Two clocks run on every personal data breach, and privacy teams have spent years drilling the wrong one.
The first clock is familiar. The GDPR gives you 72 hours from becoming aware of a breach to notifying the regulator, and mature programmes rehearse that process until they can run it under pressure. The second clock starts much earlier. It begins when the breach starts and stops when somebody notices, and it is the clock that determines how much data leaves, how many people are affected and how hard the recovery becomes. IBM's 2025 Cost of a Data Breach research puts the mean breach lifecycle at 241 days to identify and contain, with identification alone still running roughly six months.
Many organisations can explain exactly what they would do in the first 72 hours after discovering a breach.
Far fewer can explain how they would discover the breach in the first place.
The pressure is rising on both
DLA Piper's January 2026 GDPR survey counted breach notifications across Europe at an average of 443 per day, up 22% in a year and the first time the daily average has passed 400 since GDPR began. Cumulative fines have passed €7.1 billion, and more than 60% of that total was imposed since January 2023.
To be fair, detection is improving. IBM's 241-day lifecycle is the lowest recorded in nine years, driven largely by advances in AI-assisted security operations. But those advances focus on intrusion detection rather than privacy behaviour. And a clock that has improved to six months still runs some sixty times slower than the 72-hour clock everyone rehearses.
The data leaves during the quiet months. The notification window documents the harm.
Why detection belongs to nobody
The reason is organisational. Security teams monitor for intrusions and malware; their tools are designed to identify attacks. Privacy teams manage obligations, processing records and assessments; their tools are designed to demonstrate accountability. Neither function was built to watch how personal data behaves once it is inside the organisation, so privacy incidents fall into the gap between the two.
A supplier accesses more customer records than expected. A dormant account begins downloading personal data. An application starts exporting information to a destination with no business purpose. None of these necessarily look like a cyber attack. All of them can become a privacy incident.
The obligation belongs to privacy. The monitoring, often, belongs to nobody.
Managing the clock that matters
Reducing detection time is not primarily a security problem. It is a visibility problem, and the organisations that shorten the clock do three things well:
- They understand normal behaviour. Which systems process personal data, who uses it, at what volumes, for which purposes. Much of this already exists in processing records and assessments.
- They catch unusual behaviour early. Large exports, unexpected access patterns, activity outside approved purposes. These signals appear weeks or months before an incident would be formally reported, and the earlier they surface, the smaller the eventual impact.
- They assign ownership. An anomaly without an owner becomes background noise. An anomaly assigned to a named individual, with context, severity and supporting evidence, becomes an investigation. That distinction matters when the regulator later asks what happened, when it was discovered and what was done.
Every week removed from the detection cycle means fewer affected people, fewer records exposed and a more manageable notification. The organisation is not simply reacting faster. It is reducing the scale of the event itself. One clock determines compliance. The other determines consequence.
The newer reason to build it now
Privacy teams now govern the organisation's use of AI on personal data while adopting AI in their own work. Both jobs depend on the same capability. You need to understand how personal data is being used, detect behaviour outside approved patterns, and hold evidence that withstands regulatory scrutiny. Build the detection instrumentation and many of the capabilities needed for AI governance come with it.
The Prophesee Compliance Suite provides that visibility, with continuous monitoring of personal data activity, anomaly detection, named ownership of every exception and a permanent evidence trail.
Because the most important privacy clock is not the 72 hours after discovery. It is the months before it. Measure your own detection clock.