Under the Personal Data Protection Law you have 72 hours to notify SDAIA of a personal data breach, through the National Data Governance Platform. Most security teams know the number. Fewer have tested where the clock actually starts.
Awareness, not confirmation
The 72 hours run from the moment you became aware of the breach. Not from when you finished scoping it. Not from when legal signed off. Not from when the form went in.
That distinction is where most incident timelines quietly fail. Teams treat awareness as the point at which they are confident something happened. A regulator reconstructing the incident will treat it as the first point at which the evidence was in front of you.

The clock that matters is the one your own logs prove, not the one you remember.
The platform records the filing. Your logs record the knowing.
The National Data Governance Platform will timestamp your notification. It does not record when awareness began. That timestamp lives in your own systems:
Source | What it proves | Common gap |
|---|---|---|
SIEM alerts | When the first signal fired | Alert closed as noise, reopened days later |
Ticket queue | When a human picked it up | Ticket opened under the wrong severity |
On-call notes and chat | When someone said "this looks real" | Not retained, or retained outside the evidence set |
Vendor notifications | When a processor told you | Sat unread in a shared inbox |
In plain language
If an auditor lines up your alert logs against your filing time and the gap is more than 72 hours, you notified late, whatever your internal view of when the incident was confirmed.
Test the trail before you need it
Most teams have never run a reconstruction against the 72-hour standard. It is a short exercise and it surfaces the gaps quickly:
Pick a past incident, even a minor one, and rebuild the timeline from the first signal.
Mark the awareness point a reviewer would choose, not the one the team chose.
Measure the gap to when a notification would have been filed.
Fix the hand-offs that ate the time: triage rules, severity definitions, the route to legal and the DPO.
Late is not the only risk
Of the 48 violation decisions SDAIA's committees issued in the year to 16 January 2026, one of the four penalised behaviours was inadequate technical and organisational safeguards. That finding does not need a breach at all. The audit can arrive before the attacker does.
Next step. Our PDPL briefing pack sets out the breach clock, registration, transfers and what SDAIA actually penalised. Download the briefing pack →
For any comments or information please reach out to info@astragar.com







