Breach notification laws are rules that require an organization to tell affected individuals, and often regulators or other parties, when certain kinds of personal data are exposed in a security incident. In the US every state has its own breach notification law, sector rules add more, and many other jurisdictions have their own, such as the EU’s GDPR. The laws differ in what data they cover, what counts as a breach, who must be told and how fast. This entry is a general overview, not legal advice; confirm your obligations with counsel.
At a glance
- Most laws are triggered by unauthorized access to or acquisition of specific categories of personal data, not by every incident.
- Obligations usually follow where the affected people live, so one breach can trigger many laws at once.
- Recipients can include individuals, regulators, state attorneys general, credit reporting agencies and business customers, depending on the law and the number affected.
- Deadlines range from a few days for some regulator notices to “without unreasonable delay” or several weeks; the clock often starts at discovery.
- Vendors that hold your data usually have to notify you, and you usually notify the people affected.
What problem it solves
Before these laws, people whose data was stolen often never found out, so they couldn’t take steps such as freezing credit or changing passwords. Notification laws give them that chance and give regulators visibility into how organizations protect data.
For a business, the practical problem is the reverse: after a data breach, it has a short time to work out which laws apply, who must be told, what the notice must say and when it must go out, while also containing the incident. Organizations that understand their obligations in advance make faster, more defensible decisions.
How it works
Trigger. Each law defines covered data, often name plus a sensitive element such as a government ID, financial account, health or biometric data, or login credentials. Many define personally identifiable information (PII) more narrowly than everyday usage. Some exempt data that was encrypted with keys that were not compromised, or allow a documented risk-of-harm assessment.
Investigation. Incident response (IR) work establishes what was accessed, whose data it was and where those people live. Counsel often directs this work to protect privilege.
Notice. Notices typically describe what happened, what data was involved, what the organization is doing and what individuals can do. Some laws prescribe content, format or delivery method.
Third parties. A service provider that suffers a breach is usually required to notify its customer, the data owner, which then notifies individuals and regulators. Data processing agreements (DPAs) and other contracts often set shorter vendor deadlines and allocate costs.
Notification layers
These laws have no formal levels. Their closest structure is the layer of law involved and the role you play. Rules vary by jurisdiction and change; confirm with counsel.
| Layer | Who it applies to | What triggers it | What is required | Typical evidence |
|---|---|---|---|---|
| US state breach laws | Organizations holding covered data about residents of that state | Unauthorized access to or acquisition of defined personal data, subject to exceptions | Notice to affected residents; some states also require notice to the attorney general or credit reporting agencies above a threshold | Incident report, legal analysis by state, copies of notices and mailing records |
| US sector rules | For example, covered entities and business associates under HIPAA, financial institutions under GLBA-related rules, and public companies under securities disclosure rules | Breach of protected health, customer financial or other regulated data, or a material incident | Notice to individuals and the relevant regulator, sometimes the media or investors, on the rule’s timeline | Risk assessment, regulator filings, breach log |
| Non-US and supranational privacy laws | Depends on each law’s scope; the EU’s GDPR, for example, can apply to organizations established in the EU or offering goods or services to, or monitoring, people in the EU. Counsel determines applicability | Personal data breach meeting the law’s risk threshold | Notice to the supervisory authority and, when risk is high, to individuals | Internal breach register, regulator correspondence |
| Contracts (vendor role) | Service providers, processors and business associates | A breach affecting a customer’s data | Notice to the customer within the contract’s deadline and cooperation with its investigation | Contract clauses, notice records, incident report shared with the customer |
When it matters for buyers
- After a peer is hit. A common question is whether you would know which laws apply and who would make the call.
- When cyber insurance renews. Insurers ask about incident response plans, breach counsel and notification vendors.
- When signing a vendor contract. The vendor’s breach notice deadline and cost allocation are worth negotiating up front.
- When expanding to new states or countries. Each new jurisdiction can add a law with different rules, including the California Consumer Privacy Act (CCPA) for California data.
Questions to ask vendors
- How quickly will you notify us of a suspected or confirmed incident affecting our data, and is that in the contract?
- What information will your notice include, and will you share forensic findings?
- Where is our data stored, and whose data do you hold for us by state or country?
- Who pays for notification, call center and credit monitoring if your breach affects our customers?
- Do you carry cyber insurance that covers incidents affecting customer data?
- Does your incident response offering include breach counsel coordination and notification support?
How it differs from a data breach
A data breach is the event: unauthorized access to or disclosure of protected data. Breach notification laws are the legal duties that may follow it. Not every breach in the everyday sense triggers a legal notice, and the legal definition of a breach in a given law can be narrower or broader than common usage. Treat “we had a breach” and “we must notify” as separate questions, the second answered with counsel.
