Privacy and data protection support
Breach notification matrices
In a breach, the question is who has to be told, by when, and in what words, across every jurisdiction the affected people live in. We build that matrix for the specific incident, so the notification decision is a reading exercise rather than a research project at 2am.
- Published price
- $1,000–4,000 / matrix
- Turnaround
- 48 hours
- Without us
- $8,000–30,000
Fixed per unit, not hourly. No minimum engagement. Quoted before we start.
What you receive
A jurisdiction-by-jurisdiction matrix of notification deadlines and required contents for the incident.
- A jurisdiction-by-jurisdiction matrix covering every state or country in the affected population
- The notification trigger per jurisdiction, applied to the incident's actual facts
- Deadlines computed from each jurisdiction's own trigger event, not from a single assumed date
- Required content per jurisdiction, including prescribed wording where it exists
- Regulator, attorney general and credit agency notification requirements and thresholds
- Exceptions and safe harbours identified, including encryption and risk-of-harm provisions
What it costs, and what it replaces
Both figures are published ranges for the same unit of work. Ours is fixed before we start; if our process gets faster, that is our gain and your price does not move.
How engagements are structured →- Adnah Legal
- $1,000–4,000 / matrix
- Typical cost without us
- $8,000–30,000 / matrix
Roughly 87% lower at the midpoint of each published range.
How the work runs
01
Population mapping
We map the affected population by jurisdiction first, since that determines which regimes apply and in what volume, and thresholds turn on those counts.
02
Trigger analysis
Each jurisdiction's trigger is applied to the actual facts rather than assumed. Definitions of personal information and of a reportable breach vary enough that the answer genuinely differs between neighbouring states.
03
Deadline computation
Deadlines are computed from each jurisdiction's own trigger — discovery, determination, or conclusion of investigation — which is why a single notification date across all of them is usually wrong.
04
Content and delivery
Required content and prescribed wording are set out per jurisdiction, with a consolidated calendar showing what is due when, delivered within 48 hours.
What we need from you
- The incident facts: what data, how many people, and where they are
- The discovery date and the timeline of what was known when
- Whether the data was encrypted and whether the keys were affected
- Any contractual notification obligations to customers or partners
What we check before delivery
- Every jurisdiction's provision is verified at source and its currency checked
- Thresholds are applied against the actual affected counts for that jurisdiction
- Encryption and risk-of-harm safe harbours are assessed against the specific facts, not assumed
- Contractual obligations are reconciled against statutory ones so the earliest deadline governs
When firms send us this
- An active incident where notification decisions are days away
- Tabletop exercises and incident response plan preparation
- Multi-national incidents combining US state laws with other regimes
- Reviewing a notification decision already taken, before a regulator does
Questions about breach notification matrices
How fast can you turn this around during a live incident?
48 hours standard, and faster where the facts are already established. Tell us the clock you are working to and we will confirm honestly whether we can meet it.
Do you decide whether to notify?
No. We set out what each jurisdiction requires on these facts. Whether and how to notify is a legal judgment for the engaging attorney and the client.
Can you cover non-US regimes too?
Yes. Tell us the jurisdictions in the affected population and they go into the same matrix with their own triggers and deadlines.
Firms who send us this usually also send
More in Privacy and data protection support
All privacy and data protection support services →This service
Send one and judge the output.
Breach notification matrices at $1,000–4,000 per matrix, 48 hours. No minimum, no scoping call, no onboarding cycle.