• Skip to main content
  • Skip to primary sidebar
  • Skip to footer
QuestionPro

QuestionPro

questionpro logo
  • Products
    survey software iconSurvey softwareEasy to use and accessible for everyone. Design, send and analyze online surveys.research edition iconResearch SuiteA suite of enterprise-grade research tools for market research professionals.CX iconCustomer ExperienceExperiences change the world. Deliver the best with our CX management software.WF iconEmployee ExperienceCreate the best employee experience and act on real-time data from end to end.
  • Solutions
    IndustriesGamingAutomotiveSports and eventsEducationGovernment
    Travel & HospitalityFinancial ServicesHealthcareCannabisTechnology
    Use CaseAskWhyCommunitiesAudienceContactless surveysMobile
    LivePollsMember ExperienceGDPRPositive People Science360 Feedback Surveys
  • Resources
    BlogeBooksSurvey TemplatesCase StudiesTrainingHelp center
  • Features
  • Pricing
Language
  • English
  • Español (Spanish)
  • Português (Portuguese (Brazil))
  • Nederlands (Dutch)
  • العربية (Arabic)
  • Français (French)
  • Italiano (Italian)
  • 日本語 (Japanese)
  • Türkçe (Turkish)
  • Svenska (Swedish)
  • Hebrew IL (Hebrew)
  • ไทย (Thai)
  • Deutsch (German)
  • Portuguese de Portugal (Portuguese (Portugal))
  • Español / España (Spanish / Spain)
Call Us
+1 800 531 0228 +1 (647) 956-1242 +55 9448 6154 +49 030 9173 9255 +44 01344 921310 +81-3-6869-1954 +61 (02) 6190 6592 +971 529 852 540
Log In Log In
SIGN UP FREE

Home Market Research

Data Breach Notification Laws: What Every Business Should Know

data-breach-notification-laws

Data breach notification laws require businesses to tell affected people, and often state regulators, the moment personal information has been exposed. Every US state now has one on the books, and the rules differ enough that a single incident can trigger several deadlines at once. For any company that collects emails, survey responses, or customer records, understanding these laws is no longer optional.

The stakes go beyond compliance paperwork. A single breach can cost millions of dollars, damage customer trust, and invite lawsuits that outlast the incident itself. Market researchers, CX teams, and HR departments all handle exactly the kind of personal data these laws exist to protect.

This guide breaks down what a data breach actually is, how notification laws work across the US, and the steps that keep a bad day from turning into a legal one.

Content Index hide
1. What is a data breach?
2. Data breach vs. security incident vs. cyberattack
3. How do most data breaches happen?
4. Real data breach examples from the past two years
5. Do you need to send a data breach notification? A quick decision guide
6. Data breach notification laws across the US
7. What a data breach really costs
8. Steps to take immediately after a data breach
9. How to evaluate your breach readiness
10. Preparedness beats a perfect response
11. Frequently Asked Questions (FAQs)

What is a data breach?

A data breach is an incident where someone accesses, steals, or exposes protected information without authorization. It can be deliberate, such as a hacker breaking into a database, or accidental, such as an employee emailing a spreadsheet to the wrong person.

The information at risk is usually personally identifiable information, or PII, meaning any data that can be traced back to a specific individual. Names, email addresses, Social Security numbers, and login credentials all qualify. Financial records and health details count too, and many state laws treat them with extra weight.

Not every security failure is a data breach. The next section draws that line clearly, since mixing up the terms is one of the fastest ways to over-report or under-report an incident.

Data breach vs. security incident vs. cyberattack

These three terms get used interchangeably in casual conversation, but they describe different things, and the difference matters when a company has to decide whether a legal notification requirement has actually been triggered.

Term What it means Example
Data breach Unauthorized access, theft, or exposure of protected personal data A hacker downloads a customer database containing names and emails
Security incident Any event that threatens system integrity, whether or not data left the network An employee clicks a phishing link, but no data is accessed or removed
Cyberattack A deliberate attempt to compromise a system, app, or network A distributed denial-of-service attack that takes a website offline

A cyberattack does not automatically create a legal notification duty. Only an actual breach of personal data does, which is why the distinction shows up in almost every state statute.

