Reference Source

US state data breach notification deadlines by state

US state-by-state data breach notification requirements: how many days a business has to notify affected residents after discovering a breach, the deadline and resident-count threshold for notifying the state Attorney General (or equivalent regulator), and the resident-count threshold that triggers notice to consumer reporting agencies. Answers 'how many days to notify after data breach', 'data breach notification deadline [state]', 'when must a company notify the attorney general of a data breach', 'what is the breach notification law in [state]', 'how long does a company have to report a data breach to customers', 'data breach notification requirements by state'. Hard deadlines range from 30 days (California, Florida, Washington) through 45 days (Oregon, Wisconsin) to 60 days (Texas); most states require 'most expedient time possible and without unreasonable delay' with no hard number. No single government page states all 50 states together — each state's statute is the authority — which is why aggregator surveys (Foley, IAPP, Perkins Coie) exist but cite the statutes we read directly. Each record covers one state and its primary breach notification statute.

Records18
Sources18
Verified
Review by
LicenceState statutes are edicts of government and are not subject to copyright under 17 U.S.C. § 105 (for federal government works) and the equivalent edict-of-government doctrine applied by courts to state legislative materials (Building Officials v. Code Technology, 628 F.2d 730 (1st Cir. 1980); Georgia v. Public.Resource.Org, 590 U.S. 255 (2020)). Short verbatim quotes taken from each statute, attributed to the state and statute citation, for the purpose of stating a fact about the law. No compilation is reproduced wholesale. Facts are not copyrightable (Feist, 1991).

