Skip to content
Websites & online business

After a data breach: who you have to notify, and how fast the clock runs

Every state has a breach notification statute and no two of them agree. That is a nuisance for a business with one office and one town of customers, and something else entirely for anybody selling online — because the duty is owed to the person whose data was taken, wherever that person happens to live, and not to the state the business operates from. One incident on one server therefore starts a set of clocks running at different speeds, under different definitions of what was even taken. This page is about which parts of that genuinely vary and which parts are the same everywhere.

9 min readPublished How we write these

The short version

  • The statute that applies is the one where the affected person lives. Notification duties are written around residents — California Civil Code § 1798.82 speaks of "a resident of California" — so a customer list spread across thirty states is thirty statutes, whatever your own state requires.
  • The tight deadlines are now real deadlines. California replaced "without unreasonable delay" with a hard 30 calendar days from discovery on 1 January 2026 (SB 446), joining Washington and Florida at 30 days; Texas allows 60 for individuals but only 30 for its Attorney General.
  • The encryption exemption is conditional on the key. Washington requires disclosure of secured information where "the confidential process, encryption key, or other means to decipher the secured information was acquired by an unauthorized person" — which is what usually happens.
  • Personal information has outgrown name-plus-SSN. Washington counts full date of birth, biometric data, health insurance numbers and medical history; Florida counts geolocation; a username with a password is its own category in several states, with no name attached.

The first question after an incident is not how bad it was. It is whose law applies, because that decides everything downstream — what counts as a breach, how long you have, and whether you are allowed to decide that no letter is needed at all.

The duty follows the person, not the business

Breach statutes are drafted around residents. California requires disclosure to "a resident of California whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person"; Washington and Florida use the same construction for their own residents. Nothing in any of them turns on where the server sat or where the company is incorporated. The map of your obligations is your customer list sorted by address.

The practical consequence is to stop running parallel compliance and satisfy the strictest applicable rule for everyone: one letter, one date, every affected person. Segmenting a notification run by state costs more in administration and error than the days it buys. What is uniform is short — all fifty states, the District of Columbia and the territories have a law, all are keyed to computerised personal information, and all of the major ones permit delay at the request of law enforcement. In the 2026 fifty-state survey published by Privacy Rights Clearinghouse, 36 states now require notice to a regulator as well as to the individual.

Personal information has stopped meaning name plus Social Security number

The old mental model — a letter is owed when a name travelled with a Social Security or card number — under-reads most current statutes badly. Washington pairs a name with any of: full date of birth, a private key, student, military or passport identification numbers, health insurance policy numbers, "medical history or health condition" information, and biometric data "generated by automatic measurements of an individual's biological characteristics such as a fingerprint, voiceprint, eye retinas, irises". Florida's list reaches geolocation. The survey counts 22 states expressly covering biometric identifiers and 24 covering medical or health information.

One structural change matters more than any single addition. A username or email address together with a password or a security question answer is a standalone category in Washington, Florida and California — no name required — so a credential-stuffing incident against a login table is notifiable even though nothing a bank would recognise as identity data moved. Whether you owe notice is a question about your schema, not a judgement about how sensitive the incident felt.

The encryption safe harbour has a condition attached to it

Nearly every state exempts properly encrypted data, and the exemption is real: Washington defines "secured" as encrypted to a NIST standard or otherwise rendered unreadable. But it is conditional, and the condition is the part that fails. Washington requires disclosure anyway where "the confidential process, encryption key, or other means to decipher the secured information was acquired by an unauthorized person", and California extends its statute to encrypted personal information acquired together with "the encryption key or security credential".

That condition is met far more often than the word "encrypted" in an incident summary suggests. Disk-level encryption protects a stolen laptop; it does nothing about an attacker inside the application, because the application holds the credentials that decrypt the data and hands back plain text on request. The question to put to the forensics team in writing is not "was it encrypted" but "was anything the attacker held capable of reading it".

When the encryption exemption actually applies

What the attacker also took

How the data was stored

Plain text

Encrypted

No key or credential

Notify

The ordinary case. Nothing to argue about.

Exempt

The only quadrant the safe harbour covers.

Key or credential taken

Notify

Encryption was never in the picture.

Notify

Both statutes bring the encrypted data back in.

Drawn from RCW 19.255.010 and California Civil Code § 1798.82(a). Only one quadrant is exempt, and it is not the one most incident reports describe.

