goJumboGPT

Security Data breaches and identity theft

How long do companies have to report a breach?

The deadline to tell you about a data breach in the EU, the UK, California, New York, Florida, Washington and Texas, plus HIPAA and SEC rules, and when the clock starts.

8 min read How we write

The short answer

  • California, New York, Florida and Washington give a company 30 days to tell you about a breach of your personal data, and Texas gives 60.
  • The GDPR's 72 hours is the deadline for telling the regulator; in the EU and UK you must be told without undue delay, and only when the breach is likely to put you at high risk.
  • Every clock starts when the company discovers or determines the breach, not when it happened, which is why letters describe events from months earlier.
  • HIPAA gives health organizations up to 60 days from discovery, and SEC-registered investment firms must tell customers within 30 days of becoming aware.
  • The four business day rule for listed companies is a filing for investors, not a notice to you.
  • This is general information rather than legal advice, and your own state or country decides the deadline that applies to you.

In most US states that set a number, a company has 30 days to tell you your personal data was in a breach, and Texas allows 60. Health providers covered by HIPAA get up to 60 days. In the EU and the UK there is no fixed number for telling you at all: the famous 72 hours is the deadline for telling the regulator, and you must be told "without undue delay" only when the breach is likely to put you at high risk. In every one of these rules the clock starts when the company discovers or confirms the breach, not when the break-in happened, which is why letters so often describe events from months earlier.

The deadlines side by side

These are the deadlines as the laws word them. Read the third column closely: "30 days" means little until you know what starts the count.

Where or whoDeadline to tell youClock starts atRegulator notice
EU (GDPR)Without undue delay, only if high risk to youBecoming aware of the breach72 hours where feasible, with reasons if later
UK (UK GDPR)Without undue delay, only if high risk to youBecoming aware of the breachNot later than 72 hours, can be completed in phases
CaliforniaWithin 30 calendar daysDiscovery or notification of the breachSample notice to the attorney general within 15 days of notifying you, if over 500 residents
New YorkWithin 30 daysDiscovery of the breachNot covered here
FloridaNo later than 30 days, 15 more with written good causeDetermination of the breachWithin 30 days if 500 or more people
WashingtonNo more than 30 calendar daysDiscovery of the breachWithin 30 days if over 500 residents
TexasNot later than the 60th dayDetermining that the breach occurredWithin 30 days if at least 250 Texans
US health data (HIPAA)No later than 60 calendar daysDiscovery, including when it should have been knownAt the same time if 500 or more people, otherwise yearly
US brokers and investment firms (SEC Regulation S-P)As soon as practicable, no later than 30 daysBecoming aware of unauthorized accessNot part of this rule

Two things here surprise people. First, the state that decides is the one you live in, not the one the company is based in. California's law, Civil Code section 1798.82, applies to any business operating in California and protects California residents, so a company headquartered in another state still owes a Californian the 30 day notice. Second, the federal rules for health and investment data sit alongside the state rules, so one breach can carry two deadlines.

California's number is new. The section was amended in 2025 and now says the disclosure "shall be made within 30 calendar days of discovery or notification of the data breach".

Why 72 hours is the number everyone quotes

The most repeated answer to this question is that companies must tell you within 72 hours. That misreads the GDPR. It persists because 72 hours is the only hard number in the European rules, so it gets attached to the wrong audience.

Article 33 of the GDPR sets the 72 hours, and it is about the supervisory authority: the controller notifies the regulator "without undue delay and, where feasible, not later than 72 hours after having become aware of it". A late notification has to come with reasons for the delay. The UK regulator, the ICO, adds that the information can be supplied in phases, as long as the first report lands within 72 hours.

Telling you is a separate duty in Article 34, and it has no number. The company must communicate the breach to you "without undue delay", and only when the breach "is likely to result in a high risk" to your rights and freedoms. The ICO's guidance puts it as telling people "as soon as possible". A low risk breach can legally reach the regulator and never reach you. If you want to know what a company holds about you whether or not it reports anything, your right to see and correct your data covers how to ask.

Why your letter arrives months after the breach

A notice in October describing a break-in from the spring can be entirely legal. Three gaps explain it.

  1. The breach is found late. Every deadline in the table counts from discovery or determination, so the months between the theft and its discovery are not counted at all. HIPAA closes part of this gap: a breach counts as discovered on the first day the organization knew, or would have known by exercising reasonable diligence, so ignoring warning signs does not stop the clock from starting.
  2. The count can pause. California lets a business delay to accommodate law enforcement, or "as necessary to determine the scope of the breach and restore the reasonable integrity of the data system". Florida's statute also allows a delay when a law enforcement agency says notice would interfere with a criminal investigation. The scope exception has no fixed limit in the text.
  3. The breach happened somewhere else. Much of your data sits with service providers such as payroll processors and mailing platforms. Under California law the provider must notify the company that owns the data "immediately following discovery", and the GDPR requires a processor to tell the controller without undue delay. Only then does the owner's own count begin.

