What Happens When a Company Has a Data Breach Your Rights

Photo of author
Author: Alex
Published:
Updated:
Cracked shield with personal data icons illustrating data breach company obligations and notification rules

Direct Answer: When a company suffers a data breach, it is legally required to notify affected individuals and regulators within specific timeframes 72 hours under GDPR (EU/UK), and between 30 to 60 days under most US state laws. Individuals may also have the right to compensation, free credit monitoring, or the ability to file a lawsuit depending on their jurisdiction.

Data breach company obligations vary significantly depending on where you live and where the company operates but one thing is consistent across the EU, US, and UK: companies cannot just stay silent when your personal information gets exposed. Every year, billions of records are compromised in security incidents, and the laws governing how companies must respond have gotten stricter. If a company holding your data gets breached, here’s what the law actually requires them to do and what options are available to you. (Can Your Boss Watch You Work from Home?)

The Short Version

  • Under GDPR (EU) and UK GDPR, companies must report qualifying breaches to regulators within 72 hours and notify affected individuals “without undue delay” for high-risk breaches.
  • In the United States, all 50 states have breach notification laws, with deadlines ranging from 30 to 90 days depending on the state California now requires notification within 30 calendar days.
  • Companies that fail to notify can face fines up to €10 million (EU/UK) or $500,000+ per violation (US), plus class action lawsuits.
  • Affected individuals may be able to claim compensation for documented financial losses, and in some states, statutory damages are available even without proof of direct harm.

What Data Breach Company Obligations Actually Mean Under the Law

The phrase “data breach notification” refers to a company’s legal duty to tell regulators and affected people when personal data has been compromised. But the specifics depend entirely on jurisdiction.

In the European Union (GDPR)

Under Articles 33 and 34 of the General Data Protection Regulation (GDPR), a company that experiences a personal data breach must notify its supervisory authority (the relevant Data Protection Authority) within 72 hours of becoming aware of the breach. The clock starts the moment the organization has reasonable certainty that personal data was compromised not when the investigation wraps up.

If the breach poses a high risk to individuals’ rights and freedoms, the company must also notify affected people directly and without undue delay. That notification must be written in plain language and must describe what happened, what data was exposed, and what steps the company is taking.

Companies that fail to report face fines of up to €10 million or 2% of global annual revenue, whichever is higher. And every breach even those that don’t require external notification must be logged in an internal breach register that regulators can request at any time.

In the United Kingdom (UK GDPR)

The UK follows a nearly identical framework under UK GDPR, enforced by the Information Commissioner’s Office (ICO). The same 72-hour notification window applies for breaches likely to result in a risk to individuals. For high-risk breaches, direct communication with affected individuals is also mandatory.

The ICO has been active in enforcement. In 2025 alone, fines exceeding £14 million were issued against companies for inadequate security measures that led to breaches. The UK’s Data (Use and Access) Act 2025 has further strengthened the regulatory framework around breach accountability.

In the United States

The US does not have a single federal breach notification law. Instead, all 50 states plus the District of Columbia have their own statutes, creating a patchwork of requirements. Key differences include:

Notification timelines vary widely. About 20 states set fixed deadlines the strictest being Colorado, Florida, Maine, Rhode Island, and Washington at 30 days. California, under SB 446 (effective January 1, 2026), now mandates a 30-day window for individual notification and a 15-day window for Attorney General notification when 500+ residents are affected.

Many other states use vaguer language like “without unreasonable delay” or “in the most expedient time possible” which gives companies more wiggle room but also makes enforcement less predictable.

What triggers notification also differs. Most states require notification when a person’s name is exposed alongside a Social Security number, financial account number, or driver’s license number. Newer state laws are expanding covered data to include biometric identifiers, login credentials, and health information.

Three jurisdiction clocks comparing EU, US, and UK data breach company obligations and notification deadlines

Real-World Examples

Example 1: The 72-Hour Scramble (EU) A mid-size e-commerce company discovers on a Friday evening that hackers accessed a database containing customer names, email addresses, and payment card numbers. Under GDPR, the 72-hour clock starts immediately not Monday morning. The company must file an initial notification with its supervisory authority by Monday evening, even if the investigation is still ongoing. GDPR allows phased reporting, meaning the company can submit what it knows now and provide updates later.

