Home > HR compliance > Employee privacy > Data security breach notification laws by state
High value data

Data security breach notification laws by state

Stay compliant with state data breach notification requirements using expert guidance on privacy laws and security obligations.

by the Brightmine Editorial Team

Every employer maintains personal information, whether of its employees, vendors or customers. Because of the sensitive nature of such data, an employer must take steps to protect it. An employer must also understand its responsibilities if a data breach does occur (e.g., the unauthorized acquisition of unencrypted and unredacted computerized data that compromises the security, confidentiality or integrity of personal information maintained by the employer) which may have resulted in the unauthorized acquisition of such information.

While all state data breach notification laws require an employer to provide notice to affected individuals, the laws vary as to how and when the notice must be provided. Generally, the notice requirements are triggered when an employer that is covered by the law discovers or is notified of a breach. The following chart summarizes each state’s data security breach notification requirements, including:

  • Definitions of the personal information that is covered by the law;
  • The time within which an employer must provide notice;
  • The format in which notice must be provided;
  • The content that must be included in the notice; and
  • Whether notice must be provided to additional parties.

Some states’ laws have common exceptions to these requirements. For instance, Arizona, Iowa and Maryland have coverage exceptions for entities subject to HIPAA or Title V of the Gramm-Leach-Biley Act, or entities that must comply with the notification requirements or security breach procedures of their primary or functional federal regulator.

Most states also exclude certain information from the definition of personal information, such as data that is publicly available, redacted or encrypted (if the encryption key is not compromised). Many states, such as Arkansas and Iowa, also have exceptions to the notice timing requirement, such as when requested by law enforcement to prevent interference with a criminal investigation or when the covered entity needs time to determine the nature and scope of the breach.

Additionally, there are several states, including California, Georgia and New York, that provide an exception to the requirement to provide notice if, after a determination is made, the breach is unlikely to result in material harm to the individuals whose information has been accessed. There are no federal requirements relating to data breaches as indicated by N/A in the chart.

Screenshot of the Brightmine Fifty State Chart on eeo protected classes

Want to see more?

For full access to our 50 State Chart:

Data security breach notification laws by state

sign up for an HR and Compliance Center subscription today.

Share

Latest updates

Updated to reflect amendments to the New York data breach notification law, effective February 14, 2025.

Get ahead of HR compliance

Navigating today’s complex HR compliance landscape is challenging.

Get ahead with Brightmine. Access HR resources and automation tools managed by seasoned human HR experts.

Proudly partnered with LexisNexis®

You may also be interested in…

HR law guides

Maine workplace privacy laws: HR compliance guide

This guide highlights key aspects of Maine law affecting privacy in the workplace, including invasion of privacy claims, …

HR law guides

Employee privacy laws in Indiana

Learn about Indiana employee privacy laws, including rules on background checks, medical and drug testing, electronic monitoring, data …

Charts

Recording communications and video surveillance laws by state

Learn how state laws regulate workplace recordings, video surveillance, consent requirements, and employee privacy protections.

About the author

The Brightmine Editorial Team

Our in-house team of HR experts carefully monitors and updates the Brightmine HR & Compliance Center, the most comprehensive library of employment law and HR resources. This team has an unrivaled wealth of subject matter expertise, with an average of 15 years’ experience. They also bring invaluable, diverse career experiences to the table—the team includes seasoned employment law attorneys, former in-house counsel, SHRM certified professionals and career employment law editors.

In addition to managing the HR & Compliance Center, the Editorial Team supports the content across the Brightmine product portfolio. The Team also supports Marketing Resource Center with breaking HR news, Commentary and Insights, and expert review of key compliance resources, such as our free charts.

Follow Brightmine on LinkedIn

Sign up to receive expert HR insights from Brightmine

    LNRS Data Services Limited and its affiliates may contact you about relevant solutions, services, events and industry insights. You can opt-out via the unsubscribe link in the communications that you receive or by contacting us.