Law compared across the United States
Data Breach Notification Laws by State — Who Must Be Told, and How Fast, in All 50 States
Each state's statute requiring notice after a breach of personal information — the trigger, the deadline, and who must be notified.
51 states with matching statutes. Every section links to its full text.
State by state
Alabama
- AL 27 § 27-62-6 — Insurance › Insurance Data Security Law
“(g)(1) In the case of a cybersecurity event involving nonpublic information that is in the possession, custody, or control of a licensee that is an insurer or its third-party service provider for which a consumer accessed the services of the insurer through an independent insurance producer, and for which consumer notice is required by the Alabama Data Breach Notification Act of 2018, Chapter 38 of Title 8, the insurer shall notify the producers of record of all affected …”
- AL 8 § 8-38-2 — Commercial Law and Consumer Protection › Data Breach Notification Act of 2018
- AL 8 § 8-38-3 — Commercial Law and Consumer Protection › Data Breach Notification Act of 2018
- AL 8 § 8-38-4 — Commercial Law and Consumer Protection › Data Breach Notification Act of 2018
- AL 8 § 8-38-5 — Commercial Law and Consumer Protection › Data Breach Notification Act of 2018
Alaska
- AK 21 § 21.23.280 — Insurance › Risk management and insurance data security
“(d) In addition to the requirements of this section, a licensee shall comply with all applicable provisions of AS 45.48 (Alaska Personal Information Protection Act). If a licensee is required to notify the director of a cybersecurity event under (a) of this section and is also required to provide notice under AS 45.48, the licensee shall provide to the director a copy of the notice sent to consumers under AS 45.48.”
- AK 45 § 45.48.010 — Trade and Commerce › Personal Information Protection Act
Arizona
- AZ 18 § 18-552 — Information Technology › NETWORK SECURITY › Data Security Breaches
“C. A person that maintains unencrypted and unredacted computerized personal information that the person does not own or license shall notify, as soon as practicable, the owner or licensee of the information on discovering any security system breach and cooperate with the owner or the licensee of the personal information, including sharing information relevant to the breach with the owner or licensee. The person that maintains the data under an agreement with the owner or …”
- AZ 11 § 11-441 — Counties › COUNTY OFFICERS › Sheriffcited 8×
- AZ 15 § 15-341 — Education › LOCAL GOVERNANCE OF SCHOOLS › Powers and Duties of School District Governing Boardscited 3×
- AZ 32 § 32-2181.02 — Professions and Occupations › REAL ESTATE › Sale of Subdivided Landscited 1×
- AZ 28 § 28-1468 — Transportation › DRIVING UNDER THE INFLUENCE › Ignition Interlock Devices
Arkansas
- AR 4 § 4-110-105 — Title 4 — Business and Commercial Law › Chapter 110 — Personal Information Protection Act
“(1) Any person or business that acquires, owns, or licenses computerized data that includes personal information shall disclose any breach of the security of the system following discovery or notification of the breach of the security of the system to any resident of Arkansas whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person.”
- AR 4 § 4-75-315 — Title 4 — Business and Commercial Law › Chapter 75 — Unfair Practicescited 7×
- AR 4 § 4-75-212 — Title 4 — Business and Commercial Law › Chapter 75 — Unfair Practicescited 1×
- AR 19 § 19-12-21 — Title 19 — Public Finance › Chapter 12 — Tobacco Settlement Proceeds Act
California
- CA CIV § 1798.29 — OBLIGATIONS › OBLIGATIONS ARISING FROM PARTICULAR TRANSACTIONS › PERSONAL DATA › Information Practices Act of 1977 › Accounting of Disclosures
“(a) Any agency that owns or licenses computerized data that includes personal information shall disclose any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of California (1) whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, or, (2) whose encrypted personal information was, or is reasonably believed to have been, acquired …”
- CA CIV § 56.184 — PERSONS › CONFIDENTIALITY OF MEDICAL INFORMATION › Genetic Privacy
- CA GOV § 98004 — STATE–TRIBAL AGREEMENTS GOVERNING INDIAN GAMING › The Tribal Government Gaming and Economic Self-Sufficiency Act of 1998cited 4×
- CA CIV § 1798.145 — OBLIGATIONS › OBLIGATIONS ARISING FROM PARTICULAR TRANSACTIONS › California Consumer Privacy Act of 2018
- CA CIV § 1798.82 — OBLIGATIONS › OBLIGATIONS ARISING FROM PARTICULAR TRANSACTIONS › CUSTOMER RECORDS
Colorado
- CO 38 § 38-13-1407 — Property - Real and Personal
“(I) Any notification required by law concerning a data or other security breach; and”
- CO 6 § 6-1-716 — Consumer and Commercial Affairs
- CO 4 § 4-1-201 — Uniform Commercial Codecited 1×
- CO 12 § 12-10-217 — Professions and Occupations
- CO 18 § 18-1.3-106 — Criminal Code
Connecticut
- CT 36A § 36a-701b — The Banking Law of Connecticut › Regulated Activitiescited 2×
“(b) (1) Any person who owns, licenses or maintains computerized data that includes personal information, shall provide notice of any breach of security following the discovery of the breach to any resident of this state whose personal information was breached or is reasonably believed to have been breached. Such notice shall be made without unreasonable delay but not later than sixty days after the discovery of such breach, unless a shorter time is required under federal …”
- CT 16 § 16-262c — Public Service Companies › Telephone, Gas, Power and Water Companies
- CT 21 § 21-83 — Licenses › Mobile Manufactured Homes and Mobile Manufactured Home Parks. Park Owners and Residents
- CT 21 § 21-83d — Licenses › Mobile Manufactured Homes and Mobile Manufactured Home Parks. Park Owners and Residents
- CT 38A § 38a-38 — Insurance › General Provisions
Delaware
- DE 18 § 18-8606 — Miscellaneous › Insurance Data Security Act
“b. A licensee has a continuing obligation to update and supplement initial and subsequent notifications to the Commissioner regarding material changes to previously-provided information relating to a cybersecurity event.”
