Back to Blog
Compliance GuidesMarch 29, 202614 min readReviewed by the PrivacyLawMap editorial teamLast reviewed March 29, 2026

Data Breach Notification Laws by State: A Complete 2026 Guide

Share:
Turn This Guide Into a Working Privacy SetupSponsored

Termly can generate and maintain your privacy policy, consent banner, and data-request workflow as requirements change.

Start Free with Termly

What Are Data Breach Notification Laws?

Data breach notification laws require organizations to notify affected individuals — and in many cases state regulators — when personal information is compromised in a security incident. All 50 US states, the District of Columbia, and US territories now have data breach notification statutes. While comprehensive state privacy laws like the CCPA govern how data is collected and used, breach notification laws focus specifically on what happens when that data is exposed.

These laws vary widely in their timelines, definitions of personal information, notification triggers, and enforcement mechanisms. This guide breaks down the key requirements so you can build a response plan that covers every state where you have customers or employees.

Quick answer (verified June 19, 2026): All 50 US states, the District of Columbia, and three US territories have data breach notification laws as of June 2026 — there is still no single federal breach-notification statute. Deadlines to notify affected individuals range from a fixed 30 calendar days in the strictest states (California's 30-day rule took effect January 1, 2026 under SB 446) to "in the most expedient time possible and without unreasonable delay," with no fixed day-count, in roughly 20 states.

How Many States Have Breach Notification Laws?

All 50 states plus DC, Guam, Puerto Rico, and the US Virgin Islands have enacted data breach notification laws. Alabama was the last state to pass its law in 2018. There is no single federal breach notification law (despite repeated proposals), so businesses must comply with a patchwork of state-level requirements.

This is separate from the 20+ states that have enacted comprehensive consumer privacy laws. Breach notification laws are narrower — they only apply when a security incident exposes protected personal information.

Key Elements of State Breach Notification Laws

1. Notification Timelines

The most critical compliance variable is how quickly you must notify affected individuals and regulators after discovering a breach. Timelines range from as few as 30 days to "without unreasonable delay" (no fixed deadline).

TimelineStates
30 daysCalifornia (effective Jan 1, 2026, SB 446), Colorado, Florida, Washington
45 daysArizona, Ohio, Rhode Island, Wisconsin
60 daysConnecticut, Delaware, Hawaii, Iowa, Maine, Maryland, Massachusetts, Minnesota, Montana, Nebraska, New Hampshire, New Mexico, North Carolina, Oregon, South Dakota, Tennessee, Texas, Vermont, Virginia, Wyoming
72 hoursPuerto Rico (AG notification only)
90 daysAlabama
"Most expedient" / no fixed deadlineAlaska, Arkansas, Georgia, Idaho, Illinois, Indiana, Kansas, Kentucky, Louisiana, Michigan, Mississippi, Missouri, Nevada, New Jersey, New York, North Dakota, Oklahoma, Pennsylvania, South Carolina, Utah, West Virginia

Practical tip: If your business operates in multiple states, plan for the shortest applicable deadline. California's 30-day requirement (effective January 1, 2026 under SB 446) is currently the strictest fixed timeline. Use our Privacy Law Calculator to determine which states' laws apply to your business.

2. Who Must Be Notified

Most states require notification to:

  • Affected individuals — required in all states
  • State Attorney General — required in most states, but the trigger is not uniform and the recipient is not always the AG. The verified matrix below gives the exact floor, recipient and deadline per jurisdiction.
  • Consumer reporting agencies — typically required when 1,000+ residents are affected (following the federal FACTA standard)
  • State-specific agencies — some states require notification to specialized regulators (e.g., the Connecticut Insurance Department for insurance-related breaches)

Who must be notified, and at what resident count

Every row below was transcribed from the statute or regulator page linked in it, on the date shown. Where a jurisdiction is not listed, we have not yet been able to read its primary source — treat that as unknown, not as "no duty", and check the statute before you file.

