Breach Notification

State Data Breach Notification Requirements, Compared Across 48 States

Key Takeaways

  • Twenty-one of the 48 states charted set a fixed outer limit for notifying individuals — five at 30 days, eleven at 45 and five at 60. The other 27 use a reasonableness standard with no stated number.
  • Regulator thresholds fall into four patterns: 13 states require notice for every breach regardless of headcount, 20 set a numeric threshold, 13 impose no state-agency notice duty at all, and 2 make it conditional.
  • Where a numeric threshold exists it clusters tightly on three figures — 250 residents in four states, 500 in eight, and 1,000 in eight.
  • Maryland and Massachusetts require regulator notice before individuals are notified, reversing the ordering every other state uses.
  • Alaska inverts the trigger entirely: written notice goes to the Attorney General when a covered person decides not to disclose after concluding harm is not reasonably likely.

Forty-Eight States Charted, and Why Not Fifty

All fifty states have a data breach notification statute. This guide charts forty-eight of them. California and Illinois are omitted from the tables, not because their statutes do not exist — California enacted the first breach notification law in the country and Illinois regulates the question through the Personal Information Protection Act — but because the research behind this site records those two states as curated pages that do not capture their breach deadlines and regulator thresholds against a primary source.

Stating that plainly is the alternative to filling the two rows from memory or from secondary summaries. A chart of this kind is only useful if every cell in it can be traced to the statute it describes, and two acknowledged gaps are less costly to a reader than fifty rows of which two are unsourced.

For the forty-eight that are charted, every cell below is taken from the statute or the regulator publication cited for that state in the source list at the foot of this guide.

The Deadline to Notify Affected Individuals

The single most searched question about these statutes is how long a notifier has, and the answer divides the country almost in half. Twenty-one states state a fixed outer limit in days. The remaining twenty-seven state only a reasonableness standard — some version of "in the most expedient time possible and without unreasonable delay" — with no number attached.

Among the states that do set a number, the clustering is tight. Five set 30 days: Florida, New York, Washington, Colorado and Maine. Eleven set 45: Oregon, Tennessee, Maryland, Indiana, Rhode Island, Alabama, Vermont, Arizona, New Mexico, Ohio and Wisconsin. Five set 60: Texas, Connecticut, Delaware, Louisiana and South Dakota.

