{
  "name": "US state data breach notification deadlines by state",
  "description": "US state-by-state data breach notification requirements: how many days a business has to notify affected residents after discovering a breach, the deadline and resident-count threshold for notifying the state Attorney General (or equivalent regulator), and the resident-count threshold that triggers notice to consumer reporting agencies. Answers 'how many days to notify after data breach', 'data breach notification deadline [state]', 'when must a company notify the attorney general of a data breach', 'what is the breach notification law in [state]', 'how long does a company have to report a data breach to customers', 'data breach notification requirements by state'. Hard deadlines range from 30 days (California, Florida, Washington) through 45 days (Oregon, Wisconsin) to 60 days (Texas); most states require 'most expedient time possible and without unreasonable delay' with no hard number. No single government page states all 50 states together \u2014 each state's statute is the authority \u2014 which is why aggregator surveys (Foley, IAPP, Perkins Coie) exist but cite the statutes we read directly. Each record covers one state and its primary breach notification statute.",
  "url": "https://referencesource.org/data-breach-notification-clocks/",
  "licence": "State statutes are edicts of government and are not subject to copyright under 17 U.S.C. \u00a7 105 (for federal government works) and the equivalent edict-of-government doctrine applied by courts to state legislative materials (Building Officials v. Code Technology, 628 F.2d 730 (1st Cir. 1980); Georgia v. Public.Resource.Org, 590 U.S. 255 (2020)). Short verbatim quotes taken from each statute, attributed to the state and statute citation, for the purpose of stating a fact about the law. No compilation is reproduced wholesale. Facts are not copyrightable (Feist, 1991).",
  "last_verified": "2026-08-18",
  "stale_after": "2027-02-14",
  "sources": [
    "https://www.azleg.gov/ars/18/00552.htm",
    "https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?sectionNum=1798.82.&lawCode=CIV",
    "https://leg.colorado.gov/sites/default/files/images/olls/crs2023-title-06.pdf",
    "https://www.flsenate.gov/Laws/Statutes/2023/501.171",
    "https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=2702&ChapterID=67",
    "https://malegislature.gov/Laws/GeneralLaws/PartI/TitleXV/Chapter93H/Section3",
    "https://www.revisor.mn.gov/statutes/cite/325E.61",
    "https://revisor.mo.gov/main/OneSection.aspx?section=407.1500&bid=52524&hl=",
    "https://www.leg.state.nv.us/NRS/NRS-603A.html#NRS603ASec220",
    "https://legislation.nysenate.gov/pdf/bills/2019/S5575B",
    "https://www.ncleg.net/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-65.html",
    "https://codes.ohio.gov/ohio-revised-code/section-1347.12",
    "https://www.oregonlegislature.gov/bills_laws/ors/ors646a.html",
    "https://www.scstatehouse.gov/code/t39c001.php",
    "https://capitol.texas.gov/tlodocs/86R/billtext/pdf/HB04390F.pdf",
    "https://law.lis.virginia.gov/vacode/title18.2/chapter6/section18.2-186.6/",
    "https://app.leg.wa.gov/rcw/default.aspx?cite=19.255.010",
    "https://docs.legis.wisconsin.gov/statutes/statutes/134/98"
  ],
  "records": [
    {
      "state": "Arizona",
      "statute_citation": "A.R.S. \u00a7 18-552",
      "individual_notice_deadline": "within forty-five days after the determination",
      "individual_notice_days": "45",
      "ag_notice_deadline": "within forty-five days after the determination",
      "ag_notice_threshold": "more than one thousand individuals",
      "cra_notice_threshold": "more than one thousand individuals",
      "encryption_safe_harbor": "yes",
      "notes": "GLBA-covered entities and HIPAA covered entities and business associates are exempt (subsection N). AG notice and notice to the three largest nationwide consumer reporting agencies are both required at the same threshold: more than one thousand individuals affected. Notice to both the attorney general and the Director of the Arizona Department of Homeland Security is required.",
      "id": "arizona",
      "url": "https://referencesource.org/data-breach-notification-clocks/arizona/",
      "source": "https://www.azleg.gov/ars/18/00552.htm",
      "source_quote": "B. If the investigation results in a determination that there has been a security system breach, the person that owns or licenses the computerized data, within forty-five days after the determination, shall: 1. Notify the individuals affected pursuant to subsection E of this section and subject to the needs of law enforcement as provided in subsection D of this section. 2. If the breach requires notification of more than one thousand individuals, notify both: (a) The three largest nationwide consumer reporting agencies. (b) The attorney general and the director of the Arizona department of homeland security, in writing, in a form prescribed by rule or order of the attorney general or the director of the Arizona department of homeland security or by providing the attorney general or the director of the Arizona department of homeland security with a copy of the notification provided pursuant to paragraph 1 of this subsection.",
      "verified_fields": [
        "ag_notice_deadline",
        "ag_notice_threshold",
        "cra_notice_threshold",
        "individual_notice_deadline",
        "state"
      ],
      "derived_fields": [
        "encryption_safe_harbor",
        "individual_notice_days",
        "notes"
      ]
    },
    {
      "state": "California",
      "statute_citation": "Cal. Civ. Code \u00a7 1798.82",
      "individual_notice_deadline": "within 30 calendar days of discovery or notification of the data breach",
      "individual_notice_days": "30",
