US state data breach notification deadlines by state
US state-by-state data breach notification requirements: how many days a business has to notify affected residents after discovering a breach, the deadline and resident-count threshold for notifying the state Attorney General (or equivalent regulator), and the resident-count threshold that triggers notice to consumer reporting agencies. Answers 'how many days to notify after data breach', 'data breach notification deadline [state]', 'when must a company notify the attorney general of a data breach', 'what is the breach notification law in [state]', 'how long does a company have to report a data breach to customers', 'data breach notification requirements by state'. Hard deadlines range from 30 days (California, Florida, Washington) through 45 days (Oregon, Wisconsin) to 60 days (Texas); most states require 'most expedient time possible and without unreasonable delay' with no hard number. No single government page states all 50 states together — each state's statute is the authority — which is why aggregator surveys (Foley, IAPP, Perkins Coie) exist but cite the statutes we read directly. Each record covers one state and its primary breach notification statute.
The data
| State | Statute citation | Individual notice deadline | Individual notice hard deadline (days) | AG / regulator notice deadline | AG notice resident-count trigger | Consumer reporting agency notice trigger (residents) | Encryption safe harbor | Notes |
|---|---|---|---|---|---|---|---|---|
| Arizona | A.R.S. § 18-552 | within forty-five days after the determination | 45 | within forty-five days after the determination | more than one thousand individuals | more than one thousand individuals | yes | GLBA-covered entities and HIPAA covered entities and business associates are exempt (subsection N). AG notice and notice to the three largest nationwide consumer reporting agencies are both required at the same threshold: more than one thousand individuals affected. Notice to both the attorney general and the Director of the Arizona Department of Homeland Security is required. |
| California | Cal. Civ. Code § 1798.82 | within 30 calendar days of discovery or notification of the data breach | 30 | within 15 calendar days of notifying affected consumers of the security breach | 500 California residents | yes | GLBA-regulated entities and HIPAA-covered entities are not expressly exempted by this section. The safe harbor covers unencrypted personal information — encrypted personal information is outside the definition of breach unless the encryption key was also acquired. | |
| Colorado | C.R.S. § 6-1-716 | in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred | 30 | in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred | five hundred Colorado residents or more | more than one thousand Colorado residents | yes | Record taken from the Colorado Revised Statutes 2023 Title 6 text (C.R.S. § 6-1-716). The 30-day deadline and 500-resident AG threshold were added by HB 21-1130 (2021 session). GLBA-covered entities are exempt from the CRA notice requirement (subsection 2(d)). CRA notice requires anticipated date of notification and approximate number of residents, not names. |
| Florida | Fla. Stat. § 501.171 | no later than 30 days after the determination of a breach or reason to believe a breach occurred | 30 | no later than 30 days after the determination of the breach or reason to believe a breach occurred | 500 or more individuals in this state | more than 1,000 individuals at a single time | yes | Notice goes to the 'department' (Florida Department of Legal Affairs), not the Attorney General by name. GLBA-regulated entities that comply with federal regulator notice procedures are deemed in compliance. CRA notice threshold of 1,000 is stated in subsection (5). |
| Illinois | 815 ILCS 530/10 | in the most expedient time possible and without unreasonable delay | more than 500 Illinois residents | yes | The private-entity rule (§ 10) requires AG notice for breaches affecting more than 500 Illinois residents; notice must be made in the most expedient time possible and without unreasonable delay but no later than when notice is sent to consumers. State agency rule (§ 12) has a separate, stricter requirement: the state agency must notify the AG within 45 days of discovery or when it provides notice to consumers, whichever is sooner. HIPAA-covered entities and business associates that comply with § 50 are exempt from the AG notice requirement in § 10. | |||
