI Security Standards Council Document Library). Last verified 7 September 2026. |
| Cyber-insurer (YOUR policy, not a ranking) | Not a legal notification duty under GDPR Articles 33–34, HIPAA §§164.406–408, NIS2 Article 23, PCI DSS v4.0.1, or Form 8-K Item 1.05. An insurer is not a supervisory authority. | YOUR policy's notice condition — often prompt notice of an incident, sometimes before you retain a panel DFIR firm or outside counsel. Late notice, or a unilateral engagement the panel does not recognise, is a coverage argument. Read YOUR policy. This page does not interpret it and does not rank carriers. The contact-cyber-insurance page on this site is the notice-and-panel checklist. | Reading the notice clause in the first hour even if you are not yet sure it is a claim. Waiting for a complete forensic picture is how late-notice arguments start. That is practice, not a statute. | A ranking of carriers. A regulator filing. A reason to skip a legal reporting duty or to skip PCI brand notice. Do not collapse the insurer panel into 'the law'. | YOUR policy. The contact-cyber-insurance page on this site describes generic notice-and-panel conditions; it is not coverage advice. Last verified 7 September 2026. |
Legal vs contractual vs best-practice — do not collapse them
Mixing these is how a recipient map turns into fake legal advice. A legal requirement is in a statute or regulation, and only if it applies. A contractual obligation is in YOUR contract, acquiring agreement, or policy. Best practice is guidance or operational handling. PCI DSS v4.0.1 and an insurer panel sit in the contractual column. They are not 'the law'. Last verified 7 September 2026. Not legal advice.
| Kind | What it is on this page | Do not collapse into |
|---|---|---|
| Legal requirement (only if it applies) | GDPR Articles 33–34 (supervisory authority; processor→controller; high-risk data subject). HIPAA §§164.404, 164.406, 164.408 (individuals; media; Secretary) and §164.410 (business associate→covered entity). NIS2 Article 23 (CSIRT or competent authority; recipients of services where appropriate). Form 8-K Item 1.05 (SEC, if you are a registrant and the incident is determined material). | PCI DSS v4.0.1. YOUR cyber policy. CISA or FBI IC3 sharing. An FTC recommendation. Counsel's actual recipient list on YOUR facts. |
| Contractual obligation | PCI DSS v4.0.1 Requirement 12.10.1 (notify payment brands and acquirers — a standard given force by card-brand and acquirer contracts, not a statute). YOUR policy's insurer-notice clause. DPA / MSA incident-notice clauses to a customer or controller. | 'The law'. A GDPR Article 33 filing. A HIPAA Secretary notice. A NIS2 CSIRT notification. A ranking of brands or carriers. |
| Best practice / regulator guidance | FTC Data Breach Response guide (consider notifying law enforcement; notify affected parties when the facts require it). NIST SP 800-61r2 designated law-enforcement point of contact. Voluntary CSIRT or CISA sharing when no duty applies. Reading the insurer notice clause early. | A statute. A determination that you must call the FBI. A reason to skip a legal requirement that does apply. |
Checklist of recipient classes for the commander
Print the recipient table. Walk every class with counsel. A yes on one class does not skip the others. This is a question list, not a filing, and not YOUR notice list. The who-to-call page on this site is the calling order. The reporting-deadlines page on this site is the statute table of clocks. The do-I-have-to-report page on this site is the class map. The reporting-decision-tree page on this site is the branching tree. The regulator-customer-individual page on this site is the three-stream comparison. A dedicated prepare-regulatory-report, document-your-decision, and supporting-evidence guide is not on this site yet.
- Supervisory authority / regulator — does GDPR Article 33, HIPAA §164.408, Item 1.05, or another named supervisor apply? Counsel names the actual authority. This page does not.
- Sector CSIRT — does NIS2 Article 23 (or another CSIRT duty, including CRA Article 14 if it applies) apply? A CISA report is not that filing.
- Affected individuals — does GDPR Article 34 or HIPAA §164.404 (and §164.406 media, if the 500-resident test is met) apply? Article 34 is not Article 33.
- Customers / controllers — are you a processor (GDPR Article 33(2)), a business associate (HIPAA §164.410), or a NIS2 entity that must notify recipients of services? Then read YOUR DPA / MSA as well.
- Law enforcement — is there a duty on YOUR facts, or only the FTC/NIST practice of considering a call? Immediate danger is 911 first.
- Payment brands and acquirers — PCI DSS v4.0.1 Requirement 12.10.1 is a standard, not a statute. Read YOUR acquiring agreement. This page does not rank brands.
- Cyber-insurer — read YOUR notice clause. This page does not interpret the policy and does not rank carriers.
- Who is authorised to send a notice, and who is not. A named human sends it. The product does not. This map does not send a notice and does not start a clock.
