Data Breach Notification Laws by State: Deadlines, AG Notice, and the New 30-Day Floor
Last updated August 2026 · Obtainer
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
Every US state, the District of Columbia and the territories have a data breach notification law, and there is still no general federal statute that replaces them. Twenty states set an actual number, between 30 and 60 days. The remaining thirty-one jurisdictions use a qualitative standard instead, usually "in the most expedient time possible and without unreasonable delay". In a breach touching residents of more than one state, the strictest applicable clock governs the whole response, and since January 1, 2026 that floor is 30 days.
That floor moved this year. California ran on an open-ended standard for two decades. SB 446, signed in October 2025 and effective January 1, 2026, replaced it with a hard 30 calendar days from discovery, plus 15 more days to send the Attorney General a copy of the notice when 500 or more California residents are affected. If you serve customers nationally, you now build your incident response to 30 days regardless of where you are incorporated.
How long do you have to notify after a data breach?
Thirty days if any California, Colorado, Florida, New York or Washington resident is in the affected data. Forty-five days in ten more states. Sixty days in five. Everywhere else the answer is "without unreasonable delay", which sounds generous and is not: regulators read it against how long your investigation actually needed, not how long it took, and a delay you cannot explain in an incident log is the part that gets cited.
The classification below follows the 2026 fifty-state survey published by the Privacy Rights Clearinghouse. Breach statutes get amended most sessions, so confirm a row against the current text of the statute before you build a response plan on it.
| Consumer notice deadline | States | When the clock starts | What else it usually triggers |
|---|---|---|---|
| 30 calendar days | California, Colorado, Florida, New York, Washington | Discovery of the breach, or notification of it by someone else | California requires a sample copy of the consumer notice to the Attorney General within 15 days of notifying consumers, at 500 or more residents |
| 45 days | Alabama, Arizona, Indiana, New Mexico, Ohio, Oregon, Rhode Island, Tennessee, Vermont, Wisconsin | Usually discovery, sometimes the determination that a reportable breach occurred | Several of these pair the cap with a "reasonably practicable" standard, so the number is a ceiling and not a budget |
| 60 days | Connecticut, Delaware, Louisiana, South Dakota, Texas | Discovery | Texas requires notice to the Attorney General once 250 residents are affected |
| No fixed number | The other 31 jurisdictions, including DC | Not specified | "Most expedient time possible and without unreasonable delay", measured against your investigation |
Why two state-by-state surveys give you two different lists
Compare any two breach notification guides and the buckets will not match. That is not sloppiness, it is the statutes. Three things make a state hard to classify, and knowing which one applies to you matters more than the label.
Hybrid statutes carry both standards at once. Maryland is the clearest example. Md. Code Com. Law 14-3504 says notice "shall be given as soon as reasonably practicable, but not later than 45 days after the business discovers or is notified of the breach". A survey grouping by the operative standard puts Maryland with the qualitative states. A survey grouping by whether a number appears puts it at 45 days. Both are defensible readings, and neither helps you if you assumed you had 45 days when the real duty was to move as soon as you reasonably could.
Some numbers govern the regulator, not the consumer. A statute can leave consumer notice open-ended while putting a hard deadline on the Attorney General filing, or the reverse. Oklahoma's amended law, effective January 1, 2026, requires AG notice at 500 or more affected residents no later than 60 days after residents are notified. That 60 is not a consumer deadline at all.
Law enforcement delay provisions restart the math. Most states let you pause notification at the request of law enforcement. What varies is what happens afterward. Maryland gives you 7 days after the agency confirms it will not impede the investigation, if the original 45 days has already run out. Plan around the restart, not just the pause.
What changed in 2026
Two states rewrote their statutes for January 1, 2026, and both changes point the same direction: fixed numbers, wider definitions of personal information, and more reporting to the state.
| State | Before | After, effective January 1, 2026 |
|---|---|---|
| California SB 446, signed October 2025 | Notice "without unreasonable delay", no maximum | 30 calendar days from discovery or notification. Sample notice to the Attorney General within 15 days of notifying consumers when 500 or more residents are affected. Personal information expanded to reach biometric data, medical information and online account credentials |
| Oklahoma SB 626, first amendment since 2008 | 2008 statute, narrow definition, no AG reporting duty | Personal information expanded to include biometric data. AG notice at 500 or more residents, no later than 60 days after notifying them. Credit bureau notice above 1,000 residents. A defined "reasonable safeguards" standard that creates an affirmative defense for entities meeting it |
The Oklahoma affirmative defense is worth a second look even if you have no Oklahoma customers, because it is the same move Tennessee made in its privacy law. A documented program, risk assessments, training and a written incident response plan stop being paperwork and start being a legal position. That only works if the documentation exists before the incident, which is the whole point of the drafting.
