[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"article-body-72-hours-to-notify-six-months-to-detect":3},"\nTwo clocks govern every personal data breach, and privacy programmes\nhave overwhelmingly invested in the wrong one.\n\nThe first clock is the famous one, Article 33's 72 hours from\nawareness to regulator notification. It is drilled, templated and\ntabletop-exercised, and mature programmes usually meet it. The\nsecond clock is the one the regulation does not name: the time\nbetween a breach beginning and anyone becoming aware of it. [IBM's\n2025 Cost of a Data Breach research](https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai)\nputs the mean breach lifecycle at 241 days to identify and contain,\nand the identification share of that lifecycle still runs to\nroughly six months. The notification clock is measured in hours and\nmanaged to the minute. The detection clock is measured in months\nand, in most organisations, managed by nobody in particular.\n\n## The asymmetry, in current numbers\n\nThe pressure on both clocks is rising. [DLA Piper's January 2026\nGDPR survey](https://www.dlapiper.com/en/insights/publications/2026/01/dla-piper-gdpr-fines-and-data-breach-survey-january-2026)\ncounted personal data breach notifications across Europe at an\naverage of 443 per day, a 22% jump year on year and the first time\nthe daily average has exceeded 400 since GDPR began. Cumulative\nfines have passed €7.1 billion, with over 60% of that total imposed\nsince January 2023; enforcement is accelerating, not plateauing.\n\nThe honest complication belongs on the table: detection is\nimproving. IBM's 241-day lifecycle is the lowest in nine years, and\nthe report credits AI-powered defence for much of the gain. That\ntrend strengthens the argument rather than weakening it, on two\ncounts. The improvement is concentrated in security tooling, which\nwatches for intrusion; the privacy-specific signals described below\nare not what got faster. And a clock that has improved to six\nmonths is still running some sixty times slower than the 72-hour\nclock everyone drills. For every breach entering the\nwell-rehearsed notification process, months of undetected exposure\npreceded it. The data left during the quiet period. The\nnotification period is where the harm gets documented.\n\n## Why detection stayed unmanaged\n\nDetection fell into the gap between functions. Security teams run\nmonitoring, but tuned to intrusion and malware, not to the\nprivacy-specific questions: personal data moving to an unusual\ndestination, an access pattern inconsistent with a stated purpose,\na processor behaving outside its mandate. Privacy teams own the\nobligation but historically not the instrumentation; their tooling\ngeneration was built for records of processing, consent and\nassessments. Registers, again, rather than sensors.\n\nThe detection problem is, structurally, an anomaly detection and\nexception routing problem over data flows:\n\n- **Baseline the normal.** Which systems access which personal data\n  categories, at what volumes, on which purposes, is learnable from\n  the data the organisation already holds.\n- **Detect the deviation early.** The export that is ten times the\n  usual volume, the dormant account suddenly reading customer\n  records, the processor query outside its contract scope: each is\n  visible weeks or months before an incident report would name it.\n- **Route the exception to an owner.** A privacy anomaly that lands\n  in a shared inbox is a future disclosure. One that arrives with\n  context, severity and a named owner is a contained incident, and\n  the containment evidence is exactly what a regulator asks for\n  when the 72-hour letter is eventually written.\n\n> Every week cut from detection is a week of exposure that never\n> happens, and it compounds: earlier detection means smaller scope,\n> fewer subjects, lower notification burden, and a defensibly\n> shorter breach narrative.\n\n## The privacy function's second AI problem\n\nOne more clock has started recently. Privacy teams are increasingly\nasked to govern the organisation's use of AI on personal data, and\nsimultaneously to adopt AI in their own compliance work. The same\ndiscipline applies in both directions: an AI that touches personal\ndata needs monitored, evidenced behaviour, and a privacy function\nthat uses AI to classify, detect or assess needs to be able to show\na regulator how the conclusion was reached. A function that builds\nthe detection instrumentation above acquires, almost for free, the\nevidence habits the AI era will demand of it.\n\nContinuous anomaly detection over personal data flows, with\nexceptions routed to named owners and the evidence chain kept, is\nwhat the Prophesee Compliance Suite's Privacy module provides. Measure your own\ndetection clock. [Start here](/contact).\n",1786833835742]