# Data Breach Notification Deadlines: US States, GDPR & SEC 8-K (`nerolabs/breach-notification-deadlines`) Actor

Every notice a data breach triggers, with the deadline as a date: each US state (people, attorney general, credit bureaus), HIPAA, SEC 8-K, GDPR, UK ICO, Canada, Australia, sourced. Inputs: people affected per state or country, data types, date found. Charged per check. Agent-ready: x402, MCP.

- **URL**: https://apify.com/nerolabs/breach-notification-deadlines.md
- **Developed by:** [Adam Pearce](https://apify.com/nerolabs) (community)
- **Categories:** Business, AI, Developer tools
- **Stats:** 2 total users, 1 monthly users, 0.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $3.00 / 1,000 rule lookups

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

## Data Breach Notification Deadlines: US States, GDPR & SEC 8-K

One breach can trigger fifty different deadlines: 72 hours under GDPR, 4 business days for an SEC filing, 30 or 60 days in many US states, attorney general notices above set numbers. Missing one is a fine. This lists every notice owed, earliest first.

Built for security and incident response teams, privacy and legal ops tools, cyber insurers, MSPs and AI agents running an incident checklist. Every answer names the law and links the official government page it came from, so a person can check it in one click.

### What it returns

- **Who to notify and by when** (`mode: "check"`): Works out every data breach notice a company owes and the deadline for each. Give affected (how many people in each US state or country), the data types exposed (for example ssn, drivers_license, payment_card, financial_account, medical, health_insurance, username_password, biometric, passport, dob, email_address), whether the data was encrypted with the key kept safe, the date the breach was discovered, and flags: sec_registrant (US public company), sector (hipaa_covered_entity, hipaa_business_associate, glba_financial, health_app, nydfs_licensee) and role (owner, or service_provider holding data for another company). Returns each notice owed (people affected, state attorneys general, credit bureaus, HHS, SEC Form 8-K, FTC, EU and UK data protection authorities, Canada, Australia) with the deadline as a date where the law sets a fixed period, the deadline rule in words, what the notice must contain, how to send it and the official source, earliest first. Unclear cases give the SAFE answer (notice treated as required) plus what it depends on.
- **List breach laws** (`mode: "list"`): Lists breach notification laws with who is covered, which data types trigger them, encryption exemptions, every notice with its deadline rule and threshold, penalties and the official source. Filter by US state, country (ISO code or name) or scope (us_state, us_federal_sector, country, region).

Answers that depend on something you did not say come back as the **safe** answer (the stricter rule) plus a `depends_on` note saying what would change it.

### Example input

```json
{
  "mode": "check",
  "affected": [
    {
      "state": "CA",
      "count": 1200
    },
    {
      "state": "TX",
      "count": 300
    },
    {
      "country": "Germany",
      "count": 40
    },
    {
      "country": "United Kingdom",
      "count": 15
    }
  ],
  "data_types": [
    "ssn",
    "drivers_license"
  ],
  "date_discovered": "2026-10-05",
  "sec_registrant": true,
  "materiality_date": "2026-10-07"
}
```

### Example output (shortened)

```json
{
  "date_discovered": "2026-10-05",
  "verdict": "9 notices owed under 5 laws. First fixed deadline: 2026-10-08 (The competent national data protection authority (lead authority for cross-border processing), European Union and EEA (GDPR)).",
  "notices_owed": [
    {
      "deadline_date": "2026-10-08",
      "deadline_rule": "Without undue delay and, where feasible, no later than 72 hours after becoming aware. If later, give reasons for the delay. Information may be given in phases.",
      "notify": "The competent national data protection authority (lead authority for cross-border processing)",
      "notice_type": "data_protection_authority",
      "law": "European Union and EEA (GDPR)",
      "id": "EU-GDPR",
      "affected_here": 40,
      "citation": "Regulation (EU) 2016/679, Articles 33 and 34",
      "how": "Each national authority's own breach form",
      "matched_data_types": [
        "ssn",
        "drivers_license"
      ],
      "source": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679",
      "verified_on_primary_source": true
    },
    {
      "deadline_date": "2026-10-08",
      "deadline_rule": "Without undue delay and, where feasible, within 72 hours of becoming aware. Give reasons if later; details may follow in phases.",
      "notify": "Information Commissioner's Office (ICO)",
      "notice_type": "data_protection_authority",
      "law": "United Kingdom (UK GDPR)",
      "id": "UK-GDPR",
      "affected_here": 15,
      "citation": "UK GDPR Articles 33 and 34; Data Protection Act 2018",
      "how": "ICO online breach report form (about 30 minutes, cannot be saved part-way) or by phone",
      "submit_url": "https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breach-reporting/",
      "matched_data_types": [
        "ssn",
        "drivers_license"
      ],
      "source": "https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/",
      "verified_on_primary_source": true
    },
    "... 7 more"
  ],
  "not_required": [
    {
      "law": "Texas",
      "id": "US-TX",
      "notice_to": "Nationwide consumer reporting agencies"
    }
  ],
  "data_as_of": "2026-10-10"
}
```