- DE 25 § 25-7027 — Manufactured Home Communities › Manufactured Homes and Manufactured Home Communities Act › Right of First Offer
- DE 6 § 6-12B-102 — SUBTITLE II › Commerce and Trade
- DE 6 § 6-12B-103 — SUBTITLE II › Commerce and Trade
- DE 11 § 11-9601 — Special Programs › Protection of Witnesses and Crime Victims › Protection of Witnesses
District of Columbia
- DC 28 § 28-3851 — Consumer Protections › Consumer Security Breach Notification
“(1) “Breach of the security of the system” means unauthorized acquisition of computerized or other electronic data, or any equipment or device storing such data, that compromises the security, confidentiality, or integrity of personal information maintained by the person or business. The term “breach of the security system” shall not include a good faith acquisition of personal information by an employee or agent of the person or business for the purposes of the person or …”
- DC 28 § 28-3852 — Consumer Protections › Consumer Security Breach Notification
- DC 44 § 44-1002.06 — Nursing Homes and Community Residence Facilities Protections › Receiverships
- DC 9 § 9-1107.01 — National Capital Region Transportation › Washington Metropolitan Area Transit Authority Compact
Florida
- FL 501 § 501.171 — Title XXXIII - REGULATION OF TRADE, COMMERCE, INVESTMENTS, AND SOLICITATIONS > Chapter 501 - CONSUMER PROTECTION > Part I - GENERAL PROVISIONScited 2×
“(a) “Breach of security” or “breach” means unauthorized access of data in electronic form containing personal information. Good faith access of personal information by an employee or agent of the covered entity does not constitute a breach of security, provided that the information is not used for a purpose unrelated to the business or subject to further unauthorized use.”
- FL 282 § 282.318 — Title XIX - PUBLIC BUSINESS > Chapter 282 - COMMUNICATIONS AND DATA PROCESSING > Part I - INFORMATION TECHNOLOGY MANAGEMENT
- FL 282 § 282.319 — Title XIX - PUBLIC BUSINESS > Chapter 282 - COMMUNICATIONS AND DATA PROCESSING > Part I - INFORMATION TECHNOLOGY MANAGEMENT
- FL 501 § 501.703 — Title XXXIII - REGULATION OF TRADE, COMMERCE, INVESTMENTS, AND SOLICITATIONS > Chapter 501 - CONSUMER PROTECTION > Part V - DATA PRIVACY AND SECURITY
- FL 501 § 501.712 — Title XXXIII - REGULATION OF TRADE, COMMERCE, INVESTMENTS, AND SOLICITATIONS > Chapter 501 - CONSUMER PROTECTION > Part V - DATA PRIVACY AND SECURITY
Georgia
- GA 10 § 10-1-912 — Title 10. Commerce and Trade > Chapter 1. SELLING AND OTHER TRADE PRACTICES
“(a) Any information broker or data collector that maintains computerized data that includes personal information of individuals shall give notice of any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of this state whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The notice shall be made in the most expedient time …”
- GA 10 § 10-1-910 — Title 10. Commerce and Trade > Chapter 1. SELLING AND OTHER TRADE PRACTICES
- GA 10 § 10-1-911 — Title 10. Commerce and Trade > Chapter 1. SELLING AND OTHER TRADE PRACTICES
- GA 20 § 20-2-664 — Title 20. Civil Practice > Chapter 2. 20-2A-1
- GA 48 § 48-5-7.1 — Title 48. Revenue and Taxation > Chapter 5. TITLE AD VALOREM TAX ON MOTOR VEHICLES (TAVT)
Hawaii
- HI 487N § 487N-2 — Title 26 — Trade Regulation and Practice › Chapter 487N — Security Breach of Personal Information
“(a) Any business that owns or licenses personal information of residents of Hawaii, any business that conducts business in Hawaii that owns or licenses personal information in any form (whether computerized, paper, or otherwise), or any government agency that collects personal information for specific government purposes shall provide notice to the affected person that there has been a security breach following discovery or notification of the breach. The disclosure …”
- HI 487N § 487N-4 — Title 26 — Trade Regulation and Practice › Chapter 487N — Security Breach of Personal Information
- HI 487N § 487N-5 — Title 26 — Trade Regulation and Practice › Chapter 487N — Security Breach of Personal Information
- HI 490 § 490:1-201 — Title 27 — Uniform Commercial Code › Chapter 490 — Uniform Commercial Codecited 3×
- HI 412 § 412:1-109 — Title 22 — Banks and Financial Institutions › Chapter 412 — Code of Financial Institutions
Idaho
- ID 55 § 55-2014 — Title 55 — Property in General › Chapter 20 — Manufactured Home Residency Act
“(12) Before a resident shall have standing to file an action under this section, he or she must give his or her landlord three (3) days’ written notice, listing each failure or breach upon which his action will be premised and written demand requiring performance or cure. If, within three (3) days after service of the notice, any listed failure or breach has not been performed or cured by the landlord, the resident may proceed to commence an action for damages and …”
- ID 48 § 48-108 — Title 48 — Monopolies and Trade Practices › Chapter 1 — Idaho Competition Actcited 9×
- ID 33 § 33-133 — Title 33 — Education › Chapter 1 — State Board of Education
Illinois
- IL 105 § 105-85-15 — Schools › 105 ILCS 85 — Student Online Personal Protection Act
“An operator shall do the following: (1) Implement and maintain reasonable security procedures and practices that otherwise meet or exceed industry standards designed to protect covered information from unauthorized access, destruction, use, modification, or disclosure. (2) Delete, within a reasonable time period, a student's covered information if the school or school district requests deletion of covered information under the control of the school or school district, …”
- IL 105 § 105-85-27 — Schools › 105 ILCS 85 — Student Online Personal Protection Act
- IL 215 § 215-215-20 — Insurance › 215 ILCS 215 — Insurance Data Security Law
- IL 815 § 815-530-10 — Business Transactions › 815 ILCS 530 — Personal Information Protection Act
- IL 815 § 815-530-12 — Business Transactions › 815 ILCS 530 — Personal Information Protection Act
Indiana
- IN 6 § 6-8.1-7-1 — TITLE 6. TAXATION > ARTICLE 8.1. DEPARTMENT OF STATE REVENUE; TAX ADMINISTRATION > Chapter 7. Confidentialitycited 2×
“(w) The department may share a taxpayer's name and other personal identification information with a tax preparer or tax preparation software provider in cases where the department suspects that a fraudulent return has been filed on behalf of a taxpayer and the department suspects that the system of a taxpayer's previous year tax preparer or tax preparation software provider has been breached.”
