Hawaii

Hawaii Privacy Law

Hawaiʻi has not enacted a comprehensive consumer privacy law, but its three privacy chapters are broader in reach than most sectoral schemes. Chapter 487N applies to personal information in any form, paper included, rather than only to computerized data; it carries both a civil penalty and a private right of action; and it routes regulatory notice to the Office of Consumer Protection within the Department of Commerce and Consumer Affairs rather than to the Attorney General.

Sector-Specific Privacy Laws in Hawaii

Social Security number protection — HRS ch. 487J

HRS § 487J-2(a) bars a business or government agency from intentionally communicating or otherwise making available to the general public an individual’s entire Social Security number; from intentionally printing or embedding the entire number on a card required to access products or services; from requiring transmission of the entire number over the internet unless the connection is secure or the number is encrypted; from requiring the entire number to access a website unless a password, unique personal identification number or other authentication device is also required; and from printing the entire number on materials mailed to the individual outside the exceptions the section lists, which include employer-to-employee communications and materials specifically requested by the individual.

Destruction of personal information records — HRS ch. 487R

HRS § 487R-2(a) requires any business or government agency that conducts business in Hawaiʻi, and any that maintains or otherwise possesses personal information of a Hawaiʻi resident, to take reasonable measures to protect against unauthorized access to or use of that information in connection with or after its disposal. Subsection (b) describes what reasonable measures include: policies and procedures, monitored for compliance, requiring the burning, pulverizing, recycling or shredding of papers containing personal information so that the information cannot practicably be read or reconstructed, and requiring the destruction or erasure of electronic media.

Unfair and deceptive practices — HRS ch. 480

Hawaiʻi’s general unfair-and-deceptive-practices chapter supplies the background against which the privacy chapters operate. HRS § 487N-3(c) makes the point expressly for breach claims, providing that the penalties in that section “shall be cumulative to the remedies or penalties available under all other laws of this State.”

Data Breach Notification in Hawaii

HRS § 487N-2(a) applies to any business that owns or licenses personal information of Hawaiʻi residents, any business conducting business in Hawaiʻi that owns or licenses personal information “in any form (whether computerized, paper, or otherwise),” and any government agency that collects personal information for specific government purposes — a wider net than the computerized-data statutes most states enacted in the same period. Subsection (d) requires the notice to be clear and conspicuous and to describe the incident in general terms, the type of personal information subject to unauthorized access and acquisition, the general acts taken to protect the information from further unauthorized access, a telephone number for further information if one exists, and advice to review account statements and monitor free credit reports. Substitute notice is available under subsection (e)(4) where notice would cost more than $100,000 or the affected class exceeds 200,000 persons. Subsection (g) deems financial institutions covered by the federal Interagency Guidance, and health plans and healthcare providers subject to and in compliance with the HIPAA privacy and security standards, to be in compliance. Subsection (h) provides that any waiver of the section is contrary to public policy and void. Under § 487N-3(a) a business that violates the chapter is subject to penalties of not more than $2,500 for each violation, brought by the Attorney General or the executive director of the Office of Consumer Protection; subsection (b) adds liability to the injured party for actual damages, with discretionary attorney fees to the prevailing party. Neither action may be brought against a government agency.

Residents must be notified without unreasonable delay, consistent with the needs of law enforcement and with measures to determine the scope of the breach. Notify the State of Hawaiʻi Office of Consumer Protection, and the nationwide consumer reporting agencies, in writing when notice is given to more than 1,000 persons at one time. Complaints are taken by the Hawaiʻi Office of Consumer Protection, which enforces the statute.

Recent Enforcement in Hawaii

Leading the 40-state Kids Online Safety Act letter, February 2026. The Department of the Attorney General announced on February 10, 2026 that Attorney General Anne Lopez led a bipartisan coalition of 40 attorneys general in a letter to House and Senate leadership on the Kids Online Safety Act. The release states the letter was circulated in advance of possible consideration of the House version, H.R. 6484, which the signatories described as containing expansive preemption language that could undermine existing and future state laws protecting children online and limit states’ ability to respond to emerging harms. The letter expressed support for the Senate version, S. 1748, which the release describes as including a duty-of-care requirement while preserving state authority to enforce and strengthen protections for minors.