      "ag_notice_deadline": "within 15 calendar days of notifying affected consumers of the security breach",
      "ag_notice_threshold": "500 California residents",
      "encryption_safe_harbor": "yes",
      "notes": "GLBA-regulated entities and HIPAA-covered entities are not expressly exempted by this section. The safe harbor covers unencrypted personal information \u2014 encrypted personal information is outside the definition of breach unless the encryption key was also acquired.",
      "id": "california",
      "url": "https://referencesource.org/data-breach-notification-clocks/california/",
      "source": "https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?sectionNum=1798.82.&lawCode=CIV",
      "source_quote": "500 California residents as a result of a single breach of the security system shall electronically submit a single sample copy of that security breach notification, excluding any personally identifiable information, to the Attorney General within 15 calendar days of notifying affected consumers of the security breach.",
      "verified_fields": [
        "ag_notice_deadline",
        "ag_notice_threshold",
        "state"
      ],
      "derived_fields": [
        "encryption_safe_harbor",
        "individual_notice_days",
        "notes"
      ]
    },
    {
      "state": "Colorado",
      "statute_citation": "C.R.S. \u00a7 6-1-716",
      "individual_notice_deadline": "in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred",
      "individual_notice_days": "30",
      "ag_notice_deadline": "in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred",
      "ag_notice_threshold": "five hundred Colorado residents or more",
      "cra_notice_threshold": "more than one thousand Colorado residents",
      "encryption_safe_harbor": "yes",
      "notes": "Record taken from the Colorado Revised Statutes 2023 Title 6 text (C.R.S. \u00a7 6-1-716). The 30-day deadline and 500-resident AG threshold were added by HB 21-1130 (2021 session). GLBA-covered entities are exempt from the CRA notice requirement (subsection 2(d)). CRA notice requires anticipated date of notification and approximate number of residents, not names.",
      "id": "colorado",
      "url": "https://referencesource.org/data-breach-notification-clocks/colorado/",
      "source": "https://leg.colorado.gov/sites/default/files/images/olls/crs2023-title-06.pdf",
      "source_quote": "A covered entity that maintains, owns, or licenses computerized data that includes personal information about a resident of Colorado shall, when it becomes aware that a security breach may have occurred, conduct in good faith a prompt investigation to determine the likelihood that personal information has been or will be misused. The covered entity shall give notice to the affected Colorado residents unless the investigation determines that the misuse of information about a Colorado resident has not occurred and is not reasonably likely to occur. Notice must be made in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system.",
      "verified_fields": [
        "ag_notice_deadline",
        "individual_notice_deadline",
        "state"
      ],
      "derived_fields": [
        "encryption_safe_harbor",
        "individual_notice_days",
        "notes"
      ]
    },
    {
      "state": "Florida",
      "statute_citation": "Fla. Stat. \u00a7 501.171",
      "individual_notice_deadline": "no later than 30 days after the determination of a breach or reason to believe a breach occurred",
      "individual_notice_days": "30",
      "ag_notice_deadline": "no later than 30 days after the determination of the breach or reason to believe a breach occurred",
      "ag_notice_threshold": "500 or more individuals in this state",
      "cra_notice_threshold": "more than 1,000 individuals at a single time",
      "encryption_safe_harbor": "yes",
      "notes": "Notice goes to the 'department' (Florida Department of Legal Affairs), not the Attorney General by name. GLBA-regulated entities that comply with federal regulator notice procedures are deemed in compliance. CRA notice threshold of 1,000 is stated in subsection (5).",
      "id": "florida",
      "url": "https://referencesource.org/data-breach-notification-clocks/florida/",
      "source": "https://www.flsenate.gov/Laws/Statutes/2023/501.171",
      "source_quote": "(3)&#x2003; NOTICE TO DEPARTMENT OF SECURITY BREACH. &#x2014; (a)&#x2003; A covered entity shall provide notice to the department of any breach of security affecting 500 or more individuals in this state. Such notice must be provided to the department as expeditiously as practicable, but no later than 30 days after the determination of the breach or reason to believe a breach occurred. A covered entity may receive 15 additional days to provide notice as required in subsection (4) if good cause for delay is provided in writing to the department within 30 days after determination of the breach or reason to believe a breach occurred. (b)&#x2003; The written notice to the department must include: 1.&#x2003; A synopsis of the events surrounding the breach at the time notice is provided. 2.&#x2003; The number of individuals in this state who were or potentially have been affected by the breach. 3.&#x2003; Any services related to the breach being offered or scheduled to be offered, without charge, by the covered entity to individuals, and instructions as to how to use such services. 4.&#x2003; A copy of the notice required under subsection (4) or an explanation of the other actions taken pursuant to subsection (4). 5.&#x2003; The name, address, telephone number, and e-mail address of the employee or agent of the covered entity from whom additional information may be obtained about the breach. (c)&#x2003; The covered entity must provide the following information to the department upon its request: 1.&#x2003; A police report, incident report, or computer forensics report. 2.