StateDeadline to notify affected individuals
AlabamaAs expeditiously as possible and without unreasonable delay, and within 45 days of the determination that a breach occurred and is reasonably likely to cause substantial harm, or of notice from a third-party agent
AlaskaIn the most expeditious time possible and without unreasonable delay, subject to law-enforcement delay and the scope of the breach
ArizonaWithin 45 days after determining that a breach occurred
ArkansasIn the most expedient time and manner possible and without unreasonable delay; no fixed number of days for individual notice
ColoradoIn the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred
ConnecticutWithout unreasonable delay and not later than 60 days after discovery of the breach
DelawareWithout unreasonable delay and not later than 60 days after determination of the breach
FloridaAs expeditiously as practicable and without unreasonable delay, no later than 30 days after determination of a breach
GeorgiaIn the most expedient time possible and without unreasonable delay, unless a law enforcement agency determines notification will compromise a criminal investigation
HawaiiWithout unreasonable delay, consistent with the needs of law enforcement and with measures to determine the scope of the breach
IdahoAs soon as possible, in the most expedient time possible and without unreasonable delay, once an investigation finds misuse has occurred or is reasonably likely
IndianaWithout unreasonable delay and not more than 45 days after discovery of the breach
IowaIn the most expeditious manner possible and without unreasonable delay
KansasAs soon as possible, in the most expedient time possible and without unreasonable delay, once an investigation finds misuse has occurred or is reasonably likely
KentuckyIn the most expedient time possible and without unreasonable delay
LouisianaIn the most expedient time possible and without unreasonable delay, but not later than 60 days from discovery of the breach
MaineAs expediently as possible and without unreasonable delay, and no more than 30 days after becoming aware of the breach and identifying its scope where there is no law enforcement delay
MarylandAs soon as reasonably practicable, but not later than 45 days after the business discovers or is notified of the breach
MassachusettsAs soon as practicable and without unreasonable delay
MichiganWithout unreasonable delay, subject to delay for scoping and restoring the database or at the request of law enforcement
MinnesotaIn the most expedient time possible and without unreasonable delay
MississippiThe Attorney General's Consumer Protection Division identifies the Mississippi data breach notification statute as one of the laws it civilly enforces
MissouriWithout unreasonable delay after discovery or notification of the breach
MontanaWithout unreasonable delay, consistent with law enforcement needs and the measures needed to determine scope and restore integrity
NebraskaAs soon as possible and without unreasonable delay after the investigation concludes that unauthorized use has occurred or is reasonably likely
NevadaIn the most expedient time possible and without unreasonable delay
New HampshireAs quickly as possible after the determination that misuse has occurred or is reasonably likely
New JerseyIn the most expedient time possible and without unreasonable delay; the statute sets no fixed number of days
New MexicoIn the most expedient time possible, but not later than 45 calendar days following discovery of the security breach
New YorkWithin thirty days after discovery of the breach, and without unreasonable delay
North CarolinaWithout unreasonable delay, consistent with law enforcement needs and with measures to determine contact information, determine the scope of the breach and restore the data system
North DakotaIn the most expedient time possible and without unreasonable delay, consistent with the needs of law enforcement and the measures needed to determine the scope of the breach
OhioIn the most expedient time possible but not later than 45 days following discovery or notification of the breach
OklahomaWithout unreasonable delay following discovery, except as needed to determine the scope of the breach and restore the reasonable integrity of the system
OregonIn the most expeditious manner possible, without unreasonable delay, and not later than 45 days after discovering or receiving notification of the breach
PennsylvaniaWithout unreasonable delay following determination of the breach; seven business days for a State agency, and three business days for a county, public school or municipality to notify the district attorney
Rhode IslandIn the most expedient time possible and not later than 45 calendar days after confirmation of the breach for private entities; 30 days for state and municipal agencies
South CarolinaIn the most expedient time possible and without unreasonable delay following discovery; no fixed number of days
South DakotaNot later than 60 days from discovery of or notification of the breach, unless law enforcement needs a longer period
TennesseeNo later than forty-five days from the discovery or notification of the breach of system security
TexasWithout unreasonable delay and no later than 60 days after discovery
UtahIn the most expedient time possible without unreasonable delay, once the investigation reveals that misuse for identity theft or fraud has occurred or is reasonably likely to occur
VermontIn the most expedient time possible and without unreasonable delay, but not later than 45 days after discovery or notification
VirginiaWithout unreasonable delay after discovery, subject to delay for law enforcement and for determining the scope of the breach
WashingtonNo later than 30 days after the breach is discovered
West VirginiaWithout unreasonable delay, subject to law-enforcement delay and to measures needed to determine the scope of the breach and restore system integrity
WisconsinWithin a reasonable time, not to exceed 45 days after the entity learns of the acquisition
WyomingAs soon as possible after an investigation determines misuse has occurred or is reasonably likely, in the most expedient time possible and without unreasonable delay; no fixed number of days

The reasonableness states are not necessarily more permissive in practice. Several tie the clock to the conclusion of an investigation rather than to discovery — Utah, Nebraska, Idaho and Kansas each start from the point at which an investigation finds that misuse has occurred or is reasonably likely — which can run either shorter or longer than a fixed window depending on how quickly the scope of an incident resolves.

Two states set numbers that apply to public rather than private entities. Pennsylvania gives a State agency seven business days and a county, public school or municipality three business days to notify the district attorney. Rhode Island sets 45 calendar days for private entities and 30 for state and municipal agencies.

