Security incidents and data breaches: liability, costs and the first 72 hours
A serious incident and a data breach are two different categories. What deadlines actually apply after 3 April 2026, and why is liability now personal?
A serious incident and a data breach are two different categories. What deadlines actually apply after 3 April 2026, and why is liability now personal?
Why 72 hours isn't your first deadline
"We have 72 hours" is a phrase often heard in Polish organisations within the first hour of an incident. It stems from Article 33 of the GDPR and, for years, served as a sufficient shorthand. From 3 April 2026 - that is, from the entry into force of the amendment to the Act on the National Cybersecurity System - this phrase will be incorrect for key and important entities. The first binding deadline is 24 hours; it runs until a report is made to another authority and starts from a different point in time. For management, this is not merely a procedural nuance. Liability for overlooking this difference is now personal and cannot be delegated.
Two incidents, not one
The starting point is a distinction that is absent from most incident response plans. A serious incident within the meaning of the Act on the National Cybersecurity System is an event assessed in terms of its impact on the service provided - its availability, continuity, scale of disruption and geographical scope. It is reported to the relevant sectoral CSIRT. A personal data breach, as defined in Article 4 of the GDPR, is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. It is reported to the President of the Personal Data Protection Office. These categories overlap, but neither encompasses the other. Ransomware on a system containing customer data triggers both regimes. A DDoS attack that takes a service offline without accessing data - Act on the National Cybersecurity System only. An attachment sent to the wrong recipient - GDPR only. Operational implication: classification must proceed on two tracks and in parallel. Organisations that first determine whether "this is a Act on the National Cybersecurity System incident" and only then turn to the question of personal data lose hours they cannot afford to spare. The clocks also start ticking at different times. The Act on the National Cybersecurity System deadline runs from the detection of the incident. The GDPR deadline runs from the determination of the breach, i.e. from the moment the controller has obtained sufficient certainty as to its occurrence. In practice, this means that the Act on the National Cybersecurity System clock starts ticking earlier.
The schedule that actually applies
24 hours from detection - early warning of a serious incident to the relevant CSIRT. The scope is deliberately minimal: the data subject's details, the time of occurrence and detection, and a preliminary indication of whether the incident may have been the result of unlawful activity - "if it is possible to make such an assessment". It is not necessary to know the cause. It must be reported. 72 hours from detection - full report of a serious incident: impact assessment, scale, consequences, and indicators of a breach of integrity. 72 hours from determination and confirmation - notification of a data breach to the Personal Data Protection Office, provided the breach poses a risk to the rights and freedoms of individuals. Without undue delay - notification of data subjects where the risk is high. Separately, with no specified deadline: informing service users if the incident adversely affects the provision of their services. One month from notification (not from detection) - final report. If incident handling is still ongoing, a progress report must be submitted within this timeframe, and the final report within one month of the conclusion of incident handling. Two clarifications. A significant entity that is a public body is not required to issue early warnings or submit reports. Conversely, entities in the banking sector and financial market infrastructure are exempt from the provisions on the Information Security Management System and the reporting of serious incidents - they are subject to the deadlines set out in the DORA Regulation, which are shorter than those in the Act on the National Cybersecurity System. This is not a third clock, but a change of clock.
Responsibility: why this is a matter for the Management, not the IT department
Article 8 of the Act on the National Cybersecurity System imposes an obligation on the head of an entity to approve cybersecurity risk management measures and to oversee their implementation. The head remains liable even if they have delegated these duties to another person with that person's consent. Delegating tasks is permissible; delegating liability is not. There are three levels of penalties: - critical entity - up to EUR 10 million or 2 per cent of annual turnover, whichever is higher; - important entity - up to EUR 7 million or 1.4 per cent of turnover; - a breach causing a direct and serious cyber threat to defence, national security or human life and health - up to PLN 100 million. Irrespective of the penalty imposed on the organisation, the manager is personally liable to a fine of up to 300% of their remuneration, and in public sector organisations, up to 100%. However, for failure to report a data breach or for inadequate data protection, the President of the Personal Data Protection Office may impose a fine of up to EUR 20 million or 4 per cent of turnover. Penalties under both regimes are not cumulative. Article 76c of the Act on the National Cybersecurity System stipulates that if the President of the Personal Data Protection Office has already imposed a final penalty for the same offence, the competent cybersecurity authority shall not initiate proceedings and shall confine itself to issuing a warning. Paragraph 2, however, retains other supervisory measures under Article 53. Thus, it is the duplication of penalties that is excluded, not the duplication of consequences.
Costs - four layers, of which usually only one is visible
Penalties are the layer that receives the most media attention, but are not usually the largest. - Technical response - computer forensics, environment reconstruction, downtime. - Legal and regulatory support - two sets of proceedings, two lines of communication with the authorities, requests from data subjects. - Obligations towards individuals - notifications and claims under Article 82 of the GDPR, including for non-pecuniary damage. - Indirect costs - contractual penalties under SLAs and loss of contracts, as NIS2 requires to assess suppliers' risks. An incident at your organisation becomes an entry in the client's risk register. A separate cost arises from a lack of knowledge about one's own data. A notification requires specifying the scope of the breach. An organisation without an up-to-date inventory and map of personal data determines this under time pressure - and either overestimates it (triggering notifications more widely than necessary) or underestimates it (risking an allegation of an inaccurate notification).
The first 72 hours in practice
0-2 hours - two-track classification and initiation of time recording. The time of detection and the time of confirmation must be documented, as the time limits are calculated from these points. 2-24 hours - early warning to the CSIRT. In parallel: isolation, securing evidence, and determining which systems and data sets are affected by the incident. 24-72 hours - determining the scope and assessing the risk to the data subject's rights and freedoms. This is the stage at which organisations often miss the deadline - not due to a lack of procedures, but due to a lack of knowledge regarding where personal data is located within their systems. Notification to the CSIRT and, if the conditions are met, to the Personal Data Protection Office. After 72 hours - notifying individuals (Article 34 of the GDPR), providing information to service users, and submitting a final report within one month of the notification.
What really determines the outcome
None of these steps can be expedited whilst the incident is ongoing. Three pre-prepared elements are decisive: an up-to-date map of personal data within the systems, an enforced retention policy limiting the scope of a potential breach, and a rehearsed scenario for two-tier classification and effective incident management. The first of these is both the most difficult to reproduce under pressure and the easiest to establish. Systematic detection and classification of data - including sensitive data - in databases and file repositories transforms the most time-consuming stage of breach management into a simple query of an existing register.