All news
September 25, 2024

Data Breach Response: The Merchant's 72-Hour Playbook

72 hours to notify SDAIA. The clock starts the moment you detect the breach, not when you finish investigating. Here's the playbook.

Data Breach Response: The Merchant's 72-Hour Playbook

The rule, in one sentence

If a personal data breach could harm the data subject or their rights, you must notify SDAIA within 72 hours of becoming aware of it. The clock starts at detection, not when your investigation wraps up, and not when the team finally finds time for it.

What counts as a breach

Under the Personal Data Protection Law (PDPL), a personal data breach is any unauthorized access, disclosure, alteration, loss, or destruction of personal data. That covers a stolen laptop holding customer records, a misconfigured database left open to the internet, a ransomware attack, an employee exporting data without authorization, or an email sent to the wrong recipient.

Malicious intent is not required. An honest mistake, such as an employee sending a customer list to the wrong address, is still a breach. The law is concerned with exposure, not motivation.

The 72-hour clock, hour by hour

Here is how the timeline should work in practice.

Hour 0 — Detection

Someone notices the breach. It might be your monitoring system, an employee, a customer complaint, or an outside researcher. The clock starts the moment a designated responsible person becomes aware.

Hours 0 to 6 — Contain

Stop the damage. Isolate compromised systems, revoke leaked credentials, and take affected services offline if that is what it takes. Hold off on the investigation. Containment first, forensics second.

Hours 6 to 24 — Assess the scope

What data was exposed? How many individuals are affected? Which categories are involved: basic contact details, sensitive data, payment information? The answer determines whether you also need to notify affected individuals alongside SDAIA.

Hours 24 to 48 — Draft the notification

SDAIA's notification template asks for the nature of the breach, the categories and approximate number of data subjects, the likely consequences, the measures taken to contain and mitigate the incident, and the contact details of your Data Protection Officer.

Hours 48 to 72 — File with SDAIA

Submit through SDAIA's breach notification channel and keep a copy of everything. If the deadline is approaching and some details are still unclear, file what you have and mark the investigation as ongoing. An incomplete filing is far better than a late one.

What happens if you miss the deadline

Missing the 72-hour window is a PDPL violation in its own right, separate from whatever caused the breach. It tells SDAIA that you have no response capability, which moves you into a higher penalty category. Many of the heaviest fines in the first enforcement wave were not for the original breach at all. They were for the notification that arrived late or never arrived.

Write the runbook before the fire

Seventy-two hours is not much time. Drafting an incident response plan at two in the morning is exactly how companies miss deadlines. Decide in advance who acts as incident commander, who holds access to the SDAIA portal, where the notification template is stored, and who authorizes notifying affected users. Then rehearse it once a quarter.

Sources & References

Want to see Wateer on your system?

Talk to Sales