State Data Breach Notification Requirements, Compared Across 48 States
Key Takeaways
- Twenty-one of the 48 states charted set a fixed outer limit for notifying individuals — five at 30 days, eleven at 45 and five at 60. The other 27 use a reasonableness standard with no stated number.
- Regulator thresholds fall into four patterns: 13 states require notice for every breach regardless of headcount, 20 set a numeric threshold, 13 impose no state-agency notice duty at all, and 2 make it conditional.
- Where a numeric threshold exists it clusters tightly on three figures — 250 residents in four states, 500 in eight, and 1,000 in eight.
- Maryland and Massachusetts require regulator notice before individuals are notified, reversing the ordering every other state uses.
- Alaska inverts the trigger entirely: written notice goes to the Attorney General when a covered person decides not to disclose after concluding harm is not reasonably likely.
Forty-Eight States Charted, and Why Not Fifty
All fifty states have a data breach notification statute. This guide charts forty-eight of them. California and Illinois are omitted from the tables, not because their statutes do not exist — California enacted the first breach notification law in the country and Illinois regulates the question through the Personal Information Protection Act — but because the research behind this site records those two states as curated pages that do not capture their breach deadlines and regulator thresholds against a primary source.
Stating that plainly is the alternative to filling the two rows from memory or from secondary summaries. A chart of this kind is only useful if every cell in it can be traced to the statute it describes, and two acknowledged gaps are less costly to a reader than fifty rows of which two are unsourced.
For the forty-eight that are charted, every cell below is taken from the statute or the regulator publication cited for that state in the source list at the foot of this guide.
The Deadline to Notify Affected Individuals
The single most searched question about these statutes is how long a notifier has, and the answer divides the country almost in half. Twenty-one states state a fixed outer limit in days. The remaining twenty-seven state only a reasonableness standard — some version of "in the most expedient time possible and without unreasonable delay" — with no number attached.
Among the states that do set a number, the clustering is tight. Five set 30 days: Florida, New York, Washington, Colorado and Maine. Eleven set 45: Oregon, Tennessee, Maryland, Indiana, Rhode Island, Alabama, Vermont, Arizona, New Mexico, Ohio and Wisconsin. Five set 60: Texas, Connecticut, Delaware, Louisiana and South Dakota.
| State | Deadline to notify affected individuals |
|---|---|
| Alabama | As expeditiously as possible and without unreasonable delay, and within 45 days of the determination that a breach occurred and is reasonably likely to cause substantial harm, or of notice from a third-party agent |
| Alaska | In the most expeditious time possible and without unreasonable delay, subject to law-enforcement delay and the scope of the breach |
| Arizona | Within 45 days after determining that a breach occurred |
| Arkansas | In the most expedient time and manner possible and without unreasonable delay; no fixed number of days for individual notice |
| Colorado | In the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred |
| Connecticut | Without unreasonable delay and not later than 60 days after discovery of the breach |
| Delaware | Without unreasonable delay and not later than 60 days after determination of the breach |
| Florida | As expeditiously as practicable and without unreasonable delay, no later than 30 days after determination of a breach |
| Georgia | In the most expedient time possible and without unreasonable delay, unless a law enforcement agency determines notification will compromise a criminal investigation |
| Hawaii | Without unreasonable delay, consistent with the needs of law enforcement and with measures to determine the scope of the breach |
| Idaho | As soon as possible, in the most expedient time possible and without unreasonable delay, once an investigation finds misuse has occurred or is reasonably likely |
| Indiana | Without unreasonable delay and not more than 45 days after discovery of the breach |
| Iowa | In the most expeditious manner possible and without unreasonable delay |
| Kansas | As soon as possible, in the most expedient time possible and without unreasonable delay, once an investigation finds misuse has occurred or is reasonably likely |
| Kentucky | In the most expedient time possible and without unreasonable delay |
| Louisiana | In the most expedient time possible and without unreasonable delay, but not later than 60 days from discovery of the breach |
| Maine | As expediently as possible and without unreasonable delay, and no more than 30 days after becoming aware of the breach and identifying its scope where there is no law enforcement delay |
| Maryland | As soon as reasonably practicable, but not later than 45 days after the business discovers or is notified of the breach |
