Skip to content
Client login

Free Audit

Artificial intelligence

Notifying a breach within five days: the runbook, hour by hour

The clock starts the moment you know, not the moment you are certain. That is the only sentence in this article that changes anything.

Published on 12 August 2026 — Algeria Agency

On a Thursday at seven in the evening, the administrator of a private clinic receives a message from a patient: he has been sent somebody else’s report by mistake. She calls the supplier, who does not answer. She decides to look at it on Sunday. The clock started at seven, and by Sunday morning she has a little over half the deadline left.

Notifying a data breach runs to five days from the moment you know, and almost every business that misses that deadline misses it for the same reason: they wait until they are sure. An artificial intelligence project does not change the rule, it multiplies the places an incident can start.

This article gives the runbook hour by hour: what starts the clock, how the facts get established, who signs, what the notification contains, and what the weekend does to the calendar. It does not cover how to stop an incident — the four stories and the first hour are a separate subject and a better starting point for that side.

The clock starts when you know, not when you are certain

Knowledge starts the deadline. Not confirmation, not the supplier’s report, not Monday’s crisis meeting: the moment somebody in the business learns a fact that makes a breach plausible.

This is where the most days are lost, and they are lost in good faith. A team that spends three days establishing whether the incident is real feels it is doing the right thing — investigating before troubling the authority — and has spent three fifths of the deadline on something that does not suspend it.

The practical consequence is one reflex to install: note the time. The first act, before calling anybody, is to write down the date, the hour and who the information came through. That is not a formality — it is the start of the only count that will matter afterwards, and it is impossible to reconstruct three days later.

The corollary is worth saying plainly: a business that does not note that hour will not be able to prove it notified in time, even when it did. Proving a deadline was met begins with proving when it began.

What the law asks, and since when

Law 18-07 of 10 June 2018, amended and completed by law 25-11 of 24 July 2025, requires the controller to notify the national data protection authority of any personal data breach within five days of becoming aware of it.

Two obligations accompany it. Informing the person concerned where the breach presents a high risk to them. And keeping an internal record of breaches — what happened, when you knew, what you notified and what you did.

Five days, with no qualification as working days in the text’s wording. That difference decides everything in an hour-by-hour runbook: a hundred and twenty hours, not a working week. The rest of this article counts in hours for that reason.

The above describes the state of a regulation as at 21 August 2026 and does not replace a lawyer’s advice. The exact scope of each obligation is read in the text, article by article, and characterising a particular incident is discussed with a lawyer rather than with an IT supplier.

Not every fault is a breach

A data breach is not a synonym for hacking. It covers three kinds of harm: to confidentiality — somebody saw what they should not have; to integrity — data was altered; to availability — you no longer have access to it.

The third surprises people and is the one businesses wrongly rule out. A server encrypted by ransomware, a lost backup, a supplier cutting access to a database: those are harms to the availability of personal data, even if nobody read it.

Conversely, a power cut making software unavailable for two hours with no data loss is not a breach, and a file consulted by an authorised person who had no reason to may be one — that is unauthorised access even without an intrusion from outside.

The right question, and it takes ten minutes, has three parts: is personal data involved, did one of the three harms occur, and can you demonstrate that it did not. The third is the most useful: when the answer is “probably not, but we cannot show it”, treat it as a breach.

Hours 0 to 4: contain without erasing

The first hours belong to the technical side and the first hour of an incident is described elsewhere. What belongs to this article is what must not be destroyed in the meantime.

Three things are systematically lost in the rush. Logs, erased or overwritten during a reinstall. Messages, deleted because they were fraudulent. And the state of the machine, powered off to “cut the problem out”, which takes with it everything not yet written to disk.

The rule fits in one sentence: isolate rather than power off, copy before correcting. Unplugging a machine from the network takes it out of circulation without losing what it holds; switching it off does both.

You also have to start a log of facts, on paper or in a document nobody will edit: time, what was observed, what was done, by whom. That document will be half the notification, and it is infinitely easier to write while things are happening than to reconstruct afterwards.

Hours 4 to 12: establishing the facts

The notification asks for facts, not an explanation. Four questions produce them: which categories of data, roughly how many people, since when, and by what route. None of them requires knowing who is responsible.

