Breach Deadline Calculator
Answer a few questions to see each breach notice deadline this calculator counts, as a date.
What kind of firm are you?
Deadlines count from this day, not the day of the breach.
How the clocks count
- Calendar daysEvery day counts, weekends and holidays included.
- Business dayA weekday that is not a federal holiday.
- Clock hoursElapsed time.
- The IRS report counts from confirmation of the incident, which can come after the day your firm found out.
Know the day of the breach? Optional
Optional. No clock on this page runs from it.
Each state’s law protects its own residents. Add your firm’s own state too: some states also cover a firm based there.
Which federal rules reach your firm?
Leave blank to count from the day your firm found out.
Only this 72-hour clock uses the time.
How the dates are counted
Each rule, what starts it and its exceptions are set out in the breach clocks reference table.
- Every clock starts when someone finds out, not at the breach. The FTC counts from discovery, the SEC rules from becoming aware, and the IRS from confirmation of the incident. Each state row names its statute’s own trigger; where that is a later event, such as the firm’s determination that a breach occurred, the date shown is the earlier, cautious one.
- Days are calendar days. Day 1 is the day after the clock starts. The FTC, SEC and state rules say days unless a row says business days, and none of them moves a deadline off a weekend or a holiday, so this calculator does not either.
- The IRS standard is the one business-day clock. The deadline is the next weekday after confirmation that is not a federal holiday.
- The 72-hour clock is elapsed time. It runs from the moment the provider became aware, in your browser’s time zone.
- Every date is the latest the rule allows. Each rule asks for notice as soon as possible, or as soon as practicable, first.
Questions about breach notification deadlines
Does the breach notification clock start on the day of the breach or the day it is discovered?+
None of the federal clocks starts on the day of the breach. The FTC clock starts on discovery: the first day any employee, officer or other agent, other than the person committing the breach, knows of it. The SEC Regulation S-P clocks start when the firm or its service provider becomes aware. The IRS reporting standard runs from confirmation of the incident, which can come after discovery. Most state statutes run from discovery or notification of the breach, or from the firm’s determination that one occurred; each state row names its own trigger. This calculator counts every dated clock from the day your firm found out, so where a statute runs from a later event, the date shown is the earlier, cautious one.
Are breach notification deadlines counted in calendar days or business days?+
The FTC and SEC Regulation S-P rules count days, and the SEC service-provider rule counts hours. The state statutes this calculator carries count days too, except where a row says business days, as Vermont’s notice to its Attorney General does. None of them moves a deadline that lands on a weekend or a holiday, so this calculator never moves one. The IRS reporting standard is the exception: Publication 1345 says to report as soon as possible, and no later than the next business day after confirmation of the incident.
How is the 30-day FTC deadline counted?+
Day 1 is the day after discovery, so an event discovered on March 1 must be reported to the FTC by March 31. The notice is due as soon as possible, and 30 days is the outer limit. It applies only when the notification event involves the information of at least 500 consumers (16 CFR 314.4(j)(1)).
Which breach notification rules apply to accountants, law firms and financial advisors?+
It depends on what the firm does, who regulates it, and where the affected people live. The FTC Safeguards Rule covers an accountant or other tax preparation service in the business of completing income tax returns (16 CFR 314.2(h)(2)(viii)). It also names “investment advisors that are not required to register with the Securities and Exchange Commission” (16 CFR 314.1(b)). SEC Regulation S-P covers investment advisers registered with the SEC (17 CFR 248.1(b)), and its breach notice rule applies to them as covered institutions (17 CFR 248.30(d)(3)). For lawyers, a federal appeals court held in ABA v. FTC (D.C. Cir. 2005) that the FTC’s attempt to regulate the practice of law under the Gramm-Leach-Bliley Act’s privacy provisions fell outside its statutory authority. The case did not address the Safeguards Rule by name. The IRS reporting standard in Publication 1345 applies to Authorized IRS e-file Providers of individual income tax returns. Wisconsin’s statute turns on where a firm does business and whose personal information it holds, not on its profession (Wis. Stat. 134.98(1)(a), (2)). Whether a rule reaches your firm is a question for your counsel.
Which state’s breach notification law applies to my firm?+
Each state’s statute protects its own residents, so a breach that reaches clients in three states can run three state clocks. Some statutes also reach a firm based in the state: Wisconsin’s covers a firm with its principal place of business there for every person affected. A few bind only certain businesses; Georgia’s reaches information brokers and state agencies. Add every state where affected people live, and your own. Whether a statute reaches your firm is a question for your counsel.
How many days do states give a firm to notify affected residents?+
Of the 50 jurisdictions this calculator carries, 22 set a fixed outer limit to notify affected residents: 30 days in California, Colorado, Florida, Maine, New York and Washington; 45 days in Alabama, Arizona, Indiana, Maryland, New Mexico, Ohio, Oregon, Rhode Island, Tennessee, Vermont and Wisconsin; 60 days in Connecticut, Delaware, Louisiana, South Dakota and Texas. The rest require notice without unreasonable delay and set no number of days. The calculator carries no figure Claremont has verified for Nevada.
Why does the calculator ask for a time as well as a date?+
Only for the SEC service-provider clock, and only once that rule is on. It runs 72 hours from the moment the provider becomes aware of the breach, so the deadline has a time of day. The calculator counts elapsed hours in your browser’s time zone, and says so if a daylight saving change falls inside the 72 hours.
Does Wisconsin’s breach notification law apply to a CPA firm?+
It may not. Wis. Stat. 134.98(3m) says the section does not apply to an entity that is subject to, and in compliance with, the privacy and security requirements of the Gramm-Leach-Bliley Act (15 USC 6801 to 6827), if it has a policy concerning breaches of information security in effect. Whether your firm meets that test is a question for your counsel. Where the section applies, notice is due within a reasonable time, not to exceed 45 days after the firm learns of the acquisition.
Is anything I enter sent anywhere?+
No. The dates are worked out in your browser and nothing you enter is transmitted. The calendar file and the copied schedule are built on your device.
General reference, not legal or tax advice. The FTC and SEC rules were read against the Code of Federal Regulations, each state against its own breach statute, the IRS standard against Publication 1345 (Rev. 10-2024), and ABA v. FTC against the D.C. Circuit’s slip opinion. The IRS has since issued a later revision of Publication 1345; check the reporting standard against it. Claremont Security does not perform audits, issue certifications, or attest to any examination.