Notice to the Attorney General or State Regulator

The second axis is who else has to be told, and at what point. This is where the statutes diverge most sharply, and where a process built to one state's rule is most likely to miss another's.

StateRegulator notifiedThreshold and timing
AlabamaAlabama Attorney GeneralWritten notice to the Attorney General is due where the number of individuals to be notified exceeds 1,000, on the same 45-day clock
AlaskaAlaska Attorney GeneralWritten notice to the Attorney General is required where the covered person decides not to disclose after concluding harm is not reasonably likely; the 1,000-person threshold triggers notice to nationwide consumer credit reporting agencies
ArizonaArizona Attorney GeneralNotify the Attorney General and the director of the Arizona Department of Homeland Security in writing where the breach requires notice to more than 1,000 individuals
ArkansasArkansas Attorney GeneralDisclose to the Attorney General where more than 1,000 individuals are affected, at the same time as individual notice or within 45 days of determining a reasonable likelihood of harm, whichever occurs first
ColoradoColorado Attorney GeneralNotify the Colorado Attorney General within thirty days where the breach is reasonably believed to have affected 500 Colorado residents or more
ConnecticutConnecticut Attorney GeneralNotice goes to the Attorney General and to affected residents on the same 60-day clock
DelawareDelaware Department of JusticeNotify the Attorney General where more than 500 Delaware residents are to be notified
FloridaFlorida Department of Legal AffairsNotify the Department of Legal Affairs of any breach affecting 500 or more Florida individuals, no later than 30 days after determination, with 15 additional days available for written good cause
GeorgiaGeorgia Attorney GeneralThe Attorney General's Consumer Protection Division describes no general duty to report breaches to the office
HawaiiHawaiʻi Office of Consumer ProtectionNotify the State of Hawaiʻi Office of Consumer Protection, and the nationwide consumer reporting agencies, in writing when notice is given to more than 1,000 persons at one time
IdahoIdaho Attorney GeneralA public agency must notify the Attorney General within 24 hours of discovery; a commercial entity may notify but is not required to
IndianaIndiana Attorney GeneralNotify the Attorney General whenever notice is given to any Indiana resident — no headcount threshold
IowaIowa Attorney GeneralWritten notice to the director of the consumer protection division of the Attorney General’s office within five business days after giving notice to any consumer, where notification to more than 500 Iowa residents is required
KansasKansas Attorney GeneralNo Attorney General notification requirement; nationwide consumer reporting agencies must be notified when more than 1,000 consumers are notified at one time
KentuckyKentucky Attorney GeneralNo notice to the Attorney General is required of private information holders
LouisianaLouisiana Attorney GeneralUnder LAC 16:III.701 notice to the Attorney General’s Consumer Protection Section is timely if received within 10 days of distribution of notice to Louisiana citizens, and must include the names of all affected citizens
MaineMaine Attorney GeneralNotice goes to the appropriate state regulators within the Department of Professional and Financial Regulation, or to the Attorney General only where the person is not regulated by that department
MarylandMaryland Attorney GeneralNotice to the Maryland Attorney General is required before notice to consumers, for any breach, with no numeric threshold
MassachusettsMassachusetts Attorney GeneralNotice to the Attorney General and the Director of Consumer Affairs and Business Regulation is required before notice to residents, for any breach, with no numeric threshold
MichiganMichigan Attorney GeneralNo Attorney General notification requirement; notice to nationwide consumer reporting agencies is required above 1,000 residents
MinnesotaMinnesota Attorney GeneralNo notice to the Attorney General is required of private businesses; nationwide consumer reporting agencies are notified within 48 hours above 500 persons
MississippiMississippi Attorney GeneralNo general reporting threshold is described in the Attorney General's published material
MissouriMissouri Attorney GeneralNotify the Attorney General, and the nationwide consumer reporting agencies, when notice is given to more than 1,000 consumers at one time
MontanaMontana Attorney General, Office of Consumer ProtectionAn electronic copy of every consumer notification goes to the Attorney General’s consumer protection office — no headcount threshold