- IN 24 § 24-15-5-1 — TITLE 24. TRADE REGULATION > ARTICLE 15. CONSUMER DATA PROTECTION > Chapter 5. Responsibility According to Role; Controllers and Processors
- IN 24 § 24-4.9-3-1 — TITLE 24. TRADE REGULATION > ARTICLE 4.9. DISCLOSURE OF SECURITY BREACH > Chapter 3. Disclosure and Notification Requirements
- IN 24 § 24-4.9-3-2 — TITLE 24. TRADE REGULATION > ARTICLE 4.9. DISCLOSURE OF SECURITY BREACH > Chapter 3. Disclosure and Notification Requirements
- IN 24 § 24-4.9-3-3.5 — TITLE 24. TRADE REGULATION > ARTICLE 4.9. DISCLOSURE OF SECURITY BREACH > Chapter 3. Disclosure and Notification Requirements
Iowa
- IA 715C § 715C.2 — CRIMINAL LAW AND PROCEDURE › PERSONAL INFORMATION SECURITYcited 2×
“1. Any person who owns or licenses computerized data that includes a consumer’s personal information that is used in the course of the person’s business, vocation, occupation, or volunteer activities and that was subject to a breach of security shall give notice of the breach of security following discovery of such breach of security, or receipt of notification under subsection 2, to any consumer whose personal information was included in the information that was …”
- IA 554 § 554.1201 — COMMERCE › UNIFORM COMMERCIAL CODEcited 44×
- IA 11 § 11.6 — STATE SOVEREIGNTY AND MANAGEMENT › AUDITOR OF STATE
- IA 232 § 232.171 — HUMAN SERVICES › JUVENILE JUSTICE
- IA 321 § 321.24 — TRANSPORTATION › MOTOR VEHICLES AND LAW OF THE ROAD
Kansas
- KS 34 § 34-229 — Grain and Forage › Article 2 — Inspecting, Sampling, Storing, Weighing and Grading Grain; Terminal and Local Warehouses
“(a) Every applicant for a public warehouse license upon notification by the secretary of the amount of bond or letter of credit required, shall promptly file with the secretary a bond with good corporate surety qualified under the laws of the state of Kansas or letter of credit pursuant to subsection (d). The amount of the bond or letter of credit to be furnished for each warehouse shall be $.20 per bushel for the first 1,000,000 bushels of licensed capacity; $.15 per …”
- KS 40 § 40-5012a — Insurance › Article 50 — Viatical Settlements
- KS 44 § 44-771 — Labor and Industries › Article 7 — Employment Security Law
- KS 50 § 50-7a01 — Unfair Trade and Consumer Protection › Article 7a — Protection of Consumer Information
- KS 50 § 50-7a02 — Unfair Trade and Consumer Protection › Article 7a — Protection of Consumer Information
Kentucky
- KY 61 § 61.645 — Offices and Officers › Chapter 61 — General Provisions As to Offices and Officers -- Social Security for Public Employees -- Employees Retirement Systemcited 10×
“(b) Individuals may be nominated by the retirement system members which are to elect the trustee by presenting to the executive director, not less than four (4) months before a term of office of a trustee is due to expire, a petition, bearing the name, last four (4) digits of the Social Security number, and signature of no less than one-tenth (1/10) of the number voting in the last election by the retirement system members.”
- KY 365 § 365.732 — Commerce and Trade › Chapter 365 — Trade Practicescited 2×
- KY 367 § 367.3613 — Commerce and Trade › Chapter 367 — Consumer Protection
- KY 393A § 393A.830 — Descent, Wills, and Administration of Decedents' Estates › Chapter 393A — Revised Uniform Unclaimed Property Act
- KY 42 § 42.726 — Financial Administration › Chapter 42 — Finance and Administration Cabinet
Louisiana
- LA 17 § 17-3914 — Education › The Children First Act
“A. The legislature hereby declares that all personally identifiable information is protected as a right to privacy under the Constitution of Louisiana and the Constitution of the United States.”
- LA 22 § 22-2506 — Insurance
- LA 32 § 32-409.1 — Motor Vehicles and Traffic Regulation
- LA 33 § 33-9091.11 — Municipalities and Parishes › Neighborhood
- LA 33 § 33-9091.13 — Municipalities and Parishes › Neighborhood
Maine
- ME 14 § 6001 — PARTICULAR PROCEEDINGS › ENTRY AND DETAINER › RESIDENTIAL LANDLORDS AND TENANTScited 1×
“1-B. Residential lease without termination or notice language. If a written residential lease or contract does not include a provision to terminate the tenancy or does not provide for any written notice of termination in the event of a material breach of a provision of the written residential lease or contract, either the landlord or the tenant may terminate the written residential lease or contract pursuant to this subsection.”
