[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"article-body-72-hours-to-notify-six-months-to-detect":3},"\nTwo clocks run on every personal data breach, and privacy teams\nhave spent years drilling the wrong one.\n\nThe first clock is familiar. The GDPR gives you 72 hours from\nbecoming aware of a breach to notifying the regulator, and mature\nprogrammes rehearse that process until they can run it under\npressure. The second clock starts much earlier. It begins when the\nbreach starts and stops when somebody notices, and it is the clock\nthat determines how much data leaves, how many people are affected\nand how hard the recovery becomes.\n[IBM's 2025 Cost of a Data Breach research](https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai)\nputs the mean breach lifecycle at 241 days to identify and\ncontain, with identification alone still running roughly six\nmonths.\n\nMany organisations can explain exactly what they would do in the\nfirst 72 hours after discovering a breach.\n\nFar fewer can explain how they would discover the breach in the\nfirst place.\n\n## The pressure is rising on both\n\n[DLA Piper's January 2026 GDPR survey](https://www.dlapiper.com/en/insights/publications/2026/01/dla-piper-gdpr-fines-and-data-breach-survey-january-2026)\ncounted breach notifications across Europe at an average of 443\nper day, up 22% in a year and the first time the daily average has\npassed 400 since GDPR began. Cumulative fines have passed €7.1\nbillion, and more than 60% of that total was imposed since January\n2023.\n\nTo be fair, detection is improving. IBM's 241-day lifecycle is the\nlowest recorded in nine years, driven largely by advances in\nAI-assisted security operations. But those advances focus on\nintrusion detection rather than privacy behaviour. And a clock\nthat has improved to six months still runs some sixty times slower\nthan the 72-hour clock everyone rehearses.\n\nThe data leaves during the quiet months. The notification window\ndocuments the harm.\n\n## Why detection belongs to nobody\n\nThe reason is organisational. Security teams monitor for\nintrusions and malware; their tools are designed to identify\nattacks. Privacy teams manage obligations, processing records and\nassessments; their tools are designed to demonstrate\naccountability. Neither function was built to watch how personal\ndata behaves once it is inside the organisation, so privacy\nincidents fall into the gap between the two.\n\nA supplier accesses more customer records than expected. A dormant\naccount begins downloading personal data. An application starts\nexporting information to a destination with no business purpose.\nNone of these necessarily look like a cyber attack. All of them\ncan become a privacy incident.\n\nThe obligation belongs to privacy. The monitoring, often, belongs\nto nobody.\n\n## Managing the clock that matters\n\nReducing detection time is not primarily a security problem. It is\na visibility problem, and the organisations that shorten the clock\ndo three things well:\n\n- **They understand normal behaviour.** Which systems process\n  personal data, who uses it, at what volumes, for which purposes.\n  Much of this already exists in processing records and\n  assessments.\n- **They catch unusual behaviour early.** Large exports,\n  unexpected access patterns, activity outside approved purposes.\n  These signals appear weeks or months before an incident would be\n  formally reported, and the earlier they surface, the smaller the\n  eventual impact.\n- **They assign ownership.** An anomaly without an owner becomes\n  background noise. An anomaly assigned to a named individual,\n  with context, severity and supporting evidence, becomes an\n  investigation. That distinction matters when the regulator later\n  asks what happened, when it was discovered and what was done.\n\nEvery week removed from the detection cycle means fewer affected\npeople, fewer records exposed and a more manageable notification.\nThe organisation is not simply reacting faster. It is reducing the\nscale of the event itself. One clock determines compliance. The\nother determines consequence.\n\n## The newer reason to build it now\n\nPrivacy teams now govern the organisation's use of AI on personal\ndata while adopting AI in their own work. Both jobs depend on the\nsame capability. You need to understand how personal data is being\nused, detect behaviour outside approved patterns, and hold\nevidence that withstands regulatory scrutiny. Build the detection\ninstrumentation and many of the capabilities needed for AI\ngovernance come with it.\n\n[The Prophesee Compliance Suite](/solutions/compliance/privacy)\nprovides that visibility, with continuous monitoring of personal\ndata activity, anomaly detection, named ownership of every\nexception and a permanent evidence trail.\n\nBecause the most important privacy clock is not the 72 hours after\ndiscovery. It is the months before it.\n[Measure your own detection clock](/contact).\n",1786984935415]