What you need to know for compliance coast-to-coast.
Starting back in the year 2020 we unwittingly began an annual tradition by posting an article containing links to data breach laws from each state, only to have it go on to become one of our most popular posts. Because of this enduring popularity and because laws surrounding the use (and abuse) of technology are always evolving, we’ve been taking another look at these laws on an annual basis.
For this 2026 review we have removed some dead links, along with expanding information on potential penalties for noncompliance. We did not note any new laws this year, however some legislation introduced under a state House or Senate bill number have been updated to reflect their permanent statuatory designations.
While compiling this list we found many similarities between each state’s legislation, including many who do not apply their specific laws to organizations who already must comply with federal legislation such as HIPPA or GLBA. Despite these similarities, not every state is the same, which is why we’re providing the following list.
Please note: While we have made an effort to make sure this information is accurate, we are not a legal firm and this list is only intended to be a jumping-off point for your own research into the subject. As always, any policy decisions you make regarding compliance with legal statutes should be made with the advice of a lawyer.
Alabama: Statute 8-38-1– Requires notification in writing no later than 45 days after discovery of a breach. In cases impacting more than 1,000 residents more reporting requirements apply, and penalties for noncompliance can reach up to $500,000 plus a daily fine. The law also requires an investigation to determine if the breach is likely to cause substantial harm.
Alaska: Statute 45.48.010 – Requires notification “without reasonable delay” of any breach that may have resulted in unauthorized acquisition of personal information. Breaches impacting more than 1,000 residents require credit monitoring agency notification. Penalties include fines of $500 for each customer not notified, up to $50,000.
Arizona: Statute 18-552 – Requires notification within 45 days, unless the breach is not likely to result in “substantial economic loss” to those impacted. If more than 1,000 residents are impacted mandatory reporting to credit monitoring agencies, the AZ Secretary of State and AZ Attorney General applies. Organizations in compliance with GLBA are deemed to be in compliance with this law. Noncompliance is considered consumer fraud.
Arkansas: Code 4-110-101 – Requires notification “without unreasonable delay” unless there is no reasonable likelihood of harm. Notification may be delayed for law enforcement purposes. Breaches impacting more than 1,000 people require the state Attorney General to be notified. Noncomplaince is considered a violation of the Deceptive Trade Practices Act.
California: Civil Code 1798:29 – Requires notification “without unreasonable delay,” and also requires notification of the state Attorney General if more than 500 customers are impacted. Businesses in violation are subject to civil action by those impacted by the breach, in addition to civil penalties sought by the state Attorney General.
Colorado: Statute 6-1-716 – Requires notification no later than 30 days after determination of a breach, along with notification of the state Attorney General if more than 500 customers are impacted. Organizations in compliance with their own state’s regulations are deemed to be in compliance with this law. Violations are considered deceptive trade practices and can incur fines of up to $20,000.
Connecticut: Statute 36a-701b – Requires notification no later than 60 days after determination of a breach, including notification of the state Attorney General regardless of the number of customers impacted. Any breach involving an SSN/TIN requires 24 months of credit monitoring services be provided to those impacted. Noncompliance can result in a fine of up to $5,000 per impacted customer.
Delaware: Code Title 6, Chapter 12B – Requires notification no later than 60 days after determination of a breach, unless the breach is unlikely to result in harm to those impacted. Organizations with their own notification policy are deemed to be in compliance with this law, as long as notification is provided within 60 days. The Attorney General must be notified if more than 500 people are impacted, and one year of credit monitoring must be offered if an SSN/TIN was involved. Noncompliance may be prosecuted by the Attorney General.
Florida: Statute 501.171 – Requires notification no later than 30 days after determination of a breach, along with notification of the state Department of Legal Affairs if more than 500 customers are impacted. Failure to notify can result in fines of $1,000 for each day the breach remains undisclosed, increasing to $50,000 for each month thereafter.
Georgia: Code 10-1-912 – Requires notification “without unreasonable delay,” along with notification of all nationwide consumer reporting agencies if more than 10,000 customers are impacted. Violations are prosecuted under the Georgia Fair Business Practices Act and can involve fines of up to $100 per customer impacted.