| Massachusetts | M.G.L. c. 93H § 3 | as soon as practicable and without unreasonable delay | as soon as practicable and without unreasonable delay | yes | Notice must be provided concurrently to the Attorney General and the Director of Consumer Affairs and Business Regulation, not just the AG. The Director then identifies relevant consumer reporting agencies and state agencies, and the notifying party must also notify those identified agencies as soon as practicable and without unreasonable delay. GLBA-compliant financial institutions are not explicitly exempted in this section. | |||
| Minnesota | Minn. Stat. § 325E.61 | in the most expedient time possible and without unreasonable delay | more than 500 persons at one time | yes | CRA notice must be provided within 48 hours of discovering circumstances requiring notification of more than 500 persons. Financial institutions as defined by 15 U.S.C. § 6809(3) are exempt (Subd. 4). The attorney general enforces this section under Minn. Stat. § 8.31 but no separate AG notification deadline is stated in § 325E.61. | |||
| Missouri | RSMo § 407.1500 | without unreasonable delay | more than one thousand consumers | more than one thousand consumers | yes | AG notice and CRA notice are triggered simultaneously at the same threshold (more than 1,000 consumers). Financial institutions compliant with GLB Act, Federal Interagency Guidance, or NCUA 12 CFR Part 748 are deemed in compliance and effectively exempt from this section's requirements. | ||
| Nevada | NRS 603A.220 | in the most expedient time possible and without unreasonable delay | more than 1,000 persons at any one time | yes | No AG notification requirement and no numeric hard deadline are stated in NRS 603A.220. GLBA-covered entities in compliance with GLB privacy and security requirements are deemed in compliance. Persons licensed under NRS Chapter 675 are exempt (subsection 7). | |||
| New York | N.Y. Gen. Bus. Law § 899-aa | in the most expedient time possible and without unreasonable delay | without delaying notice to affected New York residents | more than five thousand New York residents | yes | AG notice (and notice to the Department of State and Division of State Police) is required whenever any New York residents are to be notified — there is no resident-count threshold for AG notice. The CRA notice threshold is 5,000 residents notified at one time. GLBA- and HIPAA-regulated entities are exempt from the individual notice requirement but must still notify the AG, Department of State, and Division of State Police. | ||
| North Carolina | G.S. § 75-65 | without unreasonable delay | without unreasonable delay | more than 1,000 persons at one time | yes | AG notice goes to the 'Consumer Protection Division of the Attorney General's Office', not the AG directly. AG notice is required for every breach that triggers individual notice (subsection e1), with no minimum resident-count threshold for AG notification. The CRA notice at 1,000+ (subsection f) also requires concurrent AG notice. | ||
| Ohio | ORC § 1347.12 | in the most expedient time possible but not later than forty-five days following its discovery or notification of the breach in the security of the system | 45 | more than one thousand residents of this state involved in a single occurrence of a breach of the security of the system | yes | CRITICAL SCOPE LIMIT: This section (ORC § 1347.12) applies ONLY to state agencies and agencies of political subdivisions — not to private businesses. The private-sector Ohio breach notification law is at ORC § 1349.19. No AG notification requirement is stated in this section (the AG may bring enforcement actions under ORC § 1349.191 and § 1349.192). CRA notice is required 'without unreasonable delay' when more than 1,000 residents are affected. | ||
| Oregon | ORS 646A.604 | in the most expeditious manner possible, without unreasonable delay, but not later than 45 days after discovering or receiving notification of the breach of security | 45 | either in writing or electronically | exceeds 250 | more than 1,000 consumers | yes | The AG threshold applies to consumers to whom the covered entity must send individual notice (i.e., 250+ affected consumers). The CRA notice (at 1,000+) must be given without unreasonable delay and must not delay individual consumer notification. Vendors have a separate 10-day deadline to notify covered entities of a breach. |
