{"id":43743,"date":"2026-07-20T10:56:32","date_gmt":"2026-07-20T08:56:32","guid":{"rendered":"https:\/\/smartfense.com\/?p=43743"},"modified":"2026-07-20T10:56:37","modified_gmt":"2026-07-20T08:56:37","slug":"data-breach-notification-72-hours-compared","status":"publish","type":"post","link":"https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/","title":{"rendered":"Data breach notification: the GDPR 72-hour clock compared with Argentina&#8217;s financial sector, HIPAA and Latin America"},"content":{"rendered":"<p>When an organization discovers it has lost control of its data, the technical team\u2019s first question is \u201chow do we contain this?\u201d. The compliance team\u2019s first question is a different one: \u201cwho do we have to notify, and how much time do we have?\u201d. Both questions share the same crisis room, and the second usually has answers far more rigid than people expect.<\/p>\n<p>The catch is that there is no single clock. A company headquartered in Spain, with financial operations in Argentina and a healthcare provider in the United States, can face three parallel deadlines for the very same incident. Confusing them, or discovering them on the day of the breach, is one of the most expensive ways to fail a compliance requirement.<\/p>\n<p>This article maps the most cited data breach notification frameworks by deadline, recipient and trigger, so the clock never catches you off guard.<\/p>\n<h2>What counts as a security breach, and why isn\u2019t it the same as an incident?<\/h2>\n<p>It helps to separate two terms that daily operations tend to blur. A <strong>security incident<\/strong> is any event that affects the availability, integrity or confidentiality of information: a downed server, a failed access attempt, a suspicious email reported in time. A <strong>security breach<\/strong> is the incident that actually compromises personal data, whether through destruction, loss, alteration, disclosure or unauthorized access.<\/p>\n<p>The distinction is not cosmetic. The duty to notify is triggered by the breach, not by the incident. And this is where the nuance that sparks the most boardroom debate appears. The regulatory clock does not start when you resolve the incident, but when you become aware that a breach has occurred. The GDPR uses exactly that phrasing, \u201chaving become aware of it\u201d, in its Article 33.<\/p>\n<p>This forces a shift in mindset. Early detection stops being merely a good technical practice and becomes the point where a legal deadline starts to run.<\/p>\n<h2>When does the GDPR\u2019s 72-hour clock start?<\/h2>\n<p>The European Union\u2019s General Data Protection Regulation sets two distinct obligations, each with a different recipient.<\/p>\n<p><strong>Article 33<\/strong> requires the data controller to notify the personal data breach to the competent supervisory authority, such as the Spanish Data Protection Agency, without undue delay and, where feasible, no later than <strong>72 hours after becoming aware of it<\/strong>. If the notification arrives later, it must be accompanied by reasons for the delay.<\/p>\n<p><strong>Article 34<\/strong> covers another front, the communication to the affected individuals. Here there is no clock in hours but a risk criterion. Data subjects are only notified when the breach is likely to result in a high risk to their rights and freedoms, and in that case the communication must be without undue delay.<\/p>\n<p>There is an exception that is often forgotten, and it is that not every breach must be notified. If the breach is unlikely to result in a risk to people\u2019s rights, Article 33 allows the controller not to notify the authority, though it still requires documenting the decision. That documentation is exactly what an auditor will ask to see later.<\/p>\n<h2>The same incident, different clocks: how to compare the frameworks<\/h2>\n<p>A single corporate group may have to answer to several regulators at once. The table below sorts four reference frameworks by what really matters in a crisis room: who to notify, how fast and what triggers the obligation.<\/p>\n<table>\n<thead>\n<tr>\n<th>Framework<\/th>\n<th>Who is notified<\/th>\n<th>Deadline<\/th>\n<th>What triggers the obligation<\/th>\n<th>The affected individuals?