Hawaii: Statute 487N-1 – Requires notification “without unreasonable delay,” along with notification of the state Office of Consumer Protection if more than 1,000 customers are impacted. Organizations in compliance with GLBA are deemed to be in compliance with this law. Penalties for noncompliance include a fine of up to $2,500 per customer impacted along with possible private civil action.
Idaho: Code 28-51-104 – Requires notification “in the most expedient time possible.” Notification of the state Attorney General is not required from commercial entities. Noncompliance can result in a fine of up to $25,000 per breach.
Illinois: 815 ILCS 530 – Requires notification “without unreasonable delay.” Organizations may develop their own notification policy so long as it complies with the state law. A breach impacting more than 500 customers requires the state Attorney General be notified. Noncompliance is considered a violation of the IL Consumer Fraud and Deceptive Business Practices Act.
Indiana: Code 4-1-11, 24-4.9 – Requires notification “without unreasonable delay” if the breach could result in identity theft or fraud. Organizations in compliance with GLBA are deemed to be in compliance with this law. All nationwide credit monitoring agencies must be notified if more than 1,000 residents are impacted. Noncompliance can result in penalties up to $150,000 per breach.
Iowa: Code 715C.1 – Requires notification “without unreasonable delay,” along with notification of the state Attorney General if more than 500 customers are impacted. Organizations in compliance with GLBA are deemed to be in compliance with this law. Violations may be prosecuted under the Iowa Consumer Fraud Act.
Kansas: Statute 50-7a01 – Requires notification “without unreasonable delay” unless personal information is unlikely to be abused. If more than 1,000 customers are impacted, all nationwide consumer reporting agencies must be notified as well. Penalties for noncompliance are at the discretion of the Attorney General.
Kentucky: Statute 365.732 – Requires notification “without unreasonable delay” unless personal information is unlikely to be abused. If more than 1,000 customers are impacted, all nationwide consumer reporting agencies must be notified as well. Organizations in compliance with GLBA are deemed to be in compliance with this law. Penalties under the Kentucky Consumer Data Protection Act can reach up to $7,500 per violation.
Louisiana: Statute 51:3071 – Requires notification no later than 60 days after a breach has been discovered, unless there is no likelihood of harm to those impacted. Notification of the state Attorney General is also required, if consumers must be notified. Organizations in compliance with GLBA are deemed to be in compliance with this law. Violations of this law are considered an unfair trade practice and can results in fines up to $5,000.
Maine: Statute 1346 – Requires notification “without unreasonable delay” (but no more than 30 days), along with notification of the state Attorney General unless there is no reasonable likelihood the information will be abused. Penalties associated with this law include fines up to $500 per violation.
Maryland: Commercial Code 14-3501 – Requires notification no later than 45 days after discovery of a breach. If more than 1,000 residents are impacted the state Attorney General must be notified before (or at the same time as) customers. Organizations in compliance with GLBA are deemed to be in compliance with this law. Noncompliance can result in fines of up to $10,000 per violation, and residents have the right to pursue damages personally.
Massachusetts: General Law 93H – Requires notification “without unreasonable delay,” along with notification of the state Attorney General and Office of Consumer Affairs and Business Regulation. Organizations in compliance with GLBA are deemed to be in compliance with this law. Penalties under this law include civil penalties up to $5,000 per violation and fines of up to $50,000.
Michigan: Statute 445.63 – Requires notification “without unreasonable delay,” unless an investigation finds the breach is not likely to cause substantial loss or injury to those impacted. Organizations in compliance with GLBA are deemed to be in compliance with this law. Civil fines for failing to provide notice can reach up to $750,000.
Minnesota: Statute 325E.61 – Requires notification “without unreasonable delay,” along with notification of all nationwide consumer reporting agencies if more than 500 customers are impacted. Violations under the Minnesota Consumer Data Privacy Act can incur penalties of up to $7.500 per violation.
Mississippi: Code 75-24-29 – Requires notification “without unreasonable delay,” unless the breach is not likely to cause substantial loss or injury to those impacted. Organizations in compliance with GLBA are deemed to be in compliance with this law. Penalties for noncompliance are handled by the Attorney General as an unfair trade practice.