- ME 10 § 1347 — REGULATION OF TRADE › NOTICE OF RISK TO PERSONAL DATA
- ME 10 § 1348 — REGULATION OF TRADE › NOTICE OF RISK TO PERSONAL DATA
- ME 22 § 1711-C — HOSPITALS AND MEDICAL CARE › GENERAL PROVISIONS
- ME 24-A § 2266 — MAINE INSURANCE DATA SECURITY ACT
Maryland
- MD CL § 12-1021 — Title 12 › Subtitle 10
“(a) (1) A credit grantor may repossess tangible personal property securing a loan under an agreement, note, or other evidence of the loan if the consumer borrower is in default.”
- MD CL § 12-921 — Title 12 › Subtitle 9
- MD CL § 14-3504 — Title 14 › Subtitle 35
- MD CL § 14-4708 — Title 14 › Subtitle 47
- MD CL § 22-102 — Title 22 › Subtitle 1
Massachusetts
- MA 111 § 111-197 — ADMINISTRATION OF THE GOVERNMENT › PUBLIC HEALTH › PUBLIC HEALTH
“(h) Any owner undertaking to abate or contain dangerous levels of lead in any dwelling unit may, at the owner's option, reasonably delay the commencement of the tenancy until a letter of compliance or interim control certificate has been issued; provided, that no duly executed lease exists between owner and tenant; and provided, further, that no such delay shall exceed thirty days. During any such period of delay of occupancy the prospective tenant shall bear any living …”
- MA 93H § 93H-1 — ADMINISTRATION OF THE GOVERNMENT › REGULATION OF TRADE › SECURITY BREACHES
- MA 93H § 93H-3 — ADMINISTRATION OF THE GOVERNMENT › REGULATION OF TRADE › SECURITY BREACHES
- MA 93H § 93H-3A — ADMINISTRATION OF THE GOVERNMENT › REGULATION OF TRADE › SECURITY BREACHES
- MA 93H § 93H-4 — ADMINISTRATION OF THE GOVERNMENT › REGULATION OF TRADE › SECURITY BREACHES
Michigan
- MI 445 § 445.72 — TRADE AND COMMERCE › IDENTITY THEFT PROTECTION ACTcited 2×
“(2) Unless the person or agency determines that the security breach has not or is not likely to cause substantial loss or injury to, or result in identity theft with respect to, 1 or more residents of this state, a person or agency that maintains a database that includes data that the person or agency does not own or license that discovers a breach of the security of the database shall provide a notice to the owner or licensor of the information of the security breach.”
- MI 125 § 125.2330a — PLANNING, HOUSING, AND ZONING › THE MOBILE HOME COMMISSION ACTcited 1×
- MI 500 § 500.559 — INSURANCE CODE OF 1956 › THE INSURANCE CODE OF 1956 › CHAPTER 5A — DATA SECURITY
- MI 500 § 500.561 — INSURANCE CODE OF 1956 › THE INSURANCE CODE OF 1956 › CHAPTER 5A — DATA SECURITY
- MI 791 § 791.220g — DEPARTMENT OF CORRECTIONS › CORRECTIONS CODE OF 1953 › Chapter I — DEPARTMENT OF CORRECTIONS.cited 1×
Minnesota
- MN 325E § 325E.64 — CHAPTER 325E. TRADE PRACTICES › ACCESS DEVICEScited 6×
“Whenever there is a breach of the security of the system of a person or entity that has violated this section, or that person's or entity's service provider, that person or entity shall reimburse the financial institution that issued any access devices affected by the breach for the costs of reasonable actions undertaken by the financial institution as a result of the breach in order to protect the information of its cardholders or to continue to provide services to …”
- MN 13 § 13.055 — CHAPTER 13. GOVERNMENT DATA PRACTICES › GENERALLYcited 1×
- MN 325E § 325E.61 — CHAPTER 325E. TRADE PRACTICES › DATA WAREHOUSES; DISCLOSURE OF PERSONAL INFORMATIONcited 1×
- MN 46A § 46A.06 — CHAPTER 46A. CUSTOMER INFORMATION DATA SECURITY
- MN 60A § 60A.0812 — CHAPTER 60A. GENERAL INSURANCE POWERS › BREACH OF POLICY
Mississippi
- MS 75 § 75-24-29 — Title 75 — Regulation of Trade, Commerce and Investments › Chapter 24 — Regulation of Business for Consumer Protection
“(11) Any person who conducts business in this state that maintains its own security breach procedures as part of an information security policy for the treatment of personal information, and otherwise complies with the timing requirements of this section, shall be deemed to be in compliance with the security breach notification requirements of this section if the person notifies affected individuals in accordance with the person’s policies in the event of a breach of …”
- MS 43 § 43-13-121 — Title 43 — Public Welfare › Chapter 13 — Medical Assistance for the Aged; Medicaidcited 8×
Missouri
- MO 407 § 407.1500 — Title XXVI — Trade and Commerce › Chapter 407 — Merchandising Practicescited 1×
“2. (1) Any person that owns or licenses personal information of residents of Missouri or any person that conducts business in Missouri that owns or licenses personal information in any form of a resident of Missouri shall provide notice to the affected consumer that there has been a breach of security following discovery or notification of the breach. The disclosure notification shall be:”
- MO 407 § 407.815 — Title XXVI — Trade and Commerce › Chapter 407 — Merchandising Practicescited 1×
- MO 160 § 160.405 — Title XI — Education and Libraries › Chapter 160 — Schools — General Provisions
- MO 161 § 161.096 — Title XI — Education and Libraries › Chapter 161 — Department of Elementary and Secondary Education
- MO 402 § 402.203 — Title XXVI — Trade and Commerce › Chapter 402 — Trust Funds for Disabled Persons
Montana
- MT 2 § 2-6-1503 — Title 2 — Government Structure and Administration › Chapter 6 — Public Records › Part 15 — State Agency Protection of Personal Information
“(1) (a) Upon discovery or notification of a breach of the security of a data system, a state agency that maintains computerized data containing personal information in the data system shall make reasonable efforts to notify any person whose unencrypted personal information was or is reasonably believed to have been acquired by an unauthorized person.”
