Once more, into the breach: Final guidelines on notification under GDPR
Many privacy pros in the U.S., with long experience complying with breach notification laws, were staggered by the GDPR’s 72-hour notification time frame. They hoped that the guidance from the WP29 would shed some light on questions such as when the notification clock starts ticking, what constitutes “awareness” of a breach, and how to determine the level of risk that triggers notification.
The draft Guidelines did address these issues, with helpful points suggesting that the WP29 had drawn lessons from the experience of other jurisdictions.
Source: Once more, into the breach: Final guidelines on notification under GDPR