&#x2003; A copy of the policies in place regarding breaches. 3.&#x2003; Steps that have been taken to rectify the breach. (d)&#x2003; A covered entity may provide the department with supplemental information regarding a breach at any time. (e)&#x2003; For a covered entity that is the judicial branch, the Executive Office of the Governor, the Department of Financial Services, or the Department of Agriculture and Consumer Services, in lieu of providing the written notice to the department, the covered entity may post the information described in subparagraphs (b)1.-4. on an agency-managed website. (4)&#x2003; NOTICE TO INDIVIDUALS OF SECURITY BREACH. &#x2014; (a)&#x2003; A covered entity shall give notice to each individual in this state whose personal information was, or the covered entity reasonably believes to have been, accessed as a result of the breach. Notice to individuals shall be made as expeditiously as practicable and without unreasonable delay, taking into account the time necessary to allow the covered entity to determine the scope of the breach of security, to identify individuals affected by the breach, and to restore the reasonable integrity of the data system that was breached, but no later than 30 days after the determination of a breach or reason to believe a breach occurred unless subject to a delay authorized under paragraph (b) or waiver under paragraph (c).",
      "verified_fields": [
        "ag_notice_deadline",
        "ag_notice_threshold",
        "individual_notice_deadline"
      ],
      "derived_fields": [
        "encryption_safe_harbor",
        "individual_notice_days",
        "notes"
      ]
    },
    {
      "state": "Illinois",
      "statute_citation": "815 ILCS 530/10",
      "individual_notice_deadline": "in the most expedient time possible and without unreasonable delay",
      "ag_notice_threshold": "more than 500 Illinois residents",
      "encryption_safe_harbor": "yes",
      "notes": "The private-entity rule (\u00a7 10) requires AG notice for breaches affecting more than 500 Illinois residents; notice must be made in the most expedient time possible and without unreasonable delay but no later than when notice is sent to consumers. State agency rule (\u00a7 12) has a separate, stricter requirement: the state agency must notify the AG within 45 days of discovery or when it provides notice to consumers, whichever is sooner. HIPAA-covered entities and business associates that comply with \u00a7 50 are exempt from the AG notice requirement in \u00a7 10.",
      "id": "illinois",
      "url": "https://referencesource.org/data-breach-notification-clocks/illinois/",
      "source": "https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=2702&ChapterID=67",
      "source_quote": "(815 ILCS 530/10) Sec. 10. Notice of breach; notice to Attorney General. (a) Any data collector that owns or licenses personal information concerning an Illinois resident shall notify the resident at no charge that there has been a breach of the security of the system data following discovery or notification of the breach. The disclosure notification shall be made in the most expedient time possible and without unreasonable delay,",
      "verified_fields": [
        "individual_notice_deadline",
        "state",
        "statute_citation"
      ],
      "derived_fields": [
        "encryption_safe_harbor",
        "notes"
      ]
    },
    {
      "state": "Massachusetts",
      "statute_citation": "M.G.L. c. 93H \u00a7 3",
      "individual_notice_deadline": "as soon as practicable and without unreasonable delay",
      "ag_notice_deadline": "as soon as practicable and without unreasonable delay",
      "encryption_safe_harbor": "yes",
      "notes": "Notice must be provided concurrently to the Attorney General and the Director of Consumer Affairs and Business Regulation, not just the AG. The Director then identifies relevant consumer reporting agencies and state agencies, and the notifying party must also notify those identified agencies as soon as practicable and without unreasonable delay. GLBA-compliant financial institutions are not explicitly exempted in this section.",
      "id": "massachusetts",
      "url": "https://referencesource.org/data-breach-notification-clocks/massachusetts/",
      "source": "https://malegislature.gov/Laws/GeneralLaws/PartI/TitleXV/Chapter93H/Section3",
      "source_quote": "(b) A person or agency that owns or licenses data that includes personal information about a resident of the commonwealth, shall provide notice, as soon as practicable and without unreasonable delay, when such person or agency (1) knows or has reason to know of a breach of security or (2) when the person or agency knows or has reason to know that the personal information of such resident was acquired or used by an unauthorized person or used for an unauthorized purpose, to the attorney general, the director of consumer affairs and business regulation and to such resident, in accordance with this chapter.",
      "verified_fields": [
        "ag_notice_deadline",
        "individual_notice_deadline"
      ],
      "derived_fields": [
        "encryption_safe_harbor",
        "notes"
      ]
    },
    {
      "state": "Minnesota",
      "statute_citation": "Minn. Stat. \u00a7 325E.61",
      "individual_notice_deadline": "in the most expedient time possible and without unreasonable delay",
      "cra_notice_threshold": "more than 500 persons at one time",
      "encryption_safe_harbor": "yes",
      "notes": "CRA notice must be provided within 48 hours of discovering circumstances requiring notification of more than 500 persons. Financial institutions as defined by 15 U.S.C. \u00a7 6809(3) are exempt (Subd. 4). The attorney general enforces this section under Minn. Stat. \u00a7 8.31 but no separate AG notification deadline is stated in \u00a7 325E.61.",
      "id": "minnesota",
