Certus
← All insightsBreach Reporting · 6 min read

Breach notification under PDPL: the decisions that matter in the first 24 hours

The instinct in the earliest hours after a suspected breach is to investigate exhaustively before saying anything — driven by a reasonable fear of over-reporting. Under a notification regime built around defined timeframes, that instinct works against you. The priority in the first hours is establishing enough facts to make a defensible severity call, not achieving certainty.

The organisations that respond well have already answered, in advance, three questions: who has the authority to declare an incident a reportable breach, who drafts and approves notification language before it is needed under pressure, and what the internal escalation path looks like outside business hours.

Health data, financial data and data belonging to vulnerable individuals typically warrant a lower threshold for notification, given the potential for harm. Building severity thresholds calibrated to data sensitivity, not just record count, produces better decisions than a single generic rule.

A breach playbook that has never been rehearsed with the actual people who will use it is, at best, a comforting document. Rehearsal — a structured tabletop exercise with real roles — is what turns it into a capability.

Want this applied to your organisation?

Talk to a Certus privacy partner about what this means for your specific risk.