NebraskaNebraska Attorney GeneralThe Attorney General is notified no later than the time notice goes to the resident — no headcount threshold
NevadaNevada Attorney GeneralNRS 603A.220 imposes no general Attorney General notice duty; the Attorney General and district attorneys may seek an injunction under NRS 603A.290
New HampshireNew Hampshire Attorney GeneralRegulated businesses notify their primary regulator; all other persons notify the Attorney General — no headcount threshold
New JerseyNew Jersey Division of Consumer AffairsThe breach and any information pertaining to it are reported to the Division of State Police in advance of the disclosure to the customer, for investigation or handling
New MexicoNew Mexico Attorney GeneralNotify the Office of the Attorney General and the nationwide consumer reporting agencies when more than 1,000 New Mexico residents are notified for a single breach
New YorkNew York Attorney GeneralNotify the Attorney General, the Department of State and the Division of State Police for any breach of a New York resident’s private information, with no numeric threshold; the Department of Financial Services is added where applicable
North CarolinaNorth Carolina Attorney GeneralReport to the Attorney General's Consumer Protection Division for every breach that triggers consumer notice, with no minimum number of residents
North DakotaNorth Dakota Attorney GeneralNotify the Attorney General by mail or email for any breach exceeding 250 individuals
OhioOhio Attorney GeneralNo Attorney General notification requirement; the nationwide consumer reporting agencies are notified where more than 1,000 Ohio residents are involved in a single occurrence
OklahomaOklahoma Attorney GeneralNo notice to the Attorney General is required by the Security Breach Notification Act; the office’s role under 24 O.S. § 165 is enforcement rather than receipt of notice
OregonOregon Attorney GeneralNotify the Attorney General where the number of consumers to be notified exceeds 250
PennsylvaniaPennsylvania Office of Attorney GeneralNotify the Office of Attorney General concurrently when notice must be given to more than 500 affected individuals in the Commonwealth
Rhode IslandRhode Island Attorney GeneralNotify the Attorney General and the major credit reporting agencies where more than 500 Rhode Island residents are to be notified
South CarolinaSouth Carolina Department of Consumer AffairsNotify the Consumer Protection Division of the Department of Consumer Affairs and the nationwide consumer reporting agencies when more than 1,000 residents are notified at one time
South DakotaSouth Dakota Attorney GeneralNotify the Attorney General for any breach exceeding 250 South Dakota residents, and also where the holder decides not to notify at all
TennesseeTennessee Attorney General and ReporterSection 47-18-2107 imposes no notice duty to the Attorney General or any other state agency
TexasTexas Attorney GeneralNotify the Texas Attorney General not later than the 60th day after determining a breach occurred, where the breach involves at least 250 Texas residents
UtahUtah Attorney GeneralNotify the Office of the Attorney General and the Utah Cyber Center where 500 or more Utah residents are involved; notify the nationwide consumer reporting agencies where 1,000 or more are involved
VermontVermont Attorney GeneralA preliminary description of the breach goes to the Attorney General, or to the Department of Financial Regulation for entities it regulates, within 14 business days of discovery or of consumer notice, whichever is sooner
VirginiaVirginia Attorney GeneralNotify the Attorney General and the nationwide consumer reporting agencies without unreasonable delay where more than 1,000 persons are notified at one time
WashingtonWashington Attorney GeneralNotify the Washington Attorney General if more than 500 residents are affected, within 30 days
West VirginiaWest Virginia Attorney GeneralNo Attorney General notification requirement; nationwide consumer reporting agencies must be notified when more than 1,000 persons are notified, unless the entity is subject to the Gramm-Leach-Bliley Act
WisconsinWisconsin Department of JusticeNo Attorney General notification requirement; notice to nationwide consumer reporting agencies is required at 1,000 or more individuals from a single incident
WyomingWyoming Attorney GeneralNo Attorney General notification requirement for private businesses; the Attorney General may bring an action for any violation

The Four Threshold Patterns

Across the forty-eight states, regulator notice falls into four patterns.