      "url": "https://referencesource.org/data-breach-notification-clocks/minnesota/",
      "source": "https://www.revisor.mn.gov/statutes/cite/325E.61",
      "source_quote": "Any person or business that conducts business in this state, and that owns or licenses data that includes personal information, shall disclose any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of this state whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in paragraph (c), or with any measures necessary to determine the scope of the breach, identify the individuals affected, and restore the reasonable integrity of the data system.",
      "verified_fields": [
        "individual_notice_deadline"
      ],
      "derived_fields": [
        "encryption_safe_harbor",
        "notes"
      ]
    },
    {
      "state": "Missouri",
      "statute_citation": "RSMo \u00a7 407.1500",
      "individual_notice_deadline": "without unreasonable delay",
      "ag_notice_threshold": "more than one thousand consumers",
      "cra_notice_threshold": "more than one thousand consumers",
      "encryption_safe_harbor": "yes",
      "notes": "AG notice and CRA notice are triggered simultaneously at the same threshold (more than 1,000 consumers). Financial institutions compliant with GLB Act, Federal Interagency Guidance, or NCUA 12 CFR Part 748 are deemed in compliance and effectively exempt from this section's requirements.",
      "id": "missouri",
      "url": "https://referencesource.org/data-breach-notification-clocks/missouri/",
      "source": "https://revisor.mo.gov/main/OneSection.aspx?section=407.1500&bid=52524&hl=",
      "source_quote": "Missouri shall provide notice to the affected consumer that there has been a breach of security following discovery or notification of the breach. The disclosure notification shall be: (a) Made without unreasonable delay;",
      "verified_fields": [
        "individual_notice_deadline",
        "state"
      ],
      "derived_fields": [
        "encryption_safe_harbor",
        "notes"
      ]
    },
    {
      "state": "Nevada",
      "statute_citation": "NRS 603A.220",
      "individual_notice_deadline": "in the most expedient time possible and without unreasonable delay",
      "cra_notice_threshold": "more than 1,000 persons at any one time",
      "encryption_safe_harbor": "yes",
      "notes": "No AG notification requirement and no numeric hard deadline are stated in NRS 603A.220. GLBA-covered entities in compliance with GLB privacy and security requirements are deemed in compliance. Persons licensed under NRS Chapter 675 are exempt (subsection 7).",
      "id": "nevada",
      "url": "https://referencesource.org/data-breach-notification-clocks/nevada/",
      "source": "https://www.leg.state.nv.us/NRS/NRS-603A.html#NRS603ASec220",
      "source_quote": "a data collector that owns or licenses computerized data which includes personal information shall disclose any breach of the security of the system data following discovery or notification of the breach to any resident of this State whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection 3, or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the system data.",
      "verified_fields": [
        "individual_notice_deadline"
      ],
      "derived_fields": [
        "encryption_safe_harbor",
        "notes"
      ]
    },
    {
      "state": "New York",
      "statute_citation": "N.Y. Gen. Bus. Law \u00a7 899-aa",
      "individual_notice_deadline": "in the most expedient time possible and without unreasonable delay",
      "ag_notice_deadline": "without delaying notice to affected New York residents",
      "cra_notice_threshold": "more than five thousand New York residents",
      "encryption_safe_harbor": "yes",
      "notes": "AG notice (and notice to the Department of State and Division of State Police) is required whenever any New York residents are to be notified \u2014 there is no resident-count threshold for AG notice. The CRA notice threshold is 5,000 residents notified at one time. GLBA- and HIPAA-regulated entities are exempt from the individual notice requirement but must still notify the AG, Department of State, and Division of State Police.",
      "id": "new-york",
      "url": "https://referencesource.org/data-breach-notification-clocks/new-york/",
      "source": "https://legislation.nysenate.gov/pdf/bills/2019/S5575B",
      "source_quote": "Such notice shall be made without delaying 24 notice to affected New York residents. 25 (b) In the event that more than five thousand New York residents are 26 to be notified at one time, the person or business shall also notify 27 consumer reporting agencies as to the timing, content and distribution 28 of the notices and approximate number of affected persons. Such notice 29 shall be made without delaying notice to affected New York residents.",
      "verified_fields": [
        "ag_notice_deadline",
        "cra_notice_threshold",
        "state"
      ],
      "derived_fields": [
        "encryption_safe_harbor",
        "notes"
      ]
    },
    {
      "state": "North Carolina",
      "statute_citation": "G.S. \u00a7 75-65",
      "individual_notice_deadline": "without unreasonable delay",
      "ag_notice_deadline": "without unreasonable delay",
      "cra_notice_threshold": "more than 1,000 persons at one time",
      "encryption_safe_harbor": "yes",
      "notes": "AG notice goes to the 'Consumer Protection Division of the Attorney General's Office', not the AG directly. AG notice is required for every breach that triggers individual notice (subsection e1), with no minimum resident-count threshold for AG notification. The CRA notice at 1,000+ (subsection f) also requires concurrent AG notice.",
      "id": "north-carolina",
      "url": "https://referencesource.org/data-breach-notification-clocks/north-carolina/",
      "source": "https://www.ncleg.net/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-65.html",