<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>GDPR (European Union)<\/strong><\/td>\n<td>Supervisory authority (e.g. AEPD in Spain)<\/td>\n<td>72 hours from awareness<\/td>\n<td>Any breach, unless unlikely to result in a risk<\/td>\n<td>Yes, without undue delay, only if there is high risk<\/td>\n<\/tr>\n<tr>\n<td><strong>BCRA, Argentine financial sector<\/strong> (Communications \u201cA\u201d 7724 and \u201cA\u201d 8280)<\/td>\n<td>Central Bank (External Systems Audit Management)<\/td>\n<td>Initial notification within the first hour of a critical cyber incident, plus updates and a closing report<\/td>\n<td>A cyber incident affecting service delivery, integrity or confidentiality<\/td>\n<td>The rule centers on the supervisor; communication to the customer follows financial consumer protection rules<\/td>\n<\/tr>\n<tr>\n<td><strong>HIPAA (US, healthcare sector)<\/strong><\/td>\n<td>Affected individuals and the Department of Health (HHS); media if 500 or more<\/td>\n<td>No later than 60 days from discovery (for fewer than 500 people, an annual report to HHS)<\/td>\n<td>Impermissible access, use or disclosure of protected health information<\/td>\n<td>Yes, to individuals, no later than 60 days<\/td>\n<\/tr>\n<tr>\n<td><strong>Chile (Law 21.719 and Framework Law 21.663)<\/strong><\/td>\n<td>Data Protection Agency; National CSIRT for entities under the cybersecurity framework<\/td>\n<td>Without undue delay under the data law; 72 hours for entities covered by Law 21.663<\/td>\n<td>A breach that destroys, leaks, loses or alters personal data<\/td>\n<td>Yes, to data subjects, if there is high risk<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Three readings jump out of the table. The first is the spread of deadlines, because from the first hour of the Argentine financial regulator to HIPAA\u2019s 60 days there are two orders of magnitude of difference. The second is that the recipient changes with the framework, since some prioritize the supervisor and others the affected person. The third is that newer frameworks, like Chile\u2019s, are aligning with the GDPR model, so the \u201c72 hours and risk-based notification\u201d criterion is becoming a regional reference standard.<\/p>\n<p>One nuance to avoid misreading the table. Argentina\u2019s Central Bank framework is not a general data protection law but a sector-specific cybersecurity regulation for financial institutions and payment service providers. It coexists with the general personal data regime rather than replacing it. That is why the same financial institution may owe the supervisor a report within the first hour and, in parallel, assess notification under whatever data protection framework applies to it.<\/p>\n<h2>Who reports, and with what evidence?<\/h2>\n<p>The notification is not drafted by the firewall. It is put together by a person, almost always under pressure and with incomplete information. In most frameworks the formal responsibility lies with the data controller or its data protection officer, but in practice the notification depends on several areas having done their part beforehand: security to characterize the incident, legal to interpret the applicable framework, business to size the impact.<\/p>\n<p>The minimum content that nearly every regulator expects is similar: the nature of the breach, the categories and approximate number of people affected, the likely consequences and the measures taken or proposed. Chile\u2019s Law 21.719, for example, requires recording exactly those elements.<\/p>\n<p>That record is the part that gets underestimated. An organization that makes a reasoned decision not to notify a low-risk breach needs to be able to show the reasoning that led to that decision. The evidence of the decision weighs as much as the decision itself. This is the same principle that applies to the rest of the compliance program. What is not documented, in an auditor\u2019s eyes, did not happen. At SMARTFENSE we see it in the most everyday terrain of <a href=\"https:\/\/smartfense.com\/en\/platform\/audit\/demonstrating-compliance-in-awareness\/\">demonstrating compliance in awareness<\/a>, where the traceable record of every action is what turns a policy into defensible evidence.<\/p>\n<h2>From framework to operations, before the clock rings<\/h2>\n<p>Knowing the deadlines is worthless if the organization discovers them on the day of the breach. The difference between meeting a requirement and failing it is settled weeks before the incident, in decisions that rarely feel urgent.<\/p>\n<p>It is worth boiling the framework down to four operational questions a committee should be able to answer in calm:<\/p>\n<ol>\n<li><strong>Do we know which frameworks apply to us, by country and by sector?<\/strong> A group with multinational operations needs a map of obligations, not a generic list. The Argentine financial sector\u2019s clock is not the same as that of a healthcare provider subject to <a href=\"https:\/\/smartfense.com\/en\/blog\/protecting-health-data-gdpr-healthcare\/\">health data protection rules<\/a>.