Data breach notification laws require businesses to tell affected people, and often state regulators, the moment personal information has been exposed. Every US state now has one on the books, and the rules differ enough that a single incident can trigger several deadlines at once. For any company that collects emails, survey responses, or customer records, understanding these laws is no longer optional.
The stakes go beyond compliance paperwork. A single breach can cost millions of dollars, damage customer trust, and invite lawsuits that outlast the incident itself. Market researchers, CX teams, and HR departments all handle exactly the kind of personal data these laws exist to protect.
This guide breaks down what a data breach actually is, how notification laws work across the US, and the steps that keep a bad day from turning into a legal one.
What is a data breach?
A data breach is an incident where someone accesses, steals, or exposes protected information without authorization. It can be deliberate, such as a hacker breaking into a database, or accidental, such as an employee emailing a spreadsheet to the wrong person.
The information at risk is usually personally identifiable information, or PII, meaning any data that can be traced back to a specific individual. Names, email addresses, Social Security numbers, and login credentials all qualify. Financial records and health details count too, and many state laws treat them with extra weight.
Not every security failure is a data breach. The next section draws that line clearly, since mixing up the terms is one of the fastest ways to over-report or under-report an incident.
Data breach vs. security incident vs. cyberattack
These three terms get used interchangeably in casual conversation, but they describe different things, and the difference matters when a company has to decide whether a legal notification requirement has actually been triggered.
| Term | What it means | Example |
|---|---|---|
| Data breach | Unauthorized access, theft, or exposure of protected personal data | A hacker downloads a customer database containing names and emails |
| Security incident | Any event that threatens system integrity, whether or not data left the network | An employee clicks a phishing link, but no data is accessed or removed |
| Cyberattack | A deliberate attempt to compromise a system, app, or network | A distributed denial-of-service attack that takes a website offline |
A cyberattack does not automatically create a legal notification duty. Only an actual breach of personal data does, which is why the distinction shows up in almost every state statute.
How do most data breaches happen?
Most data breaches trace back to a short list of root causes, and few of them require an elite hacker. Understanding the pattern is the first step toward closing it.
- Stolen or weak credentials.
Reused passwords and simple logins remain one of the easiest ways in, especially without multi-factor authentication (MFA), which requires a second verification step beyond a password.
- Phishing and social engineering.
Attackers pose as a colleague, vendor, or executive to trick someone into handing over access.
- Unpatched software.
Known vulnerabilities that never got an update give attackers a documented path inside.
- Third-party and vendor compromise.
A breach at a supplier or contractor can expose data the main company never directly handled.
- Insider negligence or misuse.
Sometimes the person with legitimate access is the source, whether by mistake or intent.
If your organization relies on survey software to collect names, emails, or payment details from respondents, that data falls squarely under most state definitions of personal information.
Real data breach examples from the past two years
Recent incidents show how differently a breach can unfold depending on the industry and the entry point attackers use.
- Change Healthcare (2024) suffered a ransomware attack, malicious software that locks or steals data until a ransom is paid, after attackers used a compromised login that had no multi-factor authentication protecting it. The incident disrupted healthcare billing systems nationwide and affected roughly 190 million people.
- National Public Data (2024), a background-check company, exposed billions of records, including Social Security numbers, after attackers accessed its systems, according to Nordstellar’s breach research. The scale made it one of the largest breaches involving government-issued ID numbers in US history.
- The 2025 credential leak involved more than 16 billion login records surfacing online, most pulled from infostealer malware infections rather than a single company’s systems, as documented by DPEX Network. It was a reminder that old, previously stolen credentials keep circulating and causing new damage years later.
Do you need to send a data breach notification? A quick decision guide
Not every incident requires notifying anyone. Whether a company must notify usually comes down to a handful of factors that most state laws share.
- What type of data was exposed.
Social Security numbers, driver’s license numbers, financial account details, and health information almost always trigger notification. Basic contact information sometimes does not, depending on the state.
- Whether the data was encrypted.
If the exposed data was encrypted and the encryption key itself was not compromised, many states waive the notification requirement.
- How many people were affected.
Several states set a minimum threshold before regulators must be notified, separate from the threshold for notifying individuals.
- Whether harm is likely.
A few states use a “risk of harm” test, meaning notification is required only if the exposure could realistically lead to identity theft or fraud.
Companies that manage market research panels often store years of respondent contact details, which raises the stakes if any of these triggers apply. When the analysis is close, involve legal counsel before deciding either way.