      "source_quote": "(a) Any business that owns or licenses personal information of residents of North Carolina or any business that conducts business in North Carolina that owns or licenses personal information in any form (whether computerized, paper, or otherwise) shall provide notice to the affected person that there has been a security breach following discovery or notification of the breach. The disclosure notification shall be made without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection (c) of this section, and consistent with any measures necessary to determine sufficient contact information, determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system. For the purposes of this section, personal information shall not include electronic identification numbers, email names or addresses, internet account numbers, internet identification names, parent's legal surname prior to marriage, or a password unless this information would permit access to a person's financial account or resources. (b) Any business that maintains or possesses records or data containing personal information of residents of North Carolina that the business does not own or license, or any business that conducts business in North Carolina that maintains or possesses records or data containing personal information that the business does not own or license shall notify the owner or licensee of the information of any security breach immediately following discovery of the breach, consistent with the legitimate needs of law enforcement as provided in subsection (c) of this section. (c) The notice required by this section shall be delayed if a law enforcement agency informs the business that notification may impede a criminal investigation or jeopardize national or homeland security, provided that such request is made in writing or the business documents such request contemporaneously in writing, including the name of the law enforcement officer making the request and the officer's law enforcement agency engaged in the investigation. The notice required by this section shall be provided without unreasonable delay after the law enforcement agency communicates to the business its determination that notice will no longer impede the investigation or jeopardize national or homeland security. (d) The notice shall be clear and conspicuous. The notice shall include all of the following: (1) A description of the incident in general terms. (2) A description of the type of personal information that was subject to the unauthorized access and acquisition. (3) A description of the general acts of the business to protect the personal information from further unauthorized access. (4) A telephone number for the business that the person may call for further information and assistance, if one exists. (5) Advice that directs the person to remain vigilant by reviewing account statements and monitoring free credit reports. (6) The toll-free numbers and addresses for the major consumer reporting agencies. (7) The toll-free numbers, addresses, and website addresses for the Federal Trade Commission and the North Carolina Attorney General's Office, along with a statement that the individual can obtain information from these sources about preventing identity theft. (e) For purposes of this section, notice to affected persons may be provided by one of the following methods: (1) Written notice. (2) Electronic notice, for those persons for whom it has a valid email address and who have agreed to receive communications electronically if the notice provided is consistent with the provisions regarding electronic records and signatures for notices legally required to be in writing set forth in 15 U.S.C. &sect;&ensp;7001. (3) Telephonic notice provided that contact is made directly with the affected persons. (4) Substitute notice, if the business demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars ($250,000) or that the affected class of subject persons to be notified exceeds 500,000, or if the business does not have sufficient contact information or consent to satisfy subdivisions (1), (2), or (3) of this subsection, for only those affected persons without sufficient contact information or consent, or if the business is unable to identify particular affected persons, for only those unidentifiable affected persons. Substitute notice shall consist of all the following: a. Email notice when the business has an email address for the subject persons. b. Conspicuous posting of the notice on the website page of the business, if one is maintained. c. Notification to major statewide media. (e1) In the event a business provides notice to an affected person pursuant to this section, the business shall notify without unreasonable delay the Consumer Protection Division of the Attorney General's Office of the nature of the breach, the number of consumers affected by the breach, steps taken to investigate the breach, steps taken to prevent a similar breach in the future, and information regarding the timing, distribution, and content of the notice. (f) In the event a business provides notice to more than 1,000 persons at one time pursuant to this section, the business shall notify, without unreasonable delay, the Consumer Protection Division of the Attorney General's Office and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in 15 U.S.C. &sect;&ensp;1681a(p), of the timing, distribution, and content of the notice.",
      "verified_fields": [
        "ag_notice_deadline",
        "cra_notice_threshold",
        "individual_notice_deadline",
        "state"
      ],
      "derived_fields": [
        "encryption_safe_harbor",
        "notes"
      ]
    },
    {
      "state": "Ohio",
      "statute_citation": "ORC \u00a7 1347.12",