The second is where businesses stall, because they look for an exact number. An openly stated order of magnitude — “between two and four hundred customer files” — is perfectly acceptable and available within an hour, where the exact figure sometimes takes days.

The fourth, the route, is the most useful for what follows and the most often ignored at the time. It is not for identifying a culprit: it is for knowing whether the gap is closed, which is the question the authority will ask immediately afterwards.

This is also where the register pays. A business that has written its six columns knows, by opening one row, which categories of data that activity holds and for how many people — two of the four answers are already written, and hunting for them on a Thursday evening is the expensive version of not having written them in January.

Who signs, and why it is not IT

The notification commits the controller — the business — to the accuracy of what it describes. It is therefore signed by management, on the basis of a file prepared by the data protection officer where there is one.

The IT manager supplies the technical facts and does not sign. The distinction is not hierarchical: they describe what they observed, which is already considerable, and they are not in a position to decide what the business declares about itself.

That split has to be written down beforehand, because the moment it is discovered is the worst one for deciding it. A business that spends six hours working out who may sign has spent a twentieth of its deadline on an org-chart question.

Provide for a deputy too. A five-day deadline frequently crosses an absence, and a procedure naming one person stops the day that person is on leave — which, statistically, will happen once in a few incidents.

Hours 12 to 48: what the notification contains

It describes the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences, and the measures taken or planned to address it and limit its effects. It also gives a point of contact.

It contains no analysis of responsibility, no employee’s name, and no promise. “We are strengthening our procedures” is not a measure; “the account’s access was revoked on the 12th at 2 p.m. and all administrator passwords were changed” is one.

The useful tone is that of a dated observation. Every sentence should be checkable by somebody reading your logs, and nothing should depend on an interpretation. A cautious, factual notification is sturdier than a reassuring one.

Write it on one page. Long notifications are not better examined: they dilute the four facts being looked for, and they add sentences nobody will be able to support if they are returned to.

Notify incomplete rather than late

This is the decision that saves the most files and the least intuitive one. A notification sent within the deadline with elements missing, saying which and when they will follow, beats a complete one sent afterwards.

The reason is that the two failings are not of the same kind. An incomplete file is a file under examination, with a business that is cooperating; a late file is a failure to comply, whatever the quality of its contents.

The wording to prepare in advance fits in one sentence: state that the investigation continues, what remains to be established, and within what period you will send the rest. It is one sentence, it is drafted calmly on a Tuesday in January, and nobody has ever written it during an incident.

The operational corollary is to set an internal deadline at half the legal one. A business aiming at sixty hours gives itself the right to be wrong once; a business aiming at a hundred and twenty has no margin, and the first surprise makes it late.

When the people concerned must also be told

Informing the people concerned is a separate obligation, triggered by the level of risk to them rather than by the size of the incident. A thousand exposed email addresses and three medical reports sent to the wrong recipient are not handled the same way, and it is the second that calls for individual notice.

The message has to be useful, not legal. What happened, which of their data is involved, what they concretely risk, what they can do — change a password, watch a statement, be wary of a call claiming to be from you — and who to write to.

What not to do is shorter: do not minimise, do not wait until you have good news to announce alongside it, and do not send a generic message to the whole database when only thirty people are affected. The third turns a contained incident into a public event.

The timing of that notice is not the timing of the notification to the authority, and the two are prepared separately. In practice the second is drafted faster than the first, because it is factual where the first requires choosing words.

Thursday evening, and the two days nobody reads

The working week runs Sunday to Thursday. A breach discovered on a Thursday at seven in the evening therefore has five days, two of which fall on a Friday and a Saturday, when the supplier does not answer, management is not at the office and the customer’s bank is closed.

That is not an incident, it is the calendar, and it happens two days in seven. A procedure written for a Monday-to-Friday week — that is, any procedure copied from a foreign template — is systematically wrong about the commonest case.

The safeguard is two lines in the procedure. A number that reaches the person who signs on Friday and Saturday, and prior agreement that the notification may go without a meeting if the four facts are established. Without the second, the first is of no use.

