What they had not accounted for was that the same breach had also started notification clocks under the UK GDPR, Brazil's LGPD, Canada's PIPEDA, Australia's NDB scheme, and four US state breach notification laws — each with different notification timelines, different notification content requirements, different thresholds for what constitutes a reportable breach, and different regulatory authorities to notify. The incident response plan had been written for one jurisdiction. The breach had occurred in fourteen.
The Multi-Jurisdiction Notification Problem
Breach notification requirements have proliferated. Every significant privacy regulatory regime now includes notification obligations. The timelines range from 24 hours (some sector-specific regulations) to 72 hours (GDPR), to 30 days (PIPEDA's breach of security safeguards), to 60 days (some US state laws), to no specified timeline with a 'without unreasonable delay' standard (Australia's NDB scheme). The content required in each notification differs. The threshold for what constitutes a notifiable breach differs. The definition of personal data that triggers notification differs.
An organization that holds personal data about individuals in multiple jurisdictions faces these requirements simultaneously when a breach occurs. The breach does not wait for the organization to identify which jurisdictions are affected before the notification clocks start. The clocks start at the moment of awareness. The organization must simultaneously manage the incident response, identify the affected jurisdictions, determine the applicable notification requirements for each, prepare jurisdiction-specific notifications, and file them within the applicable timelines — while the incident is still being contained.
Multi-jurisdiction breach notification is not a process that can be designed during an incident. The jurisdictional mapping, notification template preparation, regulatory contact identification, and decision criteria must be built before the incident. Everything built during the incident is late.
The Fourteen-Jurisdiction Reality
Different Definitions of Personal Data
GDPR defines personal data broadly as any information relating to an identifiable natural person. Brazil's LGPD follows a similar broad definition. Canada's PIPEDA covers information about an identifiable individual. Australian privacy law covers information about an individual that is reasonably identifiable. The US has no federal personal data definition — definitions are in sector-specific laws and in state laws that use varying formulations.
A breach involving a specific data set — customer records with name, email, transaction history, and device identifiers — may meet the personal data definition in some jurisdictions and not others, depending on each jurisdiction's specific definition. The jurisdictional mapping of the breach must assess which data categories meet each jurisdiction's definition, not apply a single definition across all affected jurisdictions.
Different Thresholds for Notifiability
Not every breach requires notification under every regime. GDPR requires notification to the supervisory authority unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Australia's NDB scheme requires notification only when the breach is likely to result in serious harm. Canada's PIPEDA requires notification when the breach creates a real risk of significant harm. The same breach may be notifiable under some regimes and below the threshold for notification under others. Assessing notifiability across fourteen jurisdictions requires jurisdiction-specific risk assessment against jurisdiction-specific harm thresholds.
Different Regulatory Authorities and Contact Protocols
Each jurisdiction's notification goes to a different regulatory authority with different contact protocols. The EU has 27 supervisory authorities — the relevant authority is typically determined by the controller's EU establishment or by where affected individuals are located. The UK has the ICO. Brazil has the ANPD. Canada has the OPC. Australia has the OAIC. US state laws require notification to the attorney general of each affected state. Managing fourteen simultaneous notifications to different authorities with different filing systems, different contact information, and different response protocols is a coordination challenge that requires preparation to execute in crisis conditions.
Building Multi-Jurisdiction Notification Capability
Multi-jurisdiction notification capability is built before incidents, not during them. The preparation has specific components: a jurisdictional data map that identifies which jurisdictions' regulations apply to which data processing activities, a notifiability assessment framework for each applicable jurisdiction, notification templates that meet each jurisdiction's content requirements, regulatory contact information and filing procedures for each applicable authority, and a coordination process that can manage simultaneous notifications to multiple authorities.
The jurisdictional data map is the foundation. It connects the data the organization holds — by category, by the location of the individuals whose data is held, by the location of the processing — to the regulatory regimes that apply. A breach of a specific data category triggers notification assessment under each regime that applies to that data category based on the map.
The legal function in each jurisdiction needs to be engaged before the breach, not during it. External counsel in each major jurisdiction, briefed on the organization's data processing activities and available to advise on notifiability assessment and notification content, reduces the timeline to notification in each jurisdiction. The incident is the wrong time to establish those relationships.
Build the multi-jurisdiction notification capability in the absence of an incident. The clocks in fourteen jurisdictions start simultaneously. The preparation cannot.
Map the jurisdictions before the breach. Prepare the notifications before the incident. Identify the regulators before the clock starts. The preparation is the capability. The incident tests it.
Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.
