Data Breach Notification Laws: A Plain-English Overview
A general overview of data breach notification laws in the US and beyond: state laws, HIPAA, SEC disclosure and GDPR, the questions that decide what applies, and when to call a lawyer.
Data breach notification laws require organizations to tell affected people, and often regulators, when certain personal information is compromised. In the US, every state has its own breach notification law, and the rules differ on what counts as personal information, what counts as a breach, how quickly you must notify and who else must be told. Sector rules such as HIPAA and SEC disclosure requirements add obligations on top, and the EU’s GDPR generally requires notifying the supervisory authority within 72 hours of becoming aware of a qualifying breach.
This guide is general information, not legal advice. Which laws apply to you depends on where affected people live, your industry, the data involved and your contracts, so talk to a lawyer experienced in data privacy as soon as you suspect a breach. For what to actually say to people once the legal questions are answered, see our guide on data breach communication.
Why these laws exist
Notification laws have a simple goal: when someone’s personal information is exposed, they should find out in time to protect themselves, for example by freezing their credit, changing passwords or watching their accounts. The laws also give regulators visibility of breaches, and they create a strong incentive for organizations to protect data in the first place.
For a business, these laws shape the entire response timeline. The legal deadlines determine when notices must go out, which in turn sets the pace for investigation, drafting and preparing a call center or FAQ page. That is why counsel should be involved from the first hours.
US state breach notification laws
All 50 states, plus the District of Columbia and US territories, have breach notification laws. They share a common structure but differ in the details, and the differences matter. The key point for most businesses is that the law that applies is generally the law of the state where each affected person lives, not where your business is based. A small company with customers in many states can face many sets of rules at once.
What the state laws typically cover
| Element | How state laws tend to differ |
|---|---|
| Definition of personal information | Most cover a name combined with a Social Security number, driver’s license number or financial account number with an access code. Many states go further, adding items such as medical or health insurance information, biometric data, or online account credentials. |
| Definition of a breach | Usually unauthorized acquisition of, and in some states access to, covered data. Some states let an organization skip notice if, after an investigation, it reasonably determines there is no significant risk of harm; others don’t. |
| Encryption | Many states exempt encrypted data, provided the encryption key was not also compromised. |
| Timing | Some set a specific number of days; many require notice without unreasonable delay. Most allow a delay if law enforcement asks for one. |
| Regulator notice | Many require notice to the state attorney general or another agency, sometimes only above a set number of affected residents. |
| Credit bureau notice | Some require notifying the consumer reporting agencies when a breach affects a large number of residents. |
| Content of the notice | Some states specify what the notice must include, and a few require offering free credit monitoring or identity protection in certain cases. |
| Method | Usually written notice, with electronic notice allowed in some circumstances and substitute notice (such as website posting and media notice) where direct notice isn’t practical. |
We deliberately don’t list state-by-state deadlines here. They change, they have exceptions, and a wrong number in a guide is worse than none. Your lawyer will map the affected people by state and confirm each obligation.
Service providers and vendors
If you hold or process data on behalf of another organization, many state laws require you to notify that organization rather than the individuals directly. Your contract may set a shorter deadline than the law. If a vendor of yours is breached, check your contract and talk to counsel: the notification duty to your customers may still sit with you.
Sector rules that add to state law
Healthcare: HIPAA
HIPAA has its own Breach Notification Rule for covered entities, such as health plans and most healthcare providers, and their business associates. It covers breaches of unsecured protected health information and requires notice to affected individuals and to the Department of Health and Human Services, with additional media notice for larger breaches. Business associates must notify the covered entity. Health apps and similar services that aren’t covered by HIPAA may instead fall under the FTC’s Health Breach Notification Rule. Healthcare organizations should also be careful about the public side; our healthcare reputation page covers why replies must never confirm who is a patient.
Public companies: SEC disclosure
Public companies have SEC disclosure obligations for material cybersecurity incidents, generally through a Form 8-K filed within a short window after the company determines an incident is material. They also describe their cybersecurity risk management and governance in annual reports. Materiality is a legal judgment, so securities counsel should lead, and communications with investors need to match what is disclosed.