| Massachusetts | As soon as practicable and without unreasonable delay |
| Michigan | Without unreasonable delay, subject to delay for scoping and restoring the database or at the request of law enforcement |
| Minnesota | In the most expedient time possible and without unreasonable delay |
| Mississippi | The Attorney General's Consumer Protection Division identifies the Mississippi data breach notification statute as one of the laws it civilly enforces |
| Missouri | Without unreasonable delay after discovery or notification of the breach |
| Montana | Without unreasonable delay, consistent with law enforcement needs and the measures needed to determine scope and restore integrity |
| Nebraska | As soon as possible and without unreasonable delay after the investigation concludes that unauthorized use has occurred or is reasonably likely |
| Nevada | In the most expedient time possible and without unreasonable delay |
| New Hampshire | As quickly as possible after the determination that misuse has occurred or is reasonably likely |
| New Jersey | In the most expedient time possible and without unreasonable delay; the statute sets no fixed number of days |
| New Mexico | In the most expedient time possible, but not later than 45 calendar days following discovery of the security breach |
| New York | Within thirty days after discovery of the breach, and without unreasonable delay |
| North Carolina | Without unreasonable delay, consistent with law enforcement needs and with measures to determine contact information, determine the scope of the breach and restore the data system |
| North Dakota | In the most expedient time possible and without unreasonable delay, consistent with the needs of law enforcement and the measures needed to determine the scope of the breach |
| Ohio | In the most expedient time possible but not later than 45 days following discovery or notification of the breach |
| Oklahoma | Without unreasonable delay following discovery, except as needed to determine the scope of the breach and restore the reasonable integrity of the system |
| Oregon | In the most expeditious manner possible, without unreasonable delay, and not later than 45 days after discovering or receiving notification of the breach |
| Pennsylvania | Without unreasonable delay following determination of the breach; seven business days for a State agency, and three business days for a county, public school or municipality to notify the district attorney |
| Rhode Island | In the most expedient time possible and not later than 45 calendar days after confirmation of the breach for private entities; 30 days for state and municipal agencies |
| South Carolina | In the most expedient time possible and without unreasonable delay following discovery; no fixed number of days |
| South Dakota | Not later than 60 days from discovery of or notification of the breach, unless law enforcement needs a longer period |
| Tennessee | No later than forty-five days from the discovery or notification of the breach of system security |
| Texas | Without unreasonable delay and no later than 60 days after discovery |
| Utah | In the most expedient time possible without unreasonable delay, once the investigation reveals that misuse for identity theft or fraud has occurred or is reasonably likely to occur |
| Vermont | In the most expedient time possible and without unreasonable delay, but not later than 45 days after discovery or notification |
| Virginia | Without unreasonable delay after discovery, subject to delay for law enforcement and for determining the scope of the breach |
| Washington | No later than 30 days after the breach is discovered |
| West Virginia | Without unreasonable delay, subject to law-enforcement delay and to measures needed to determine the scope of the breach and restore system integrity |
| Wisconsin | Within a reasonable time, not to exceed 45 days after the entity learns of the acquisition |
| Wyoming | As soon as possible after an investigation determines misuse has occurred or is reasonably likely, in the most expedient time possible and without unreasonable delay; no fixed number of days |
The reasonableness states are not necessarily more permissive in practice. Several tie the clock to the conclusion of an investigation rather than to discovery — Utah, Nebraska, Idaho and Kansas each start from the point at which an investigation finds that misuse has occurred or is reasonably likely — which can run either shorter or longer than a fixed window depending on how quickly the scope of an incident resolves.
Two states set numbers that apply to public rather than private entities. Pennsylvania gives a State agency seven business days and a county, public school or municipality three business days to notify the district attorney. Rhode Island sets 45 calendar days for private entities and 30 for state and municipal agencies.
Notice to the Attorney General or State Regulator
The second axis is who else has to be told, and at what point. This is where the statutes diverge most sharply, and where a process built to one state's rule is most likely to miss another's.