How do most data breaches happen?

Most data breaches trace back to a short list of root causes, and few of them require an elite hacker. Understanding the pattern is the first step toward closing it.

  • Stolen or weak credentials.
    Reused passwords and simple logins remain one of the easiest ways in, especially without multi-factor authentication (MFA), which requires a second verification step beyond a password.
  • Phishing and social engineering.
    Attackers pose as a colleague, vendor, or executive to trick someone into handing over access.
  • Unpatched software.
    Known vulnerabilities that never got an update give attackers a documented path inside.
  • Third-party and vendor compromise.
    A breach at a supplier or contractor can expose data the main company never directly handled.
  • Insider negligence or misuse.
    Sometimes the person with legitimate access is the source, whether by mistake or intent.

If your organization relies on survey software to collect names, emails, or payment details from respondents, that data falls squarely under most state definitions of personal information.

Real data breach examples from the past two years

Recent incidents show how differently a breach can unfold depending on the industry and the entry point attackers use.

  • Change Healthcare (2024) suffered a ransomware attack, malicious software that locks or steals data until a ransom is paid, after attackers used a compromised login that had no multi-factor authentication protecting it. The incident disrupted healthcare billing systems nationwide and affected roughly 190 million people.
  • National Public Data (2024), a background-check company, exposed billions of records, including Social Security numbers, after attackers accessed its systems, according to Nordstellar’s breach research. The scale made it one of the largest breaches involving government-issued ID numbers in US history.
  • The 2025 credential leak involved more than 16 billion login records surfacing online, most pulled from infostealer malware infections rather than a single company’s systems, as documented by DPEX Network. It was a reminder that old, previously stolen credentials keep circulating and causing new damage years later.

Do you need to send a data breach notification? A quick decision guide

Not every incident requires notifying anyone. Whether a company must notify usually comes down to a handful of factors that most state laws share.

  • What type of data was exposed.
    Social Security numbers, driver’s license numbers, financial account details, and health information almost always trigger notification. Basic contact information sometimes does not, depending on the state.
  • Whether the data was encrypted.
    If the exposed data was encrypted and the encryption key itself was not compromised, many states waive the notification requirement.
  • How many people were affected.
    Several states set a minimum threshold before regulators must be notified, separate from the threshold for notifying individuals.
  • Whether harm is likely.
    A few states use a “risk of harm” test, meaning notification is required only if the exposure could realistically lead to identity theft or fraud.

Companies that manage market research panels often store years of respondent contact details, which raises the stakes if any of these triggers apply. When the analysis is close, involve legal counsel before deciding either way.

Data breach notification laws across the US

As of 2026, all 50 states, the District of Columbia, and three US territories have data breach notification laws, according to Privacy Rights Clearinghouse’s 50-state survey. There is still no single federal law covering every industry, so companies operating nationally often have to satisfy several state requirements from one incident.

The laws vary in three main ways. Some states set a fixed deadline, such as California’s 30-day rule that took effect in January 2026, while others simply require notice “without unreasonable delay.” States also differ on when the attorney general must be notified, and on exactly which categories of data count as personal information.

One rule surprises a lot of companies: the location of the affected person determines which state’s law applies, not the location of the business. A company based in one state with customers in a dozen others may need to comply with a dozen different sets of rules from a single breach. Businesses with customers in the European Union face an additional layer under the General Data Protection Regulation, or GDPR, which requires notifying regulators within 72 hours of discovery.

What a data breach really costs

The financial impact of a breach has climbed for years, and the numbers vary sharply by region and industry.

Metric 2025 average cost
Global average per breach $4.44 million
United States average per breach $10.22 million
Healthcare industry average $7.42 million
Notification costs alone Around $390,000

According to IBM’s Cost of a Data Breach Report, the US figure marks the 15th consecutive year America has recorded the highest breach costs of any country studied, driven largely by regulatory fines and the cost of detecting and containing an incident. Notification is only one line item, but it is rarely the most expensive part of a breach.

