Definition
When a security breach exposes subscriber personal data — email addresses, names, purchase history, or any other PII — most privacy regulations require timely notification. The specific requirements vary by jurisdiction.
Notification Requirements by Regulation
- GDPR (EU/UK): Notify supervisory authority within 72 hours. Notify affected individuals if the breach poses a high risk to their rights and freedoms.
- CCPA (California): Notify affected residents without unreasonable delay.
- CAN-SPAM (US): No specific breach notification requirement (covered by state laws).
- CASL (Canada): Report breaches to the Office of the Privacy Commissioner and affected individuals.
Best Practices
Have a breach notification plan ready before an incident occurs. The plan should identify who is responsible for notification, template language for informing subscribers, and a timeline for each step. Quick, transparent communication preserves trust even when the breach is not your fault.
Related Glossary Terms
CAN-SPAM Act
The CAN-SPAM Act is a US law that sets rules for commercial email. It requires accurate subject lines, a physical address, a clear opt-out mechanism, and prompt processing of unsubscribes. Violations can result in penalties up to $51,744 per email.
Consent Expiry (Email Marketing)
Consent expiry is the time period after which a subscriber's permission to send marketing emails legally expires and must be re-obtained, varying by jurisdiction and consent type.
Right to Data Portability (GDPR)
The right to data portability allows individuals to obtain and reuse their personal data across different services, including exporting subscriber data from email marketing platforms.
Data Processing Agreement (DPA)
A Data Processing Agreement (DPA) is a legally binding contract between a data controller and a data processor that defines how personal data will be handled, required under GDPR for email service providers.
Data Retention Schedule (Email Marketing)
A data retention schedule defines how long subscriber personal data is stored after unsubscribing or becoming inactive, ensuring compliance with GDPR, CCPA, and similar privacy laws.
Data Subject Access Request (DSAR)
A Data Subject Access Request (DSAR) is a GDPR right allowing individuals to request access to their personal data held by an organisation, including email marketing data.