### Inputs

- `affected`: Where the affected people live: \[{"state":"CA","count":1200},{"state":"TX","count":300},{"country":"Germany","count":40},{"country":"United Kingdom","count":15},{"country":"Canada","province":"Quebec","count":5}]. A bare two-letter code is read as a US state (CA = California); use {"country":"CA"} or "Canada" for Canada.
- `data_types`: Personal data exposed, for example \["ssn","drivers_license","payment_card"]. If left out every law is treated as triggered (SAFE).
- `encrypted`: True only if all the exposed data was encrypted and the key was not exposed. Many US state laws then need no notice. Default false.
- `date_discovered`: Date the breach was discovered (or you became aware of it), YYYY-MM-DD. Defaults to today. Deadlines are counted from it.
- `sec_registrant`: True for a company that files reports with the US SEC (listed in the US). Adds Form 8-K Item 1.05.
- `materiality_date`: SEC registrants: date the company decided the incident is material, YYYY-MM-DD. The 8-K is due 4 business days after it.
- `sector`: Sector rules that apply: hipaa_covered_entity, hipaa_business_associate, glba_financial (non-bank financial firms under the FTC Safeguards Rule), health_app (FTC Health Breach Notification Rule), nydfs_licensee (New York DFS regulated).
- `role`: owner (default): the company that owns or licenses the data. service_provider: holds it for another company, which mostly means notifying that company quickly.
- `lookups`: many questions in one run (up to 1,000), each item with the fields above.

### Pricing

**$0.003 per answered lookup** (a listing mode is one lookup). Failed lookups (for example an address the US Census geocoder cannot find) are not charged. 1,000 lookups cost $3 US dollars.

### For AI agents

- Runs through Apify's MCP server (`https://mcp.apify.com/?tools=nerolabs/breach-notification-deadlines`) and through x402, so an agent without an Apify account can pay per call.
- A **free MCP server** with the same rules is at `https://breach-notification-deadlines.nerolabs.workers.dev/mcp` for chat use; this actor adds bulk runs, datasets, scheduling, webhooks and Apify billing.
- Part of **Nero Labs Rules**: tools that answer rules which change after a model's training cutoff. The others: US minimum wage, pay transparency, US sales tax nexus, data breach deadlines.

### Data and limits

- Built from primary sources only (statutes, regulators, revenue departments, official gazettes), each figure with its source URL and a `verified_on_primary_source` flag.
- Rules data is checked and updated by Nero Labs; every answer carries `data_as_of`.
- Information, not legal or tax advice. Check the linked source before acting on a close call.

# Actor input Schema

## `mode` (type: `string`):

check (default) answers one question, or every item in Lookups. The other modes list the rules themselves. Every mode is charged as one lookup per answer.

## `affected` (type: `array`):

Where the affected people live: \[{"state":"CA","count":1200},{"state":"TX","count":300},{"country":"Germany","count":40},{"country":"United Kingdom","count":15},{"country":"Canada","province":"Quebec","count":5}]. A bare two-letter code is read as a US state (CA = California); use {"country":"CA"} or "Canada" for Canada.

## `data_types` (type: `array`):

Personal data exposed, for example \["ssn","drivers_license","payment_card"]. If left out every law is treated as triggered (SAFE).

## `encrypted` (type: `boolean`):

True only if all the exposed data was encrypted and the key was not exposed. Many US state laws then need no notice. Default false.