<\/li>\n<li><strong>Have we defined the moment of \u201cawareness\u201d?<\/strong> Someone has to be able to state, with backing, when the organization knew about the breach. The deadline count depends on that moment.<\/li>\n<li><strong>Are the roles clear?<\/strong> Who characterizes the incident, who decides whether to notify, who signs the communication to the regulator. Without those roles assigned, the first hours are lost to coordination.<\/li>\n<li><strong>Do our people know how to report quickly?<\/strong> The clock starts when the organization becomes aware, and that awareness often begins with a person who reports a strange email or an unusual access. A team trained to report early gives the organization hours it cannot recover later.<\/li>\n<\/ol>\n<p>The first three questions are governance questions and are settled in the program\u2019s design. A solid <a href=\"https:\/\/smartfense.com\/en\/platform\/management-of-regulations-policies-and-procedures\/\">system for managing regulations, policies and procedures<\/a> keeps that map alive and traceable. The fourth is cultural, and it is the one that takes longest to mature, because it cannot be bought. It is built with a sustained security awareness program, in the same way that <a href=\"https:\/\/smartfense.com\/blog\/ley-de-proteccion-de-datos-personales-capacitacion-y-concientizacion-como-requisito\/\">data protection demands training as a requirement, not an accessory<\/a>.<\/p>\n<h2>The deadline is the symptom, continuity is the goal<\/h2>\n<p>It is tempting to read breach notification as a formality of arriving on time, drafting well and avoiding the penalty. But the regulatory deadline is only the visible symptom of something larger. An organization that can characterize a breach, decide who to notify and do so within the deadline is, almost by definition, an organization that understands its own data, its dependencies and its risks.<\/p>\n<p>That same capability is what sustains business continuity when the incident escalates. The 72-hour clock does not measure compliance alone; it measures how ready the organization is to keep operating the day something goes wrong. Preparing for the deadline is, in the end, preparing for the worst day of the year.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Breach notification runs on different clocks: 72 hours under the GDPR, the first hour in Argentine banking, up to 60 days under HIPAA.<\/p>\n","protected":false},"author":34,"featured_media":43751,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[3,686],"tags":[2123,1362,2308,1364,1721],"class_list":["post-43743","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-analisis-de-riesgos","tag-cumplimiento-normativo-en","tag-data-breach","tag-gdpr-en","tag-proteccion-de-datos-en"],"acf":[],"yoast_head":" \n<title>Data breach notification: the 72-hour GDPR clock compared<\/title>\n<meta name=\"description\" content=\"Breach notification runs on different clocks: 72 hours under the GDPR, the first hour in Argentine banking, up to 60 days under HIPAA.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data breach notification: the 72-hour GDPR clock compared\" \/>\n<meta property=\"og:description\" content=\"Breach notification runs on different clocks: 72 hours under the GDPR, the first hour in Argentine banking, up to 60 days under HIPAA.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/\" \/>\n<meta property=\"og:site_name\" content=\"SMARTFENSE\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-20T08:56:32+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-20T08:56:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-12.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1376\" \/>\n\t<meta property=\"og:image:height\" content=\"768\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Carla Caggiano\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Carla Caggiano\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/data-breach-notification-72-hours-compared\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/data-breach-notification-72-hours-compared\\\/\"},\"author\":{\"name\":\"Carla Caggiano\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/person\\\/f88c39d826fb9430f0e1bad25938ae2c\"},\"headline\":\"Data breach notification: the GDPR 72-hour clock compared with Argentina&#8217;s financial sector, HIPAA and Latin America\",\"datePublished\":\"2026-07-20T08:56:32+00:00\",\"dateModified\":\"2026-07-20T08:56:37+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/data-breach-notification-72-hours-compared\\\/\"},\"wordCount\":1561,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/data-breach-notification-72-hours-compared\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/hero-1-12.jpg\",\"keywords\":[\"an\u00e1lisis