A single incident affecting customers across the US can trigger notification duties in dozens of states at once, each with its own definition, deadline and regulator. Researching that during the incident is not viable, which is why the work has to be done in advance.
What varies between states
- The definition of personal information. Most cover name plus a sensitive identifier. Many now extend to health information, biometrics, credentials, and username-and-password combinations — meaning an incident that is not notifiable in one state is in another.
- The deadline. Some states specify a fixed number of days from discovery; others require notification "without unreasonable delay". Where a fixed clock exists it is often shorter than teams assume.
- Regulator notification. Many states require notifying the attorney general, often at a defined threshold of affected residents, sometimes with a specific form.
- Consumer reporting agency notification above a threshold.
- Content requirements for the notice itself — some states prescribe what it must contain.
- Substitute notice rules where individual contact is impracticable.
The one broadly consistent feature is the encryption safe harbour: if the data was encrypted and the keys were not compromised, notification is generally not required. That is the most concrete regulatory payoff for encryption at rest anywhere in US law, and it belongs in your business case for it.
Know your obligations before the incident
GRC Copilot keeps regulatory and contractual obligations mapped against the systems and data they cover, so the notification question has a prepared answer.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Build the matrix in advance
One table, maintained now, covering the states where you hold resident data. For each: the definition that applies, the deadline and its trigger, the regulator threshold and submission route, content requirements, and whether the encryption safe harbour applies to your storage.
Two practical details cause real problems in the moment. Attorney general portals require registration, which takes time you will not have. And the deadline usually runs from discovery, not from completing the investigation — so the process must be able to notify with partial facts and supplement.
Sector rules sit on top
State law is the floor, not the ceiling. HIPAA imposes its own breach notification regime for covered entities and business associates. The GLBA Safeguards Rule carries an FTC notification duty. Financial regulators including NYDFS impose shorter clocks. Public companies face SEC materiality disclosure. Several of these can apply to the same incident simultaneously, on different timelines, to different recipients.
Who decides
Notification is a legal determination, made by counsel with facts from security — not a call for the incident responder at 2am. Agree in advance who convenes it, what triggers convening, and how the decision and its timing are recorded. Document breaches you decide are not notifiable, with reasoning; that record is what demonstrates a process existed.
Frequently asked questions
Do we notify based on where we are or where the customer is?
Where the affected individual resides. That is why a single incident reaches many states at once.
Does encryption remove the obligation?
Generally yes under most state statutes, provided the keys were not also compromised. Confirm per state and document your encryption status.
Is there a federal breach law?
No comprehensive one. Sector rules exist — HIPAA, GLBA, SEC disclosure — and apply alongside state law.
What if we cannot identify affected individuals quickly?
Deadlines generally run from discovery regardless. Notify on what is known, and supplement — delay is the greater exposure.
Key takeaways
- Obligations follow the individual's residence, so one incident triggers many.
- Deadlines usually run from discovery, not from finishing the investigation.
- Register attorney general portals in advance.
- The encryption safe harbour is the strongest regulatory argument for encryption at rest.