Hacker News new | ask | show | jobs
by spacebanana7 200 days ago
I wonder whether OpenAI could be okay if they themselves weren't notified within 72hrs.
1 comments

Typically: yes. The clock starts ticking the moment you or anybody within your organization becomes aware of the breach. Three days is plenty. It even gives you time to consult your lawyers if you are not sure if a breach is reportable or not, but you could always do a provisional which gives you a way to back out later.