de riesgos\",\"Cumplimiento Normativo\",\"data breach\",\"GDPR\",\"protecci\u00f3n de datos\"],\"articleSection\":[\"Blog\",\"Blog\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/data-breach-notification-72-hours-compared\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/data-breach-notification-72-hours-compared\\\/\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/data-breach-notification-72-hours-compared\\\/\",\"name\":\"Data breach notification: the 72-hour GDPR clock compared\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/data-breach-notification-72-hours-compared\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/data-breach-notification-72-hours-compared\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/hero-1-12.jpg\",\"datePublished\":\"2026-07-20T08:56:32+00:00\",\"dateModified\":\"2026-07-20T08:56:37+00:00\",\"description\":\"Breach notification runs on different clocks: 72 hours under the GDPR, the first hour in Argentine banking, up to 60 days under HIPAA.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/data-breach-notification-72-hours-compared\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/data-breach-notification-72-hours-compared\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/data-breach-notification-72-hours-compared\\\/#primaryimage\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/hero-1-12.jpg\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/hero-1-12.jpg\",\"width\":1376,\"height\":768,\"caption\":\"Varios relojes de pared marcando horas distintas sobre una pared de oficina, met\u00e1fora de los plazos regulatorios simult\u00e1neos ante una brecha\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/data-breach-notification-72-hours-compared\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Portada\",\"item\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data breach notification: the GDPR 72-hour clock compared with Argentina&#8217;s financial sector, HIPAA and Latin America\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\",\"name\":\"SMARTFENSE - Concienciaci\u00f3n en Ciberseguridad\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/smartfense.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\",\"name\":\"SMARTFENSE\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-smartfense-240x40-1.png\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-smartfense-240x40-1.png\",\"width\":241,\"height\":40,\"caption\":\"SMARTFENSE\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/person\\\/f88c39d826fb9430f0e1bad25938ae2c\",\"name\":\"Carla Caggiano\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-Carla-Caggiano-96x96.png\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-Carla-Caggiano-96x96.png\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-Carla-Caggiano-96x96.png\",\"caption\":\"Carla Caggiano\"},\"description\":\"Ejecutiva en Gobierno, Riesgo y Cumplimiento (GRC), Seguridad de la Informaci\u00f3n y Continuidad del Negocio, con m\u00e1s de 8 a\u00f1os liderando equipos y proyectos en banca, salud y tecnolog\u00eda. Dise\u00f1a e implementa marcos basados en ISO 27001, ISO 22301 e ISO 31000, y traduce regulaciones complejas (SOX, NIST, GDPR, DORA, COBIT) en soluciones aplicables y sostenibles.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/carla-v-caggiano\\\/\"],\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/author\\\/carla\\\/\"}]}<\/script>\n ","yoast_head_json":{"title":"Data breach notification: the 72-hour GDPR clock compared","description":"Breach notification runs on different clocks: 72 hours under the GDPR, the first hour in Argentine banking, up to 60 days under HIPAA.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/","og_locale":"en_US","og_type":"article","og_title":"Data breach notification: the 72-hour GDPR clock compared","og_description":"Breach notification runs on different clocks: 72 hours under the GDPR, the first hour in Argentine banking, up to 60 days under HIPAA.","og_url":"https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/","og_site_name":"SMARTFENSE","article_published_time":"2026-07-20T08:56:32+00:00","article_modified_time":"2026-07-20T08:56:37+00:00","og_image":[{"width":1376,"height":768,"url":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-12.jpg","type":"image\/jpeg"}],"author":"Carla Caggiano","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Carla Caggiano","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/#article","isPartOf":{"@id":"https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/"},"author":{"name":"Carla