| State | Regulator notified | Threshold and timing |
|---|---|---|
| Alabama | Alabama Attorney General | Written notice to the Attorney General is due where the number of individuals to be notified exceeds 1,000, on the same 45-day clock |
| Alaska | Alaska Attorney General | Written notice to the Attorney General is required where the covered person decides not to disclose after concluding harm is not reasonably likely; the 1,000-person threshold triggers notice to nationwide consumer credit reporting agencies |
| Arizona | Arizona Attorney General | Notify the Attorney General and the director of the Arizona Department of Homeland Security in writing where the breach requires notice to more than 1,000 individuals |
| Arkansas | Arkansas Attorney General | Disclose to the Attorney General where more than 1,000 individuals are affected, at the same time as individual notice or within 45 days of determining a reasonable likelihood of harm, whichever occurs first |
| Colorado | Colorado Attorney General | Notify the Colorado Attorney General within thirty days where the breach is reasonably believed to have affected 500 Colorado residents or more |
| Connecticut | Connecticut Attorney General | Notice goes to the Attorney General and to affected residents on the same 60-day clock |
| Delaware | Delaware Department of Justice | Notify the Attorney General where more than 500 Delaware residents are to be notified |
| Florida | Florida Department of Legal Affairs | Notify the Department of Legal Affairs of any breach affecting 500 or more Florida individuals, no later than 30 days after determination, with 15 additional days available for written good cause |
| Georgia | Georgia Attorney General | The Attorney General's Consumer Protection Division describes no general duty to report breaches to the office |
| Hawaii | Hawaiʻi Office of Consumer Protection | Notify the State of Hawaiʻi Office of Consumer Protection, and the nationwide consumer reporting agencies, in writing when notice is given to more than 1,000 persons at one time |
| Idaho | Idaho Attorney General | A public agency must notify the Attorney General within 24 hours of discovery; a commercial entity may notify but is not required to |
| Indiana | Indiana Attorney General | Notify the Attorney General whenever notice is given to any Indiana resident — no headcount threshold |
| Iowa | Iowa Attorney General | Written notice to the director of the consumer protection division of the Attorney General’s office within five business days after giving notice to any consumer, where notification to more than 500 Iowa residents is required |
| Kansas | Kansas Attorney General | No Attorney General notification requirement; nationwide consumer reporting agencies must be notified when more than 1,000 consumers are notified at one time |
| Kentucky | Kentucky Attorney General | No notice to the Attorney General is required of private information holders |
| Louisiana | Louisiana Attorney General | Under LAC 16:III.701 notice to the Attorney General’s Consumer Protection Section is timely if received within 10 days of distribution of notice to Louisiana citizens, and must include the names of all affected citizens |
| Maine | Maine Attorney General | Notice goes to the appropriate state regulators within the Department of Professional and Financial Regulation, or to the Attorney General only where the person is not regulated by that department |
| Maryland | Maryland Attorney General | Notice to the Maryland Attorney General is required before notice to consumers, for any breach, with no numeric threshold |
| Massachusetts | Massachusetts Attorney General | Notice to the Attorney General and the Director of Consumer Affairs and Business Regulation is required before notice to residents, for any breach, with no numeric threshold |
| Michigan | Michigan Attorney General | No Attorney General notification requirement; notice to nationwide consumer reporting agencies is required above 1,000 residents |
| Minnesota | Minnesota Attorney General | No notice to the Attorney General is required of private businesses; nationwide consumer reporting agencies are notified within 48 hours above 500 persons |
| Mississippi | Mississippi Attorney General | No general reporting threshold is described in the Attorney General's published material |
| Missouri | Missouri Attorney General | Notify the Attorney General, and the nationwide consumer reporting agencies, when notice is given to more than 1,000 consumers at one time |
| Montana | Montana Attorney General, Office of Consumer Protection | An electronic copy of every consumer notification goes to the Attorney General’s consumer protection office — no headcount threshold |
| Nebraska | Nebraska Attorney General | The Attorney General is notified no later than the time notice goes to the resident — no headcount threshold |
| Nevada | Nevada Attorney General | NRS 603A.220 imposes no general Attorney General notice duty; the Attorney General and district attorneys may seek an injunction under NRS 603A.290 |
| New Hampshire | New Hampshire Attorney General | Regulated businesses notify their primary regulator; all other persons notify the Attorney General — no headcount threshold |
| New Jersey | New Jersey Division of Consumer Affairs | The breach and any information pertaining to it are reported to the Division of State Police in advance of the disclosure to the customer, for investigation or handling |