Deciding no notice is required, and what that decision has to look like

Many states let a business conclude that a breach will not cause harm and send nothing. Fewer make that a free decision. Florida permits it where the business "reasonably determine[s] that the breach has not and will not likely result in identity theft or any other financial harm" — but only "after an appropriate investigation and consultation with relevant federal, state, or local law enforcement agencies", and the determination has to be documented in writing, kept for five years, and filed with the Department of Legal Affairs within 30 days whether or not it asks. That is not a get-out; it is a file the regulator can ask for, written before you know how the incident will be reported.

California, which wrote the first breach law in the country, has no harm threshold at all. The trigger is acquisition of unencrypted personal information by an unauthorised person, full stop. So the same set of facts can be a no-notice event in one state and a mandatory 30-day letter in another, which is the second reason to notify everyone on the strictest timetable rather than run the analysis fifty times.

Can you decide not to notify?

You have concluded the incident is unlikely to harm anyone. Can you stay silent?

A state with a harm threshold

Florida allows it, but only after consulting law enforcement, and the written determination is filed with the Department of Legal Affairs within 30 days.

California, or anything under HIPAA

California has no harm off-ramp. HIPAA presumes a breach unless you demonstrate a low probability of compromise on four named factors.

Under 45 CFR § 164.402 an impermissible disclosure of health information is presumed to be a breach, and the burden of rebutting that sits with you.

The clocks, and which one is tightest

The direction of travel is away from judgement and towards day counts. Privacy Rights Clearinghouse counts 20 states with a numeric deadline and 31 still using language like "in the most expedient time possible and without unreasonable delay". California moved between those camps on 1 January 2026: SB 446 replaced the reasonableness standard with disclosure "within 30 calendar days of discovery or notification of the data breach", and requires the sample notice to reach the Attorney General "within 15 calendar days of notifying affected consumers" where more than 500 California residents are involved.

Four clocks from one discovery date

  1. Day 0

    Discovery

    Or the day reasonable diligence would have found it.

  2. 4 business days

    SEC Form 8-K

    Public companies, from determining the incident is material.

  3. 30 days

    The tight states

    California, Washington and Florida individuals; Texas Attorney General at 250 residents.

  4. 60 days

    The outer limit

    HIPAA, the FTC health rule, Texas and Connecticut individuals.

Discovery is usually a legal construct rather than an event — HIPAA treats a breach as discovered on the first day it was known or would have been known by exercising reasonable diligence by anyone other than the person who caused it.

Regulator notice runs on its own thresholds and often its own clock. Florida and Washington require it at more than 500 affected residents within 30 days; Texas at 250 residents within 30 days, even though its consumer deadline is 60; Connecticut requires it no later than the moment residents are notified. Two more triggers sit underneath: the nationwide consumer reporting agencies must be told at more than 1,000 affected people in Florida and more than 10,000 in Texas, and substitute notice — website posting, email and statewide media instead of letters — becomes available in California and Florida where direct notice would cost more than $250,000 or reach more than 500,000 people.

Draft the notification letter

Free full text. A dated notice with the prescribed headings, sent to everyone on the same day, is what turns a scramble into a record you can hand a regulator.

Open

The federal rules that sit on top of the state one

None of these replaces the state duty; they run alongside it, with their own regulators and their own clocks.

RegimeWho it catchesDeadline and regulator
HIPAA Breach Notification RuleCovered entities and their business associates60 days to individuals; media notice at more than 500 residents of a state; HHS contemporaneously at 500+, annually below that
FTC Health Breach Notification RuleHealth apps and personal health record vendors outside HIPAA60 days to individuals and media; FTC contemporaneously at 500 or more
GLBA Safeguards RuleNon-bank financial institutions — lenders, brokers, tax preparers30 days to the FTC where 500 or more consumers are involved
SEC Item 1.05Public companies and foreign private issuersFour business days from determining the incident is material
The HIPAA rule reaches a small business mainly through its vendors — what a business associate agreement has to say covers who is caught and who owns the clock.

Your vendor’s notice clause decides whether the deadline is survivable

Most breaches at a small business happen somewhere else — the payroll provider, the booking system, the email platform. The structure is consistent across regimes: the processor notifies the business, and the business notifies the people. California puts it starkly for anyone holding data they do not own, requiring notice to the owner or licensee "immediately following discovery". HIPAA is more generous to the vendor and worse for you: a business associate has up to 60 calendar days to tell the covered entity, which is the entire period the covered entity itself has.