      "individual_notice_deadline": "in the most expedient time possible but not later than forty-five days following its discovery or notification of the breach in the security of the system",
      "individual_notice_days": "45",
      "cra_notice_threshold": "more than one thousand residents of this state involved in a single occurrence of a breach of the security of the system",
      "encryption_safe_harbor": "yes",
      "notes": "CRITICAL SCOPE LIMIT: This section (ORC \u00a7 1347.12) applies ONLY to state agencies and agencies of political subdivisions \u2014 not to private businesses. The private-sector Ohio breach notification law is at ORC \u00a7 1349.19. No AG notification requirement is stated in this section (the AG may bring enforcement actions under ORC \u00a7 1349.191 and \u00a7 1349.192). CRA notice is required 'without unreasonable delay' when more than 1,000 residents are affected.",
      "id": "ohio",
      "url": "https://referencesource.org/data-breach-notification-clocks/ohio/",
      "source": "https://codes.ohio.gov/ohio-revised-code/section-1347.12",
      "source_quote": "The state agency or agency of a political subdivision shall make the disclosure described in division (B)(1) of this section in the most expedient time possible but not later than forty-five days following its discovery or notification of the breach in the security of the system, subject to the legitimate needs of law enforcement activities described in division (D) of this section and consistent with any measures necessary to determine the scope of the breach, including which residents' personal information was accessed and acquired, and to restore the reasonable integrity of the data system.",
      "verified_fields": [
        "individual_notice_deadline"
      ],
      "derived_fields": [
        "encryption_safe_harbor",
        "individual_notice_days",
        "notes"
      ]
    },
    {
      "state": "Oregon",
      "statute_citation": "ORS 646A.604",
      "individual_notice_deadline": "in the most expeditious manner possible, without unreasonable delay, but not later than 45 days after discovering or receiving notification of the breach of security",
      "individual_notice_days": "45",
      "ag_notice_deadline": "either in writing or electronically",
      "ag_notice_threshold": "exceeds 250",
      "cra_notice_threshold": "more than 1,000 consumers",
      "encryption_safe_harbor": "yes",
      "notes": "The AG threshold applies to consumers to whom the covered entity must send individual notice (i.e., 250+ affected consumers). The CRA notice (at 1,000+) must be given without unreasonable delay and must not delay individual consumer notification. Vendors have a separate 10-day deadline to notify covered entities of a breach.",
      "id": "oregon",
      "url": "https://referencesource.org/data-breach-notification-clocks/oregon/",
      "source": "https://www.oregonlegislature.gov/bills_laws/ors/ors646a.html",
      "source_quote": "\ufffd\ufffd\ufffd\ufffd\ufffd (a) A public corporation, including the Oregon Health and Science University and the Oregon State Bar, or a public body, as defined in ORS 174.109; \ufffd\ufffd\ufffd\ufffd\ufffd (b) Protected health information that a covered entity or business associate processes in accordance with, or documents that a covered entity or business associate creates for the purpose of complying with, the Health Insurance Portability and Accountability Act of 1996, P.L. 104-191, and regulations promulgated under the Act, as in effect on January 1, 2024; \ufffd\ufffd\ufffd\ufffd\ufffd (c) Information used only for public health activities and purposes described in 45 C.F.R.",
      "verified_fields": [
        "state"
      ],
      "derived_fields": [
        "encryption_safe_harbor",
        "individual_notice_days",
        "notes"
      ]
    },
    {
      "state": "South Carolina",
      "statute_citation": "S.C. Code Ann. \u00a7 39-1-90",
      "individual_notice_deadline": "in the most expedient time possible and without unreasonable delay",
      "ag_notice_threshold": "more than one thousand persons",
      "cra_notice_threshold": "more than one thousand persons",
      "encryption_safe_harbor": "yes",
      "notes": "The AG notice goes to the Consumer Protection Division of the Department of Consumer Affairs, not directly the Attorney General. AG and CRA thresholds are the same (1,000 persons). Banks and financial institutions compliant with Gramm-Leach-Bliley Act or the federal Interagency Guidance are explicitly exempt (subsections I and J).",
      "id": "south-carolina",
      "url": "https://referencesource.org/data-breach-notification-clocks/south-carolina/",
      "source": "https://www.scstatehouse.gov/code/t39c001.php",
      "source_quote": "(K) If a business provides notice to more than one thousand persons at one time pursuant to this section, the business shall notify, without unreasonable delay, the Consumer Protection Division of the Department of Consumer Affairs and all consumer reporting agencies that compile and maintain files on a nationwide basis, as defined in 15 U.S.C. Section 1681a(p), of the timing, distribution, and content of the notice. HISTORY: 2008 Act No. 190, SECTION 7.A, eff July 1, 2009; 2013 Act No. 15, SECTION 3, eff April 23, 2013. Effect of Amendment The 2013 amendment rewrote subsection (D)(3), the definition of \"Personal identifying information\". South Carolina",
      "verified_fields": [
        "ag_notice_threshold",
        "cra_notice_threshold",
        "individual_notice_deadline",
        "state"
      ],
      "derived_fields": [
        "encryption_safe_harbor",
        "notes"
      ]
    },
    {
      "state": "Texas",
      "statute_citation": "Tex. Bus. & Com. Code \u00a7 521.053",
      "individual_notice_deadline": "not later than the 60th day after the date on which the person determines that the breach occurred",
      "individual_notice_days": "60",