Caggiano","@id":"https:\/\/smartfense.com\/en\/#\/schema\/person\/f88c39d826fb9430f0e1bad25938ae2c"},"headline":"Data breach notification: the GDPR 72-hour clock compared with Argentina&#8217;s financial sector, HIPAA and Latin America","datePublished":"2026-07-20T08:56:32+00:00","dateModified":"2026-07-20T08:56:37+00:00","mainEntityOfPage":{"@id":"https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/"},"wordCount":1561,"commentCount":0,"publisher":{"@id":"https:\/\/smartfense.com\/en\/#organization"},"image":{"@id":"https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/#primaryimage"},"thumbnailUrl":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-12.jpg","keywords":["an\u00e1lisis de riesgos","Cumplimiento Normativo","data breach","GDPR","protecci\u00f3n de datos"],"articleSection":["Blog","Blog"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/","url":"https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/","name":"Data breach notification: the 72-hour GDPR clock compared","isPartOf":{"@id":"https:\/\/smartfense.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/#primaryimage"},"image":{"@id":"https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/#primaryimage"},"thumbnailUrl":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-12.jpg","datePublished":"2026-07-20T08:56:32+00:00","dateModified":"2026-07-20T08:56:37+00:00","description":"Breach notification runs on different clocks: 72 hours under the GDPR, the first hour in Argentine banking, up to 60 days under HIPAA.","breadcrumb":{"@id":"https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/#primaryimage","url":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-12.jpg","contentUrl":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-12.jpg","width":1376,"height":768,"caption":"Varios relojes de pared marcando horas distintas sobre una pared de oficina, met\u00e1fora de los plazos regulatorios simult\u00e1neos ante una brecha"},{"@type":"BreadcrumbList","@id":"https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/smartfense.com\/en\/"},{"@type":"ListItem","position":2,"name":"Data breach notification: the GDPR 72-hour clock compared with Argentina&#8217;s financial sector, HIPAA and Latin America"}]},{"@type":"WebSite","@id":"https:\/\/smartfense.com\/en\/#website","url":"https:\/\/smartfense.com\/en\/","name":"SMARTFENSE - Concienciaci\u00f3n en Ciberseguridad","description":"","publisher":{"@id":"https:\/\/smartfense.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/smartfense.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/smartfense.com\/en\/#organization","name":"SMARTFENSE","url":"https:\/\/smartfense.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/smartfense.com\/file\/2023\/08\/logo-smartfense-240x40-1.png","contentUrl":"https:\/\/smartfense.com\/file\/2023\/08\/logo-smartfense-240x40-1.png","width":241,"height":40,"caption":"SMARTFENSE"},"image":{"@id":"https:\/\/smartfense.com\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/smartfense.com\/en\/#\/schema\/person\/f88c39d826fb9430f0e1bad25938ae2c","name":"Carla Caggiano","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/file\/2026\/06\/cropped-Carla-Caggiano-96x96.png","url":"https:\/\/smartfense.com\/file\/2026\/06\/cropped-Carla-Caggiano-96x96.png","contentUrl":"https:\/\/smartfense.com\/file\/2026\/06\/cropped-Carla-Caggiano-96x96.png","caption":"Carla Caggiano"},"description":"Ejecutiva en Gobierno, Riesgo y Cumplimiento (GRC), Seguridad de la Informaci\u00f3n y Continuidad del Negocio, con m\u00e1s de 8 a\u00f1os liderando equipos y proyectos en banca, salud y tecnolog\u00eda. Dise\u00f1a e implementa marcos basados en ISO 27001, ISO 22301 e ISO 31000, y traduce regulaciones complejas (SOX, NIST, GDPR, DORA, COBIT) en soluciones aplicables y sostenibles.","sameAs":["https:\/\/www.linkedin.com\/in\/carla-v-caggiano\/"],"url":"https:\/\/smartfense.com\/en\/author\/carla\/"}]}},"_links":{"self":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/43743","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/users\/34"}],"replies":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/comments?post=43743"}],"version-history":[{"count":2,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/43743\/revisions"}],"predecessor-version":[{"id":43757,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/43743\/revisions\/43757"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/media\/43751"}],"wp:attachment":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/media?parent=43743"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/categories?post=43743"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/tags?post=43743"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}