| New Mexico | New Mexico Attorney General | Notify the Office of the Attorney General and the nationwide consumer reporting agencies when more than 1,000 New Mexico residents are notified for a single breach |
| New York | New York Attorney General | Notify the Attorney General, the Department of State and the Division of State Police for any breach of a New York resident’s private information, with no numeric threshold; the Department of Financial Services is added where applicable |
| North Carolina | North Carolina Attorney General | Report to the Attorney General's Consumer Protection Division for every breach that triggers consumer notice, with no minimum number of residents |
| North Dakota | North Dakota Attorney General | Notify the Attorney General by mail or email for any breach exceeding 250 individuals |
| Ohio | Ohio Attorney General | No Attorney General notification requirement; the nationwide consumer reporting agencies are notified where more than 1,000 Ohio residents are involved in a single occurrence |
| Oklahoma | Oklahoma Attorney General | No notice to the Attorney General is required by the Security Breach Notification Act; the office’s role under 24 O.S. § 165 is enforcement rather than receipt of notice |
| Oregon | Oregon Attorney General | Notify the Attorney General where the number of consumers to be notified exceeds 250 |
| Pennsylvania | Pennsylvania Office of Attorney General | Notify the Office of Attorney General concurrently when notice must be given to more than 500 affected individuals in the Commonwealth |
| Rhode Island | Rhode Island Attorney General | Notify the Attorney General and the major credit reporting agencies where more than 500 Rhode Island residents are to be notified |
| South Carolina | South Carolina Department of Consumer Affairs | Notify the Consumer Protection Division of the Department of Consumer Affairs and the nationwide consumer reporting agencies when more than 1,000 residents are notified at one time |
| South Dakota | South Dakota Attorney General | Notify the Attorney General for any breach exceeding 250 South Dakota residents, and also where the holder decides not to notify at all |
| Tennessee | Tennessee Attorney General and Reporter | Section 47-18-2107 imposes no notice duty to the Attorney General or any other state agency |
| Texas | Texas Attorney General | Notify the Texas Attorney General not later than the 60th day after determining a breach occurred, where the breach involves at least 250 Texas residents |
| Utah | Utah Attorney General | Notify the Office of the Attorney General and the Utah Cyber Center where 500 or more Utah residents are involved; notify the nationwide consumer reporting agencies where 1,000 or more are involved |
| Vermont | Vermont Attorney General | A preliminary description of the breach goes to the Attorney General, or to the Department of Financial Regulation for entities it regulates, within 14 business days of discovery or of consumer notice, whichever is sooner |
| Virginia | Virginia Attorney General | Notify the Attorney General and the nationwide consumer reporting agencies without unreasonable delay where more than 1,000 persons are notified at one time |
| Washington | Washington Attorney General | Notify the Washington Attorney General if more than 500 residents are affected, within 30 days |
| West Virginia | West Virginia Attorney General | No Attorney General notification requirement; nationwide consumer reporting agencies must be notified when more than 1,000 persons are notified, unless the entity is subject to the Gramm-Leach-Bliley Act |
| Wisconsin | Wisconsin Department of Justice | No Attorney General notification requirement; notice to nationwide consumer reporting agencies is required at 1,000 or more individuals from a single incident |
| Wyoming | Wyoming Attorney General | No Attorney General notification requirement for private businesses; the Attorney General may bring an action for any violation |
The Four Threshold Patterns
Across the forty-eight states, regulator notice falls into four patterns.
- Every breach, no headcount (13 states). New York, Connecticut, Montana, Nebraska, New Hampshire, New Jersey, Maryland, Indiana, Massachusetts, North Carolina, Maine, Vermont and Louisiana require notice to a state body whenever consumer notice is triggered, regardless of how many residents are affected.
- A numeric threshold (20 states). Texas, Oregon, North Dakota and South Dakota set it at 250 residents. Florida, Washington, Colorado, Delaware, Iowa, Utah, Rhode Island and Pennsylvania set it at 500. Virginia, Alabama, Arizona, Arkansas, Hawaii, South Carolina, Missouri and New Mexico set it at 1,000.
- No state-agency notice duty (13 states). Wyoming, Tennessee, Kentucky, Oklahoma, Nevada, Minnesota, Kansas, Michigan, Ohio, West Virginia, Wisconsin, Georgia and Mississippi impose no general duty to report a breach to the attorney general. Several of these still require notice to the nationwide consumer reporting agencies above a threshold.
- Conditional (2 states). Alaska and Idaho each make regulator notice depend on something other than a headcount.
The absence of a reporting duty is not the same as the absence of enforcement authority. Wyoming states no attorney general notification requirement for private businesses while preserving the Attorney General's power to bring an action for any violation, and Oklahoma places its office's role under 24 O.S. section 165 in enforcement rather than in receipt of notice.
