logoalt Hacker News

bfleschtoday at 8:42 AM4 repliesview on HN

This is in breach of the 72hr GDPR notification window


Replies

fmajidtoday at 10:58 AM

China’s is even more stringent at 4 hours, down to 1 hour for high-severity incidents:

https://www.theregister.com/2025/09/16/china_1hour_cyber_rep...

https://privacymatters.dlapiper.com/2025/09/china-new-strict...

gcbirzantoday at 1:35 PM

Only the supervisory authorities are required to be informed in 72 hour, and even there, it's not a hard rule, you can have excuses.

skeeter2020today at 3:43 PM

this is for the regulator or governing body, not public. Most big clients will have an explicit reporting window in their contract though