  • Every breach, no headcount (13 states). New York, Connecticut, Montana, Nebraska, New Hampshire, New Jersey, Maryland, Indiana, Massachusetts, North Carolina, Maine, Vermont and Louisiana require notice to a state body whenever consumer notice is triggered, regardless of how many residents are affected.
  • A numeric threshold (20 states). Texas, Oregon, North Dakota and South Dakota set it at 250 residents. Florida, Washington, Colorado, Delaware, Iowa, Utah, Rhode Island and Pennsylvania set it at 500. Virginia, Alabama, Arizona, Arkansas, Hawaii, South Carolina, Missouri and New Mexico set it at 1,000.
  • No state-agency notice duty (13 states). Wyoming, Tennessee, Kentucky, Oklahoma, Nevada, Minnesota, Kansas, Michigan, Ohio, West Virginia, Wisconsin, Georgia and Mississippi impose no general duty to report a breach to the attorney general. Several of these still require notice to the nationwide consumer reporting agencies above a threshold.
  • Conditional (2 states). Alaska and Idaho each make regulator notice depend on something other than a headcount.

The absence of a reporting duty is not the same as the absence of enforcement authority. Wyoming states no attorney general notification requirement for private businesses while preserving the Attorney General's power to bring an action for any violation, and Oklahoma places its office's role under 24 O.S. section 165 in enforcement rather than in receipt of notice.

The States That Invert or Accelerate the Clock

Five states depart from the ordinary sequence in ways a process built to the common pattern would not anticipate.

Alaska inverts the trigger. Written notice goes to the Attorney General where the covered person decides not to disclose, after concluding that harm is not reasonably likely — so the filing obligation attaches to the decision to stay silent rather than to the decision to notify. The 1,000-person figure in Alaska triggers notice to the nationwide consumer credit reporting agencies instead.

Maryland and Massachusetts reverse the ordering. Both require notice to the state before notice to residents, for any breach and with no numeric threshold, which means the regulator learns of an incident first as a matter of statute rather than as a matter of practice.

Three states run a separate, shorter clock for the regulator filing than for consumer notice. Iowa requires written notice to the director of the consumer protection division within five business days after notice is given to any consumer. Vermont requires a preliminary description of the breach within fourteen business days of discovery or of consumer notice, whichever is sooner. Louisiana, under LAC 16:III.701, treats notice to the Attorney General's Consumer Protection Section as timely if received within ten days of distribution of notice to Louisiana citizens, and requires it to include the names of all affected citizens.

Idaho splits by sector rather than by size: a public agency notifies the Attorney General within twenty-four hours of discovery, while a commercial entity may notify but is not required to. Minnesota runs its own short clock for a different recipient, requiring notice to the nationwide consumer reporting agencies within forty-eight hours above 500 persons.

Substitute Notice, Encryption and Consumer Reporting Agencies

Three further mechanisms recur across these statutes, and the research behind this site documents each of them for some but not all of the forty-eight states. The counts below state the coverage rather than implying the mechanism is absent elsewhere.

Substitute notice — permission to give notice by email, website posting and statewide media where direct notice would be disproportionately costly or the contact information is unavailable — is documented for twenty-six of the forty-eight. Encryption safe harbours, under which the acquisition of encrypted data does not trigger the notification duty unless the key was also acquired, are documented for nineteen. Notice to the nationwide consumer reporting agencies, generally at a 1,000-person threshold, is documented for twenty.

For the states not counted, no claim is made here either way. The state pages linked in the sources set out what each statute provides on its own terms.

Where the Record Is Incomplete

Three gaps in this chart are worth naming rather than leaving for a reader to discover.

