
Short answer: States set their own rules for telling people their data was stolen, and the rules differ on how fast you must act. Among the ten states read for this guide, five set a 30-day limit (California, New York, Florida, Washington and Colorado). Ohio sets 45 days and Texas sets 60. Illinois, Massachusetts and Virginia set no number and say "without unreasonable delay." If you have customers in several states, plan to the shortest deadline and the widest list of who must be told. This is general information, not legal advice.
TL;DR
- A breach notification law is a statute (a law passed by a legislature) that says when you must tell people, and sometimes the state, that their data was exposed.
- This guide covers ten named states, each read from the official statute text. It does not cover all 50.
- The big differences are the deadline, when the clock starts, what data counts, and whether a regulator, the state office that enforces the law, must also be told.
- Each law protects the residents of its own state. One breach can trigger several laws at once. Note where each person lives and the discovery and decision dates.
- Laws change. Confirm every row against the current statute.
What a breach notification law does
A data breach, in these laws, is an incident where someone without permission gets at computer data about people. The statutes ask three questions. Is the data the kind the law protects? Does the event count as a breach? How long do you have to tell people?
Personal information, the data these laws protect, means a person's name plus a sensitive item, such as a Social Security number or a bank card number. Newer laws add medical records, fingerprints and online login details.
I read each section on the official state site in October 2026. I chose ten states because they are large or show the range of approaches.
State data breach notification laws: ten states side by side
In the table, the AG is the state attorney general, the state's chief legal officer. A credit bureau is a consumer reporting agency such as Equifax. "Residents" means people who live in that state. Encrypted data is scrambled so it cannot be read without a key. Redacted data is masked, such as showing only the last four digits. Biometric data is body-based, like a fingerprint. Geolocation data shows where a person has been. "Acquisition" means someone obtained the data, while "access" means they could view it.
| State and citation | What counts as a breach, and what data | Deadline to tell individuals | Who else must be told |
|---|---|---|---|
| California, Cal. Civ. Code § 1798.82 | Unauthorized acquisition of data. Name plus Social Security, government ID, account, medical, health insurance, biometric, genetic or license plate reader data, or login details | Within 30 calendar days of discovery or notification | AG gets a copy of the notice sent if more than 500 residents, within 15 calendar days of notifying them |
| Texas, Tex. Bus. & Com. Code § 521.053 (definitions in § 521.002) | Unauthorized acquisition. Name plus Social Security, ID or account data, or health information that identifies a person | Without unreasonable delay, and no later than the 60th day after you determine a breach occurred | AG within 30 days if at least 250 residents; credit bureaus if more than 10,000 people notified |
| New York, N.Y. Gen. Bus. Law § 899-aa | Unauthorized access to or acquisition of data. Name-type identifier plus Social Security, ID, account, biometric, medical or health insurance data, or login details | Within 30 days after the breach is discovered | AG, Department of State and State Police; credit bureaus if more than 5,000 residents |
| Florida, Fla. Stat. § 501.171 | Unauthorized access of data. Name plus Social Security, ID, account, medical, health insurance, biometric or geolocation data, or login details | As expeditiously as practicable, no later than 30 days after you determine the breach; 15 more days if you show good cause in writing | Department of Legal Affairs within 30 days if 500 or more people; credit bureaus if more than 1,000 |
| Illinois, 815 ILCS 530/10 (definitions in 530/5) | Unauthorized acquisition. Name plus Social Security, ID, account, medical, health insurance or biometric data, or login details | "Most expedient time possible and without unreasonable delay." No number | AG if more than 500 residents, no later than when consumers are told |
| Washington, RCW 19.255.010 (definitions in 19.255.005) | Unauthorized acquisition of data that was not encrypted or otherwise made unreadable. Name plus Social Security, ID, account, birth date, health, biometric and other items, or login details | No more than 30 calendar days after the breach was discovered | AG within 30 days if more than 500 residents |