It has to be arranged with suppliers too. A contract imposing a twenty-four-hour notification on the supplier is what leaves you the rest of the deadline — their deadline has to be shorter than yours, and it is the clause most often absent from the contracts we review.

The dry run: one hour, unannounced

Here is the exercise, and it is done without us. Pick an ordinary Tuesday, send three people a message describing a plausible incident — a report sent to the wrong patient, a stolen laptop, a supplier reporting unusual access — and ask them to produce, within an hour, what they would send to the authority.

Do not warn them beforehand and do not help during. What you are measuring is not their knowledge of the law but four things: how long to work out who decides, how long to find the categories of data involved, how long to establish an order of magnitude for the number of people, and whether anybody noted the start time.

The commonest result we see is that an hour is not enough and that half of it goes on the first question. That is valuable information and it costs an hour: it says your real deadline is not a hundred and twenty hours but a hundred and twenty hours minus that time.

Do it once a year, and change the scenario. A procedure rehearsed once is a procedure people remember having read, which is not the same as knowing how to run it.

What we do, and what we refuse

We write the one-page procedure with you: who notes the time, who establishes the facts, who signs, who deputises, and the sentence to send while the file is still incomplete. We also check that the logs exist and go back far enough, because a notification without logs is a notification describing impressions.

We run the dry run and we time it, including when the result is awkward for the person who brought us in. It is the part of this work with the most measurable value and it is the part we are asked for least.

We send nothing to the authority in your name and we do not sign your notification. It commits your business to the accuracy of what it describes, and a declaration signed by a technical supplier is a declaration management discovers afterwards. We prepare; you sign.

And we will not say an incident is not a breach. That characterisation has legal consequences, it belongs to a lawyer or to your officer, and a supplier who reassures you on that point saves you a declaration while costing you the only protection the declaration offered — having acted within the deadline.

Frequently asked questions

From exactly when does the deadline run?

From the moment the business becomes aware of a fact that makes a breach plausible, not from the moment it is certain. That is why the first act is to note the time and who received the information: it is the start of the count, it cannot be reconstructed later, and it conditions your proof that you notified in time.

What if we do not yet know how many people are affected?

Notify with an openly stated order of magnitude and say the investigation continues. An incomplete file sent within the deadline is a file under examination; a complete one sent after it is a failure to comply, whatever the quality of its contents. The sentence announcing the rest is drafted calmly in advance.

Is ransomware that exfiltrated nothing a breach?

You have to examine the harm to availability, which is one of the three forms the concept covers: personal data you no longer have access to is involved even if nobody read it. Whether anything was exfiltrated changes the risk to the people and therefore the duty to inform them; it does not on its own rule the characterisation out.

Do we notify if the supplier has fixed the problem?

The gap being closed is a measure taken, to be described in the notification, not a reason not to make it. It is also why the contract must require the supplier to tell you quickly: your clock starts when you know, and a supplier quietly repairing for three days spends your deadline on your behalf.

What if we discover the incident two months later?

The deadline runs from your knowledge, so it starts at discovery and not at the events. What the delay changes is the “likely consequences” part: two months of exposure is not described like two hours, and it is that description that has to be honest rather than the date.

Do we have to tell the people concerned every time?

No: that obligation is separate and depends on the level of risk to them. An incident without high risk is notified to the authority without individual notice. Where the risk is high, the message has to be useful rather than legal — what is involved, what they concretely risk, what they can do, and who to write to.

Where we come in

The dry run nearly always ends the same way: an hour gone, half of it spent finding out who is allowed to decide. Your real deadline is a hundred and twenty hours minus that time.

  • The sheet fits on a page: recording the hour, establishing facts, signing, standing in.
  • We draft the partial-filing text ahead of time, calmly, rather than on a Thursday evening.
  • We check how deep your logs reach: without them a declaration describes impressions.

No signature will come from us, and ruling that an event falls outside the scope is not ours to do: that is settled with a lawyer.

Read next

Let us talk about your project

A free audit, no commitment: we look at your online presence and tell you what is holding it back.

We measure how this site is used with Google Analytics, to learn which pages actually help. You can stop that measurement at any time from the footer. Cookie policy