- MT 30 § 30-14-1704 — Title 30 — Trade and Commerce › Chapter 14 — Unfair Trade Practices and Consumer Protection › Part 17 — Impediment of Identity Theft
- MT 33 § 33-19-321 — Title 33 — Insurance and Insurance Companies › Chapter 19 — Insurance Information and Privacy Protection › Part 3 — Disclosure of Information
- MT 30 § 30-1-201 — Title 30 — Trade and Commerce › Chapter 1 — Uniform Commercial Code General Provisions › Part 2 — General Definitions and Principles of Interpretationcited 2×
- MT 30 § 30-14-2813 — Title 30 — Trade and Commerce › Chapter 14 — Unfair Trade Practices and Consumer Protection › Part 28 — Consumer Data Privacy Act
Nebraska
- NE 45 § 45-345 — Chapter 45 — Interest, Loans, and Debtcited 1×
“(1) A licensee shall notify the director through the Nationwide Mortgage Licensing System and Registry at least thirty days prior to the occurrence of any change of the licensee's name, trade name, or doing business as designation. (2)(a) Except as provided in subdivisions (b) and (c) of this subsection, a licensee shall notify the director in writing or through the Nationwide Mortgage Licensing System and Registry within three business days from the time that the …”
- NE 32 § 32-330 — Chapter 32 — Elections
- NE 45 § 45-373 — Chapter 45 — Interest, Loans, and Debt
- NE 45 § 45-912 — Chapter 45 — Interest, Loans, and Debt
- NE 8 § 8-2721 — Chapter 8 — Banks and Banking
Nevada
- NV 116 § 116.310312 — Title 10 — Property Rights and Transactions › Chapter 116 — Common-Interest Ownership (Uniform Act)cited 12×
“1. A person who holds a security interest in a unit must provide the association with the person’s contact information as soon as reasonably practicable, but not later than 30 days after the person:”
- NV 388 § 388.2955 — Title 34 — Education › Chapter 388 — System of Public Instruction
- NV 603A § 603A.220 — Title 52 — Trade Regulations and Practices › Chapter 603A — Security and Privacy of Personal Information
- NV 603A § 603A.280 — Title 52 — Trade Regulations and Practices › Chapter 603A — Security and Privacy of Personal Information
- NV 675 § 675.283 — Title 55 — Banks and Related Organizations; Other Financial Institutions › Chapter 675 — Installment Loans
New Hampshire
- NH 644 § 644:8 — TITLE LXII: CRIMINAL CODE › CHAPTER 644: BREACHES OF THE PEACE AND RELATED OFFENSEScited 2×
“(c) If a person convicted of any offense of cruelty to animals appeals the conviction in an initial de novo or subsequent appeal and any confiscated animal remains in the custody of the arresting officer, the arresting officer's agency, or the arresting officer's agency's designee pending disposition of the appeal, in order for the defendant or appellant to maintain a future interest in the animal, the trial or appellate court, after consideration of the income of the …”
- NH 106-F § 106-F:9 — TITLE VII: SHERIFFS, CONSTABLES, AND POLICE OFFICERS › CHAPTER 106-F: PRIVATE INVESTIGATORS, SECURITY GUARDS, AND BAIL RECOVERY AGENTS
- NH 359-C § 359-C:20 — TITLE XXXI: TRADE AND COMMERCE › CHAPTER 359-C: RIGHT TO PRIVACY
- NH 420-P § 420-P:6 — TITLE XXXVII: INSURANCE › CHAPTER 420-P: INSURANCE DATA SECURITY LAW
- NH 540-A § 540-A:4 — TITLE LV: PROCEEDINGS IN SPECIAL CASES › CHAPTER 540-A: PROHIBITED PRACTICES AND SECURITY DEPOSITS
New Jersey
- NJ 56 § 56:8-163 — TRADE NAMES, TRADE-MARKS AND UNFAIR TRADE PRACTICES › Chapter 8cited 2×
“12. a. Any business that conducts business in New Jersey, or any public entity that compiles or maintains computerized records that include personal information, shall disclose any breach of security of those computerized records following discovery or notification of the breach to any customer who is a resident of New Jersey whose personal information was, or is reasonably believed to have been, accessed by an unauthorized person. The disclosure to a customer shall be …”
- NJ 56 § 56:8-166.13 — TRADE NAMES, TRADE-MARKS AND UNFAIR TRADE PRACTICES › Chapter 8
- NJ 2C § 2C:58-2 — THE NEW JERSEY CODE OF CRIMINAL JUSTICE › Chapter 58cited 3×
- NJ 56 § 56:8-166.16 — TRADE NAMES, TRADE-MARKS AND UNFAIR TRADE PRACTICES › Chapter 8
- NJ 56 § 56:8-42 — TRADE NAMES, TRADE-MARKS AND UNFAIR TRADE PRACTICES › Chapter 8
New Mexico
- NM 47 § 47-8-33 — Chapter 47 — Property Law › Article 8 — Owner-Resident Relations
“A. Except as provided in the Uniform Owner-Resident Relations Act, if there is noncompliance with Section 47-8-22 NMSA 1978 materially affecting health and safety or upon the initial material noncompliance by the resident with the rental agreement or any separate agreement, the owner shall deliver a written notice to the resident specifying the acts and omissions constituting the breach, including the dates and specific facts describing the nature of the alleged breach, …”
- NM 55 § 55-9-406 — Chapter 55 — Uniform Commercial Code › Article 9 — Secured Transactions
- NM 57 § 57-12C-2 — Chapter 57 — Trade Practices and Regulations › Article 12C — Data Breach Notification
- NM 57 § 57-12C-4 — Chapter 57 — Trade Practices and Regulations › Article 12C — Data Breach Notification
- NM 57 § 57-12C-5 — Chapter 57 — Trade Practices and Regulations › Article 12C — Data Breach Notification
New York
- NY EDN § 2-d — General Provisions Article 1 Short Title and Definitions (§§ › Short Title and Definitions
“§ 2-d. Unauthorized release of personally identifiable information. 1.\nDefinitions. As used in this section the following terms shall have the\nfollowing meanings:\n a. "Building principal" means a building principal subject to annual\nperformance evaluation review under the provisions of section three\nthousand twelve-c, section three thousand twelve-d, or section three\nthousand twelve-e of this chapter.\n b. "Classroom teacher" means a teacher subject to annual …”
- NY GBS § 380-t — Fair Credit Reporting Act
- NY GBS § 899-aa — Notification of Unauthorized Acquisition of Private Information; Data Security Protections
- NY RPP § 231-c — Landlord and Tenant
- NY STT § 208 — Internet Security and Privacy Act
North Carolina