      "ag_notice_deadline": "not later than the 60th day after the date on which the person determines that the breach occurred",
      "ag_notice_threshold": "at least 250 residents of this state",
      "encryption_safe_harbor": "yes",
      "notes": "Source is HB 4390 (86th Legislature, 2019), the enrolled bill that amended \u00a7 521.053. The individual notice deadline text includes a bracketed deletion '[as quickly as possible]' reflecting the bill's amendment of existing law.",
      "id": "texas",
      "url": "https://referencesource.org/data-breach-notification-clocks/texas/",
      "source": "https://capitol.texas.gov/tlodocs/86R/billtext/pdf/HB04390F.pdf",
      "source_quote": "(b)AAA person who conducts business in this state and owns or 9 licenses computerized data that includes sensitive personal 10 information shall disclose any breach of system security, after 11 discovering or receiving notification of the breach, to any 12 individual whose sensitive personal information was, or is 13 reasonably believed to have been, acquired by an unauthorized 14 person. The disclosure shall be made without unreasonable delay and 15 in each case not later than the 60th day after the date on which the 16 person determines that the breach occurred [as quickly as 17 possible], except as provided by Subsection (d) or as necessary to 18 determine the scope of the breach and restore the reasonable 19 integrity of the data system. 20 (i)AAA person who is required to disclose or provide 21 notification of a breach of system security under this section 22 shall notify the attorney general of that breach not later than the 23 60th day after the date on which the person determines that the 24 breach occurred if the breach involves at least 250 residents of 1 H.B.ANo.A4390 1 this state. The notification under this subsection must include: 2 (1)AAa detailed description of the nature and 3 circumstances of the breach or the use of sensitive personal 4 information acquired as a result of the breach; 5 (2)AAthe number of residents of this state affected by 6 the breach at the time of notification; 7 (3)AAthe measures taken by the person regarding the 8 breach; 9 (4)AAany measures the person intends to take regarding 10 the breach after the notification under this subsection; and",
      "verified_fields": [
        "ag_notice_deadline",
        "individual_notice_deadline"
      ],
      "derived_fields": [
        "encryption_safe_harbor",
        "individual_notice_days",
        "notes"
      ]
    },
    {
      "state": "Virginia",
      "statute_citation": "Va. Code \u00a7 18.2-186.6",
      "individual_notice_deadline": "without unreasonable delay",
      "ag_notice_deadline": "without unreasonable delay",
      "cra_notice_threshold": "more than 1,000 persons at one time",
      "encryption_safe_harbor": "yes",
      "notes": "AG notice (Office of the Attorney General) is concurrent with individual notice \u2014 no separate threshold for AG notification; both are required 'without unreasonable delay'. CRA notice at 1,000+ also triggers concurrent AG notice. GLBA-regulated financial institutions are exempt under subsection G. Statute applies only where breach 'causes, or the individual or entity reasonably believes has caused or will cause, identity theft or another fraud'.",
      "id": "virginia",
      "url": "https://referencesource.org/data-breach-notification-clocks/virginia/",
      "source": "https://law.lis.virginia.gov/vacode/title18.2/chapter6/section18.2-186.6/",
      "source_quote": "B. If unencrypted or unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person and causes, or the individual or entity reasonably believes has caused or will cause, identity theft or another fraud to any resident of the Commonwealth, an individual or entity that owns or licenses computerized data that includes personal information shall disclose any breach of the security of the system following discovery or notification of the breach of the security of the system to the Office of the Attorney General and any affected resident of the Commonwealth without unreasonable delay. Notice required by this section may be reasonably delayed to allow the individual or entity to determine the scope of the breach of the security of the system and restore the reasonable integrity of the system. Notice required by this section may be delayed if, after the individual or entity notifies a law-enforcement agency, the law-enforcement agency determines and advises the individual or entity that the notice will impede a criminal or civil investigation, or homeland or national security. Notice shall be made without unreasonable delay after the law-enforcement agency determines that the notification will no longer impede the investigation or jeopardize national or homeland security. C. An individual or entity shall disclose the breach of the security of the system if encrypted information is accessed and acquired in an unencrypted form, or if the security breach involves a person with access to the encryption key and the individual or entity reasonably believes that such a breach has caused or will cause identity theft or other fraud to any resident of the Commonwealth. D. An individual or entity that maintains computerized data that includes personal information that the individual or entity does not own or license shall notify the owner or licensee of the information of any breach of the security of the system without unreasonable delay following discovery of the breach of the security of the system, if the personal information was accessed and acquired by an unauthorized person or the individual or entity reasonably believes the personal information was accessed and acquired by an unauthorized person. E. In the event an individual or entity provides notice to more than 1,000 persons at one time pursuant to this section, the individual or entity shall notify, without unreasonable delay, the Office of the Attorney General and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in 15 U.S.C. \u00a7 1681a (p), of the timing, distribution, and content of the notice.",