Regulator notice verified from primary sources for 20 of 51 US jurisdictions as of August 15, 2026. The remaining 31 are not shown because they are unverified, which is not the same as having no duty.
StateRegulator notice triggerWho must be notifiedRegulator deadlineFiling published?Primary source
Alabama More than 1,000 residents The Attorney General, in writing As expeditiously as possible and without unreasonable delay, and within 45 days of determining the breach occurred Shielded — the statute exempts filed information from public records Ala. Code § 8-38-6 (retrieved August 13, 2026)
Arizona More than 1,000 residents The Attorney General and the Director of the Arizona Department of Homeland Security Within 45 days of determining the breach occurred Not verified Ariz. Rev. Stat. § 18-552(B)(2) (retrieved August 12, 2026)
California More than 500 residents The California Attorney General A sample copy of the notice is submitted when notice is sent to residents Yes — public database California Attorney General, Data Breach Database (Cal. Civ. Code § 1798.82) (retrieved August 13, 2026)
Delaware More than 500 residents The Attorney General Not later than when notice is provided to residents Not verified Del. Code tit. 6, § 12B-102(d) (retrieved August 12, 2026)
District of Columbia 50 or more residents The Office of the Attorney General for the District of Columbia Promptly, and no later than when notice is provided to residents Not verified D.C. Code § 28-3852(b-1) (retrieved August 13, 2026)
Hawaii More than 1,000 people notified The State of Hawaii's Office of Consumer Protection In writing, without unreasonable delay Not verified Haw. Rev. Stat. § 487N-2(f) (retrieved August 13, 2026)
Iowa More than 500 residents The Director of the Consumer Protection Division of the Office of the Attorney General Within 5 business days after notifying consumers Not verified Iowa Code § 715C.2(8) (retrieved August 12, 2026)
Kansas No regulator notice required None — no regulator notice duty No fixed deadline stated Not applicable — nothing is filed Kan. Stat. Ann. § 50-7a02 (retrieved August 13, 2026)
Maine Any reportable breach (no minimum) The appropriate state regulators within the Department of Professional and Financial Regulation, or the Attorney General if the person is not regulated by the department No fixed deadline stated Not verified Me. Rev. Stat. tit. 10, § 1348(5) (retrieved August 12, 2026)
Minnesota No regulator notice required None — no regulator notice duty No fixed deadline stated Not applicable — nothing is filed Minn. Stat. § 325E.61 (retrieved August 12, 2026)
New Mexico More than 1,000 residents The Office of the Attorney General In the most expedient time possible and no later than 45 calendar days following discovery of the breach Not verified N.M. Stat. Ann. § 57-12C-10 (retrieved August 13, 2026)
New York Any reportable breach (no minimum) The state Attorney General, the Department of State, and the Division of State Police No fixed deadline stated Not verified N.Y. Gen. Bus. Law § 899-aa(8)(a) (retrieved August 12, 2026)
North Dakota More than 250 residents The Attorney General, by mail or electronic mail In the most expedient time possible and without unreasonable delay Not verified N.D. Cent. Code § 51-30-02 (retrieved August 12, 2026)
Oklahoma 500 or more residents The Attorney General Without unreasonable delay and no more than 60 days after notice is given to the affected residents Shielded — the statute exempts filed information from public records Okla. Stat. tit. 24, § 163(E) (retrieved August 13, 2026)
South Carolina More than 1,000 people notified The Consumer Protection Division of the South Carolina Department of Consumer Affairs Without unreasonable delay Not verified S.C. Code Ann. § 39-1-90(K) (retrieved August 13, 2026)
South Dakota More than 250 residents The Attorney General, by mail or electronic mail Not later than 60 days from discovery or notification of the breach Not verified S.D. Codified Laws § 22-40-20 (retrieved August 13, 2026)
Texas 250 or more residents The Texas Attorney General, electronically on the form it publishes As soon as practicable and no later than 30 days after determining the breach occurred Yes — the statute requires a public listing Tex. Bus. & Com. Code § 521.053(i)-(j) (retrieved August 15, 2026)
Virginia Any reportable breach (no minimum) The Office of the Attorney General Without unreasonable delay Not verified Va. Code § 18.2-186.6(B) (retrieved August 12, 2026)
Washington More than 500 residents The Attorney General No more than 30 days after the breach was discovered Not verified Wash. Rev. Code § 19.255.010(7) (retrieved August 12, 2026)
Wyoming No regulator notice required None — no regulator notice duty No fixed deadline stated Not applicable — nothing is filed Wyo. Stat. Ann. § 40-12-502 (retrieved August 13, 2026)