Financial services and other sectors
Banks, other financial institutions, insurers, government contractors, education providers and telecom companies can each have regulator-specific rules. Card payment rules and contracts with payment processors can also require notice. If you operate in a regulated industry, your regulator’s requirements may be the tightest deadline you face.
Outside the US: GDPR and similar laws
If you process personal data of people in the EU, the GDPR generally requires notifying the relevant supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to people’s rights and freedoms. If the breach is likely to result in a high risk, you must also inform the affected individuals without undue delay. Processors must notify the controller without undue delay. The UK has a similar regime under the UK GDPR.
Many other countries have their own breach notification requirements, with different thresholds and timelines. If you serve customers internationally, your lawyer should check each country where affected people live.
What to do in the first days: a general sequence
Every incident is different, and counsel should direct the order. As a general outline:
- Contain the incident and preserve evidence. Don’t wipe systems before investigators have what they need.
- Call your lawyer and, if you have one, your cyber insurer. Insurers often have required steps and approved vendors.
- Bring in forensic investigators to establish what happened, what data was involved and whose.
- Map the affected people by where they live and what data of theirs was exposed. This drives which laws apply.
- Identify every obligation: state laws, sector rules, international laws and contracts, with deadlines.
- Consider law enforcement, which counsel will usually coordinate.
- Prepare notices, an FAQ page and a call center before notices go out.
- Notify regulators, individuals and others on the timelines counsel confirms, and keep records of every notice.
A named crisis team with legal, IT, communications and leadership in the same room makes this far faster.
Not sure where to start?
Get a free audit of your search results and review profiles, with a prioritized fix list.
Get a free auditA worked example
This is an illustrative scenario, not a real client. An online retailer based in Ohio learns that malicious code on its checkout page may have captured customer names, addresses and payment card details for several weeks.
The owner calls the company’s outside counsel the same morning and notifies its cyber insurer, which connects it with a forensic firm. Investigators confirm the dates and the data involved. Counsel maps the affected customers: they live in most US states and a handful of EU countries. That means dozens of state laws, card network and processor requirements, and the GDPR for the EU customers, with its 72-hour window for notifying the supervisory authority where the breach poses a risk.
Counsel builds a timeline from the date the company became aware of the issue, prepares state-specific notice versions where the laws require different content, and handles regulator filings. The communications lead prepares an FAQ page and a hotline script so they go live the day the first notices arrive. The owner’s instinct had been to wait until the investigation was completely finished; counsel explained that several deadlines would pass before then.
Common mistakes
- Assuming only your home state’s law applies. The residence of affected people usually decides.
- Waiting for a complete investigation. Deadlines often run before investigations end. Notify on what you have confirmed and update later.
- Relying on an online chart of deadlines. Laws change, and charts miss exceptions. Get current legal advice.
- Forgetting contracts. Customer, partner and vendor agreements often have their own notice duties and deadlines.
- Treating notification as only a legal task. The notice is also the moment most people form their view of how you handled it. Communications and legal need to work together.
- Talking publicly before counsel reviews. Early public statements about scope or cause can conflict with later findings and create legal risk.
After notification
A breach can stay attached to your name online through news coverage, regulator listings, forum threads and reviews. Keep your own incident page updated with a closing summary, reply to reviews with the same facts, and publish evidence of the fixes you’ve made. If the incident is still shaping what customers see months later, our crisis management service can help with the communication and the online recovery. Legal questions should always go to your lawyer.
Frequently asked questions
Does every US state have a data breach notification law?
Yes. All 50 states, plus the District of Columbia and US territories, have breach notification laws. They differ in how they define personal information and a breach, how quickly you must notify and whether regulators or credit bureaus must also be told.
Which state's law applies to a data breach?
Generally the law of the state where each affected person lives, not where your business is located. A breach affecting customers in many states can trigger many different sets of rules, which is why counsel usually maps affected people by state early on.
What is the GDPR's 72-hour rule?
Under the GDPR, a controller generally must notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to people’s rights and freedoms. High-risk breaches must also be communicated to affected individuals without undue delay.
Do small businesses have to follow breach notification laws?
In most cases, yes. State laws generally apply to businesses that own or hold covered personal information about residents, regardless of size, though details vary. Talk to a lawyer about your specific situation.