      "verified_fields": [
        "ag_notice_deadline",
        "cra_notice_threshold",
        "individual_notice_deadline"
      ],
      "derived_fields": [
        "encryption_safe_harbor",
        "notes"
      ]
    },
    {
      "state": "Washington",
      "statute_citation": "RCW 19.255.010",
      "individual_notice_deadline": "no more than thirty calendar days after the breach was discovered",
      "individual_notice_days": "30",
      "ag_notice_deadline": "no more than thirty days after the breach was discovered",
      "ag_notice_threshold": "more than five hundred Washington residents",
      "encryption_safe_harbor": "yes",
      "id": "washington",
      "url": "https://referencesource.org/data-breach-notification-clocks/washington/",
      "source": "https://app.leg.wa.gov/rcw/default.aspx?cite=19.255.010",
      "source_quote": "Any person or business that is required to issue a notification pursuant to this section to more than five hundred Washington residents as a result of a single breach shall notify the attorney general of the breach no more than thirty days after the breach was discovered. (a) The notice to the attorney general shall include the following information: (i) The number of Washington consumers affected by the breach, or an estimate if the exact number is not known; (ii) A list of the types of personal information that were or are reasonably believed to have been the subject of a breach; (iii) A time frame of exposure, if known, including the date of the breach and the date of the discovery of the breach; (iv) A summary of steps taken to contain the breach; and (v) A single sample copy of the security breach notification, excluding any personally identifiable information. (b) The notice to the attorney general must be updated if any of the information identified in (a) of this subsection is unknown at the time notice is due. (8) Notification to affected consumers under this section must be made in the most expedient time possible, without unreasonable delay, and no more than thirty calendar days after the breach was discovered, unless the delay is at the request of law enforcement as provided in subsection (3) of this section, or the delay is due to any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.",
      "verified_fields": [
        "ag_notice_deadline",
        "ag_notice_threshold",
        "individual_notice_deadline",
        "state"
      ],
      "derived_fields": [
        "encryption_safe_harbor",
        "individual_notice_days"
      ]
    },
    {
      "state": "Wisconsin",
      "statute_citation": "Wis. Stat. \u00a7 134.98",
      "individual_notice_deadline": "within a reasonable time, not to exceed 45 days after the entity learns of the acquisition of personal information",
      "individual_notice_days": "45",
      "cra_notice_threshold": "1,000 or more individuals",
      "encryption_safe_harbor": "yes",
      "notes": "No AG notification requirement is stated in the statute. GLBA-covered entities in compliance with GLB privacy and security requirements are exempt (subsection 3m(a)). HIPAA-covered entities in compliance with 45 CFR Part 164 are exempt (subsection 3m(b)). CRA notice must be made 'without unreasonable delay' when 1,000 or more individuals are affected.",
      "id": "wisconsin",
      "url": "https://referencesource.org/data-breach-notification-clocks/wisconsin/",
      "source": "https://docs.legis.wisconsin.gov/statutes/statutes/134/98",
      "source_quote": "1,000 or more individuals that personal information pertaining to the individuals has been acquired, the entity shall without unreasonable delay notify all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in <https://docs.legis.wisconsin.gov/document/usc/15%20USC%201681a> 15 USC 1681a (p), of the timing, distribution, and content of the notices sent to the individuals. <https://docs.legis.wisconsin.gov/document/statutes/134.98(2)(cm)> 134.98(2)(cm) (cm) Notwithstanding pars. <https://docs.legis.wisconsin.gov/document/statutes/134.98(2)(a)> (a) , <https://docs.legis.wisconsin.gov/document/statutes/134.98(2)(b)> (b) , <https://docs.legis.wisconsin.gov/document/statutes/134.98(2)(bm)> (bm) , and <https://docs.legis.wisconsin.gov/document/statutes/134.98(2)(br)> (br) , an entity is not required to provide notice of the acquisition of personal information if any of the following applies: <https://docs.legis.wisconsin.gov/document/statutes/134.98(2)(cm)1.> 134.98(2)(cm)1. 1. The acquisition of personal information does not create a material risk of identity theft or fraud to the subject of the personal information. <https://docs.legis.wisconsin.gov/document/statutes/134.98(2)(cm)2.> 134.98(2)(cm)2. 2. The personal information was acquired in good faith by an employee or agent of the entity, if the personal information is used for a lawful purpose of the entity. <https://docs.legis.wisconsin.gov/document/statutes/134.98(3)> 134.98(3) (3) Timing and manner of notice; other requirements. <https://docs.legis.wisconsin.gov/document/statutes/134.98(3)(a)> 134.98(3)(a) (a) Subject to sub. <https://docs.legis.wisconsin.gov/document/statutes/134.98(5)> (5) , an entity shall provide the notice required under sub. <https://docs.legis.wisconsin.gov/document/statutes/134.98(2)> (2) within a reasonable time, not to exceed 45 days after the entity learns of the acquisition of personal information.",
      "verified_fields": [
        "cra_notice_threshold",
        "individual_notice_deadline",
        "state"
      ],
      "derived_fields": [
        "encryption_safe_harbor",
        "individual_notice_days",
        "notes"
      ]
    }
  ]
}