A cloud security team confirms a breach that exposed regulated personal data. What is the primary factor that determines when the relevant data protection regulator must be notified?
- AThe moment the incident response team has fully eradicated the threat and closed the incident
- BThe notification timeframe defined by the applicable law or regulation, measured from awareness of the breach Correct
- CThe next scheduled quarterly compliance review with the internal audit function
- DThe cloud provider's preference for when its customers should contact outside authorities
Why A is wrong: Waiting for full closure is tempting but wrong; many regimes require notification while response is still underway, well before eradication.
Why B is correct: Regulatory notification duties are set by law and run from the point the organisation becomes aware, so the legal timeframe is the controlling factor.
Why C is wrong: Aligning to an internal review cadence sounds orderly but ignores statutory clocks that demand notification within days, not at the next review.
Why D is wrong: A provider may offer support, but a customer's legal notification duty is set by regulation, not by the provider's scheduling preference.