Where complaints go. Hawaiʻi splits the regulatory role that most states give entirely to the Attorney General. HRS § 487N-2(f) directs the notice that follows a breach affecting more than one thousand persons to the State of Hawaiʻi’s Office of Consumer Protection, and § 487N-3(a) permits either the Attorney General or the executive director of that Office to bring a penalty action. The Office, part of the Department of Commerce and Consumer Affairs, publishes its own complaint channel and news releases.

Pending Privacy Legislation

No comprehensive consumer-privacy statute has been enacted in Hawaiʻi. Chapter 487N dates from Act 135 of 2006 and was last amended by Act 19 of 2008; chapters 487J and 487R come from the same period. The Attorney General’s February 2026 letter on the Kids Online Safety Act argued against federal preemption of state online-safety laws, which is the posture Hawaiʻi has taken as those bills have moved in Congress.

Federal Privacy Laws That Apply in Hawaii

Federal privacy law applies in Hawaii by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The state-law counterpart to section 5 is the Unfair and deceptive practices — HRS ch. 480, which the Hawaiʻi Office of Consumer Protection enforces against businesses whose stated data practices differ from their actual ones.

Industry Rules That Reach Hawaii Businesses

With no comprehensive state statute, most privacy obligations on a Hawaii business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach Hawaii businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Hawaii itself has none, and any business holding personal information about Hawaii residents is subject to the state’s breach-notification statute described above.

Hawaii Privacy Law FAQ

Does Hawaiʻi’s breach law cover paper records?
Yes, which distinguishes it from most state breach statutes. HRS § 487N-2(a) reaches any business conducting business in Hawaiʻi that owns or licenses personal information “in any form (whether computerized, paper, or otherwise).” The same subsection separately covers businesses that own or license personal information of Hawaiʻi residents and government agencies that collect personal information for specific government purposes.
Who receives regulatory notice of a Hawaiʻi breach?
The Office of Consumer Protection, not the Attorney General. HRS § 487N-2(f) provides that where a business gives notice to more than one thousand persons at one time, it shall notify in writing, without unreasonable delay, the State of Hawaiʻi’s office of consumer protection and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, of the timing, distribution and content of the notice.
Can an individual sue over a Hawaiʻi breach?
HRS § 487N-3(b) provides that, in addition to the civil penalty, any business that violates the chapter “shall be liable to the injured party in an amount equal to the sum of any actual damages sustained by the injured party as a result of the violation,” and permits the court to award reasonable attorney fees to the prevailing party. The same subsection bars such an action against a government agency.
What is the penalty for violating chapter 487N?
HRS § 487N-3(a) sets penalties of not more than $2,500 for each violation, and provides that the Attorney General or the executive director of the Office of Consumer Protection may bring the action. No such action may be brought against a government agency. Subsection (c) provides that these penalties are cumulative to the remedies or penalties available under all other Hawaiʻi laws.
Can a Hawaiʻi contract waive the breach-notice requirements?
HRS § 487N-2(h) provides that “any waiver of the provisions of this section is contrary to public policy and is void and unenforceable.” The subsection is unqualified, so it applies to waivers however they are packaged.
Does a HIPAA-covered provider in Hawaiʻi also have to comply with chapter 487N?
HRS § 487N-2(g)(2) deems in compliance with the section any health plan or healthcare provider that is subject to and in compliance with the HIPAA standards for the privacy of individually identifiable health information and the security standards for the protection of electronic health information. Subsection (g)(1) provides the parallel treatment for financial institutions subject to the federal Interagency Guidance published on March 29, 2005 or to 12 C.F.R. Part 748.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.