The States That Invert or Accelerate the Clock
Five states depart from the ordinary sequence in ways a process built to the common pattern would not anticipate.
Alaska inverts the trigger. Written notice goes to the Attorney General where the covered person decides not to disclose, after concluding that harm is not reasonably likely — so the filing obligation attaches to the decision to stay silent rather than to the decision to notify. The 1,000-person figure in Alaska triggers notice to the nationwide consumer credit reporting agencies instead.
Maryland and Massachusetts reverse the ordering. Both require notice to the state before notice to residents, for any breach and with no numeric threshold, which means the regulator learns of an incident first as a matter of statute rather than as a matter of practice.
Three states run a separate, shorter clock for the regulator filing than for consumer notice. Iowa requires written notice to the director of the consumer protection division within five business days after notice is given to any consumer. Vermont requires a preliminary description of the breach within fourteen business days of discovery or of consumer notice, whichever is sooner. Louisiana, under LAC 16:III.701, treats notice to the Attorney General's Consumer Protection Section as timely if received within ten days of distribution of notice to Louisiana citizens, and requires it to include the names of all affected citizens.
Idaho splits by sector rather than by size: a public agency notifies the Attorney General within twenty-four hours of discovery, while a commercial entity may notify but is not required to. Minnesota runs its own short clock for a different recipient, requiring notice to the nationwide consumer reporting agencies within forty-eight hours above 500 persons.
Substitute Notice, Encryption and Consumer Reporting Agencies
Three further mechanisms recur across these statutes, and the research behind this site documents each of them for some but not all of the forty-eight states. The counts below state the coverage rather than implying the mechanism is absent elsewhere.
Substitute notice — permission to give notice by email, website posting and statewide media where direct notice would be disproportionately costly or the contact information is unavailable — is documented for twenty-six of the forty-eight. Encryption safe harbours, under which the acquisition of encrypted data does not trigger the notification duty unless the key was also acquired, are documented for nineteen. Notice to the nationwide consumer reporting agencies, generally at a 1,000-person threshold, is documented for twenty.
For the states not counted, no claim is made here either way. The state pages linked in the sources set out what each statute provides on its own terms.
Where the Record Is Incomplete
Three gaps in this chart are worth naming rather than leaving for a reader to discover.
California and Illinois are absent from both tables, for the reason given at the top of this guide. Mississippi appears in the tables but its deadline cell does not state a deadline: the research found that the Attorney General's Consumer Protection Division identifies the state breach notification statute among the laws it enforces civilly, without publishing an individual-notice deadline the way other states do. The one Mississippi breach-reporting deadline published by a state agency belongs to the insurance sector, where the Insurance Data Security Law requires a licensee to notify the Commissioner no later than three business days after determining that a cybersecurity event involving nonpublic information has occurred.
Recording those three as gaps rather than approximating them is the same standard applied throughout this site: a claim that cannot be traced to a primary source in this guide is labelled as such, not presented as though it were sourced.
Sectoral Federal Overlays
State breach statutes do not operate alone. The HHS breach notification rule at 45 C.F.R. part 164 subpart D governs protected health information in the hands of covered entities and business associates; the Gramm-Leach-Bliley Act safeguards framework governs customer information at financial institutions; and sector regulators impose their own filings, as the Mississippi insurance example above shows.
Several state statutes address the overlap directly rather than leaving it to be worked out. West Virginia excepts entities subject to the Gramm-Leach-Bliley Act from its consumer reporting agency notice duty. New Hampshire routes regulated businesses to their primary regulator instead of the Attorney General. Maine directs notice to the appropriate regulators within the Department of Professional and Financial Regulation, reaching the Attorney General only where the person is not regulated by that department. Vermont substitutes the Department of Financial Regulation for the Attorney General for the entities it regulates.
Frequently Asked Questions
How many days does a company have to report a data breach?
Which states require notifying the attorney general of every data breach?
What is the most common attorney general reporting threshold?
Do any states require notifying the regulator before notifying consumers?
Does encrypted data trigger breach notification?
Sources
Everything above is reported from these documents. Follow them to verify.
