← All posts

Email Breach Notification Requirements: A Practical Walkthrough

September 16, 2026

Who must be told, how quickly, and what the notice has to say — mapped to the decisions you will actually face after a mailbox compromise.

Once counsel decides that a mailbox compromise is notifiable, the work becomes procedural. Here is the shape of it.

General information, not legal advice.

Step 1: define the data set

Search the compromised mailbox and any reachable files for the categories that trigger duties: names with identifiers, Social Security or driver's licence numbers, financial account details, health information, and credentials. In practice this is the longest phase, because mailboxes are unstructured and duplicative. Deduplicating a list of affected individuals across years of attachments is genuinely hard work.

Step 2: map jurisdictions

Obligations follow the affected individuals, so a single mailbox can put you under a dozen state regimes plus sector rules and, if EU or UK data is present, GDPR's 72-hour regulator clock. Contractual deadlines often bind first.

Step 3: watch the clocks

Timelines run from discovery or determination, not from when you finish investigating. HIPAA allows 60 days to individuals. Several states specify 30 to 45 days. GDPR gives 72 hours for regulator notice. Contracts sometimes say 24. Build the calendar on day one.

Step 4: write the notice

Most regimes require a description of the incident, the data involved, the dates, what you are doing about it, what recipients should do, and a contact point. Some require an offer of credit monitoring, and some prescribe format or prohibit certain language. Regulator and, above thresholds, media notice may also apply.

Step 5: document everything

Keep the timeline, the forensic findings, the decision rationale, and copies of every notice sent. If a regulator or plaintiff asks two years from now, the record is your defence.

The lever that matters

Everything above is cheaper when logging existed beforehand. Mailbox audit logging routinely reduces "we must assume all mail was read" to "these 40 messages were accessed" — which is the difference between notifying 12,000 people and notifying 40. That is a configuration decision made months before the incident. Our Microsoft 365 security engagements set it as a baseline.


Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.

breach notificationcomplianceemail breachregulators

24 / 7 Recovery

When the worst day hits, every minute matters.

Our breach team is standing by — call, email, or submit a request and we respond within minutes.