Data Breach Notification Deadlines: US States, GDPR & SEC 8-K
Pricing
from $3.00 / 1,000 rule lookups
Data Breach Notification Deadlines: US States, GDPR & SEC 8-K
Every notice a data breach triggers, with the deadline as a date: each US state (people, attorney general, credit bureaus), HIPAA, SEC 8-K, GDPR, UK ICO, Canada, Australia, sourced. Inputs: people affected per state or country, data types, date found. Charged per check. Agent-ready: x402, MCP.
Pricing
from $3.00 / 1,000 rule lookups
Rating
0.0
(0)
Developer
Adam Pearce
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
2 hours ago
Last modified
Categories
Share
One breach can trigger fifty different deadlines: 72 hours under GDPR, 4 business days for an SEC filing, 30 or 60 days in many US states, attorney general notices above set numbers. Missing one is a fine. This lists every notice owed, earliest first.
Built for security and incident response teams, privacy and legal ops tools, cyber insurers, MSPs and AI agents running an incident checklist. Every answer names the law and links the official government page it came from, so a person can check it in one click.
What it returns
- Who to notify and by when (
mode: "check"): Works out every data breach notice a company owes and the deadline for each. Give affected (how many people in each US state or country), the data types exposed (for example ssn, drivers_license, payment_card, financial_account, medical, health_insurance, username_password, biometric, passport, dob, email_address), whether the data was encrypted with the key kept safe, the date the breach was discovered, and flags: sec_registrant (US public company), sector (hipaa_covered_entity, hipaa_business_associate, glba_financial, health_app, nydfs_licensee) and role (owner, or service_provider holding data for another company). Returns each notice owed (people affected, state attorneys general, credit bureaus, HHS, SEC Form 8-K, FTC, EU and UK data protection authorities, Canada, Australia) with the deadline as a date where the law sets a fixed period, the deadline rule in words, what the notice must contain, how to send it and the official source, earliest first. Unclear cases give the SAFE answer (notice treated as required) plus what it depends on. - List breach laws (
mode: "list"): Lists breach notification laws with who is covered, which data types trigger them, encryption exemptions, every notice with its deadline rule and threshold, penalties and the official source. Filter by US state, country (ISO code or name) or scope (us_state, us_federal_sector, country, region).
Answers that depend on something you did not say come back as the safe answer (the stricter rule) plus a depends_on note saying what would change it.
Example input
{"mode": "check","affected": [{"state": "CA","count": 1200},{"state": "TX","count": 300},{"country": "Germany","count": 40},{"country": "United Kingdom","count": 15}],"data_types": ["ssn","drivers_license"],"date_discovered": "2026-10-05","sec_registrant": true,"materiality_date": "2026-10-07"}
Example output (shortened)
{"date_discovered": "2026-10-05","verdict": "9 notices owed under 5 laws. First fixed deadline: 2026-10-08 (The competent national data protection authority (lead authority for cross-border processing), European Union and EEA (GDPR)).","notices_owed": [{"deadline_date": "2026-10-08","deadline_rule": "Without undue delay and, where feasible, no later than 72 hours after becoming aware. If later, give reasons for the delay. Information may be given in phases.","notify": "The competent national data protection authority (lead authority for cross-border processing)","notice_type": "data_protection_authority","law": "European Union and EEA (GDPR)","id": "EU-GDPR","affected_here": 40,"citation": "Regulation (EU) 2016/679, Articles 33 and 34","how": "Each national authority's own breach form","matched_data_types": ["ssn","drivers_license"],"source": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679","verified_on_primary_source": true},{"deadline_date": "2026-10-08","deadline_rule": "Without undue delay and, where feasible, within 72 hours of becoming aware. Give reasons if later; details may follow in phases.","notify": "Information Commissioner's Office (ICO)","notice_type": "data_protection_authority","law": "United Kingdom (UK GDPR)","id": "UK-GDPR","affected_here": 15,"citation": "UK GDPR Articles 33 and 34; Data Protection Act 2018","how": "ICO online breach report form (about 30 minutes, cannot be saved part-way) or by phone","submit_url": "https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breach-reporting/","matched_data_types": ["ssn","drivers_license"],"source": "https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/","verified_on_primary_source": true},"... 7 more"],"not_required": [{"law": "Texas","id": "US-TX","notice_to": "Nationwide consumer reporting agencies"}],"data_as_of": "2026-10-10"}
Inputs
affected: Where the affected people live: [{"state":"CA","count":1200},{"state":"TX","count":300},{"country":"Germany","count":40},{"country":"United Kingdom","count":15},{"country":"Canada","province":"Quebec","count":5}]. A bare two-letter code is read as a US state (CA = California); use {"country":"CA"} or "Canada" for Canada.data_types: Personal data exposed, for example ["ssn","drivers_license","payment_card"]. If left out every law is treated as triggered (SAFE).encrypted: True only if all the exposed data was encrypted and the key was not exposed. Many US state laws then need no notice. Default false.date_discovered: Date the breach was discovered (or you became aware of it), YYYY-MM-DD. Defaults to today. Deadlines are counted from it.sec_registrant: True for a company that files reports with the US SEC (listed in the US). Adds Form 8-K Item 1.05.materiality_date: SEC registrants: date the company decided the incident is material, YYYY-MM-DD. The 8-K is due 4 business days after it.sector: Sector rules that apply: hipaa_covered_entity, hipaa_business_associate, glba_financial (non-bank financial firms under the FTC Safeguards Rule), health_app (FTC Health Breach Notification Rule), nydfs_licensee (New York DFS regulated).role: owner (default): the company that owns or licenses the data. service_provider: holds it for another company, which mostly means notifying that company quickly.lookups: many questions in one run (up to 1,000), each item with the fields above.
Pricing
$0.003 per answered lookup (a listing mode is one lookup). Failed lookups (for example an address the US Census geocoder cannot find) are not charged. 1,000 lookups cost $3 US dollars.
For AI agents
- Runs through Apify's MCP server (
https://mcp.apify.com/?tools=nerolabs/breach-notification-deadlines) and through x402, so an agent without an Apify account can pay per call. - A free MCP server with the same rules is at
https://breach-notification-deadlines.nerolabs.workers.dev/mcpfor chat use; this actor adds bulk runs, datasets, scheduling, webhooks and Apify billing. - Part of Nero Labs Rules: tools that answer rules which change after a model's training cutoff. The others: US minimum wage, pay transparency, US sales tax nexus, data breach deadlines.
Data and limits
- Built from primary sources only (statutes, regulators, revenue departments, official gazettes), each figure with its source URL and a
verified_on_primary_sourceflag. - Rules data is checked and updated by Nero Labs; every answer carries
data_as_of. - Information, not legal or tax advice. Check the linked source before acting on a close call.