Four things in that table routinely surprise response teams. The recipient is not always the attorney general: Hawaii sends the filing to the state Office of Consumer Protection and South Carolina to the Consumer Protection Division of the Department of Consumer Affairs — in neither state does the AG receive it. Arizona requires the Director of the Arizona Department of Homeland Security in the same filing, New York requires three separate bodies, and Maine routes the notice to a sector regulator first and only falls back to the AG. The floors are far apart, and they do not all count the same people: the District of Columbia binds at 50 or more District residents, Texas and North Dakota at 250, Washington at more than 500 — but Hawaii and South Carolina count more than 1,000 people notified, wherever they live, so a national breach can cross those two on out-of-state headcount alone. The regulator is sometimes told first: Texas gives you 30 days to report to the attorney general and 60 to notify the affected people, which inverts the sequence most response plans assume. And "no minimum" is not the same as "no duty": New York and Virginia require regulator notice for any reportable breach, while Minnesota, Kansas and Wyoming impose no regulator-notice duty at all. Each of the three is routinely listed in secondhand charts with a threshold — Minnesota's 500-person trigger is notice to the nationwide consumer reporting agencies within 48 hours (Minn. Stat. § 325E.61 subd. 2) and Kansas's 1,000-consumer trigger is the same thing (Kan. Stat. Ann. § 50-7a02(f)); in all three states the attorney general appears only as the enforcer.

The part most response plans miss (verified August 13, 2026): in California, notifying the Attorney General is not a private regulatory filing — it is a publication. The California AG runs a searchable public Data Breach Database of the sample notices it receives, listing the reporting organization, the breach date and the reported date, and it can be downloaded in bulk as a CSV (California Attorney General, Data Breach Database, retrieved August 13, 2026). Once you cross California's threshold — a sample copy goes to the AG when the notice is sent to more than 500 California residents — your notice becomes a permanent, indexable, machine-readable public record that journalists, plaintiffs' firms and competitors routinely mine.

The practical consequence is a sequencing one. If your breach crosses that California threshold, the notice letter is a public communication from the day it is filed, so it needs communications and executive sign-off inside the same 30-day clock as the legal review — not after it. Draft the letter as though it will be read by someone who was not affected, because it will be.

3. What Data Triggers Notification

All states cover the "classic" combination of a name plus one of: Social Security number, driver's license or state ID number, or financial account/credit card number. Many states have expanded their definitions to include:

  • Medical/health information — California, Connecticut, Maryland, Montana, North Dakota, Texas, and others
  • Biometric data — California, Colorado, Connecticut, Illinois, Maryland, Nebraska, New York, Texas, and others
  • Online account credentials (email + password) — California, Florida, Maryland, Rhode Island, and others
  • Tax ID numbers — many states beyond just SSNs
  • Passport/immigration numbers — Arizona, Maryland, New York, and others

States with broader definitions of personal information create more situations where notification is required. Check whether the type of data your business handles falls under each applicable state's definition.

4. Safe Harbors and Exemptions

Several important exemptions can reduce your obligations:

  • Encryption safe harbor — Most states exempt breaches where the data was encrypted and the encryption key was not also compromised. This is one of the strongest arguments for encryption at rest and in transit.
  • Risk of harm assessment — Some states (e.g., Alaska, Michigan, Ohio, Kansas) allow organizations to skip notification if an internal investigation determines the breach is unlikely to cause substantial harm.
  • Law enforcement delay — Nearly all states allow notification to be delayed if law enforcement determines it would impede a criminal investigation.
  • HIPAA preemption — Entities already subject to HIPAA's breach notification rule may be exempt from state requirements, but this varies — some states explicitly do not exempt HIPAA-covered entities. See our state privacy law vs. HIPAA comparison.

