Breach notification statutes require notice to affected individuals, and often to state attorneys general and credit reporting agencies, within a defined period after discovery. Timelines commonly range from thirty to sixty days, with some jurisdictions requiring notice without unreasonable delay.
Many statutes provide a safe harbor where the compromised data was encrypted and the keys were not affected.
Alternative Names:
Notification Obligation, Breach Reporting
Why it Matters?
A firm suffering a breach faces overlapping obligations: statutory notice in every state where affected individuals reside, contractual notice to clients often within seventy-two hours or less, HIPAA notification where health information is involved, and ethical duties to clients. The multiplicity is why an incident response plan with pre-identified counsel matters more than the technical remediation.
Frequently Confused with
Related terms
Frequently asked questions
How quickly must notice be given?
Does encryption avoid notification?





