On 16 September 2026, the Data team hosted a breakfast briefing on cross-border personal data breach response, bringing together our experts to share practical lessons from live, multi-jurisdictional incidents.
The session was chaired by Aselle Ibraimova, with a panel comprising Jon Baines, Louise Schofield, and Paolo Sbuttoni. The panel worked through a hypothetical scenario: a personal data breach affecting individuals across multiple jurisdictions (including APAC countries), involving a security incident, a threat actor, third-party service providers, and information about the breach already circulating publicly. This allowed attendees to test how response strategy, notification obligations and personal liability play out in practice when a breach crosses borders and the clock is already running.
Topics for discussion
- The critical first moves: appointing a point of contact in each affected jurisdiction, and the cost of getting this wrong early in an incident.
- The senior risk: personal exposure for directors and officers arising from late or non-reporting, including custodial risk in certain jurisdictions.
- Reputational risk beyond customer service: why regulatory notifications can become public, and how to manage that risk before filing.
- The regulators behind the curtain: how regulatory process, expectations and tone differ across jurisdictions, and how to tailor a single response strategy accordingly.
- The invisible actors: how response and notification strategy differs depending on whether the cause of a breach is known internally or attributable to a malicious actor.
Five key takeaways
Preparation happens long before the incident, not during it
The single thread running through the session was that the decisions that matter most are made in advance: who sits on the response team (Legal, IT/security, PR/communications and HR), who the local counsel contacts are in each jurisdiction, what the global communications script says, and whether directors and officers understand the personal exposure they may be carrying. A live incident is the wrong moment to be working out who is authorised to shut down systems or what "reportable" means in a given market. Organisations that run tabletop exercises and simulations in advance make calmer, better decisions when the real call comes in.
"Asia" is not a jurisdiction, and GDPR alignment does not equal global compliance
Even within a small cluster of Asian markets, breach notification regimes diverge sharply: some operate purely voluntary notification, others impose mandatory notification once defined thresholds of harm or affected individuals are met, and at least one market (South Korea) has recently moved to a notification trigger based on the mere possibility of a breach, rather than a confirmed one. A global programme built around a GDPR-style 72-hour notification standard can still fall short of local requirements, particularly where data protection officer appointment rules are tightening and increasingly demand a named, locally resident, language-proficient individual rather than a general compliance contact.
Personal liability for directors and officers varies significantly by market
In several jurisdictions, criminal offences and custodial risk can attach to directors or officers personally for data protection failures, not only to the company. Once personal exposure is on the table, the calculus for decision-makers shifts from reputational management to individual protection, creating the potential for tension between legal, the board and local management. Directors and officers should map, before an incident occurs, which jurisdictions in their footprint carry this kind of personal officer liability.
A regulatory notification can itself become public, so draft accordingly
Notifications made in confidence do not necessarily stay confidential: some regulators proactively publish enforcement and notification-related information, and in certain jurisdictions notifications can become subject to freedom of information requests. The practical guidance from the panel was to draft every regulatory notification as if it could be read by a journalist or a claimant's lawyer, and to prepare a single, consistent global communications script in advance so that internal and external messaging does not diverge under pressure.
Regulators differ in process, tone and expectations, so build one narrative and tailor it locally
Unless the concept of the main establishment applies to your organisation, where you only notify where your main administrative office is, a notifiable personal data breach must be notified in each country in the EU under the GDPR. Even within a single country, notifications to multiple regulators may be required where a country is a federation of multiple states (e.g. Germany, Canada), and notification forms and language requirements vary by regulator. Rather than chasing every regulator's bespoke form during a live incident, the more workable approach is to build one clear, consistent global narrative and adapt it for each local regulator, while remaining alert to the markets where strict local compliance carries the greatest enforcement and personal liability risk.
Mishcon de Reya can help
If you would like to discuss how these issues apply to your organisation's own cross-border footprint, please get in touch with Aselle Ibraimova or Paolo Sbuttoni. We run regular horizon-scanning reports for clients covering data protection and breach reporting obligations worldwide. Please enquire and we can adjust the format to suit your organisation.