| South Carolina | S.C. Code Ann. § 39-1-90 | in the most expedient time possible and without unreasonable delay | more than one thousand persons | more than one thousand persons | yes | The AG notice goes to the Consumer Protection Division of the Department of Consumer Affairs, not directly the Attorney General. AG and CRA thresholds are the same (1,000 persons). Banks and financial institutions compliant with Gramm-Leach-Bliley Act or the federal Interagency Guidance are explicitly exempt (subsections I and J). | ||
| Texas | Tex. Bus. & Com. Code § 521.053 | not later than the 60th day after the date on which the person determines that the breach occurred | 60 | not later than the 60th day after the date on which the person determines that the breach occurred | at least 250 residents of this state | yes | Source is HB 4390 (86th Legislature, 2019), the enrolled bill that amended § 521.053. The individual notice deadline text includes a bracketed deletion '[as quickly as possible]' reflecting the bill's amendment of existing law. | |
| Virginia | Va. Code § 18.2-186.6 | without unreasonable delay | without unreasonable delay | more than 1,000 persons at one time | yes | AG notice (Office of the Attorney General) is concurrent with individual notice — no separate threshold for AG notification; both are required 'without unreasonable delay'. CRA notice at 1,000+ also triggers concurrent AG notice. GLBA-regulated financial institutions are exempt under subsection G. Statute applies only where breach 'causes, or the individual or entity reasonably believes has caused or will cause, identity theft or another fraud'. | ||
| Washington | RCW 19.255.010 | no more than thirty calendar days after the breach was discovered | 30 | no more than thirty days after the breach was discovered | more than five hundred Washington residents | yes | ||
| Wisconsin | Wis. Stat. § 134.98 | within a reasonable time, not to exceed 45 days after the entity learns of the acquisition of personal information | 45 | 1,000 or more individuals | yes | No AG notification requirement is stated in the statute. GLBA-covered entities in compliance with GLB privacy and security requirements are exempt (subsection 3m(a)). HIPAA-covered entities in compliance with 45 CFR Part 164 are exempt (subsection 3m(b)). CRA notice must be made 'without unreasonable delay' when 1,000 or more individuals are affected. |
Where this came from
Every record above links the page it was taken from and quotes the sentence that states it. These are the 18 sources this dataset was assembled from.
- azleg.govhttps://www.azleg.gov/ars/18/00552.htm
- leginfo.legislature.ca.govhttps://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?sectionNum=1798.82.&lawCode=CIV
- leg.colorado.govhttps://leg.colorado.gov/sites/default/files/images/olls/crs2023-title-06.pdf
- flsenate.govhttps://www.flsenate.gov/Laws/Statutes/2023/501.171
- ilga.govhttps://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=2702&ChapterID=67
- malegislature.govhttps://malegislature.gov/Laws/GeneralLaws/PartI/TitleXV/Chapter93H/Section3
- revisor.mn.govhttps://www.revisor.mn.gov/statutes/cite/325E.61
- revisor.mo.govhttps://revisor.mo.gov/main/OneSection.aspx?section=407.1500&bid=52524&hl=
- leg.state.nv.ushttps://www.leg.state.nv.us/NRS/NRS-603A.html#NRS603ASec220
- legislation.nysenate.govhttps://legislation.nysenate.gov/pdf/bills/2019/S5575B
- ncleg.nethttps://www.ncleg.net/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-65.html
- codes.ohio.govhttps://codes.ohio.gov/ohio-revised-code/section-1347.12
- oregonlegislature.govhttps://www.oregonlegislature.gov/bills_laws/ors/ors646a.html
- scstatehouse.govhttps://www.scstatehouse.gov/code/t39c001.php
- capitol.texas.govhttps://capitol.texas.gov/tlodocs/86R/billtext/pdf/HB04390F.pdf
- law.lis.virginia.govhttps://law.lis.virginia.gov/vacode/title18.2/chapter6/section18.2-186.6/
- app.leg.wa.govhttps://app.leg.wa.gov/rcw/default.aspx?cite=19.255.010
- docs.legis.wisconsin.govhttps://docs.legis.wisconsin.gov/statutes/statutes/134/98
Machine-readable
- data.jsonThe whole dataset — every record with its source URL and source quote.
- Open Knowledge Format bundleOne JSON object per line — every record's frontmatter and quoted span exactly as it is held here, in one fetch.
- How this is made and checkedWhat "verified against source" does and does not mean.