- Ala. Code § 8-38-2 — Data breach notification; definitions statute
- House Bill 65 (25th Legislature), enrolled — Alaska Personal Information Protection Act, ch. 92 SLA 08 statute
- A.R.S. § 18-552 — Notification of security system breaches statute
- Act 1526 of 2005 — Personal Information Protection Act as enacted statute
- Colorado Revised Statutes 2024, Title 6 — Consumer and Commercial Affairs (§§ 6-1-112, 6-1-716, 6-1-1301 to 6-1-1314) statute
- Conn. Gen. Stat. § 36a-701b — Breach of security re computerized data containing personal information statute
- Del. Code tit. 6, ch. 12B — Computer Security Breaches statute
- Fla. Stat. § 501.171 — Security of confidential personal information statute
- Georgia Attorney General — Multistate settlement with 23andMe over the genetic data breach (July 14, 2026) agency release
- HRS § 487N-2 — Notice of security breach statute
- Idaho Code § 28-51-105 — Disclosure of breach of security statute
- Ind. Code art. 24-4.9 — Disclosure of Security Breach statute
- Iowa Code ch. 715C — Personal Information Security Breach Protection statute
- K.S.A. 50-7a01 — Consumer information; security breach; definitions statute
- Ky. Rev. Stat. § 365.732 — Notification of computer security breach statute
- La. R.S. 51:3074 — Disclosure upon breach in the security of personal information statute
- 10 M.R.S. § 1348 — Security breach notice requirements statute
- Md. Code, Com. Law § 14-3504 — Notification of breach of security statute
- 201 CMR 17.00 — Standards for the Protection of Personal Information of Residents of the Commonwealth regulation
- MCL 445.72 — Notice of security breach (Identity Theft Protection Act, sec. 12) statute
- Minn. Stat. § 325E.64 — Access devices; breach of security statute
- Mississippi Insurance Department — Mississippi Cybersecurity Law (Insurance Data Security Law, §§ 83-5-801 to 83-5-825) agency release
- RSMo 407.1500 — Notice to consumer for breach of security statute
- Mont. Code Ann. § 30-14-1704 — Computer security breach statute
- Neb. Rev. Stat. § 87-1122 — Notification of violations; response statute
- Nevada Attorney General — $600 million Equifax data breach settlement agency release
- N.H. Rev. Stat. Ann. ch. 359-C — Right to Privacy (breach notification at 359-C:20) statute
- P.L.2005, c.226 — Identity Theft Prevention Act, including N.J.S.A. 56:8-163 and 56:8-164 statute
- Data Breach Notification Act — House Bill 15, 2017 regular session, final version statute
- N.Y. Gen. Bus. Law § 899-aa — Notification; person without valid authorization has acquired private information statute
- N.C. Gen. Stat. § 75-65 — Protection from security breaches statute
- N.D.C.C. ch. 51-30 — Notice of Security Breach for Personal Information statute
- R.C. 1349.19 — Private disclosure of security breach of computerized personal information data statute
- Enrolled House Bill 2245 (2008) — Security Breach Notification Act, 24 O.S. §§ 161–166 statute
- Or. Rev. Stat. ch. 646A — Trade Regulation (OCPA at 646A.570 to 646A.589; breach at 646A.600 to 646A.628; data brokers at 646A.593) statute
- Breach of Personal Information Notification Act — Act of Dec. 22, 2005, P.L. 474, No. 94, as amended statute
- R.I. Gen. Laws § 11-49.3-4 — Notification of breach statute
- S.C. Code § 39-1-90 — Business data, breach of security; notifications, definitions, penalties, exceptions statute
- SDCL § 22-40-19 — Definitions for the breach-notification sections statute
- Tennessee Attorney General — multistate settlement over the 23andMe genetic data breach agency release
- Texas Attorney General — $150 million settlement against 23andMe over the genetic data breach agency release
- Utah S.B. 127 (2023) — Protection of Personal Information Act amendments, enrolled copy statute
- 9 V.S.A. § 2435 — Security Breach Notice Act statute
- Va. Code § 18.2-186.6 — Breach of personal information notification statute
- Wash. Rev. Code § 19.255.010 — Personal information; notice of security breaches statute
- W. Va. Code § 46A-2A-102 — Notice of breach of security of computerized personal information statute
- Wis. Stat. § 134.98 — Notice of unauthorized acquisition of personal information statute
- Wyoming Statutes title 40 — Trade and Commerce, including W.S. 40-12-101 to 40-12-114 and 40-12-501 to 40-12-511 statute
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.