GDPR, HIPAA, PCI-DSS, NIS2 and DORA, each with its own trigger, its own requirements and its own clock.
Each of these has its own trigger, and if one applies it applies unambiguously. What it then asks for is written as requirements rather than principles: named authentication controls, named logging intervals, named notification windows.

| Framework | What it asks that the others don't | Notification clock |
|---|---|---|
| GDPR | Rights and disclosure records, with erasure that carries through to processors. | 72 hours to the supervisory authority |
| HIPAA | Unique user identification, automatic logoff, and transmission security. | 60 days from discovery |
| PCI-DSS | Multi-factor authentication on every entry into the cardholder data environment, and logging reviewed daily. | Immediate, under card brand rules and the acquirer contract |
| NIS2 | Access control policy with multi-factor authentication, and supply chain obligations passed down to you. | 24 hours early warning, 72 hours incident notification, one month to the final report |
| DORA | Incident classification, and a four-hour notification clock once an incident is classified as major. | 4 hours from classification as major, 24 hours from becoming aware |
Awareness, discovery, classification. Each of those is a point in time you have to evidence, and the difference between a 24-hour clock and a 72-hour one is academic if you cannot say when it started. DLP timestamps the detection, so that moment is a record rather than a reconstruction.