Data Breach Notification Requirements
Every state has a data breach notification law, and none of them exempt small businesses. Here's the general shape of what you're required to do if it happens to you.
Last updated: August 2026
The short answer
If your business experiences a data breach involving personal information, you're generally required to notify the people affected, and often a state regulator too. All 50 states, DC, and several US territories have their own breach notification law. The specifics vary by state and by industry, but the core obligation is consistent: if protected data was compromised, you have to tell people.
This page is general education, not a response plan for an incident you're dealing with right now. If you're actually in the middle of a breach, the specifics of your state, industry, and contract obligations matter more than anything a general guide can tell you, talk to a lawyer first.
There's no small-business exemption
This is the part that surprises people using this site the most: notification laws generally don't have a size threshold. A 10-person company has the same disclosure obligation as a 10,000-person one if the breach involves protected data. Small businesses are also targeted more often precisely because they tend to have fewer defenses in place, not less because they're small.
What actually counts as a breach
Generally, unauthorized access to or acquisition of personal information, whether through hacking, a lost device, or an employee mistake. Most states only require notification if the breach creates a real risk of harm (identity theft, fraud), though some require it regardless of assessed risk. One meaningful exception: many states provide a safe harbor for encrypted data, if the data was encrypted and the encryption keys weren't also compromised, notification often isn't required at all. This is one of the stronger arguments for encrypting sensitive data in the first place.
The general framework
- The clock starts at discovery, not investigation. You're expected to notify promptly once you discover a breach, not once you've fully figured out every detail. Notify with what you know, then update as you learn more.
- Requirements vary by state. If your customers are spread across multiple states, you may need to comply with several different laws for the same incident. California's rules changed notably as of January 1, 2026, with stricter deadlines than before.
- Sector-specific rules can add obligations. Healthcare businesses may fall under HIPAA's Breach Notification Rule. Financial services businesses may have obligations under the Gramm-Leach-Bliley Act. These stack on top of, not instead of, your state's general law.
- Large breaches may require notifying credit agencies too. Some states require notifying consumer reporting agencies when a breach affects a large number of residents.
This page deliberately doesn't cite specific day-count deadlines by state, those vary and change, and citing one specific number risks it being wrong for your state or stale by the time you read it. If you're actually responding to a breach, check your state's current requirement directly or talk to a lawyer, this is not the moment for a general guide.
What this looks like in practice
Say a small e-commerce store discovers that a former employee's laptop, which had access to a customer database, was stolen from their car. The database included customer names, email addresses, and partial payment information. Here's roughly how that plays out: the owner discovers the theft on a Monday, that's the discovery date, the clock the notification laws care about. They don't wait until they've confirmed exactly which records were accessed, they start the process immediately: check which states their customers live in, since that determines which laws apply, pull out the notification letter template they'd already drafted (or write one now, more slowly, under pressure), and notify affected customers within whatever window their state requires. If enough California residents were affected, they may also owe a notice to the state. If the laptop's hard drive was encrypted and the encryption key wasn't also on it, several states' safe-harbor provisions may mean formal notification isn't required at all, worth checking before assuming the worst.
Preparing before it happens
The businesses that handle this well generally did the preparation months earlier, not during the breach itself. Worth having in place ahead of time: a basic inventory of what personal data you actually collect and where it's stored, a sense of which states' laws apply based on where your customers are, a notification letter template you're not writing from scratch under pressure, and knowing who on your team (even if that's just you) handles this if it happens.
Frequently asked questions
Do I need a lawyer if I have a data breach?
For anything beyond the smallest, clearest-cut incident, yes. Multi-state notification, sector-specific rules, and tight timelines are exactly the kind of situation where general guidance like this page isn't a substitute for someone who can look at your specific facts.
Does this apply if the breach happened at a vendor, not my business?
Often yes, in some form. If a third-party vendor holding your customers' data has a breach, you may still have notification obligations depending on your state and your contract with that vendor.
How does this relate to my privacy policy?
They're related but separate. Your privacy policy discloses your general data practices ahead of time. Breach notification is what you do after a specific incident. See GDPR and CCPA basics and the CCPA compliance checklist for the related compliance picture, including California's 2026 updates.
Sources
- State data breach notification laws (all 50 states, DC, and several US territories have one; specific citations vary by state)
- HHS HIPAA Breach Notification Rule; Gramm-Leach-Bliley Act (sector-specific federal requirements)
- FTC small business cybersecurity resources
This page describes the general shape of these requirements, not a specific state's statute or exact deadline, both of which vary and should be verified directly for your situation.