Skip to content
All resources

Compliance

You had a breach: what to do (and the 72-hour rule)

Law 7593 requires notifying incidents within 72 hours. How to detect a breach, the response steps, what not to do and how to prevent one.

The 72-hour rule

Paraguay's Law 7593 requires companies to notify the authority of breaches compromising personal data within 72 hours. The clock starts when you find out, not when it happened.

How you detect a breach

Sometimes it's obvious (an encrypted system, a ransom demand). Other times it's subtle: strange logins, data appearing for sale, customers reporting fraud, or a change in your surface you didn't make.

Most companies find out late precisely because no one was watching.

The first steps

  • Contain: isolate the affected system to stop the leak.
  • Document: what happened, what data, since when, who is affected.
  • Notify the authority within 72 hours.
  • Inform affected people where applicable.
  • Preserve the evidence for later analysis.

What NOT to do

Don't delete logs or “turn it off and on” without documenting: you destroy the evidence you need to understand the scope. Don't hide the incident: beyond being illegal, it worsens the reputational damage when it comes out —and it almost always does—.

Communication

Be clear and timely: to the authority, within the deadline; to affected people, with what happened and what to do (e.g., change passwords). Honest, fast communication protects trust; silence destroys it.

Afterwards: learn from the incident

Once the urgency passes, reconstruct how they got in and close that door for good. Most breaches start with something exposed that no one was watching.

How to prevent it

Continuous monitoring of your surface reduces the risk and helps you catch changes in time —before they become an incident—.

Start by seeing what you expose: enter your domain in NEO, free.

See what your company exposes — free

Analyze your domain