Do you have to notify the attorney general?
In most of the country, yes, above a threshold. Thirty-six states, about 71 percent, require a report to the Attorney General or another state agency. Thresholds cluster at 250, 500 and 1,000 affected residents, counted per state rather than in total, so a 900-person breach can trigger a filing in one state and nothing in its neighbor.
Two practical wrinkles. The recipient is not always the Attorney General: Hawaii routes reports to its Office of Consumer Protection and South Carolina to its Department of Consumer Affairs. And only about 21 states publish those filings in a searchable portal, so the absence of your incident from a public list says nothing about whether you filed correctly.
Can consumers sue over a data breach?
In roughly half the country. The Privacy Rights Clearinghouse survey counts 24 states, about 47 percent, providing some private right of action tied to breach violations. California's is the one that shapes litigation strategy nationally: Civil Code 1798.150 lets a consumer whose nonencrypted and nonredacted personal information was exposed through a failure to maintain reasonable security recover statutory damages per consumer per incident, or actual damages if greater. The statute sets that range at $100 to $750, and because the CCPA's dollar amounts are adjusted for inflation in January of every odd-numbered year, the amounts currently in force are $107 to $799. Note where that sits. It is the one CCPA provision with a private right of action, and the civil penalties enforced by the CPPA and the Attorney General run separately from it.
Why the notification list is a discovery problem before it is a legal one
The clock starts at discovery, not when forensics finishes. Inside those 30 days you have to answer three questions that no security tool answers for you: which individuals had records in the affected system, which data elements about each of them were exposed, and which state each of those individuals lives in. Only the third one decides your deadline and your Attorney General thresholds, and it is the one most companies cannot answer quickly, because residency lives in a billing record or a shipping address rather than in the breached system.
That is the same work a privacy request needs, run at population scale instead of one person at a time. Teams that already know where personal data lives across their systems spend the first week of an incident scoping the notification list. Teams that do not spend it building an inventory under deadline pressure, which is the expensive way to learn what you have.
Detection deserves the same honesty. The clock runs from discovery however discovery happens, and plenty of teams learn about an incident from a customer post or a researcher's write-up before their own alerting catches it, which is why some pair internal monitoring with watching where the brand is being talked about across the web. An incident you hear about secondhand still started your 30 days.
What happens after the notices go out
Requests. A breach notice tells thousands of people, in writing, that you hold data about them, and a predictable share of them will ask what you have, ask you to delete it, or both. Those arrive as data subject requests under the state privacy laws, on their own clocks: generally 45 days plus a 45-day extension in eighteen states, 90 plus 45 in Iowa, and 45 plus 15 in Florida. They are separate obligations from the breach notice and they do not pause because you are mid-incident.
So the incident that consumed your privacy team for a month is followed by the request volume it generated, from the same population, against the same systems, on a second set of deadlines you now have to track per request. Planning for that wave in the response plan, rather than discovering it in week five, is the difference between a hard month and a bad quarter.
How to build one process instead of fifty
Four decisions, made before you need them:
- Build to 30 days. The strictest clock governs a multi-state breach and it is now 30. Designing to a 60-day statute and hoping no Californian is in the file is not a plan.
- Keep a residency count you can pull on demand. Your per-state resident numbers decide which Attorney General thresholds you cross. This is the same count that decides which state privacy laws apply to you in the first place, so it earns its keep twice.
- Write down the thresholds now. 250 in Texas, 500 in California and a group of others, 1,000 elsewhere, plus the credit bureau notice most states require above 1,000. Deciding these mid-incident is how filings get missed.
- Document a decision not to notify. Where you conclude notice is not required, record why. Maryland requires the business to keep those records for three years after the determination, and even where a state does not say so, a written analysis is the only version of that decision that survives a later inquiry.
None of this is legal advice, and the notification decision itself belongs to your counsel. What can be prepared in advance is the evidence underneath it: an accurate picture of which systems hold personal data about whom, and a record of what was searched and what was found. That preparation is also what makes the twenty comprehensive state privacy laws manageable, because a breach and a consumer data request under the CCPA ask you the same underlying question and only differ in how many people they ask it about.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.