## `date_discovered` (type: `string`):

Date the breach was discovered (or you became aware of it), YYYY-MM-DD. Defaults to today. Deadlines are counted from it.

## `sec_registrant` (type: `boolean`):

True for a company that files reports with the US SEC (listed in the US). Adds Form 8-K Item 1.05.

## `materiality_date` (type: `string`):

SEC registrants: date the company decided the incident is material, YYYY-MM-DD. The 8-K is due 4 business days after it.

## `sector` (type: `array`):

Sector rules that apply: hipaa_covered_entity, hipaa_business_associate, glba_financial (non-bank financial firms under the FTC Safeguards Rule), health_app (FTC Health Breach Notification Rule), nydfs_licensee (New York DFS regulated).

## `role` (type: `string`):

owner (default): the company that owns or licenses the data. service_provider: holds it for another company, which mostly means notifying that company quickly.

## `lookups` (type: `array`):

Optional list of lookups for the check mode, up to 1,000 per run, each charged as one lookup. Each item uses the same field names as above, for example {"affected": \[{"state": "CA", "count": 1200}, {"state": "TX", "count": 300}, {"country": "Germany", "count": 40}, {"country": "United Kingdom", "count": 15}], "data_types": \["ssn", "drivers_license"], "date_discovered": "2026-10-05", "sec_registrant": true, "materiality_date": "2026-10-07"}.

## `state` (type: `string`):

Used by the 'List breach laws' mode. Optional US state code or name.

## `country` (type: `string`):

Used by the 'List breach laws' mode. Optional country code or name, for example "GB", "Germany", "Canada".

## `scope` (type: `string`):

Used by the 'List breach laws' mode. Optional: us_state, us_federal_sector, country or region.

## Actor input object example

```json
{
  "mode": "check",
  "affected": [
    {
      "state": "CA",
      "count": 1200
    },
    {
      "state": "TX",
      "count": 300
    },
    {
      "country": "Germany",
      "count": 40
    },
    {
      "country": "United Kingdom",
      "count": 15
    }
  ],
  "data_types": [
    "ssn",
    "drivers_license"
  ],
  "date_discovered": "2026-10-05",
  "sec_registrant": true,
  "materiality_date": "2026-10-07"
}
```

# Actor output Schema

## `results` (type: `string`):

One row per lookup (or per rule in a listing mode), with the official source for each answer.

## `summary` (type: `string`):

Lookups asked, answered and failed, and the free MCP server URL.

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "affected": [
        {
            "state": "CA",
            "count": 1200
        },
        {
            "state": "TX",
            "count": 300
        },
        {
            "country": "Germany",
            "count": 40
        },
        {
            "country": "United Kingdom",
            "count": 15
        }
    ],
    "data_types": [
        "ssn",
        "drivers_license"
    ],
    "date_discovered": "2026-10-05",
    "sec_registrant": true,
    "materiality_date": "2026-10-07"
};

// Run the Actor and wait for it to finish
const run = await client.actor("nerolabs/breach-notification-deadlines").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {
    "affected": [
        {
            "state": "CA",
            "count": 1200,
        },
        {
            "state": "TX",
            "count": 300,
        },
        {
            "country": "Germany",
            "count": 40,
        },
        {
            "country": "United Kingdom",
            "count": 15,
        },
    ],
    "data_types": [
        "ssn",
        "drivers_license",
    ],
    "date_discovered": "2026-10-05",
    "sec_registrant": True,
    "materiality_date": "2026-10-07",
}

# Run the Actor and wait for it to finish
run = client.actor("nerolabs/breach-notification-deadlines").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "affected": [
    {
      "state": "CA",
      "count": 1200
    },
    {
      "state": "TX",
      "count": 300
    },
    {
      "country": "Germany",
      "count": 40
    },
    {
      "country": "United Kingdom",
      "count": 15
    }
  ],
  "data_types": [
    "ssn",
    "drivers_license"
  ],
  "date_discovered": "2026-10-05",
  "sec_registrant": true,
  "materiality_date": "2026-10-07"
}' |
apify call nerolabs/breach-notification-deadlines --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,nerolabs/breach-notification-deadlines"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/HLijoDxfbyO4fIEMf/builds/RIKLub4z7QTVWVgG5/openapi.json