So a letter from a familiar company about a stranger's systems is not, on its own, a sign of a fake. What a breach notification actually tells you walks through the stock phrases and what each one does and does not claim.

What the letter has to contain

Deadlines are only half of what the laws set. California prescribes the format: the notice must be in plain language, titled "Notice of Data Breach", and laid out under five headings: "What Happened?", "What Information Was Involved?", "What We Are Doing", "What You Can Do" and "For More Information".

The useful section is "What Information Was Involved?", because the fields that leaked decide your whole response. And because the format is fixed by law, scammers can copy it: five correct headings prove nothing about the sender. The safe habit is the one described in how phishing messages get past careful people: type the company's address yourself and never sign in through the letter.

One trigger in the California text is worth knowing. The duty covers unencrypted personal information, and encrypted information only where the key was also taken or is reasonably believed to have been. So "the data was encrypted" in a letter is partly a statement about whether the law required them to write at all.

Public company filings are not a message to you

A fourth deadline gets mixed in with the rest: four business days. That comes from the SEC's 2023 cybersecurity disclosure rules, under which a listed company files a Form 8-K "four business days after a registrant determines that a cybersecurity incident is material". It is written for investors. It tells the market something significant happened to the company, and it is not a duty to tell you what happened to your data.

The SEC rule that does protect customers is the 2024 amendment to Regulation S-P. It covers broker-dealers, investment companies, registered investment advisers and transfer agents, and requires notice to affected individuals as soon as practicable but no later than 30 days after the firm becomes aware of unauthorized access to customer information. Larger firms had 18 months from the rule's publication to comply and smaller ones 24 months.

Where these rules stop

This is general information, not legal advice about a particular breach. The table covers five states; others set their own triggers and wording, so read your own state's statute rather than assuming 30 days. Each law also defines which personal information counts, so a leak that triggers a letter in one state may trigger none in another. Outside the US, the EU and the UK, national privacy laws set their own timing.

What to do with the answer

The deadline tells you how stale the news probably is, and that sets the order of your next moves.

  1. Assume the data has been out for a while. Thirty days from discovery plus the time before discovery can mean several months. Change the affected password and every reuse of it today, starting with email, using the breach checklist in priority order.
  2. Check for exposure nobody told you about. In Europe a low risk breach owes you no letter at all, so a quick check on whether a password you still use has leaked covers the gaps.
  3. Lock down the inbox. Your email resets everything else, so securing your email account comes before anything at the company that was breached.
  4. Watch for accounts you did not open. If the letter lists identity numbers or dates of birth, the risk is new credit in your name, and the early signs of identity theft tell you what to look for in the months after.
  5. Decide whether to stay. If the company handled it badly, closing the account so the data actually goes is the step that keeps you out of its next breach.

Common questions

Does a company have to tell me about a data breach within 72 hours?

No. Under the GDPR and UK GDPR, 72 hours is the deadline for notifying the data protection regulator, and even that can run late if the company gives reasons. Individuals must be told without undue delay, with no fixed number of hours, and only when the breach is likely to result in a high risk to them. In the US the 72 hour figure does not appear in the state deadlines covered here at all.

Is it legal for a company to tell me about a breach months later?

Often, yes. US state deadlines count from when the company discovers or determines the breach, so the time before discovery does not count. California also allows delay for law enforcement and to determine the scope of the breach, and Florida allows delay when police say notice would interfere with an investigation. A long gap is a reason to act quickly, not proof the company broke the rules.

Which state's law applies if the company is in another state?

Generally the state where you live. California's statute, for example, applies to any business operating in California and protects California residents, wherever the company is headquartered. A company with customers in many states can owe each of them a different deadline for the same breach.

Do I have to be told if the stolen data was encrypted?

Often not. California's duty covers unencrypted personal information, and encrypted data only where the key or credential was also taken or reasonably believed to have been. The GDPR lets a company skip the individual notice when the data was unintelligible to whoever took it. That is why breach letters often say whether the data was encrypted.

How long does a hospital or doctor have to tell me about a breach?

Under HIPAA, no later than 60 calendar days after the breach is discovered, and without unreasonable delay before that. Discovery means the first day the organization knew, or would have known with reasonable diligence. Breaches affecting 500 or more people also go to the federal health department at the same time, and smaller ones are reported to it yearly.