- NC 132 § 132-1.10 — Social security numbers and other personal identifying informationcited 1×
“(1) The social security number can be used as a tool to perpetuate fraud against a person and to acquire sensitive personal, financial, medical, and familial information, the release of which could cause great financial or personal harm to an individual. While the social security number was intended to be used solely for the administration of the federal Social Security System, over time this unique numeric identifier has been used extensively for identity verification …”
- NC 75 § 75-65 — Identity Theft Protection Actcited 1×
- NC 113 § 113-391.1 — Oil and Gas Conservation
- NC 115C § 115C-402.5 — Protective Provisions and Maintenance of Student Records
- NC 162 § 162-39 — County Prisoners
North Dakota
- ND 13 § 13-01.2-03 — Debtor and Creditor Relationship › Financial Institution Data Security Program
“(5) A general description of the notification event; and (6) A statement whether any law enforcement official has provided the financial corporation with a written determination that notifying the public of the breach would impede a criminal investigation or cause damage to national security, and a means for the commissioner to contact the law enforcement official. A law enforcement official may request an initial delay of up to forty-five days following the date when …”
- ND 26.1 § 26.1-02.2-05 — Insurance › Insurance Data Security
- ND 47 § 47-30.2-73 — Property › Revised Uniform Unclaimed Property Act
- ND 51 § 51-30-02 — Sales and Exchanges › Notice of Security Breach for Personal Information
- ND 51 § 51-30-04 — Sales and Exchanges › Notice of Security Breach for Personal Information
Ohio
- OH 1322 § 1322.05 — Title 13 Commercial Transactions › Chapter 1322 | Ohio Residential Mortgage Lending Act (RMLA)
“(ii) At any time prior to the date the application for exemption is approved, a felony involving an act of fraud, dishonesty, a breach of trust, theft, or money laundering.”
- OH 1347 § 1347.12 — Title 13 Commercial Transactions › Chapter 1347 | Personal Information Systems
- OH 1349 § 1349.19 — Title 13 Commercial Transactions › Chapter 1349 | Consumer Protection
- OH 1923 § 1923.02 — Title 19 Courts-Municipal-Mayor's-County › Chapter 1923 | Forcible Entry And Detainercited 2×
- OH 1522 § 1522.01 — Title 15 Conservation of Natural Resources › Chapter 1522 | Great Lakes-St. Lawrence River Basin Water Resources Compact
Oklahoma
- OK 24 § 24-163 — Title 24 — Debtor and Creditor
“A. An individual or entity that owns or licenses computerized data that includes personal information shall provide notice of any breach of the security of the system following determination or notification of the breach of the security of the system to any resident of this state whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person and that causes, or the individual or entity …”
- OK 24 § 24-164 — Title 24 — Debtor and Creditor
- OK 36 § 36-675 — Title 36 — Insurance
- OK 60 § 60-175.57 — Title 60 — Property
- OK 74 § 74-3113.1 — Title 74 — State Government
Oregon
- OR 71 § 71.2010 — Commercial Transactions › General Provisions for Uniform Commercial Codecited 90×
“(jj)(A) “Security interest” means an interest in personal property or fixtures which secures payment or performance of an obligation. “Security interest” includes any interest of a consignor and a buyer of accounts, chattel paper, a payment intangible or a promissory note in a transaction that is subject to ORS chapter 79A.”
- OR 734 § 734.510 — Insurance › Rehabilitation, Liquidation and Conservation of Insurerscited 16×
- OR 37 § 37.030 — Remedies and Special Actions and Proceedings › Receivershipcited 1×
- OR 305 § 305.804 — Revenue and Taxation › Administration of Revenue and Tax Laws; Appeals
- OR 432 § 432.033 — Public Health and Safety › Vital Statistics
Pennsylvania
- PA 40 § 40-4518 — Title 40 - Insurance › Chapter 45 - Insurance Data Security
“(1) In the case of a cybersecurity event involving nonpublic information that is used by a licensee, which is acting as an assuming insurer, or that is in the possession, custody or control of a licensee, which is acting as an assuming insurer and which does not have a direct contractual relationship with the affected consumers, the assuming insurer shall notify its affected ceding insurers and the commissioner of its state of domicile within three business days of making …”
- PA 13 § 13-1201 — Title 13 - Commercial Code › Chapter 12 - General Definitions and Principles of Interpretation
- PA 13 § 13-9408 — Title 13 - Commercial Code › Chapter 94 - Rights of Third Parties
Rhode Island
- RI 11 § 11-49.3-4 — Criminal Offenses › Identity Theft Protection Act of 2015
“(a)(1) Any municipal agency, state agency, or person who or that stores, owns, collects, processes, maintains, acquires, uses, or licenses data that includes personal information shall provide notification as set forth in this section of any disclosure of personal information, or any breach of the security of the system, that poses a significant risk of identity theft to any resident of Rhode Island whose personal information was, or is reasonably believed to have been, …”
- RI 11 § 11-49.3-6 — Criminal Offenses › Identity Theft Protection Act of 2015
- RI 19 § 19-14-36 — Financial Institutions › Licensed Activities
- RI 27 § 27-1-46 — Insurance › Domestic Insurance Companies
- RI 11 § 11-49.3-3 — Criminal Offenses › Identity Theft Protection Act of 2015
South Carolina
- SC 40 § 40-18-70 — Title 40 - Professions and Occupations › Chapter 18 - Private Security and Investigation Agenciescited 1×
“(B) The applicant must post a ten thousand dollar bond with SLED in a form approved by the Attorney General in favor of the State. The bond must be issued by a surety insurer licensed to transact surety insurance in this State. The surety on the bond may cancel the bond upon giving thirty days' notice to SLED and is relieved of liability for a breach of condition after the effective date of cancellation.”