| Colorado, C.R.S. § 6-1-716 | Unauthorized acquisition of unencrypted data. Name plus Social Security, ID, medical, health insurance or biometric data; also login details or account numbers with codes | Most expedient time possible, no later than 30 days after you determine a breach occurred | AG within 30 days if 500 or more residents; credit bureaus if more than 1,000 |
| Massachusetts, M.G.L. c. 93H, §§ 1, 3 and 3A | Unauthorized acquisition or use that creates a serious chance of identity theft or fraud. Name plus Social Security, ID or financial account number | "As soon as practicable and without unreasonable delay." No number | AG and the Director of Consumer Affairs and Business Regulation, with no minimum count; bureaus the Director names |
| Ohio, Ohio Rev. Code § 1349.19 | Unauthorized access and acquisition that is believed to create a real chance of identity theft or fraud. Name plus Social Security, ID or financial account data | No later than 45 days after discovery or notification | No AG notice required in this section; credit bureaus if more than 1,000 residents |
| Virginia, Va. Code § 18.2-186.6 | Unauthorized access and acquisition of unencrypted, unredacted data that causes or is believed to cause identity theft or fraud. Name plus Social Security, ID, account, passport or military ID | "Without unreasonable delay." No number | AG, with no minimum count; AG and credit bureaus if more than 1,000 people notified at once |
Some add extras. California requires a notice titled "Notice of Data Breach" under set headings. It also requires any identity theft services you offer to be free for at least 12 months when your business was the source and a Social Security or government ID number was exposed. Massachusetts requires at least 18 months of free credit monitoring when a Social Security number is involved. Its notice to residents may not describe the nature of the breach. Florida allows money penalties of up to $500,000. Virginia's AG may impose up to $150,000 per breach. Colorado changed this section in 2026 (House Bill 26-1426, effective August 12, 2026). California's 30-day limit came from Senate Bill 446 of 2025, effective January 1, 2026.
Each row comes from the official site of that state's legislature or code publisher. Ohio's section shows a single version, effective March 30, 2007. You can read two of these yourself: the California statute and the Texas chapter. Our guide to citing a statute in plain English explains the citations in the first column. In short, RCW means Revised Code of Washington, ILCS means Illinois Compiled Statutes, and C.R.S. means Colorado Revised Statutes.
One sentence that sets the deadline
Washington puts its deadline in one sentence. This is RCW 19.255.010(8), from the Washington Legislature's site:
"Notification to affected consumers under this section must be made in the most expedient time possible, without unreasonable delay, and no more than thirty calendar days after the breach was discovered, unless the delay is at the request of law enforcement ..."
Three things matter here. "Most expedient time possible" still applies, so 30 days is a ceiling. The clock starts at discovery. The rest of the sentence, cut here, also allows delay for the work needed to learn what was taken.
How the states differ
The deadline. Some states give a number of days. Others say "without unreasonable delay." No number does not mean no deadline. What counts as reasonable is decided case by case.
When the clock starts. California, New York and Washington count from discovery. Texas, Florida and Colorado count from when you decide a breach occurred. Ohio counts from discovery or notification. That choice can move the date, so write down when each event happened.
What data counts. Three states protect a short list of Social Security, government ID and financial account numbers. Others add health data, biometrics and online login details.
What event counts. Most states ask whether data was acquired. New York says "access to or acquisition of," and Florida says "access." Massachusetts adds unauthorized use. Massachusetts, Ohio and Virginia also tie the breach to a risk of identity theft or fraud.
Who else is told. Texas sets the lowest count for the attorney general, 250 residents. Several states use 500. Massachusetts and Virginia set no count. Nine of the ten states have a rule to notify a regulator. Ohio is the exception in the section I read. Credit bureau notice usually starts above 1,000 people, though New York uses 5,000 and Texas 10,000.