So the deadline you can actually meet is set in the contract, not the statute. Three lines in a vendor agreement do the work: notice to you within a fixed short period of the vendor’s discovery rather than its confirmation, an obligation to preserve logs and forensic artefacts and give you access to them, and a prohibition on the vendor notifying your customers or a regulator on your behalf without written agreement. The last one matters because your customers are the vendor’s data subjects only in a technical sense; the letter they receive should come from the business they gave the data to.

The first seventy-two hours

Nothing in these statutes rewards speed of investigation. They reward the ability to prove, later, what you knew and when. Two decisions in the first days determine whether that is possible.

Before the forensics start

  • Stop deletion before anything else. Logs, backups and mailboxes on short retention are the evidence, and the preservation duty has almost certainly already attached — see litigation holds.
  • Engage counsel first and have counsel engage the forensic firm, under a scope written for that incident.
  • Keep the incident log factual and dated: what was seen, when, by whom. Avoid conclusions about cause or liability in it.
  • Fix the affected-resident count by state early. It sets every regulator threshold and it is the number you will be asked for first.
  • Diary each deadline separately in the deadline tracker — individuals, regulators, reporting agencies — because they do not share a start date.

The privilege point is not theoretical. In the Capital One litigation (E.D. Va., No. 1:19-md-02915) the magistrate judge ordered production of the Mandiant forensic report despite outside counsel having retained the firm, because Mandiant was already under a pre-breach statement of work for the same services, the cost was booked as a business expense, and the report went to regulators and the accountants. The report "would have been prepared in substantially similar form, whether or not litigation was to ensue". Retaining counsel is not the protection; retaining a firm you were not already paying to do that work is closer to it.

The unglamorous truth is that most of the work is done before anything happens. A business that already knows which data fields it holds, where its customers live and what its vendors must tell it can run this in a week. One that has to answer those questions during the incident will miss a 30-day deadline it never knew applied, in a state it does not operate in, for a customer it acquired two years ago. That, and not the intrusion, is what regulators end up writing about.

General information, not legal advice. This guide explains how these documents and rules generally work. Law varies by jurisdiction and changes, and none of it is applied to your circumstances here. For anything consequential, consult a licensed attorney where you are.

Frequently asked

Which state’s breach notification law applies to my business?

Every state where an affected person lives, not the state where the business is based. California Civil Code § 1798.82 is written around notice to "a resident of California", and Washington, Florida and Texas use the same construction for their own residents. A single incident affecting customers in twenty states triggers twenty statutes at once, which is why most businesses notify everyone on the strictest applicable timetable.

How long do I have to notify customers after a data breach?

It ranges from 30 calendar days to no fixed number. California, Washington and Florida require individual notice within 30 days; Texas and Connecticut allow 60. Privacy Rights Clearinghouse counts 20 states with a numeric deadline in 2026 and 31 still using standards such as "without unreasonable delay". California only moved to a fixed 30 days on 1 January 2026 under SB 446.

Do I have to notify the state Attorney General as well?

In most states, above a threshold. Florida and Washington require it where more than 500 residents are affected, within 30 days. Texas requires it at 250 residents within 30 days even though consumers get 60. Connecticut requires it no later than the time residents are notified. The 2026 fifty-state survey puts the number of states requiring regulator notice at 36.

Is encrypted data still a reportable breach?

Usually not, unless the attacker also took the means of decrypting it. Washington requires disclosure where "the encryption key, or other means to decipher the secured information was acquired by an unauthorized person", and California extends its statute to encrypted data taken along with the key or security credential. Disk encryption protects a stolen drive; it does not help where the application itself was compromised.

My vendor was breached. Who notifies my customers?

You do. The consistent structure is that the vendor notifies the business and the business notifies the people whose data it is. California requires anyone maintaining data they do not own to tell the owner "immediately following discovery", but HIPAA gives a business associate up to 60 days — the covered entity’s entire window. The contract has to shorten that, or the statutory deadline is unmeetable.

Do the whole thing on your phone

Draft it, check it for risk, rewrite the clauses you do not like, sign it and send it — without opening a laptop.

  • 136 templates across 12 categories
  • AI review in plain English
  • Free every month — 3 documents, 2 reviews
Download on theApp Store
Free to download · no account

iPhone, iPad, Mac & Vision Pro · iOS 15.6+ · 76.1 MB
Premium from $1.99/week