Data breach notification laws across the US
As of 2026, all 50 states, the District of Columbia, and three US territories have data breach notification laws, according to Privacy Rights Clearinghouse’s 50-state survey. There is still no single federal law covering every industry, so companies operating nationally often have to satisfy several state requirements from one incident.
The laws vary in three main ways. Some states set a fixed deadline, such as California’s 30-day rule that took effect in January 2026, while others simply require notice “without unreasonable delay.” States also differ on when the attorney general must be notified, and on exactly which categories of data count as personal information.
One rule surprises a lot of companies: the location of the affected person determines which state’s law applies, not the location of the business. A company based in one state with customers in a dozen others may need to comply with a dozen different sets of rules from a single breach. Businesses with customers in the European Union face an additional layer under the General Data Protection Regulation, or GDPR, which requires notifying regulators within 72 hours of discovery.
What a data breach really costs
The financial impact of a breach has climbed for years, and the numbers vary sharply by region and industry.
| Metric | 2025 average cost |
|---|---|
| Global average per breach | $4.44 million |
| United States average per breach | $10.22 million |
| Healthcare industry average | $7.42 million |
| Notification costs alone | Around $390,000 |
According to IBM’s Cost of a Data Breach Report, the US figure marks the 15th consecutive year America has recorded the highest breach costs of any country studied, driven largely by regulatory fines and the cost of detecting and containing an incident. Notification is only one line item, but it is rarely the most expensive part of a breach.
Steps to take immediately after a data breach
The first 72 hours after discovering a breach shape everything that follows. A clear sequence keeps a chaotic moment from becoming a compounding one.
- Contain the exposure. Isolate affected systems, revoke compromised credentials, and stop further data loss before anything else.
- Assess the scope. Determine what data was accessed, how many people are affected, and which states or countries those people live in.
- Loop in legal counsel early. Notification timelines and thresholds vary enough that guessing is risky.
- Notify regulators and affected individuals. Meet the shortest applicable deadline first if multiple states are involved.
- Communicate clearly. Explain what happened, what data was involved, and what the company is doing about it, without vague language or delay.
- Review and strengthen defenses. Use the post-incident review to close the specific gap that allowed the breach.
When QuestionPro faced an extortion attempt against a backup server in 2022, it published a public incident statement explaining what happened, who was affected, and what changed afterward. That kind of transparency, backed by an ongoing security review process, is a useful model for how a notification should actually read.
How to evaluate your breach readiness
Most companies do not find out how ready they are until an incident forces the question. A short self-assessment can surface the gaps earlier.
Questions to test your readiness
- Do you know exactly what personal data you store, and where it lives?
- Could your team detect unauthorized access within 24 hours?
- Is multi-factor authentication required on every account with access to sensitive data?
- Does your incident response plan name specific people and specific deadlines, not just a general process?
Mistakes that make a breach worse
- Collecting more personally identifiable information than the business actually needs.
- Waiting for full certainty before notifying anyone, when most laws only require a reasonable belief that a breach occurred.
- Treating notification as a single email blast instead of a coordinated legal, technical, and customer response.
- Skipping a review of PII collected through surveys, which often sits in accounts longer than anyone realizes.
Preparedness beats a perfect response
No notification letter, however well written, undoes the fact that someone’s data got out. The companies that recover fastest from a breach are usually the ones that had already mapped their data, trained their teams, and written the response plan before they ever needed it.
Compliance tells you what to do after the fact. The better goal is never needing to send that letter at all.
Frequently Asked Questions (FAQs)
Most states protect Social Security numbers, driver’s license numbers, financial account numbers combined with access codes, and login credentials. Some states also cover health information, biometric data, or usernames paired with security questions, so the exact list depends on where affected individuals live.
Timelines vary by state. Some, like California, now require notice within 30 days under a 2026 law. Others use vaguer language like “without unreasonable delay,” with no fixed number of days, which still means acting as fast as reasonably possible.
Yes. Almost no state law exempts businesses based on size. A five-person company that stores customer emails and payment details faces the same notification duty as a large enterprise if that data is exposed.
Often, yes. Most state laws hold the business that owns the customer relationship responsible for notification, even if a third-party vendor’s system was the actual point of failure. Vendor contracts should spell out who handles what.
Usually not, as long as the encryption key was not also compromised. If attackers accessed both the encrypted data and the key needed to unlock it, most states treat that as an exposure requiring notification anyway.