Steps to take immediately after a data breach

The first 72 hours after discovering a breach shape everything that follows. A clear sequence keeps a chaotic moment from becoming a compounding one.

  1. Contain the exposure. Isolate affected systems, revoke compromised credentials, and stop further data loss before anything else.
  2. Assess the scope. Determine what data was accessed, how many people are affected, and which states or countries those people live in.
  3. Loop in legal counsel early. Notification timelines and thresholds vary enough that guessing is risky.
  4. Notify regulators and affected individuals. Meet the shortest applicable deadline first if multiple states are involved.
  5. Communicate clearly. Explain what happened, what data was involved, and what the company is doing about it, without vague language or delay.
  6. Review and strengthen defenses. Use the post-incident review to close the specific gap that allowed the breach.

When QuestionPro faced an extortion attempt against a backup server in 2022, it published a public incident statement explaining what happened, who was affected, and what changed afterward. That kind of transparency, backed by an ongoing security review process, is a useful model for how a notification should actually read.

How to evaluate your breach readiness

Most companies do not find out how ready they are until an incident forces the question. A short self-assessment can surface the gaps earlier.

Questions to test your readiness

  • Do you know exactly what personal data you store, and where it lives?
  • Could your team detect unauthorized access within 24 hours?
  • Is multi-factor authentication required on every account with access to sensitive data?
  • Does your incident response plan name specific people and specific deadlines, not just a general process?

Mistakes that make a breach worse

  • Collecting more personally identifiable information than the business actually needs.
  • Waiting for full certainty before notifying anyone, when most laws only require a reasonable belief that a breach occurred.
  • Treating notification as a single email blast instead of a coordinated legal, technical, and customer response.
  • Skipping a review of PII collected through surveys, which often sits in accounts longer than anyone realizes.

Preparedness beats a perfect response

No notification letter, however well written, undoes the fact that someone’s data got out. The companies that recover fastest from a breach are usually the ones that had already mapped their data, trained their teams, and written the response plan before they ever needed it.

Compliance tells you what to do after the fact. The better goal is never needing to send that letter at all.

Experiences change the world. Deliver the best with our CX management software and delight your customers at every touchpoint. Request Demo

Frequently Asked Questions (FAQs)

What personal information is protected under most data breach notification laws?

Most states protect Social Security numbers, driver’s license numbers, financial account numbers combined with access codes, and login credentials. Some states also cover health information, biometric data, or usernames paired with security questions, so the exact list depends on where affected individuals live.

How quickly must a company report a data breach in the US?

Timelines vary by state. Some, like California, now require notice within 30 days under a 2026 law. Others use vaguer language like “without unreasonable delay,” with no fixed number of days, which still means acting as fast as reasonably possible.

Do small businesses have to comply with data breach notification laws?

Yes. Almost no state law exempts businesses based on size. A five-person company that stores customer emails and payment details faces the same notification duty as a large enterprise if that data is exposed.

Is a company liable if a vendor causes the data breach?

Often, yes. Most state laws hold the business that owns the customer relationship responsible for notification, even if a third-party vendor’s system was the actual point of failure. Vendor contracts should spell out who handles what.

Can encrypted data still trigger a notification requirement?

Usually not, as long as the encryption key was not also compromised. If attackers accessed both the encrypted data and the key needed to unlock it, most states treat that as an exposure requiring notification anyway.

SHARE THIS ARTICLE:

About the author
Ivana Taylor
Ivana Taylor provides DIY Marketing advice, marketing trends and marketing how-to tips and strategies for small business owners and CEOs.
View all posts by Ivana Taylor

Primary Sidebar

Take full control of your customer journey

Make immediate business actions with our CX management platform

Learn more

RELATED ARTICLES

HubSpot - QuestionPro Integration

Why DPDPA Matters More for Banks Than Any Other Industry?

