What the 72-hour breach clock actually starts from
Most organizations know there is a 72-hour deadline. Fewer know what starts it, and that is where the failures happen.
It starts from belief, not proof
The clock begins at knowledge or reasonable belief that a notifiable personal data breach has occurred. Not at confirmation. Not when the investigation concludes. Not when the forensic report lands.
That distinction decides most cases. An organization that spends four days carefully establishing the facts before notifying has already missed the deadline — and will have to explain a delay that felt, internally, like diligence.
If you reasonably believe a notifiable breach has happened, the obligation is live. You notify on what you know, and you supplement as you learn more.
Notifiable is a three-part test
Not every incident is notifiable. All three conditions have to be present:
- The breach involves sensitive personal information, or information that could be used to enable identity fraud
- There is reason to believe the information was acquired by an unauthorised person
- The acquisition is likely to give rise to a real risk of serious harm to the affected data subjects
A laptop lost in a locked bag with full-disk encryption and no evidence of access may well fail the second test. An exposed database of borrower records fails none of them.
The point of running the test is that you document having run it. An organization that decided not to notify and can show the reasoning is in a very different position from one that simply did not think about it.
Two deadlines, not one
| Obligation | Deadline |
|---|---|
| Notify the NPC and affected data subjects | 72 hours from knowledge or reasonable belief |
| Submit the full report through the DBNMS portal | 5 days from discovery |
And if you are in a regulated sector, there may be a third. Notifying the National Privacy Commission does not discharge a separate obligation to notify a sector regulator, and the two deadlines are rarely the same.
Concealment is a separate offense
Deciding not to notify because notifying looks bad is not a strategy. Concealing a breach is its own criminal offense under the Data Privacy Act, carrying imprisonment and a fine — entirely separately from whatever the underlying breach attracts.
What actually makes the deadline achievable
Nothing about 72 hours is difficult if the work was done beforehand. What makes it impossible is starting from nothing at 2am:
- A named response team, with deputies, who know they are on it
- A written notifiability test someone can apply under pressure
- Draft notification templates for the NPC and for data subjects
- A current record of processing, so you can say what data was involved
- At least one tabletop exercise, so the first time you run the plan is not live
A breach response plan that has never been exercised is not a tested plan, and an audit will say so.