California and Illinois are absent from both tables, for the reason given at the top of this guide. Mississippi appears in the tables but its deadline cell does not state a deadline: the research found that the Attorney General's Consumer Protection Division identifies the state breach notification statute among the laws it enforces civilly, without publishing an individual-notice deadline the way other states do. The one Mississippi breach-reporting deadline published by a state agency belongs to the insurance sector, where the Insurance Data Security Law requires a licensee to notify the Commissioner no later than three business days after determining that a cybersecurity event involving nonpublic information has occurred.

Recording those three as gaps rather than approximating them is the same standard applied throughout this site: a claim that cannot be traced to a primary source in this guide is labelled as such, not presented as though it were sourced.

Sectoral Federal Overlays

State breach statutes do not operate alone. The HHS breach notification rule at 45 C.F.R. part 164 subpart D governs protected health information in the hands of covered entities and business associates; the Gramm-Leach-Bliley Act safeguards framework governs customer information at financial institutions; and sector regulators impose their own filings, as the Mississippi insurance example above shows.

Several state statutes address the overlap directly rather than leaving it to be worked out. West Virginia excepts entities subject to the Gramm-Leach-Bliley Act from its consumer reporting agency notice duty. New Hampshire routes regulated businesses to their primary regulator instead of the Attorney General. Maine directs notice to the appropriate regulators within the Department of Professional and Financial Regulation, reaching the Attorney General only where the person is not regulated by that department. Vermont substitutes the Department of Financial Regulation for the Attorney General for the entities it regulates.

Frequently Asked Questions

How many days does a company have to report a data breach?
It depends on the state. Twenty-one of the 48 states charted here set a fixed outer limit — 30 days in five states, 45 in eleven and 60 in five. The other 27 require notice in the most expedient time possible and without unreasonable delay, with no stated number of days.
Which states require notifying the attorney general of every data breach?
Thirteen: New York, Connecticut, Montana, Nebraska, New Hampshire, New Jersey, Maryland, Indiana, Massachusetts, North Carolina, Maine, Vermont and Louisiana. Each requires notice to a state body whenever consumer notice is triggered, with no headcount threshold.
What is the most common attorney general reporting threshold?
Among the 20 states that set a numeric threshold, 500 residents and 1,000 residents are equally common at eight states each, and 250 residents applies in four — Texas, Oregon, North Dakota and South Dakota.
Do any states require notifying the regulator before notifying consumers?
Maryland and Massachusetts both require notice to the state before notice to affected residents, for any breach and with no numeric threshold. Iowa, Vermont and Louisiana instead run a separate short clock for the regulator filing that follows consumer notice.
Does encrypted data trigger breach notification?
Nineteen of the 48 state records behind this guide document an encryption safe harbour, under which acquisition of encrypted data does not trigger the duty unless the encryption key was also acquired. The remaining states were not documented on this point and no inference is drawn about them here.

Sources

Everything above is reported from these documents. Follow them to verify.

