About this tool
Map the review and notification milestones required from the date a breach is discovered.
The Breach Notification Timeline Planner turns a single incident-discovery date into a dated milestone schedule, counting forward in hours from the moment awareness is recorded: containment and evidence preservation at +4 hours, initial scope and risk review at +12, the authority-notification decision at your configured target (72 hours by default), the affected-person decision at yours (96 by default), and a post-incident review at +168 hours, one week out. It is for whoever is running the response and needs the internal clock written down while the incident is still unfolding. Both notification targets are editable so the schedule reflects the regime or internal policy you actually operate under, which you name on the output.
Open Breach Notification Timeline Planner on AltFTool — it loads instantly in your browser.
Add your input to the workspace.
Adjust the options until the result looks right.
Copy or download the output and put it to work.
Everything counts forward from the recorded discovery moment, which is the point every notification regime keys off and the one most often left undocumented.
Containment at +4 hours and an initial scope and risk review at +12 sit ahead of the notification decisions, because you cannot assess notifiability without them.
The authority and affected-person windows are inputs rather than hardcoded, and the jurisdiction or policy you type is carried onto the output so the schedule states which rule it was built against.
Because it is the most widely used window: under the GDPR's Article 33, a controller must notify the supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of a personal data breach. Other regimes use different clocks, so change the field to match the one that governs you.
From awareness — the point at which you have a reasonable degree of certainty a breach has occurred — not from when the incident happened or when it was fully investigated. This planner uses the discovery date you enter as that anchor, which is why documenting when awareness occurred is the first item on its checklist.
Usually only when the breach is likely to result in a high risk to their rights and freedoms, which is why the affected-person decision is a separate, later milestone than the authority one. The assessment itself still has to happen and be recorded even where you conclude notification is not required.
No — it is an internal planning aid that arithmetic alone produces from the hours you enter. It does not encode any statute, does not account for sector rules, multiple jurisdictions, processor-to-controller timelines or regulator guidance, so confirm the current law and take advice from your legal counsel or data protection officer before acting on it.