- SC 1 § 1-11-490 — Title 1 - Administration of the Government › Chapter 11 - Department of Administration › Article General Provisions
- SC 37 § 37-22-140 — Title 37 - Consumer Protection Code › Chapter 22 - Mortgage Lending
- SC 38 § 38-99-40 — Title 38 - Insurance › Chapter 99 - Insurance Data Security Act
- SC 39 § 39-1-90 — Title 39 - Trade and Commerce › Chapter 1 - General Provisions
South Dakota
- SD 22 § 22-40-20 — CRIMES › IDENTITY CRIMES
“Following the discovery by or notification to an information holder of a breach of system security an information holder shall disclose in accordance with § 22-40-22 the breach of system security to any resident of this state whose personal or protected information was, or is reasonably believed to have been, acquired by an unauthorized person. A disclosure under this section shall be made not later than sixty days from the discovery or notification of the breach of …”
- SD 22 § 22-40-22 — CRIMES › IDENTITY CRIMES
- SD 22 § 22-40-23 — CRIMES › IDENTITY CRIMES
- SD 22 § 22-40-26 — CRIMES › IDENTITY CRIMES
- SD 57A § 57A-1-201 — UNIFORM COMMERCIAL CODE › GENERAL PROVISIONScited 5×
Tennessee
- TN 47 § 47-18-2107 — Title 47 — Commercial Instruments And Transactions › Chapter 18 — Part 55 Uniform Debt-Management Services Act
“(11) Following discovery or notification of a breach of system security by an information holder, the information holder shall disclose the breach of system security to any resident of this state whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure must be made no later than forty-five (45) days from the discovery or notification of the breach of system security, unless a longer period of time is …”
- TN 55 § 55-3-103 — Title 55 — Motor and Other Vehicles › Chapter 3 — Part 2 Wrecked, Damaged, Dismantled or Rebuilt Motor Vehiclescited 7×
- TN 36 § 36-5-501 — Title 36 — Domestic Relations › Chapter 5 — Part 31 Enforcement Without Transfer of Jurisdictioncited 4×
- TN 63 § 63-6-204 — Title 63 — Professions Of The Healing Arts › Chapter 6 — Part 12 Cytopathology Servicescited 4×
Texas
- TX BC § 521.053 — PERSONAL IDENTITY INFORMATION › IDENTITY THEFT › UNAUTHORIZED USE OF IDENTIFYING INFORMATION › IDENTITY THEFTcited 1×
“(b) A person who conducts business in this state and owns or licenses computerized data that includes sensitive personal information shall disclose any breach of system security, after discovering or receiving notification of the breach, to any individual whose sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure shall be made without unreasonable delay and in each case not later than the 60th day …”
- TX BC § 503A.002 — PERSONAL IDENTITY INFORMATION › IDENTIFYING INFORMATION › DIRECT-TO-CONSUMER GENETIC TESTING COMPANIES; RIGHTS REGARDING DNA
- TX BC § 509.002 — PERSONAL IDENTITY INFORMATION › IDENTIFYING INFORMATION › USE OF DIGITAL SERVICES BY MINORS › GENERAL PROVISIONS
- TX BC § 541.002 — PERSONAL IDENTITY INFORMATION › CONSUMER DATA PROTECTION › CONSUMER DATA PROTECTION › GENERAL PROVISIONS
- TX BC § 541.104 — PERSONAL IDENTITY INFORMATION › CONSUMER DATA PROTECTION › CONSUMER DATA PROTECTION › CONTROLLER AND PROCESSOR DATA-RELATED DUTIES AND PROHIBITIONS
Utah
- UT 13 § 13-44-202 — Title 13 › Chapter 44 — Protection of Personal Information Act › Part 2 — Protection of Personal Information
“(b) If a person maintains the person's own notification procedures as part of an information security policy for the treatment of personal information the person is considered to be in compliance with the notification requirement in Subsection (1)(b) if the procedures are otherwise consistent with this chapter's timing requirements and the person notifies each affected Utah resident in accordance with the person's information security policy in the event of a breach.”
- UT 13 § 13-44-301 — Title 13 › Chapter 44 — Protection of Personal Information Act › Part 3 — Enforcement
- UT 63A § 63A-19-405 — Title 63A › Chapter 19 — Government Data Privacy Act › Part 4 — Duties of Governmental Entities
- UT 67 § 67-4a-1407 — Title 67 › Chapter 4a — Revised Uniform Unclaimed Property Act › Part 14 — Confidentiality and Security of Information
- UT 13 § 13-61-301 — Title 13 › Chapter 61 — Utah Consumer Privacy Act › Part 3 — Requirements for Controllers and Processors
Vermont
- VT 27 § 27-1617 — Unclaimed Property › CONFIDENTIALITY AND SECURITY OF INFORMATION
“(A) any notification required by law concerning a data or other security breach; and”
- VT 8 § 8-4728 — Insurance Trade Practices
- VT 9 § 9-2435 — Protection of Personal Information › SECURITY BREACH NOTICE ACT
- VT 9 § 9-41b — Interest › INTEREST GENERALLY
Virginia
- VA 59.1 § 59.1-501.2 — Trade and Commerce › Chapter 43. Uniform Computer Information Transactions Act › Article 1. General Provisionscited 1×
“(15) "Consumer" means an individual who is a licensee of information or informational rights that the individual at the time of contracting intended to be used primarily for personal, family, or household purposes. The term does not include an individual who is a licensee primarily for professional or commercial purposes, including agriculture, business management, and investment management other than management of the individual's personal or family investments.”
