The short version
- The statute that applies is the one where the affected person lives. Notification duties are written around residents — California Civil Code § 1798.82 speaks of "a resident of California" — so a customer list spread across thirty states is thirty statutes, whatever your own state requires.
- The tight deadlines are now real deadlines. California replaced "without unreasonable delay" with a hard 30 calendar days from discovery on 1 January 2026 (SB 446), joining Washington and Florida at 30 days; Texas allows 60 for individuals but only 30 for its Attorney General.
- The encryption exemption is conditional on the key. Washington requires disclosure of secured information where "the confidential process, encryption key, or other means to decipher the secured information was acquired by an unauthorized person" — which is what usually happens.
- Personal information has outgrown name-plus-SSN. Washington counts full date of birth, biometric data, health insurance numbers and medical history; Florida counts geolocation; a username with a password is its own category in several states, with no name attached.
The first question after an incident is not how bad it was. It is whose law applies, because that decides everything downstream — what counts as a breach, how long you have, and whether you are allowed to decide that no letter is needed at all.
The duty follows the person, not the business
Breach statutes are drafted around residents. California requires disclosure to "a resident of California whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person"; Washington and Florida use the same construction for their own residents. Nothing in any of them turns on where the server sat or where the company is incorporated. The map of your obligations is your customer list sorted by address.
The practical consequence is to stop running parallel compliance and satisfy the strictest applicable rule for everyone: one letter, one date, every affected person. Segmenting a notification run by state costs more in administration and error than the days it buys. What is uniform is short — all fifty states, the District of Columbia and the territories have a law, all are keyed to computerised personal information, and all of the major ones permit delay at the request of law enforcement. In the 2026 fifty-state survey published by Privacy Rights Clearinghouse, 36 states now require notice to a regulator as well as to the individual.
Personal information has stopped meaning name plus Social Security number
The old mental model — a letter is owed when a name travelled with a Social Security or card number — under-reads most current statutes badly. Washington pairs a name with any of: full date of birth, a private key, student, military or passport identification numbers, health insurance policy numbers, "medical history or health condition" information, and biometric data "generated by automatic measurements of an individual's biological characteristics such as a fingerprint, voiceprint, eye retinas, irises". Florida's list reaches geolocation. The survey counts 22 states expressly covering biometric identifiers and 24 covering medical or health information.
One structural change matters more than any single addition. A username or email address together with a password or a security question answer is a standalone category in Washington, Florida and California — no name required — so a credential-stuffing incident against a login table is notifiable even though nothing a bank would recognise as identity data moved. Whether you owe notice is a question about your schema, not a judgement about how sensitive the incident felt.
The encryption safe harbour has a condition attached to it
Nearly every state exempts properly encrypted data, and the exemption is real: Washington defines "secured" as encrypted to a NIST standard or otherwise rendered unreadable. But it is conditional, and the condition is the part that fails. Washington requires disclosure anyway where "the confidential process, encryption key, or other means to decipher the secured information was acquired by an unauthorized person", and California extends its statute to encrypted personal information acquired together with "the encryption key or security credential".
That condition is met far more often than the word "encrypted" in an incident summary suggests. Disk-level encryption protects a stolen laptop; it does nothing about an attacker inside the application, because the application holds the credentials that decrypt the data and hands back plain text on request. The question to put to the forensics team in writing is not "was it encrypted" but "was anything the attacker held capable of reading it".
When the encryption exemption actually applies
What the attacker also took
How the data was stored
Plain text
Encrypted
No key or credential
Notify
The ordinary case. Nothing to argue about.
Exempt
The only quadrant the safe harbour covers.
Key or credential taken
Notify
Encryption was never in the picture.
Notify
Both statutes bring the encrypted data back in.
Deciding no notice is required, and what that decision has to look like
Many states let a business conclude that a breach will not cause harm and send nothing. Fewer make that a free decision. Florida permits it where the business "reasonably determine[s] that the breach has not and will not likely result in identity theft or any other financial harm" — but only "after an appropriate investigation and consultation with relevant federal, state, or local law enforcement agencies", and the determination has to be documented in writing, kept for five years, and filed with the Department of Legal Affairs within 30 days whether or not it asks. That is not a get-out; it is a file the regulator can ask for, written before you know how the incident will be reported.
