EU — GDPR (72h)
US — SEC (96h)
US states (720h)
US — HIPAA (1440h)
Drag to pan · scroll to zoom
When a data breach is discovered, the legal exposure that follows is governed less by the attack itself than by the calendar: GDPR gives EU controllers 72 hours to notify a supervisory authority, US public companies face a 4-business-day SEC disclosure clock, most US states expect notice "without unreasonable delay" with a statutory backstop around 30 days, and HIPAA-covered entities have 60 days. This 2D edition renders those four deadlines as concentric top-down countdown rings sweeping around a shared incident core — file each jurisdiction's notification before its ring completes a lap, or watch potential fine exposure accrue live once it does, scaled by how long detection itself was delayed.