Why plan to the strictest rule
Each statute protects the residents of its own state, so the state where your company sits does not decide which law applies. A breach touching customers in California, New York and Texas can trigger all three laws. Texas lets notice under another state's law count for that state's residents.
That is simpler than it sounds. You do not need ten plans. You need one plan built on the tightest points in the table. For planning, prepare to tell individuals within 30 days of discovery. Prepare to tell any regulator within 30 days where the threshold is met. Check the exceptions for police requests and for fields with their own federal rules, such as health care and banking. Several of these statutes treat HIPAA (the federal health privacy law) and the Gramm-Leach-Bliley Act (the federal law for financial firms) differently.
Common mistakes
- Following only your home state's law. The residents' states decide, so list where each affected person lives.
- Reading "no fixed number" as "no deadline." Illinois, Massachusetts and Virginia still require speed.
- Starting the clock late. A date of "discovery" and a date of "determination" are not always the same. Record both.
- Forgetting the regulator. Telling customers does not tell the attorney general. Nine of these ten states have a regulator notice rule, some only above a size threshold.
- Treating encryption as a full exemption. In California, Washington, Colorado and Illinois, notice is still required if the key to decode the data was also taken.
- Skipping the written file. New York and Florida let you skip notice after a written finding that the breach is unlikely to hurt anyone. You must keep that finding for five years.
- Using an old chart. Several sections here were amended in 2023 or later. Check the history line at the foot of each one.
What this guide does not cover
This guide covers ten states. It does not cover the other states, the District of Columbia or the territories, and a missing state does not mean it has no law. To find the rest, follow our guide on how to run a 50-state survey. For wider privacy rules, see our state privacy laws guide. Our post on legal data freshness explains why charts fall behind.
This guide is not legal advice. Definitions and deadlines change, and facts decide how a rule applies to you. Confirm each row against the current statute, and ask a lawyer before you act on a real incident.
This guide is part of US Law Data: The Complete Guide, a map of where US law comes from and how to use it.
FAQ
What is the deadline to notify people of a data breach?
It depends on the state. Among the ten read here, five say 30 days, one says 45, one says 60, and three give no number. Plan to the shortest one that covers your customers.
Which state's law applies to my business?
The law of each state where affected people live can apply, whether or not your company is based there. A single breach can trigger several states' laws. List the home state of every affected person first.
Do I have to tell the attorney general?
Often, but not always. Texas requires it from 250 residents. California asks for a copy of the notice above 500. Massachusetts and Virginia set no minimum. The Ohio section I read has no such notice. Check each state.
Does encryption mean I do not have to give notice?
Not by itself. If the key to decode the data was also taken, several states still require notice.
What counts as personal information?
At a minimum, a name plus a Social Security number, a driver's license number or a bank account number. Many states add health data, fingerprints and login details. The table shows each state's list.
What happens if I am late?
Florida allows money penalties of up to $500,000. Virginia's attorney general may impose up to $150,000 per breach. New York allows a money penalty for knowing or reckless violations.
Where do I find the other states?
Start on each state legislature's official site and search the phrase "breach of security." Then follow the six steps in our 50-state survey guide.
To pull current statute text into your own state chart, see our legal API, a data feed that software can use.
New legal AI guides, weekly.
Further Reading
State Consumer Protection Laws (UDAP Statutes) Explained: 12 States Side by Side
Read postDeepfake Laws by State: What Is Actually on the Books (14 States)
Read postState Privacy Laws: Which States Have One and Where to Read It
Read postHow to Run a 50-State Survey: A Step-by-Step Guide
Read postUSC vs CFR: What the Abbreviations Mean and How They Differ
Read postWhat Does Codified Mean in Law? A Plain Guide With Real Examples
Read post
Co-Founder & CTO
Priyansh leads engineering and AI at Vaquill AI: the pipelines that pull statutes, regulations and court rules from every US jurisdiction's official publisher, and the REST API, MCP server and open dataset that serve them.