The forensic picture is incomplete — how do you decide a personal-data breach notification duty has arisen?
answer
- enough, not everything
- three findings gate it
- scope and cause do not
- should-have-known counts
- parallel workstreams, dated memo
basics
~10 sDecide on a reasonable degree of certainty that personal data was compromised, not on a finished investigation. Establish that promptly and record it: facts you should have established count as facts you had.
solid answer
~50 sThe standard is not certainty and it is not a finished report — it is a reasonable degree of confidence that a security incident involved personal data and that access is established or cannot be excluded. Three findings get you there: that an incident occurred, that personal data was within its reach, and that retrieval is proven or unprovable. None of those requires knowing the full scope, the root cause or the actor. The investigative duty runs alongside: you are expected to establish those facts promptly, so deliberately slow-walking the analysis does not hold the clock, because awareness can be judged from when you reasonably should have known. Record the determination as a dated memo — what was known, what was not, what would change the answer — and start the notification workstream in parallel with the investigation rather than after it.
go deeper
Be ready to say that the trigger is a reasonable degree of certainty that personal data was compromised, not a completed investigation, and that scope and root cause are refinements rather than preconditions.
Explain the three findings that gate the determination and why an unanswerable retrieval question counts toward it rather than against it. Know that the investigation itself is expected to be prompt.
Show that you run the notification workstream in parallel, that you produce a dated determination memo separating known from unknown, and that you can push back on a delay whose only effect is to move the paper record of awareness.
Own the standing rule for the organisation: who makes this call, what standard they apply, and how the business is prevented from converting an uncomfortable determination into an open-ended investigation.
## The question is when you know enough, not when you know everything The single most common mistake in this decision is waiting for the forensic report. A determination that a notification duty has arisen is not the conclusion of an investigation; it is a judgement made partway through one, on the facts then available, and it is expected to be made quickly. Three findings are usually sufficient, and none of them requires a complete picture: 1. **A security incident occurred** — a control failed, an account behaved in a way the organisation did not authorise, data moved somewhere it should not have. 2. **Personal data was within its reach** — the objects, the store or the mailbox involved held personal data. You establish this from the data, not from an assumption about the system. 3. **Access is established or cannot be excluded** — either you hold a retrieval record, or you have exposure with no trustworthy read-level telemetry across the window. What you explicitly do **not** need: the number of affected individuals, the root cause, the identity or motive of the actor, confirmation that the data has been misused, or the completion of eradication. Each of those refines the notification; none of them gates the determination. ## The clock and the investigation run together, not in sequence Regimes differ on what they call the trigger, but they share a structure: a period during which you are expected to investigate with reasonable speed, and a point of awareness after which a deadline runs. The consequence that matters operationally is that **not investigating is not a way to stay unaware**. If a reasonable responder with your telemetry would have reached the determination a week earlier, that week is not free. This is why a case with a two-day pause waiting for outside forensics to be retained is dangerous — the pause is visible in your own ticket history, and it is exactly what a regulator asks about. The practical implication is to run two workstreams in parallel from the moment the incident looks like it touches personal data: the forensic thread, and a notification-readiness thread that assembles the draft, identifies the recipients, and prepares the scope statement. If the determination lands, you are hours from filing rather than days. If it does not, you have lost a modest amount of effort and gained a documented decision record. ## Make the determination an artefact The determination should exist as a short, dated, named-owner memo, written at the time and never backdated. It records: - the facts relied on, each tied to its source; - the material facts still unknown, and why — telemetry absent, retention exceeded, analysis in progress; - the conclusion reached and the standard applied; - what new fact would change the conclusion in either direction; - who made the call, and who was in the room. That last clause matters because the decision is rarely made by the responder alone: privacy, legal and the business are in it. The memo protects everyone by distinguishing *what was known* from *what was later learned*, which is precisely the distinction a later correction depends on. ## The pressures you will feel, and how to hold the line - **Wait until we are sure.** Certainty is not the standard, and it usually arrives after the deadline. The counter is to name the standard out loud and show that the three findings are already met. - **We have no evidence of access.** Test whether that means *we looked with adequate telemetry and found nothing* or *we had nothing to look at*. Only the first is a finding. The second is the cannot-exclude case, and stating it as the first is the sentence that later reads as misleading. - **Reporting an incomplete picture will look bad.** A prompt notification saying `this is what we know as of today, the review continues` is a normal filing. A late one accompanied by a complete picture invites the question of when you first knew. - **Do not write that down.** Contemporaneous factual records are the basis of every defensible determination. How legal advice is handled is a matter for counsel; the facts, their sources and their timestamps still have to be captured while they are recoverable. ## When the answer is genuinely unknown at the deadline Sometimes the deadline arrives with the retrieval question still open — for instance, a slow transfer to a destination you cannot reach, where retention no longer covers the first half of the window. The answer is to notify on the incomplete picture and say so precisely: the categories of data involved, the scope identified to date and the method by which it was identified, the part of the window your telemetry no longer covers, and the commitment to supplement. Silence is not a neutral option, and a determination deferred because the picture was untidy is the one you will have to defend hardest. ## What good looks like A candidate who answers this well says the standard out loud, separates the three findings from the many facts that do not gate the decision, insists that the investigation and the notification workstream run in parallel, and treats the memo as a deliverable of the incident rather than paperwork after it.
- Counsel proposes pausing analysis until an outside forensics firm is retained next week. What do you say?That the pause does not stop the clock. Awareness can be judged from when a reasonable responder with our telemetry should have known, so a documented week of deliberate inactivity is the worst possible artefact. I would keep the internal thread running on preservation and the three determination findings, scope the outside firm to the deeper analysis, and make sure the delay is a resourcing fact rather than a decision to look away.
- Does the count of affected individuals gate the determination?No. The count refines the notification, it does not trigger it. You need an incident, personal data within its reach, and access that is established or cannot be excluded. Waiting on a final count is one of the most common reasons a filing goes late, and the fix is to notify with the figure identified to date plus the method used to identify it.
- What is the difference between no evidence of access and access cannot be excluded?The first claims a search was conducted with telemetry capable of showing retrieval and it found none. The second admits the telemetry to answer the question does not exist or does not cover the window. They read similarly and mean opposite things, and using the first when you mean the second is what turns a later scope increase into an accusation of misleading the regulator.
saying these in an interview costs you the question
- Waits for the final forensic report before determining
- Says the clock starts only when scope is fully counted
- Believes delaying the investigation delays awareness
- Runs notification only after the investigation closes
- Leaves the determination undocumented and undated