DxtraBETA
Back to blog
GuidesSmall Business August 2026 7 min read

A customer email lands in the wrong inbox: your first 72 hours, hour by hour

Most small-business data breaches aren't hackers — they're a newsletter sent with every address visible, a laptop on a train, a spreadsheet shared with the wrong person. Here's what to do in the first 72 hours, hour by hour.

A laptop showing a newsletter's To: field crowded with visible email address chips, beside a clock and a handwritten incident log on a warm desk.

It's 4:50pm on a Friday. You've just sent your monthly newsletter — 1,800 customers, a new product line, a discount code. Then the first reply arrives: "You've put everyone's email address in the To: field."

No hacker. No ransomware. No hooded figure in a stock photo. Just a tired thumb and the wrong send button — and now 1,800 people can see each other's addresses, and a handful of them are asking what you're going to do about it.

This is what most small-business data breaches actually look like. A misdirected email. A laptop left on a train. A former staff member whose login still works. A supplier who got phished. And the difference between a bad afternoon and a genuinely damaging month is almost entirely decided in the first 72 hours — which happens to be exactly the deadline the strictest regulators give you.

Here's the clock, hour by hour.

First: is this actually a breach?

A personal data breach isn't only data being stolen. Under the GDPR and most modern privacy laws it's any incident where personal data is accidentally or unlawfully destroyed, lost, altered, disclosed, or accessed. Three flavours:

  • Confidentiality — someone saw data they shouldn't (the newsletter To: field, the misdirected invoice).
  • Integrity — data was altered without authorisation.
  • Availability — data was lost or made inaccessible (the stolen laptop with the only copy, the ransomware-locked drive).

If personal data was involved and one of those happened, treat it as a breach and start the clock. You can always stand down later; you can't get the hours back.

Hour 0–1: stop the bleeding, start the log

Two jobs, in parallel.

Contain. Whatever is still leaking, stop it. Revoke the sharing link. Disable the compromised account and reset its password. Remotely lock or wipe the lost device. If a supplier's system is the source, tell them now — not after you've finished investigating.

Start a written log. Open a document and note the time you found out, how you found out, and every action you take from here with a timestamp. This log is the single most valuable thing you'll produce all weekend. Regulators are consistently harder on businesses that can't show what they did and when than on businesses that simply had an incident.

One thing not to do in hour one: don't email all your customers yet. A premature, vague announcement ("we may have had an incident, details to follow") creates panic without giving anyone anything to act on. Notification comes — but it comes after assessment.

Hour 1–12: work out what actually happened

Now the questions that determine everything downstream:

  • What data? Email addresses only? Names and orders? Payment details, passwords, ID documents, health information? The sensitivity of the data drives the risk assessment.
  • Whose data, and how many? Customers, staff, suppliers? Ten people or ten thousand? Which countries are they in? (This decides which regulators and which deadlines apply.)
  • How did it happen, and is it still happening?
  • Was the data protected? A lost laptop with full-disk encryption and a strong password is a very different incident from an unencrypted one.

This is where businesses with their records in order pull ahead. If you already have a record of processing activities — what data you hold, where it lives, which systems and vendors touch it — scoping takes an hour. If you don't, this step burns your whole weekend, and you'll be guessing in your regulator notification.

Hour 12–24: assess the risk, decide who must be told

Notification is not automatic. The test, in most regimes, is risk to the people affected.

  • No real risk? (Encrypted laptop, strong key, remotely wiped.) You may not need to notify anyone — but you must still record the breach and your reasoning internally. Under the GDPR this internal register is itself a legal requirement.
  • A risk? Notify your regulator.
  • A high risk? (Passwords, financial data, sensitive categories, fraud potential.) Notify the affected people too.

Be honest in this assessment, and write it down. "We decided not to notify, and here is our reasoning, recorded at the time" is a defensible position. Silence with no record is not.

Hour 24–72: the regulator clock

If notification is required, the deadlines are tight and they vary by regime. The headline numbers:

  • EU (GDPR) and UK (UK GDPR): without undue delay and within 72 hours of becoming aware, to your supervisory authority (the ICO in the UK). If you miss 72 hours, you must explain the delay.
  • Singapore (PDPA): assess quickly; once a breach is notifiable, inform the PDPC within 3 calendar days.
  • Malaysia (PDPA): under the 2024 Amendment Act, in force since 1 June 2025, a breach that risks significant harm (or hits significant scale) must be notified to the Commissioner as soon as practicable — and no later than 72 hours — with affected individuals told within 7 days of that notification where the harm threshold is met.
  • Australia (Notifiable Data Breaches scheme): notify the OAIC and affected individuals as soon as practicable once you have reasonable grounds; assessments themselves are expected within 30 days.
  • United States: no single federal clock — state laws set the pace, and sector rules (health, finance) can be far stricter. "Without unreasonable delay" is the common thread.

Two practical notes. You notify where your affected people are, not just where you are — the Melbourne store selling to EU customers may owe the ICO's European counterparts a notification too. And partial notification is allowed almost everywhere: if you don't have all the answers at hour 60, notify with what you know and supplement later. Waiting for perfect information past the deadline is the worse mistake.

Telling your customers like a human

If you do have to notify the people affected, remember they will judge you on this email more than on the breach itself. The pattern that works:

  • Say what happened, plainly. "On Friday we sent an email that made recipients' addresses visible to each other."
  • Say what it means for them. What data, what someone could do with it, what to watch for.
  • Say what you've done and what they should do. Password reset, watch for phishing, here's who to contact.
  • Don't minimise, don't grovel, don't bury it in legalese.

Publishing the same information on your public privacy page — so people who hear second-hand can check the facts — does more for trust than any apology paragraph.

After the dust settles

The week after, while it's fresh: fix the root cause, not just the symptom (the newsletter tool gets a proper mailing-list mode; the offboarding checklist gets a "revoke access" line). Review the vendor if one was involved. Update your breach log with the closure. And keep the register — a documented history of small incidents handled well is evidence of a functioning privacy operation, not a rap sheet.

The part nobody does in advance

Everything above is ten times easier if two things exist before the bad Friday: a current record of what data you hold and where, and a written who-does-what for incidents — even if "who" is just you and your co-founder.

This is unglamorous work, which is why Dxtra automates it. The platform maintains your processing activity log and data mapping continuously, manages your vendors and processors, and its breach & incident reporting workflows walk you through exactly the sequence in this article — containment log, risk assessment, regulator deadlines by region, and customer notification — instead of leaving you to reconstruct it from a blog post at 5pm on a Friday. Your Transparency Center gives you the public page for honest customer communication when it matters. Plans start at $10/month, with a 14-day money-back guarantee on the START plan.

If you'd like to know how exposed you are before an incident finds out for you, the free privacy scan reads your site the way a regulator would and returns a risk band with cited findings — including where your data-handling evidence has gaps. No website? The 30-second quiz covers you too.

Sources

Current as of 5 August 2026. Deadlines, thresholds and guidance move; check the linked source before you rely on any of them.

This article is general information, not legal advice. Notification duties vary by jurisdiction and circumstance; confirm anything that matters with your regulator — the ICO, PDPC, OAIC, or your national authority — or a qualified adviser before you rely on it. For a live incident, get advice now, not after the deadline.

Ready to be the business with the log?

Nobody plans to have a breach. The good ones plan for the 72 hours after. Get started with Dxtra from $10/month, or take the product tour to see the breach and incident workflows.

Ready to get compliant?

Start your privacy program today — from $10/month.