What Are Breach Notification Laws?

Also called: Data breach notification laws, Breach disclosure laws

Related problems: Not sure what we would legally have to do after a breach; Customers in many states and countries with different notice rules; A vendor had a breach and we don't know whether we have to notify anyone; Cyber insurer asking about our notification process

Breach notification laws are rules that require an organization to tell affected individuals, and often regulators or other parties, when certain kinds of personal data are exposed in a security incident. In the US every state has its own breach notification law, sector rules add more, and many other jurisdictions have their own, such as the EU’s GDPR. The laws differ in what data they cover, what counts as a breach, who must be told and how fast. This entry is a general overview, not legal advice; confirm your obligations with counsel.

At a glance

  • Most laws are triggered by unauthorized access to or acquisition of specific categories of personal data, not by every incident.
  • Obligations usually follow where the affected people live, so one breach can trigger many laws at once.
  • Recipients can include individuals, regulators, state attorneys general, credit reporting agencies and business customers, depending on the law and the number affected.
  • Deadlines range from a few days for some regulator notices to “without unreasonable delay” or several weeks; the clock often starts at discovery.
  • Vendors that hold your data usually have to notify you, and you usually notify the people affected.

What problem it solves

Before these laws, people whose data was stolen often never found out, so they couldn’t take steps such as freezing credit or changing passwords. Notification laws give them that chance and give regulators visibility into how organizations protect data.

For a business, the practical problem is the reverse: after a data breach, it has a short time to work out which laws apply, who must be told, what the notice must say and when it must go out, while also containing the incident. Organizations that understand their obligations in advance make faster, more defensible decisions.

How it works

Trigger. Each law defines covered data, often name plus a sensitive element such as a government ID, financial account, health or biometric data, or login credentials. Many define personally identifiable information (PII) more narrowly than everyday usage. Some exempt data that was encrypted with keys that were not compromised, or allow a documented risk-of-harm assessment.

Investigation. Incident response (IR) work establishes what was accessed, whose data it was and where those people live. Counsel often directs this work to protect privilege.

Notice. Notices typically describe what happened, what data was involved, what the organization is doing and what individuals can do. Some laws prescribe content, format or delivery method.

Third parties. A service provider that suffers a breach is usually required to notify its customer, the data owner, which then notifies individuals and regulators. Data processing agreements (DPAs) and other contracts often set shorter vendor deadlines and allocate costs.

Notification layers

These laws have no formal levels. Their closest structure is the layer of law involved and the role you play. Rules vary by jurisdiction and change; confirm with counsel.

Layer Who it applies to What triggers it What is required Typical evidence
US state breach laws Organizations holding covered data about residents of that state Unauthorized access to or acquisition of defined personal data, subject to exceptions Notice to affected residents; some states also require notice to the attorney general or credit reporting agencies above a threshold Incident report, legal analysis by state, copies of notices and mailing records
US sector rules For example, covered entities and business associates under HIPAA, financial institutions under GLBA-related rules, and public companies under securities disclosure rules Breach of protected health, customer financial or other regulated data, or a material incident Notice to individuals and the relevant regulator, sometimes the media or investors, on the rule’s timeline Risk assessment, regulator filings, breach log
Non-US and supranational privacy laws Depends on each law’s scope; the EU’s GDPR, for example, can apply to organizations established in the EU or offering goods or services to, or monitoring, people in the EU. Counsel determines applicability Personal data breach meeting the law’s risk threshold Notice to the supervisory authority and, when risk is high, to individuals Internal breach register, regulator correspondence
Contracts (vendor role) Service providers, processors and business associates A breach affecting a customer’s data Notice to the customer within the contract’s deadline and cooperation with its investigation Contract clauses, notice records, incident report shared with the customer

When it matters for buyers

  • After a peer is hit. A common question is whether you would know which laws apply and who would make the call.
  • When cyber insurance renews. Insurers ask about incident response plans, breach counsel and notification vendors.
  • When signing a vendor contract. The vendor’s breach notice deadline and cost allocation are worth negotiating up front.
  • When expanding to new states or countries. Each new jurisdiction can add a law with different rules, including the California Consumer Privacy Act (CCPA) for California data.

Questions to ask vendors

  • How quickly will you notify us of a suspected or confirmed incident affecting our data, and is that in the contract?
  • What information will your notice include, and will you share forensic findings?
  • Where is our data stored, and whose data do you hold for us by state or country?
  • Who pays for notification, call center and credit monitoring if your breach affects our customers?
  • Do you carry cyber insurance that covers incidents affecting customer data?
  • Does your incident response offering include breach counsel coordination and notification support?

How it differs from a data breach

A data breach is the event: unauthorized access to or disclosure of protected data. Breach notification laws are the legal duties that may follow it. Not every breach in the everyday sense triggers a legal notice, and the legal definition of a breach in a given law can be narrower or broader than common usage. Treat “we had a breach” and “we must notify” as separate questions, the second answered with counsel.

Frequently Asked Questions

Does every security incident require notification?
No. Most laws are triggered only when certain categories of personal data are, or are reasonably believed to be, accessed or acquired without authorization. Many have exceptions, such as for properly encrypted data or a documented finding of low risk of harm. Whether a specific incident triggers notice is a legal question for counsel. This is not legal advice.
How quickly do we have to notify?
It depends on the law. Some set a fixed deadline, from a few days for some regulator notices to several weeks for individual notices; others require notice without unreasonable delay. GDPR, for example, requires notice to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach that triggers it. Because the clock may start at discovery, plan your process in advance.
Which law applies if our customers are in many states or countries?
Usually the laws where the affected people live, not just where your company is based, plus any sector rules you fall under. A single breach can trigger several laws with different content, timing and recipients. Counsel or a breach coach typically maps them.
Who notifies if our vendor is breached?
Usually the vendor must notify you, and you, as the organization that owns the relationship with the affected people, are responsible for notifying them and regulators. Contracts often set the vendor's notice deadline and who pays for notification costs. Check those clauses before an incident.
Does cyber insurance cover notification costs?
Many cyber policies cover some notification, call center, credit monitoring and legal costs, subject to limits, deductibles and approved-vendor requirements. Check your specific policy and notify your insurer early, as policies often require it.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.