California, which wrote the first breach law in the country, has no harm threshold at all. The trigger is acquisition of unencrypted personal information by an unauthorised person, full stop. So the same set of facts can be a no-notice event in one state and a mandatory 30-day letter in another, which is the second reason to notify everyone on the strictest timetable rather than run the analysis fifty times.
Can you decide not to notify?
You have concluded the incident is unlikely to harm anyone. Can you stay silent?
A state with a harm threshold
Florida allows it, but only after consulting law enforcement, and the written determination is filed with the Department of Legal Affairs within 30 days.
California, or anything under HIPAA
California has no harm off-ramp. HIPAA presumes a breach unless you demonstrate a low probability of compromise on four named factors.
The clocks, and which one is tightest
The direction of travel is away from judgement and towards day counts. Privacy Rights Clearinghouse counts 20 states with a numeric deadline and 31 still using language like "in the most expedient time possible and without unreasonable delay". California moved between those camps on 1 January 2026: SB 446 replaced the reasonableness standard with disclosure "within 30 calendar days of discovery or notification of the data breach", and requires the sample notice to reach the Attorney General "within 15 calendar days of notifying affected consumers" where more than 500 California residents are involved.
Four clocks from one discovery date
Day 0
Discovery
Or the day reasonable diligence would have found it.
4 business days
SEC Form 8-K
Public companies, from determining the incident is material.
30 days
The tight states
California, Washington and Florida individuals; Texas Attorney General at 250 residents.
60 days
The outer limit
HIPAA, the FTC health rule, Texas and Connecticut individuals.
Regulator notice runs on its own thresholds and often its own clock. Florida and Washington require it at more than 500 affected residents within 30 days; Texas at 250 residents within 30 days, even though its consumer deadline is 60; Connecticut requires it no later than the moment residents are notified. Two more triggers sit underneath: the nationwide consumer reporting agencies must be told at more than 1,000 affected people in Florida and more than 10,000 in Texas, and substitute notice — website posting, email and statewide media instead of letters — becomes available in California and Florida where direct notice would cost more than $250,000 or reach more than 500,000 people.
Draft the notification letter
Free full text. A dated notice with the prescribed headings, sent to everyone on the same day, is what turns a scramble into a record you can hand a regulator.
The federal rules that sit on top of the state one
None of these replaces the state duty; they run alongside it, with their own regulators and their own clocks.
| Regime | Who it catches | Deadline and regulator |
|---|---|---|
| HIPAA Breach Notification Rule | Covered entities and their business associates | 60 days to individuals; media notice at more than 500 residents of a state; HHS contemporaneously at 500+, annually below that |
| FTC Health Breach Notification Rule | Health apps and personal health record vendors outside HIPAA | 60 days to individuals and media; FTC contemporaneously at 500 or more |
| GLBA Safeguards Rule | Non-bank financial institutions — lenders, brokers, tax preparers | 30 days to the FTC where 500 or more consumers are involved |
| SEC Item 1.05 | Public companies and foreign private issuers | Four business days from determining the incident is material |
Your vendor’s notice clause decides whether the deadline is survivable
Most breaches at a small business happen somewhere else — the payroll provider, the booking system, the email platform. The structure is consistent across regimes: the processor notifies the business, and the business notifies the people. California puts it starkly for anyone holding data they do not own, requiring notice to the owner or licensee "immediately following discovery". HIPAA is more generous to the vendor and worse for you: a business associate has up to 60 calendar days to tell the covered entity, which is the entire period the covered entity itself has.
So the deadline you can actually meet is set in the contract, not the statute. Three lines in a vendor agreement do the work: notice to you within a fixed short period of the vendor’s discovery rather than its confirmation, an obligation to preserve logs and forensic artefacts and give you access to them, and a prohibition on the vendor notifying your customers or a regulator on your behalf without written agreement. The last one matters because your customers are the vendor’s data subjects only in a technical sense; the letter they receive should come from the business they gave the data to.
The first seventy-two hours
Nothing in these statutes rewards speed of investigation. They reward the ability to prove, later, what you knew and when. Two decisions in the first days determine whether that is possible.
Before the forensics start
- Stop deletion before anything else. Logs, backups and mailboxes on short retention are the evidence, and the preservation duty has almost certainly already attached — see litigation holds.
- Engage counsel first and have counsel engage the forensic firm, under a scope written for that incident.