State-by-State Spotlight: Key Requirements

California

California's breach notification law (Civil Code § 1798.82) is among the most expansive. Senate Bill 446, signed by Governor Newsom on October 3, 2025 and effective January 1, 2026, replaced the old "most expedient time possible" standard with a fixed 30-calendar-day deadline to notify affected individuals — currently the strictest fixed timeline in the country. For breaches affecting more than 500 California residents, businesses must also notify the California Attorney General within 15 calendar days of notifying individuals. California's definition of personal information is broad, covering biometric data, medical information, and online account credentials. Substitute notice must include email notification, conspicuous website posting, and notification to major statewide media. California also requires the notification to be written in plain language and to include specific elements like a description of the incident, types of data compromised, and remediation steps. For more on California's broader privacy framework, see our CCPA compliance guide. Source check: Last verified June 19, 2026 against California Civil Code § 1798.82 as amended by SB 446 (2025) (date_retrieved: 2026-06-19).

Texas

Texas (Business & Commerce Code § 521.053) gives you 60 days to notify affected people but only 30 days to notify the attorney general, counted from the day you determine the breach occurred, once at least 250 Texans are involved — so the regulator filing is the earlier deadline, not the later one (§ 521.053(b), (i), retrieved August 13, 2026). The report must be submitted electronically on the OAG's own form, and § 521.053(j) requires the attorney general to publish a listing of the reports it receives. Texas has one of the broadest breach notification triggers — it includes any "sensitive personal information" which encompasses biometric data, financial data, and health data. The Texas Attorney General has been increasingly aggressive with privacy enforcement, as demonstrated by the record $1.4 billion Meta settlement. For the broader privacy framework, see our TDPSA guide.

Florida

Florida's Information Protection Act (§ 501.171) has a 30-day notification deadline — one of the shortest. It requires AG notification when 500+ residents are affected and has a unique feature: the AG must be notified within 30 days even if the investigation is still ongoing. Penalties can reach $500,000 per breach incident. Florida also requires entities to provide identity theft protection services at no cost for at least 12 months if SSNs were compromised.

New York

New York's SHIELD Act (General Business Law § 899-aa) expanded the state's breach notification law significantly. It broadened the definition of "private information" to include biometric data and online credentials, and imposed data security requirements on all businesses holding New York residents' data (not just those conducting business in New York). Notification must be made "in the most expedient time possible" with no fixed deadline, and the AG, Division of State Police, and Division of Consumer Protection must all be notified.

Massachusetts

Massachusetts (M.G.L. ch. 93H) has robust requirements including 60-day notification, detailed AG notification via an online portal, and a requirement that notice be provided to the Director of Consumer Affairs. Massachusetts also mandates that the notification include a right to obtain a police report and information about security freezes. Uniquely, Massachusetts requires notification even when the breach involves only a first name or initial with last name, combined with one triggering data element.

Illinois

Illinois's Personal Information Protection Act (815 ILCS 530) requires notification "in the most expedient time possible and without unreasonable delay." For breaches affecting 500+ Illinois residents, the AG must be notified. Illinois is also notable for its Biometric Information Privacy Act (BIPA), which provides a private right of action for biometric data violations — unlike most states where only the AG can enforce.

Building a Multi-State Breach Response Plan

Given the patchwork of requirements, here's a practical approach to building a response plan that keeps you compliant everywhere:

Step 1: Map Your Data

Identify what personal information you hold, where it's stored, and which states' residents are represented. This determines which states' laws apply to you. Our Privacy Law Calculator can help you assess applicability for comprehensive privacy laws, and the same jurisdictional analysis applies to breach notification.

