An organization has confirmed a data breach involving customer PII. The IR team lead is determining notification requirements. Which factor MOST directly affects breach notification timelines?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — c is correct because notification timelines are primarily governed by regulatory requirements — GDPR mandates 72 hours, HIPAA has specific requirements, US states have varying laws — and contractual obligations including payment card industry agreements. A is wrong because investigation cost affects budget, not notification timing requirements.
Full explanation below image
Full Explanation
C is correct because notification timelines are primarily governed by regulatory requirements — GDPR mandates 72 hours, HIPAA has specific requirements, US states have varying laws — and contractual obligations including payment card industry agreements. A is wrong because investigation cost affects budget, not notification timing requirements. B is wrong because attacker identification is not a prerequisite for breach notification under any major regulation. D is wrong because insurance deductibles relate to financial recovery, not legal notification obligations.