- Keep the incident log factual and dated: what was seen, when, by whom. Avoid conclusions about cause or liability in it.
- Fix the affected-resident count by state early. It sets every regulator threshold and it is the number you will be asked for first.
- Diary each deadline separately in the deadline tracker — individuals, regulators, reporting agencies — because they do not share a start date.
The privilege point is not theoretical. In the Capital One litigation (E.D. Va., No. 1:19-md-02915) the magistrate judge ordered production of the Mandiant forensic report despite outside counsel having retained the firm, because Mandiant was already under a pre-breach statement of work for the same services, the cost was booked as a business expense, and the report went to regulators and the accountants. The report "would have been prepared in substantially similar form, whether or not litigation was to ensue". Retaining counsel is not the protection; retaining a firm you were not already paying to do that work is closer to it.
The unglamorous truth is that most of the work is done before anything happens. A business that already knows which data fields it holds, where its customers live and what its vendors must tell it can run this in a week. One that has to answer those questions during the incident will miss a 30-day deadline it never knew applied, in a state it does not operate in, for a customer it acquired two years ago. That, and not the intrusion, is what regulators end up writing about.
Sources
- California Civil Code § 1798.82 — the 30-day deadline, the encryption condition and the notice format
- California SB 446 (Stats. 2025, ch. 319) — the amendment effective 1 January 2026
- RCW 19.255.010 — Washington: 30 days, Attorney General at 500 residents, the encryption key condition
- RCW 19.255.005 — Washington: the definition of personal information and of "secured"
- Florida Statutes § 501.171 — 30 days, the written harm determination and the reporting-agency threshold
- Texas Business & Commerce Code § 521.053 — 60 days to individuals, 30 to the Attorney General at 250 residents
- Connecticut Attorney General — reporting a data breach, 60 days and 24 months of credit monitoring
- 45 CFR § 164.404 — HIPAA notification to individuals within 60 days of discovery
- 45 CFR § 164.410 — the business associate’s 60-day notice to the covered entity
- 16 CFR Part 318 — the FTC Health Breach Notification Rule
- 16 CFR § 314.4(j) — the Safeguards Rule notification event, 30 days at 500 consumers
- SEC — cybersecurity incident disclosure compliance guide, Item 1.05 of Form 8-K
- Privacy Rights Clearinghouse — Data Breach Notification Laws: A 50-State Survey (2026)
- HHS Office for Civil Rights — the public portal of reported breaches of 500 or more records
General information, not legal advice. This guide explains how these documents and rules generally work. Law varies by jurisdiction and changes, and none of it is applied to your circumstances here. For anything consequential, consult a licensed attorney where you are.
Frequently asked
Which state’s breach notification law applies to my business?
Every state where an affected person lives, not the state where the business is based. California Civil Code § 1798.82 is written around notice to "a resident of California", and Washington, Florida and Texas use the same construction for their own residents. A single incident affecting customers in twenty states triggers twenty statutes at once, which is why most businesses notify everyone on the strictest applicable timetable.
How long do I have to notify customers after a data breach?
It ranges from 30 calendar days to no fixed number. California, Washington and Florida require individual notice within 30 days; Texas and Connecticut allow 60. Privacy Rights Clearinghouse counts 20 states with a numeric deadline in 2026 and 31 still using standards such as "without unreasonable delay". California only moved to a fixed 30 days on 1 January 2026 under SB 446.
Do I have to notify the state Attorney General as well?
In most states, above a threshold. Florida and Washington require it where more than 500 residents are affected, within 30 days. Texas requires it at 250 residents within 30 days even though consumers get 60. Connecticut requires it no later than the time residents are notified. The 2026 fifty-state survey puts the number of states requiring regulator notice at 36.
Is encrypted data still a reportable breach?
Usually not, unless the attacker also took the means of decrypting it. Washington requires disclosure where "the encryption key, or other means to decipher the secured information was acquired by an unauthorized person", and California extends its statute to encrypted data taken along with the key or security credential. Disk encryption protects a stolen drive; it does not help where the application itself was compromised.
My vendor was breached. Who notifies my customers?
You do. The consistent structure is that the vendor notifies the business and the business notifies the people whose data it is. California requires anyone maintaining data they do not own to tell the owner "immediately following discovery", but HIPAA gives a business associate up to 60 days — the covered entity’s entire window. The contract has to shorten that, or the statutory deadline is unmeetable.