  1. Ala. Code § 8-38-2 — Data breach notification; definitions statute
  2. House Bill 65 (25th Legislature), enrolled — Alaska Personal Information Protection Act, ch. 92 SLA 08 statute
  3. A.R.S. § 18-552 — Notification of security system breaches statute
  4. Act 1526 of 2005 — Personal Information Protection Act as enacted statute
  5. Colorado Revised Statutes 2024, Title 6 — Consumer and Commercial Affairs (§§ 6-1-112, 6-1-716, 6-1-1301 to 6-1-1314) statute
  6. Conn. Gen. Stat. § 36a-701b — Breach of security re computerized data containing personal information statute
  7. Del. Code tit. 6, ch. 12B — Computer Security Breaches statute
  8. Fla. Stat. § 501.171 — Security of confidential personal information statute
  9. Georgia Attorney General — Multistate settlement with 23andMe over the genetic data breach (July 14, 2026) agency release
  10. HRS § 487N-2 — Notice of security breach statute
  11. Idaho Code § 28-51-105 — Disclosure of breach of security statute
  12. Ind. Code art. 24-4.9 — Disclosure of Security Breach statute
  13. Iowa Code ch. 715C — Personal Information Security Breach Protection statute
  14. K.S.A. 50-7a01 — Consumer information; security breach; definitions statute
  15. Ky. Rev. Stat. § 365.732 — Notification of computer security breach statute
  16. La. R.S. 51:3074 — Disclosure upon breach in the security of personal information statute
  17. 10 M.R.S. § 1348 — Security breach notice requirements statute
  18. Md. Code, Com. Law § 14-3504 — Notification of breach of security statute
  19. 201 CMR 17.00 — Standards for the Protection of Personal Information of Residents of the Commonwealth regulation
  20. MCL 445.72 — Notice of security breach (Identity Theft Protection Act, sec. 12) statute
  21. Minn. Stat. § 325E.64 — Access devices; breach of security statute
  22. Mississippi Insurance Department — Mississippi Cybersecurity Law (Insurance Data Security Law, §§ 83-5-801 to 83-5-825) agency release
  23. RSMo 407.1500 — Notice to consumer for breach of security statute
  24. Mont. Code Ann. § 30-14-1704 — Computer security breach statute
  25. Neb. Rev. Stat. § 87-1122 — Notification of violations; response statute
  26. Nevada Attorney General — $600 million Equifax data breach settlement agency release
  27. N.H. Rev. Stat. Ann. ch. 359-C — Right to Privacy (breach notification at 359-C:20) statute
  28. P.L.2005, c.226 — Identity Theft Prevention Act, including N.J.S.A. 56:8-163 and 56:8-164 statute
  29. Data Breach Notification Act — House Bill 15, 2017 regular session, final version statute
  30. N.Y. Gen. Bus. Law § 899-aa — Notification; person without valid authorization has acquired private information statute
  31. N.C. Gen. Stat. § 75-65 — Protection from security breaches statute
  32. N.D.C.C. ch. 51-30 — Notice of Security Breach for Personal Information statute
  33. R.C. 1349.19 — Private disclosure of security breach of computerized personal information data statute
  34. Enrolled House Bill 2245 (2008) — Security Breach Notification Act, 24 O.S. §§ 161–166 statute
  35. Or. Rev. Stat. ch. 646A — Trade Regulation (OCPA at 646A.570 to 646A.589; breach at 646A.600 to 646A.628; data brokers at 646A.593) statute
  36. Breach of Personal Information Notification Act — Act of Dec. 22, 2005, P.L. 474, No. 94, as amended statute
  37. R.I. Gen. Laws § 11-49.3-4 — Notification of breach statute
  38. S.C. Code § 39-1-90 — Business data, breach of security; notifications, definitions, penalties, exceptions statute
  39. SDCL § 22-40-19 — Definitions for the breach-notification sections statute
  40. Tennessee Attorney General — multistate settlement over the 23andMe genetic data breach agency release
  41. Texas Attorney General — $150 million settlement against 23andMe over the genetic data breach agency release
  42. Utah S.B. 127 (2023) — Protection of Personal Information Act amendments, enrolled copy statute
  43. 9 V.S.A. § 2435 — Security Breach Notice Act statute
  44. Va. Code § 18.2-186.6 — Breach of personal information notification statute
  45. Wash. Rev. Code § 19.255.010 — Personal information; notice of security breaches statute
  46. W. Va. Code § 46A-2A-102 — Notice of breach of security of computerized personal information statute
  47. Wis. Stat. § 134.98 — Notice of unauthorized acquisition of personal information statute
  48. Wyoming Statutes title 40 — Trade and Commerce, including W.S. 40-12-101 to 40-12-114 and 40-12-501 to 40-12-511 statute

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.