Regulations › US states

State breach laws

US state data breach notification laws

In force breach notification
WhenIn force in all 50 states, the District of Columbia, Puerto Rico, Guam and the US Virgin Islands. Definitions, deadlines and regulator notices differ.
Who enforces itState Attorneys General
Who it applies toAny organization holding personal information of residents of the state.

Every state requires notice to affected residents after a breach of personal information. Deadlines, regulator notices and what counts as personal information differ, so a multi-state breach means applying several laws at once.

The law in brief

Every US state, the District of Columbia, Puerto Rico, Guam and the US Virgin Islands has a law requiring organizations to notify people when their personal information is compromised. There is no single federal breach law for most businesses, so a breach affecting people in many states means applying many laws at once.

The laws share a common shape: a definition of personal information, a definition of breach, a duty to notify affected residents, and often a duty to tell the state regulator. They differ in the details that decide your timeline, and those details are where multi-state responses go wrong.

Who it applies to

  • Any organization that owns, licenses or maintains personal information about residents of the state, wherever the organization is located. The residence of the affected person decides which law applies, not where you are.
  • Personal information is typically a first name or initial and last name combined with a Social Security number, a driver's license or state ID number, or a financial account or card number with the code needed to use it. Many states add biometric data, health or medical information, health insurance numbers, passport numbers, and online account credentials (a username or email with its password).
  • A breach is usually unauthorized acquisition of unencrypted personal information. Some states, such as New York, also count unauthorized access.
  • Vendors that hold data for another organization must generally notify that organization, which then notifies the affected people.

The resident's state decides

Each affected person's state of residence determines which law applies to their notice. One incident can trigger dozens of laws with different deadlines.

What it requires

Notify affected residents

Notify residents whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person, in the most expedient time possible. Many states set a fixed outer limit, commonly 30, 45 or 60 days.

Tell the regulator

Many states require notice to the attorney general or another state agency, often when a breach affects more than a set number of residents, such as 500 or 1,000, and sometimes before or with the resident notice.

Tell the credit bureaus for large breaches

Many states require notice to the nationwide consumer reporting agencies when more than a set number of residents, often 1,000, are notified.

Include the required content

Notices must carry the content each state requires, commonly a description of the incident, the types of information involved, contact details, and steps residents can take. Some states prescribe headings or format.

Vendors tell the data owner

An organization that maintains data it does not own must notify the owner or licensee promptly after discovering a breach.

People's rights

Affected residents are entitled to a notice that tells them what happened, what information was involved, what the organization is doing, and what they can do to protect themselves. Some states require an offer of free credit monitoring or identity theft protection when Social Security numbers are involved (for example, Connecticut and Massachusetts). A few states, including California, let individuals sue over breaches caused by a failure to maintain reasonable security.

Enforcement and penalties

Enforced mainly by state attorneys general, usually under the state's consumer protection law, with civil penalties that vary widely by state. Late or incomplete notices are among the most common grounds for settlements. Where a private right of action exists, class actions often follow large breaches.

What's changing

Deadlines keep tightening. States continue to replace "without unreasonable delay" with fixed outer limits and to widen the definition of personal information. New York, for example, set a 30-day limit in 2024. Regulatory Watch reports amendments as states pass them.

What to do first

  1. Keep a state matrix: definition of personal information, deadline, regulator notice and threshold, credit bureau notice, and content rules for every state where you hold resident data.
  2. Know where your data subjects live, so you can tell within days which states' laws apply.
  3. Encrypt personal information at rest and in transit; most states exempt encrypted data when the key was not compromised.
  4. Put breach reporting clauses in vendor contracts with a short deadline to tell you.
  5. Prepare notice templates that meet the strictest content rules, and a process to add state-specific paragraphs.
  6. Rehearse with counsel, including the decision on whether an incident is a notifiable breach.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.

Sources

Primary sources are being added to this entry.