Glossary
These are teaching labels for this page. They are not legal conclusions about YOUR facts.
| Term | How this page uses it |
|---|---|
| Recipient class | A kind of notifiable party (regulator, CSIRT, individual, customer, law enforcement, payment brand, insurer). Not the named addressee on YOUR facts. Counsel names those. |
| Legal requirement | A duty in a cited statute or regulation, only if that instrument applies. Not PCI DSS, and not YOUR policy. |
| Contractual obligation | A duty in YOUR contract, acquiring agreement, or insurance policy. Includes PCI DSS v4.0.1 Requirement 12.10.1 as a standard given force by those contracts. |
| Best practice | Regulator guidance or operational handling (FTC guide, NIST SP 800-61r2, voluntary CSIRT sharing). Not a statute. |
| Supervisory authority | GDPR Article 33(1)'s recipient, competent under Article 55. Not a CSIRT, not the SEC, not HHS, and not a payment brand. |
| CSIRT | NIS2 Article 23's computer-security incident-response team (or the competent authority where applicable). CRA Article 14 uses the CSIRT designated as coordinator plus ENISA — a different instrument. |
| Processor → controller | GDPR Article 33(2). The processor notifies the controller. That is not the controller's Article 33(1) notice to the supervisory authority. |
| PCI DSS v4.0.1 | A payment-card industry standard, not a statute. Requirement 12.10.1 requires the IRP to include notification of payment brands and acquirers, at a minimum. |
Where this shows up in ShipReady Metrics
The signed-in app does not send notices, does not name YOUR recipients, does not interpret YOUR policy, and does not start a clock. None of the surfaces below is a notification, a recipient list, or an instruction to submit a filing.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour / 72-hour / 14-day ladder from recorded awareness for findings the organization has classified as CRA-in-scope. That is a product tracker for a clock the organization already recorded. It is not a notice to a CSIRT, not a determination that CRA applies, and a named human still submits.
The obligation map lists frameworks the organization has marked in-scope. That mark is not a recipient list, not a legal opinion that a notification duty applies, and not a list of addressees. signed-in app → Compliance → Questionnaires drafts answers to customer security questions from recorded posture; it is not a notification channel and does not send a customer, individual, regulator, CSIRT, payment-brand, or insurer notice. The cyber risk register lives under Security. None of those surfaces files a GDPR Article 33 or 34 notice, a NIS2 Article 23 notification, a HIPAA §164.404 / §164.406 / §164.408 notice, a Form 8-K Item 1.05, a PCI brand notice, or an insurer claim notice.
Primary sources (last verified 7 September 2026)
Every regulatory and standards claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2016/679 Articles 33 and 34 are legal requirements only when GDPR applies. HIPAA 45 CFR §§164.406 and 164.408 (media; Secretary) sit with §164.404 (individuals) and §164.410 (business associate) — legal requirements only when HIPAA applies. Directive (EU) 2022/2555 Article 23 is a legal requirement only as transposed and only if you are an in-scope essential or important entity. Form 8-K Item 1.05 and 17 CFR 229.106 are securities-law disclosure, only if you are a registrant and the incident is determined material. PCI DSS v4.0.1 Requirement 12.10.1 is a payment-card standard published by PCI SSC, not a statute; the full text is in the PCI SSC Document Library (licence terms apply). The FTC Data Breach Response guide and NIST SP 800-61r2 are guidance. These are examples of classes, not a complete world list. Not legal advice.
The do-I-have-to-report page on this site is the class map. The reporting-decision-tree page on this site is the branching tree. The reporting-deadlines page on this site is the statute table. The regulator-customer-individual page on this site is the three-stream comparison. The which-jurisdictions-apply page on this site is the applicability map. A dedicated prepare-regulatory-report, supporting-evidence, document-your-decision, failure-to-report-consequences, how-regulators-determine-knowledge, GDPR, NIS2, DORA, CRA, UK GDPR, US-state-laws, SEC cyber-disclosure, HIPAA, Canada PIPEDA, Australia NDB, India DPDP / CERT-In, and UAE/Dubai guide is not on this site yet. Naming them is not a link.
Frequently asked questions
Who must be notified after a data breach?
This map cannot name YOUR recipients. Supervisory authorities, CSIRTs, affected individuals, customers or controllers, law enforcement, payment brands, and the cyber-insurer are different classes. Each is a legal requirement, a contractual obligation, or best practice only when it applies. Counsel names the actual addressees. Last verified 7 September 2026. Not legal advice.
Is this legal advice?
No. It is a recipient-class map distilled from GDPR Articles 33–34, HIPAA 45 CFR §§164.406–408, PCI DSS v4.0.1 Requirement 12.10.1, NIS2 Article 23, and Form 8-K Item 1.05. Whether any duty applies, who the named recipient is, and whether a clock has started are legal questions for counsel on your facts. This page does not start a reporting clock.
Does ShipReady send these notices?
No. The signed-in app does not send notices, does not name YOUR recipients, and does not interpret YOUR policy. Compliance → CRA reporting tracks the Article 14 ladder from recorded awareness for CRA-in-scope findings; that is not a notice to a CSIRT. The obligation map is in-scope frameworks, not a recipient list. Questionnaires draft answers to customer security questions; they are not a notification channel.
Is notifying payment brands a legal requirement?
PCI DSS v4.0.1 Requirement 12.10.1 is a payment-card standard, not a statute: the incident-response plan includes notification of payment brands and acquirers, at a minimum. That standard is typically given force by card-brand operating regulations and YOUR acquirer agreement. Do not collapse it into 'the law'. This page does not rank brands and does not interpret YOUR contract. Not legal advice.
Does this page start a reporting clock?
No. GDPR Article 33 runs from becoming aware; NIS2 Article 23(4) runs from becoming aware of a significant incident; HIPAA §164.404 runs from discovery; Item 1.05 runs from determination of materiality. Reading a public recipient map is none of those events. The signed-in CRA ladder tracks recorded awareness; it does not start a clock either.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.