Step 2: Plan for the Strictest Deadline

If you operate in California or Florida, you're looking at a 30-day clock. Build your incident response plan around that timeline. Key milestones within 30 days should include: discovery and containment (days 1–3), forensic investigation (days 4–14), impact assessment and legal review (days 10–20), notification drafting and delivery (days 15–30).

Step 3: Prepare Template Notifications

Pre-draft notification templates for each state that include the required elements. Most states require: a description of the incident, the types of information compromised, what the organization is doing in response, contact information for the reporting entity, and information about consumer reporting agencies and identity theft protection.

Step 4: Know Your AG Reporting Portals

Many state AGs have moved to online submission portals. Familiarize your legal team with these portals before an incident occurs. California, New York, Massachusetts, and Texas all have online reporting systems that require specific fields and formats.

Step 5: Document Everything

Maintain a detailed incident log from the moment a potential breach is discovered. This documentation protects you if regulators later question whether you met notification deadlines or conducted a thorough investigation. For state-specific compliance checklists, use our interactive tools.

2026 Trends in Breach Notification

Several trends are shaping breach notification compliance in 2026:

  • Shorter timelines — California's move to 30 days (from "most expedient time possible") signals a trend toward fixed, shorter deadlines. More states are likely to follow.
  • Expanded data definitions — Biometric data, online credentials, and health data are being added to breach notification triggers across states.
  • Stricter AG reporting — States are lowering the thresholds for AG notification and requiring more detailed incident reports.
  • Enforcement growth — With 20+ states now having comprehensive privacy laws and dedicated enforcement budgets, the risk of enforcement actions following a breach has increased significantly. See our enforcement action tracker and penalties guide.
  • Universal opt-out interaction — For organizations subject to both breach notification and comprehensive privacy laws, a breach can trigger obligations under both regimes. See our universal opt-out compliance guide.

Penalties for Non-Compliance

Failing to comply with breach notification requirements can result in significant penalties:

  • California: Up to $7,988 per violation (per affected individual); AG enforcement
  • Florida: Up to $500,000 per breach; $1,000/day for first 30 days, $50,000/day thereafter for late notification
  • New York: Up to $5,000 per violation under the SHIELD Act; AG enforcement plus private right of action for certain claims
  • Texas: Up to $100 per individual per day of delayed notification, capped at $250,000 per breach
  • Connecticut: Up to $5,000 per violation under the CUTPA

Beyond statutory penalties, businesses face class action litigation, reputational damage, and loss of customer trust. Timely and compliant notification is always less costly than the alternative.

Frequently Asked Questions

Is there a federal data breach notification law?

No. Despite numerous proposals over the years, the US does not have a comprehensive federal data breach notification law as of 2026. Sector-specific federal laws exist — HIPAA for healthcare, the Gramm-Leach-Bliley Act for financial institutions, and the FTC Act for general unfair/deceptive practices — but there is no single federal standard. Businesses must comply with each applicable state's law.

Does encryption prevent the need to notify?

In most states, yes — if the compromised data was encrypted and the encryption key was not also compromised, notification is not required. This is often called the "encryption safe harbor." However, some states have nuances: a few require notification even for encrypted data if there's reason to believe the encryption was compromised, and California requires redaction or encryption to be "in a manner that renders the name or the information unusable."

How do state breach notification laws interact with the CCPA and other comprehensive privacy laws?

They're separate but complementary. A data breach can trigger obligations under both: breach notification laws require you to notify affected individuals and regulators about the incident, while comprehensive privacy laws (like the CCPA) may provide a private right of action for the underlying security failure. In California, the CCPA's data breach private right of action (§ 1798.150) allows consumers to sue for $100–$750 per incident when a breach results from a business's failure to implement reasonable security measures.

Do I need to notify if only employee data was breached?

Yes. Breach notification laws generally apply to any personal information, regardless of whether the individuals are customers, employees, contractors, or any other category. Many comprehensive privacy laws exempt employee data from their scope, but breach notification laws typically do not make this distinction.