Missouri: Statute 407.1500 – Requires notification “without unreasonable delay,” unless there is no likelihood of identity theft or fraud. Notification of the state Attorney General and all nationwide consumer reporting agencies is required if more than 1,000 customers are impacted. Organizations in compliance with GLBA are deemed to be in compliance with this law. There is a cap of $150,000 per breach for violations of this statute.
Montana: Code 30-14-1704 – Requires notification “without unreasonable delay,” along with notification of the state Attorney General’s office of Consumer Protection. The Attorney General can levy penalties under the Montana Consumer Protection Act.
Nebraska: Statute 87-801 – Requires notification “without unreasonable delay,” unless it is unlikely the disclosed information will be abused. Organizations in compliance with GLBA are deemed to be in compliance with this law. The state Attorney General must also be notified at the same time as customers. The Attorney General can also pursue damages on behalf of citizens impacted by the breach.
Nevada: Statute 603A.010 – Requires notification “without unreasonable delay,” along with notification of all consumer reporting agencies if more than 1,000 customers are impacted. Notification of the Attorney General is optional; their office can pursue damages under the state’s consumer protection laws.
New Hampshire: Statute 359-C:20 – Requires notification “as soon as possible,” along with notification of the state Attorney General and all consumer reporting agencies if more than 1,000 customers are impacted. Organizations in compliance with GLBA are not bound by this law. New Hampshire residents can pursue private action against companies responsible for a breach.
New Jersey: Statute 56:8-163 – Requires notification “without unreasonable delay,” unless misuse of the information is not reasonably possible. Prior to notification of customers, the State Police department of Law and Public Safety must be notified. Willful noncompliance can be punished with penalties of up to $10,000 on a first offence.
New Mexico: Statute 57-12B-1 – Requires notification no later than 45 days after discovery of a breach. If more than 1,000 customers are impacted, notification of the state Attorney General and all nationwide consumer reporting agencies is also required. Organizations in compliance with GLBA are exempt from this law. Noncompliance can result in penalties of up to $150,000.
New York: General Business Law 899-aa – Requires notification “without unreasonable delay” after a breach is discovered. Additionally, the state Attorney General, the NY Department of State and State Police must also be notified. If more than 5,000 customers are impacted, consumer reporting agencies must also be notified. Maximum penalties for noncompliance are capped at $250,000.
North Carolina: Statute 75-65 – Requires notification “without unreasonable delay” after a breach is discovered. The state Attorney General’s office must be notified, as well as all nationwide consumer reporting agencies if more than 1,000 customers have been impacted. The Attorney General and private citizens can pursue damages for noncompliance.
North Dakota: Code 51-30-01 – Requires notification “without unreasonable delay,” along with notification of the state Attorney General if more than 250 customers are impacted. Organizations may maintain their own notification policies so long as they comply with state law. Noncompliance is considered an unlawful business practice and can be prosecuted by the Attorney General.
Ohio: Revised Code 1349.19 – Requires notification within 45 days after discovery of a breach. If more than 1,000 customers are impacted, all nationwide consumer reporting agencies must be notified as well. Organizations in compliance with GLBA are deemed to be in compliance with this law. Violations can be prosecuted under the Ohio Consumer Sales Practices Act.
Oklahoma: Statute 24-161 – Requires notification “without unreasonable delay” after discovery of a breach. Organizations may maintain their own notification policies so long as they are in compliance with state law. If more than 500 residents are impacted, the state Attorney General must be notified, and if more than 1,000 residents are impacted all nationwide credit reporting agencies must also be notified. The state Attorney General can also pursue civil action against companies for noncompliance.
Oregon: Statute 646A.600 – Requires notification no later than 45 days after discovery of a breach. The state Attorney General must also be notified if more than 250 customers are impacted. If more than 1,000 customers are impacted, all nationwide consumer reporting agencies must also be notified. Organizations in compliance with GLBA are deemed to be in compliance with this law. Violations may be treated by the Attorney General as an unfair business practice.
Pennsylvania: Statute 73-2301 – Requires notification “without unreasonable delay,” along with notification of the state Attorney General if more than 500 people are impacted, and all nationwide consumer reporting agencies if more than 1,000 are impacted. Violations can be prosecuted under the PA Unfair Trade Practices and Consumer Protection law.