- VA 18.2 § 18.2-186.6 — Crimes and Offenses Generally › Chapter 6. Crimes Involving Fraud › Article 5. False Representations to Obtain Property or Credit
- VA 32.1 § 32.1-127.1:05 — Health › Chapter 5. Regulation of Medical Care Facilities and Services › Article 1. Hospital and Nursing Home Licensure and Inspection
- VA 32.1 § 32.1-138.5:1 — Health › Chapter 5. Regulation of Medical Care Facilities and Services › Article 2. Rights and Responsibilities of Patients in Nursing Homes
- VA 38.2 § 38.2-625 — Insurance › Chapter 6. Insurance Information and Privacy Protection › Article 2. Insurance Data Security Act
Washington
- WA 19 § 19.255.020 — BUSINESS REGULATIONS—MISCELLANEOUS › PERSONAL INFORMATION—NOTICE OF SECURITY BREACHEScited 3×
“(b) "Breach" has the same meaning as "breach of the security of the system" in RCW 19.255.010.”
- WA 19 § 19.255.010 — BUSINESS REGULATIONS—MISCELLANEOUS › PERSONAL INFORMATION—NOTICE OF SECURITY BREACHEScited 2×
- WA 42 § 42.56.590 — PUBLIC OFFICERS AND AGENCIES › PUBLIC RECORDS ACTcited 1×
- WA 19 § 19.255.030 — BUSINESS REGULATIONS—MISCELLANEOUS › PERSONAL INFORMATION—NOTICE OF SECURITY BREACHES
- WA 19 § 19.255.040 — BUSINESS REGULATIONS—MISCELLANEOUS › PERSONAL INFORMATION—NOTICE OF SECURITY BREACHES
West Virginia
- WV 56 § 56-3-34 — Chapter 56 — Pleading and Practice › Article 3 — Writs, Process and Order of Publicationcited 1×
“(a) Every nonresident bail bond enforcer or bail bondsman, for the privilege of entering this state to act in the capacity of a bail bond enforcer, either personally or through an agent, appoints the Secretary of State, or his or her successor in office, to be his or her agent or attorney-in-fact upon whom may be served all lawful process in any action or proceeding against him or her in any court of record in this state for any act occurring within this state resulting …”
- WV 31 § 31-17-4a — Chapter 31 — Corporations › Article 17 — West Virginia Residential Mortgage Lender, Broker and Servicer Act
- WV 46A § 46A-2A-101 — Chapter 46A — West Virginia Consumer Credit and Protection Act › Article 2A — Breach of Security of Consumer Information
- WV 46A § 46A-2A-102 — Chapter 46A — West Virginia Consumer Credit and Protection Act › Article 2A — Breach of Security of Consumer Information
- WV 46A § 46A-2A-103 — Chapter 46A — West Virginia Consumer Credit and Protection Act › Article 2A — Breach of Security of Consumer Information
Wisconsin
- WI 425 § 425.206 — Chapter 425 — Consumer Transactions - Remedies and Penalties › Subchapter II — Enforcement of Security Interests in Collateralcited 9×
“(a) 3. and, no sooner than 15 days after the merchant gives the notice specified in s. 425.205 (1g) (a), the merchant has taken possession of the collateral or goods in accordance with sub. (2).”
- WI 50 § 50.05 — Chapter 50 — Uniform Licensure › Subchapter I — Care and Service Residential Facilities
- WI 601 § 601.954 — Chapter 601 — Insurance - Administration › Subchapter IX — Insurance Data Security
- WI 51 § 51.20 — Chapter 51 — State Alcohol, Drug Abuse, Developmental Disabilities and Mental Health Actcited 80×
- WI 218 § 218.0116 — Chapter 218 — Finance Companies, Auto Dealers, Adjustment Companies and Collection Agencies › Subchapter I — Motor Vehicle Dealers; Salespersons; Sales Finance Companiescited 9×
Wyoming
- WY 40 § 40-12-502 — TRADE AND COMMERCE › CONSUMER PROTECTION › CREDIT FREEZE REPORTS
“(g) Any person who maintains computerized data that includes personal identifying information on behalf of another business entity shall disclose to the business entity for which the information is maintained any breach of the security of the system as soon as practicable following the determination that personal identifying information was, or is reasonably believed to have been, acquired by an unauthorized person. The person who maintains the data on behalf of another …”
- WY 21 § 21-2-202 — EDUCATION › THE ADMINISTRATION OF THE STATE › SUPERINTENDENT OF PUBLIC INSTRUCTION AND DEPARTMENT OF EDUCATION
- WY 21 § 21-3-110 — EDUCATION › SCHOOL DISTRICTS IN GENERAL › IN GENERAL
- WY 40 § 40-12-501 — TRADE AND COMMERCE › CONSUMER PROTECTION › CREDIT FREEZE REPORTS
No matching section found
Our full-text match found no section on this subject in: Puerto Rico, Guam, U.S. Virgin Islands, Northern Mariana Islands, American Samoa. That can mean the state genuinely has no such statute — or that its code phrases the subject differently than our search terms. Both are worth knowing.
How this page is built: each state’s full code text (and the United States Code) is searched for this subject’s terms (breach of security notification personal information · security breach notice resident); per state, the sections most squarely about the subject rank first, then the most-cited. No AI wrote or selected any statute text. Tell us what to compare next →