Which US states publish data breach notifications publicly?

At least one does so as a searchable, bulk-downloadable database: California. The California Attorney General publishes the sample breach notices it receives at oag.ca.gov/privacy/databreach/list, searchable by organization name and date range and downloadable as a CSV (retrieved August 13, 2026). Texas is the other confirmed publisher, and it is confirmed a different way: the duty to publish is written into the statute itself. Business & Commerce Code § 521.053(j) orders the attorney general to post a listing of every breach report it receives, to update it within 30 days of each new report, and to remove an entry on its first anniversary if that filer has reported nothing further — so a Texas filing is public, but not permanently so. Two states answer in the opposite direction, and again the statute is what answers: Alabama and Oklahoma shield the filing by law. Ala. Code § 8-38-6(d) puts anything the filer marks confidential outside every open-records, freedom-of-information and other public-record disclosure law, and Okla. Stat. tit. 24, § 163(F) requires personal information submitted to the attorney general to be kept confidential (both retrieved August 13, 2026). The "Filing published?" column separates all four cases on purpose: Yes — public database means we loaded the registry ourselves, the statute requires a public listing means we read the provision that requires it but the listing sits behind a portal that refused an automated request, Shielded means we read a provision putting filed material outside public records, and Not verified means none of those. Several other state attorneys general are widely reported to maintain public breach listings; their pages refused automated requests when this update was compiled, so they read Not verified rather than no. If you need to know whether a specific state will publish your filing, load that state's AG website before you send the notice — not after.

Do I have to notify the state attorney general, and at what number of affected residents?

Usually yes, but the trigger is not uniform, there is no single national number, and in a handful of verified states the answer is no at any headcount. The lowest numeric floor we have read in a primary source is the District of Columbia's, at 50 or more District residents (D.C. Code § 28-3852(b-1), retrieved August 13, 2026). Of the 20 jurisdictions verified from primary sources above, the numeric floors run 50 or more residents (District of Columbia); 250 or more residents (Texas); more than 250 residents (North Dakota and South Dakota); 500 or more residents (Oklahoma); more than 500 residents (California, Delaware, Iowa and Washington); more than 1,000 residents (Alabama, Arizona and New Mexico); more than 1,000 people notified (Hawaii and South Carolina). Maine, New York and Virginia set no minimum at all: any reportable breach triggers the regulator notice. Kansas, Minnesota and Wyoming impose no regulator-notice duty at any headcount. Watch the comparator rather than the number: a breach touching exactly 250 people is reportable in Texas and not in North Dakota, and exactly 500 is reportable in Oklahoma and not in California. The full per-state matrix, with the recipient and deadline for each, is in the table above. Because the floors differ this widely, the recipient is not always the attorney general, and two states count people notified rather than their own residents, the safe operating assumption for a multi-state breach is that some jurisdiction's regulator must be notified even when the affected headcount looks small — so build regulator notice into the response plan by default and check each applicable statute for its own trigger.

Which states have the strictest data breach notification deadlines?

As of 2026, the strictest fixed deadlines are 30 calendar days, found in California (effective January 1, 2026 under SB 446), Colorado, Florida, and Washington. Rhode Island, Ohio, Arizona, and Wisconsin use a 45-day deadline, and roughly 20 states — including Texas (60 days), Connecticut (60 days), and a broad group requiring notice "in the most expedient time possible and without unreasonable delay" with no fixed day-count (Illinois, New York, Michigan, and others) — round out the rest. Businesses operating nationwide should build their incident-response timeline around the 30-day floor, then notify each state Attorney General according to its own resident-count threshold.

This article provides general educational information and is not legal advice. Consult qualified legal counsel for guidance specific to your organization. Published: March 29, 2026. Last verified: August 13, 2026.

Put This Guide Into PracticeSponsored

Termly can turn the requirements above into a maintained privacy policy, consent banner, and data-request workflow.

Start Free with Termly