Breach Notification

Breach Notification

Breach Notification

Breach notification statutes require notice to affected individuals, and often to state attorneys general and credit reporting agencies, within a defined period after discovery. Timelines commonly range from thirty to sixty days, with some jurisdictions requiring notice without unreasonable delay.

Many statutes provide a safe harbor where the compromised data was encrypted and the keys were not affected.

Alternative Names:

Notification Obligation, Breach Reporting

Why it Matters?

A firm suffering a breach faces overlapping obligations: statutory notice in every state where affected individuals reside, contractual notice to clients often within seventy-two hours or less, HIPAA notification where health information is involved, and ethical duties to clients. The multiplicity is why an incident response plan with pre-identified counsel matters more than the technical remediation.

Frequently Confused with

Related terms

Frequently asked questions

How quickly must notice be given?

How quickly must notice be given?

It varies. State statutes commonly require thirty to sixty days from discovery, GDPR requires seventy-two hours to regulators, and client contracts frequently require faster notice than any statute.

Does encryption avoid notification?

Does encryption avoid notification?

Often. Most state statutes provide a safe harbor for encrypted data, provided the encryption keys were not also compromised.