Feb 10,2026

HubSpot - QuestionPro Integration

Best 17 Online Reputation Management Software in 2026

Apr 17,2024

HubSpot - QuestionPro Integration

Moderated Usability Testing: Process and Best Practices

Oct 20,2023

BROWSE BY CATEGORY

Footer

MORE LIKE THIS

ai-powered-ex-analytics

Turn EX Survey Data into Instant Action: Introducing AI-Powered Summary and Action Recommendations with Organizational Context

Oct 1, 2026

dashboard-allowed-filters

How Dashboard Allowed Filters Eliminate Data Noise in Employee Experience Analytics

Oct 1, 2026

bi-lite

BI Lite: QuestionPro BI for Every License

Sep 30, 2026

research-agent

Keep the thinking, hand off the build: how Research Agent turns your brief into a working survey

Sep 28, 2026

Other categories

questionpro-logo-nw
Help center Live Chat SIGN UP FREE
  • Sample questions
  • Sample reports
  • Survey logic
  • Branding
  • Integrations
  • Professional services
  • Security
  • Survey Software
  • Customer Experience
  • Workforce
  • Communities
  • Audience
  • Polls Explore the QuestionPro Poll Software - The World's leading Online Poll Maker & Creator. Create online polls, distribute them using email and multiple other options and start analyzing poll results.
  • Research Edition
  • LivePolls
  • InsightsHub
  • Blog
  • Articles
  • eBooks
  • Survey Templates
  • Case Studies
  • Training
  • Webinars
  • All Plans
  • Nonprofit
  • Academic
  • Qualtrics Alternative Explore the list of features that QuestionPro has compared to Qualtrics and learn how you can get more, for less.
  • SurveyMonkey Alternative
  • VisionCritical Alternative
  • Medallia Alternative
  • Likert Scale Complete Likert Scale Questions, Examples and Surveys for 5, 7 and 9 point scales. Learn everything about Likert Scale with corresponding example for each question and survey demonstrations.
  • Conjoint Analysis
  • Net Promoter Score (NPS) Learn everything about Net Promoter Score (NPS) and the Net Promoter Question. Get a clear view on the universal Net Promoter Score Formula, how to undertake Net Promoter Score Calculation followed by a simple Net Promoter Score Example.
  • Offline Surveys
  • Customer Satisfaction Surveys
  • Employee Survey Software Employee survey software & tool to create, send and analyze employee surveys. Get real-time analysis for employee satisfaction, engagement, work culture and map your employee experience from onboarding to exit!
  • Market Research Survey Software Real-time, automated and advanced market research survey software & tool to create surveys, collect data and analyze results for actionable market insights.
  • GDPR & EU Compliance
  • Employee Experience
  • Customer Journey
  • Synthetic Data
  • About us
  • Executive Team
  • In the news
  • Testimonials
  • Advisory Board
  • Careers
  • Brand
  • Media Kit
  • Contact Us

QuestionPro in your language

  • English
  • Español (Spanish)
  • Português (Portuguese (Brazil))
  • Nederlands (Dutch)
  • العربية (Arabic)
  • Français (French)
  • Italiano (Italian)
  • 日本語 (Japanese)
  • Türkçe (Turkish)
  • Svenska (Swedish)
  • Hebrew IL (Hebrew)
  • ไทย (Thai)
  • Deutsch (German)
  • Portuguese de Portugal (Portuguese (Portugal))
  • Español / España (Spanish / Spain)

Awards & certificates

  • survey-leader-asia-leader-2023
  • survey-leader-asiapacific-leader-2023
  • survey-leader-enterprise-leader-2023
  • survey-leader-europe-leader-2023
  • survey-leader-latinamerica-leader-2023
  • survey-leader-leader-2023
  • survey-leader-middleeast-leader-2023
  • survey-leader-mid-market-leader-2023
  • survey-leader-small-business-leader-2023
  • survey-leader-unitedkingdom-leader-2023
  • survey-momentumleader-leader-2023
  • bbb-acredited
The Experience Journal

Find innovative ideas about Experience Management from the experts

  • © 2022 QuestionPro Survey Software | +1 (800) 531 0228
  • Sitemap
  • Privacy Statement
  • Terms of Use