Example 2: Multi-State Headache (US) A US healthcare company suffers a ransomware attack exposing patient records across 12 states. Each state has different notification requirements. California demands notification within 30 days. Florida also requires 30 days. But other affected states may allow up to 60 or 90 days. The company must comply with the shortest applicable deadline for each group of affected residents and may need to send different notices to different state attorneys general.

Example 3: The UK ICO Investigation A UK financial services firm sends a spreadsheet containing customer account details to the wrong email recipient. Even though this was an accident not a hack it still qualifies as a personal data breach under UK GDPR. The company must assess the risk, and if the breach could lead to identity theft or financial loss, it must notify the ICO within 72 hours and warn affected customers directly.

What People in This Situation Typically Do

  1. Check breach notifications carefully. When a company sends a breach notice, it typically explains what data was exposed, when the breach happened, and what the company is doing about it. Reading the full notice matters it often includes instructions for next steps.
  2. Place a fraud alert or credit freeze. In the US, individuals can place a free fraud alert with any of the three major credit bureaus (Equifax, Experian, TransUnion). A credit freeze also free goes further by blocking new accounts from being opened in your name entirely.
  3. Monitor financial accounts. Watching bank statements and credit reports for unfamiliar activity is a practical first step after any breach involving financial data.
  4. Take advantage of free credit monitoring. Many companies offer free credit monitoring as part of their breach response. In the US, six states (including California, Connecticut, and Massachusetts) legally require companies to provide this after certain types of breaches.
  5. Consider legal options. In the US, class action lawsuits are common after major breaches. Settlements have ranged from modest payouts of $50–$100 per person to larger amounts for documented losses the Equifax settlement totaled $575–$700 million, and AT&T settled for $177 million in 2025. Under the California Consumer Privacy Act (CCPA), statutory damages of $100 to $750 per person per incident are available even without proof of specific financial harm.
  6. File a complaint with regulators. In the EU, complaints can be filed with the national Data Protection Authority. In the UK, the ICO accepts complaints online. In the US, the FTC and state attorneys general handle enforcement.

Tools That Can Help

After a data breach, one of the biggest ongoing risks is that stolen personal information gets sold to data brokers companies that collect and resell personal data. Even after a breach is resolved, your information can keep circulating.

  • DeleteMe A service that removes your personal information from major data broker sites. After a breach, this can help reduce the amount of exposed data floating around online.
  • NordVPN Offers a Dark Web Monitor feature that alerts you if your credentials appear in known breach databases, plus encrypted browsing to reduce future exposure.

Related Articles

Frequently Asked Questions

How quickly must a company notify me of a data breach?

It depends on where you live. In the EU and UK, regulators must be notified within 72 hours under GDPR, and affected individuals must be told “without undue delay” for high-risk breaches. In the US, timelines range from 30 to 90 days depending on the state. California’s deadline is 30 days as of January 2026.

Can I sue a company for exposing my data in a breach?

In many cases, yes. In the US, class action lawsuits are filed after most major breaches. Under the CCPA, California residents can seek $100 to $750 per person in statutory damages. In the EU and UK, individuals can claim compensation under GDPR Article 82 for material or non-material damage caused by a breach.

What compensation can I get after a data breach?

Compensation varies. US class action settlements typically offer $50 to $100 per person for basic claims, with higher amounts (up to $5,000–$7,500) for documented financial losses. Many settlements also include free credit monitoring for two to three years. In the EU, compensation claims under GDPR have included payments for emotional distress, not just financial losses.

What’s the difference between GDPR and US breach notification laws?

The biggest difference is structure. GDPR is a single regulation covering the entire EU (and mirrored by UK GDPR), with a uniform 72-hour notification deadline. The US has no single federal law instead, 50+ separate state statutes create a patchwork of different timelines, definitions, and penalties. GDPR also covers all personal data broadly, while US state laws typically focus on specific data types like Social Security numbers and financial account details.

Understanding data breach company obligations across different jurisdictions is the first step toward knowing what to expect and what actions are available when a breach hits. The laws are getting stricter, notification timelines are shrinking, and enforcement is increasing which means companies are under more pressure than ever to act fast and be transparent.

This article is for educational purposes only and does not constitute legal advice. Laws vary by jurisdiction and change frequently. For advice specific to your situation, consult a qualified attorney.

Sources & Further Reading

Written by Alex

Alex is the editorial pen name of Mohammed Ez-Zayady, a law student based in Morocco and the founder of Jovonk. The content is provided for educational purposes and does not constitute legal advice.