Rhode Island: General Law 11-49.3 – Requires notification no later than 45 days after discovery of a breach. If more than 500 customers are impacted, the state Attorney General and all major credit reporting agencies must also be notified. Organizations in compliance with GLBA are deemed to be in compliance with this law. The Attorney General can seek civil penalties for violations of this law.
South Carolina: Code 39-1-90 – Requires notification “without unreasonable delay” after discovery of a breach. The state Department of Consumer Affairs and all nationwide reporting agenices must be notified if more than 1,000 customers are impacted. Organizations in compliance with GLBA are deemed to be in compliance with this law. Residents can sue for negligence in the event of noncompliance, along with penalties assessed by the SC Department of Consumer Affairs.
South Dakota: Statute 22-40-19 – Requires notification within 60 days of discovering a breach. Consumer reporting agencies must also be notified of the breach. If more than 250 customers are impacted, the state Attorney General must also be notified. Organizations in compliance with GLBA are deemed to be in compliance with this law. Violations are treated as unfair business practices, with the Attorney General able to levy penalties of up to $500,000 per breach.
Tennessee: Code 47-48-2107 – Requires notification within 45 days of the discovery of a breach. All consumer reporting agencies must be notified if more than 1,000 customers are impacted. Organizations in compliance with GLBA are deemed to be in compliance with this law. In 2021, the law was a,emded to change reporting deadlines in the case of a pending criminal investigation. The Attorney General can seek penalties under the state Consumer Protection Act.
Texas: Statute 521.053 – Requires notification “as quickly as possible” after discovery of a breach, and no later than 60 days. If more than 250 residents are impacted the state Attorney General must be notified, if more than 10,000 are impacted all nationwide consumer reporting agencies must be notified as well. The Attorney General can assess fees of up to $50,000 for noncompliance, along with $100 per individual impacted per day up to $250,000.
Utah: Code 13-44-101 – Requires notification “without unreasonable delay” after discovery of a breach, unless misuse of data is unlikely. If more than 500 residents are impacted the state Attorney General and Cyber Center must be notified, and if more than 1,000 are impacted all nationwide reporting agencies must be notified as well. Noncompliance can result in civil penalties from the state Attorney General.
Vermont: Statute 9-2430 – Requires notification within 45 days of the discovery of a breach. The state Attorney General or Department of Financial Regulation must also be notified within 14 days. All consumer reporting agencies must also be informed if more than 1,000 customers are impacted. Violations can be prosecuted under the Vermont Data Privacy and Online Surveilance Act, with penalties of up to $10,000 per violation.
Virginia: Code 18.2-186.6 – Requires notification “without unreasonable delay” after discovery of a breach. The state Attorney General must also be notified, along with all nationwide consumer reporting agencies if more than 1,000 customers are impacted. Organizations in compliance with GLBA are deemed to be in compliance with this law. The state Attorney General can assess a penalty of up to $150,000 per breach for noncompliance.
Washington: Code 19.255.010 – Requires notification no later than 30 days after the discovery of a breach, unless the breach is unlikely to cause harm. If more than 500 customers are impacted, the attorney general must also be notified. The Attorney General can seek damages under the WA Consumer Protection Act, and citizens can bring private legal action as well.
West Virginia: Code 46A-2A-101 – Requires notification “without unreasonable delay,” along with notification of all consumer reporting agencies if more than 1,000 customers are impacted. Organizations in compliance with GLBA are deemed to be in compliance with this law. Failure to comply is considered an unfair or deceptive practice under WV consumer protection laws.
Wisconsin: Statute 134.98 – Requires notification within 45 days of the discovery of a breach. All nationwide consumer reporting agencies must also be notified if more than 1,000 customers are impacted. Organizations in compliance with GLBA are deemed to be in compliance with this law. Failure to comply can result in penalties of up to $1,000 per incident.
Wyoming: Statute 40-12-501 – Requires notification “without unreasonable delay” after the discovery of a breach. Organizations in compliance with GLBA are deemed to be in compliance with this law. The state Attorney General has the right to bring action against organizations for noncompliance.
Original article by Matt Jolley CISA. Staff Auditor / Data Security Analyst, infotex
Matt is Vigilize, bringing you Article Reviews for years.