The data

StateStatute citationIndividual notice deadlineIndividual notice hard deadline (days)AG / regulator notice deadlineAG notice resident-count triggerConsumer reporting agency notice trigger (residents)Encryption safe harborNotes
ArizonaA.R.S. § 18-552within forty-five days after the determination45within forty-five days after the determinationmore than one thousand individualsmore than one thousand individualsyesGLBA-covered entities and HIPAA covered entities and business associates are exempt (subsection N). AG notice and notice to the three largest nationwide consumer reporting agencies are both required at the same threshold: more than one thousand individuals affected. Notice to both the attorney general and the Director of the Arizona Department of Homeland Security is required.
CaliforniaCal. Civ. Code § 1798.82within 30 calendar days of discovery or notification of the data breach30within 15 calendar days of notifying affected consumers of the security breach500 California residentsyesGLBA-regulated entities and HIPAA-covered entities are not expressly exempted by this section. The safe harbor covers unencrypted personal information — encrypted personal information is outside the definition of breach unless the encryption key was also acquired.
ColoradoC.R.S. § 6-1-716in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred30in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurredfive hundred Colorado residents or moremore than one thousand Colorado residentsyesRecord taken from the Colorado Revised Statutes 2023 Title 6 text (C.R.S. § 6-1-716). The 30-day deadline and 500-resident AG threshold were added by HB 21-1130 (2021 session). GLBA-covered entities are exempt from the CRA notice requirement (subsection 2(d)). CRA notice requires anticipated date of notification and approximate number of residents, not names.
FloridaFla. Stat. § 501.171no later than 30 days after the determination of a breach or reason to believe a breach occurred30no later than 30 days after the determination of the breach or reason to believe a breach occurred500 or more individuals in this statemore than 1,000 individuals at a single timeyesNotice goes to the 'department' (Florida Department of Legal Affairs), not the Attorney General by name. GLBA-regulated entities that comply with federal regulator notice procedures are deemed in compliance. CRA notice threshold of 1,000 is stated in subsection (5).
Illinois815 ILCS 530/10in the most expedient time possible and without unreasonable delaymore than 500 Illinois residentsyesThe private-entity rule (§ 10) requires AG notice for breaches affecting more than 500 Illinois residents; notice must be made in the most expedient time possible and without unreasonable delay but no later than when notice is sent to consumers. State agency rule (§ 12) has a separate, stricter requirement: the state agency must notify the AG within 45 days of discovery or when it provides notice to consumers, whichever is sooner. HIPAA-covered entities and business associates that comply with § 50 are exempt from the AG notice requirement in § 10.
MassachusettsM.G.L. c. 93H § 3as soon as practicable and without unreasonable delayas soon as practicable and without unreasonable delayyesNotice must be provided concurrently to the Attorney General and the Director of Consumer Affairs and Business Regulation, not just the AG. The Director then identifies relevant consumer reporting agencies and state agencies, and the notifying party must also notify those identified agencies as soon as practicable and without unreasonable delay. GLBA-compliant financial institutions are not explicitly exempted in this section.
MinnesotaMinn. Stat. § 325E.61in the most expedient time possible and without unreasonable delaymore than 500 persons at one timeyesCRA notice must be provided within 48 hours of discovering circumstances requiring notification of more than 500 persons. Financial institutions as defined by 15 U.S.C. § 6809(3) are exempt (Subd. 4). The attorney general enforces this section under Minn. Stat. § 8.31 but no separate AG notification deadline is stated in § 325E.61.
MissouriRSMo § 407.1500without unreasonable delaymore than one thousand consumersmore than one thousand consumersyesAG notice and CRA notice are triggered simultaneously at the same threshold (more than 1,000 consumers). Financial institutions compliant with GLB Act, Federal Interagency Guidance, or NCUA 12 CFR Part 748 are deemed in compliance and effectively exempt from this section's requirements.
NevadaNRS 603A.220in the most expedient time possible and without unreasonable delaymore than 1,000 persons at any one timeyesNo AG notification requirement and no numeric hard deadline are stated in NRS 603A.220. GLBA-covered entities in compliance with GLB privacy and security requirements are deemed in compliance. Persons licensed under NRS Chapter 675 are exempt (subsection 7).
New YorkN.Y. Gen. Bus. Law § 899-aain the most expedient time possible and without unreasonable delaywithout delaying notice to affected New York residentsmore than five thousand New York residentsyesAG notice (and notice to the Department of State and Division of State Police) is required whenever any New York residents are to be notified — there is no resident-count threshold for AG notice. The CRA notice threshold is 5,000 residents notified at one time. GLBA- and HIPAA-regulated entities are exempt from the individual notice requirement but must still notify the AG, Department of State, and Division of State Police.
North CarolinaG.S. § 75-65without unreasonable delaywithout unreasonable delaymore than 1,000 persons at one timeyesAG notice goes to the 'Consumer Protection Division of the Attorney General's Office', not the AG directly. AG notice is required for every breach that triggers individual notice (subsection e1), with no minimum resident-count threshold for AG notification. The CRA notice at 1,000+ (subsection f) also requires concurrent AG notice.
OhioORC § 1347.12in the most expedient time possible but not later than forty-five days following its discovery or notification of the breach in the security of the system45more than one thousand residents of this state involved in a single occurrence of a breach of the security of the systemyesCRITICAL SCOPE LIMIT: This section (ORC § 1347.12) applies ONLY to state agencies and agencies of political subdivisions — not to private businesses. The private-sector Ohio breach notification law is at ORC § 1349.19. No AG notification requirement is stated in this section (the AG may bring enforcement actions under ORC § 1349.191 and § 1349.192). CRA notice is required 'without unreasonable delay' when more than 1,000 residents are affected.
OregonORS 646A.604in the most expeditious manner possible, without unreasonable delay, but not later than 45 days after discovering or receiving notification of the breach of security45either in writing or electronicallyexceeds 250more than 1,000 consumersyesThe AG threshold applies to consumers to whom the covered entity must send individual notice (i.e., 250+ affected consumers). The CRA notice (at 1,000+) must be given without unreasonable delay and must not delay individual consumer notification. Vendors have a separate 10-day deadline to notify covered entities of a breach.
South CarolinaS.C. Code Ann. § 39-1-90in the most expedient time possible and without unreasonable delaymore than one thousand personsmore than one thousand personsyesThe AG notice goes to the Consumer Protection Division of the Department of Consumer Affairs, not directly the Attorney General. AG and CRA thresholds are the same (1,000 persons). Banks and financial institutions compliant with Gramm-Leach-Bliley Act or the federal Interagency Guidance are explicitly exempt (subsections I and J).
TexasTex. Bus. & Com. Code § 521.053not later than the 60th day after the date on which the person determines that the breach occurred60not later than the 60th day after the date on which the person determines that the breach occurredat least 250 residents of this stateyesSource is HB 4390 (86th Legislature, 2019), the enrolled bill that amended § 521.053. The individual notice deadline text includes a bracketed deletion '[as quickly as possible]' reflecting the bill's amendment of existing law.
VirginiaVa. Code § 18.2-186.6without unreasonable delaywithout unreasonable delaymore than 1,000 persons at one timeyesAG notice (Office of the Attorney General) is concurrent with individual notice — no separate threshold for AG notification; both are required 'without unreasonable delay'. CRA notice at 1,000+ also triggers concurrent AG notice. GLBA-regulated financial institutions are exempt under subsection G. Statute applies only where breach 'causes, or the individual or entity reasonably believes has caused or will cause, identity theft or another fraud'.
WashingtonRCW 19.255.010no more than thirty calendar days after the breach was discovered30no more than thirty days after the breach was discoveredmore than five hundred Washington residentsyes
WisconsinWis. Stat. § 134.98within a reasonable time, not to exceed 45 days after the entity learns of the acquisition of personal information451,000 or more individualsyesNo AG notification requirement is stated in the statute. GLBA-covered entities in compliance with GLB privacy and security requirements are exempt (subsection 3m(a)). HIPAA-covered entities in compliance with 45 CFR Part 164 are exempt (subsection 3m(b)). CRA notice must be made 'without unreasonable delay' when 1,000 or more individuals are affected.

Where this came from

Every record above links the page it was taken from and quotes the sentence that states it. These are the 18 sources this dataset was assembled from.

Machine-readable

18 records. last verified against source . due for re-check by .

Licence. State statutes are edicts of government and are not subject to copyright under 17 U.S.C. § 105 (for federal government works) and the equivalent edict-of-government doctrine applied by courts to state legislative materials (Building Officials v. Code Technology, 628 F.2d 730 (1st Cir. 1980); Georgia v. Public.Resource.Org, 590 U.S. 255 (2020)). Short verbatim quotes taken from each statute, attributed to the state and statute citation, for the purpose of stating a fact about the law. No compilation is reproduced wholesale. Facts are not copyrightable (Feist, 1991).