Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
Which US state breach-notification laws might apply?
Updated
All 50 US states now have a data-breach notification law. Individual, attorney-general, and credit-bureau notices are different recipient classes with different clocks. This representative table is not a restatement of every statute. Not legal advice; does not start a clock.
US-state jurisdiction guide, last verified 8 September 2026 against official statute text for Cal. Civ. Code §§1798.29 and 1798.82, N.Y. Gen. Bus. Law §899-aa, Mass. Gen. Laws ch. 93H §3, Fla. Stat. §501.171, Tex. Bus. & Com. Code §521.053, Colo. Rev. Stat. §6-1-716, and D.C. Code §28-3852, plus state Attorney General breach pages actually fetched. 201 CMR 17.00 is the Massachusetts safeguard regulation, not the notification clock. It is not legal advice, not a filing, not a 50-state restatement, and not a substitute for counsel.
This is a representative guide, not a 50-state code
Audience: a founder, CISO, or counsel at a US-operating company triaging an incident that may touch residents of more than one state. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that any named statute applies, that personal information as that statute defines it was acquired, that a risk-of-harm trigger is met, or that you must file.
This table is a representative comparison of high-variance states. It does not restate every state's statute verbatim. Last verified 8 September 2026, all 50 states have a data-breach notification law. Alabama's Data Breach Notification Act of 2018 (Ala. Code §§8-38-1 to 8-38-12, Acts 2018-396) is the official chapter that completed that map; this page does not invent a signing date beyond that 2018 chapter title. The District of Columbia has a verified statute (D.C. Code §28-3852). Puerto Rico, the U.S. Virgin Islands, Guam, and the Commonwealth of the Northern Mariana Islands are not treated here — this page did not fetch those territorial texts. Last verified 8 September 2026. Not legal advice.
- Statute versus guidance: the cited Civil Code, General Business Law, General Laws, Florida Statutes, Business and Commerce Code, Colorado Revised Statutes, and D.C. Code provisions are legal requirements only if they apply. Attorney General portals and how-to pages are AG materials, not the statute. This page quotes which kind of text it is relying on.
- This page does not convert 'without unreasonable delay', 'as soon as practicable', or 'as expeditiously as practicable' into a number of days. Fixed-day clocks stay exact: 30 calendar days is not 30 days is not 60 days.
- Individual notice, attorney-general notice, and credit-bureau notice are different recipient classes with different thresholds. Do not collapse them. Filing California does not discharge New York.
- Cal. Civ. Code §1798.82 (customer records) and §1798.29 (agency) are breach-notification statutes. CCPA/CPRA (Cal. Civ. Code §1798.100 et seq., including §1798.150) is a different regime. Do not paste CCPA onto §1798.82.
- The which-jurisdictions-apply page on this site is the applicability map. The who-to-notify page on this site is the recipient-class map. The reporting-deadlines page on this site is the statute table of clocks.
- The signed-in CRA ladder tracks recorded awareness for findings the organisation classified as CRA-in-scope. That tracker is not a US-state clock, and it does not file with an attorney general, a resident, or a credit bureau. A named human still submits.
Common structure — then the variances start
Most US-state statutes share a skeleton: a definition of personal information, a definition of breach (often unauthorized acquisition of computerized data), an encryption or key-compromise limb, a duty to notify affected residents, and often a separate duty to notify the attorney general and nationwide consumer reporting agencies once a numeric threshold is met. The words inside that skeleton are not uniform. Last verified 8 September 2026. Not legal advice.
| Limb | What varies | What this page does not do |
|---|---|---|
| Personal information | Name-plus-data-element lists differ. California §1798.82(h) includes medical information, health insurance information, unique biometric data, automated license-plate data, and genetic data, plus username-or-email plus password. New York uses 'private information' in §899-aa(1)(b), including biometric, medical, and health-insurance elements as of the 2025-03-28 revision fetched. Massachusetts ch. 93H is narrower in the definition this page fetched. Do not paste one state's list onto another. | Does not decide that YOUR dataset is personal information under any named statute. |
| Encryption / key | Several statutes treat encrypted data as outside the trigger unless the key or credential is also acquired. California §1798.82(a)(1) reaches encrypted personal information when the encryption key or security credential was, or is reasonably believed to have been, acquired, and the owner has a reasonable belief the key could render the information readable or usable. Colorado §6-1-716(2)(a.4) requires disclosure of encrypted information if the confidential process, encryption key, or other means to decipher was also acquired or reasonably believed acquired. There is no uniform encryption safe harbor. | Does not find that YOUR encryption, key handling, or 'reasonable belief' meets any statute. |
| Risk-of-harm / misuse | Some statutes notify on acquisition. Some add a harm or misuse screen. Massachusetts ch. 93H §1 (definitions, last fetched 8 September 2026) defines 'breach of security' as unauthorized acquisition or use that creates a substantial risk of identity theft or fraud against a resident. Florida §501.171(4)(c) lets a covered entity skip individual notice if, after investigation and consultation with law enforcement, it reasonably determines the breach has not and will not likely result in identity theft or any other financial harm — documented in writing and kept at least 5 years. Colorado §6-1-716(2)(a) requires a good-faith prompt investigation and notice unless misuse has not occurred and is not reasonably likely to occur. The Alabama Attorney General's Data Breach Notification page (fetched 8 September 2026) describes Acts 2018-396 as requiring AG notice when unauthorized acquisition of sensitive personally identifying information is reasonably likely to cause substantial harm. These tests are not the same sentence. | Does not apply a risk-of-harm test to YOUR facts. Does not invent a uniform trigger. |
| Timing words | Three families, not one number. (1) Open-ended: 'without unreasonable delay' / 'as soon as practicable' with no outer day count in the notice sentence. (2) Open-ended plus a fixed outer mark. (3) A fixed-day clock from discovery or from determination. 'Without unreasonable delay' is not 30 days. 'As expeditiously as practicable' is not a number. | Does not start YOUR clock. Does not convert an open-ended phrase into days. |
| Three recipient classes | Residents, the attorney general (or a named department), and nationwide consumer reporting agencies. Thresholds differ: any resident (New York AG under §899-aa(8)(a); Massachusetts AG and OCABR under ch. 93H §3(b)), 50 District residents (D.C. Code §28-3852(b-1)), 500 (California sample copy; Florida department; Colorado AG), more than 1,000 (Florida and Colorado credit bureaus), more than 5,000 (New York credit bureaus). Those numbers are not interchangeable. | Does not collapse resident, AG, and bureau notice. Does not file with any of them. |
Representative comparison — high-variance states
These rows are the statutes this page actually fetched. They are not the 50-state code. Last verified 8 September 2026. Not legal advice. Not YOUR clock.
| Instrument | Individual-notice timing (statute words) | AG / department | Credit bureaus | Last verified |
|---|---|---|---|---|
| Cal. Civ. Code §1798.82 — person or business; customer records. Legal requirement only if it applies. Not CCPA/CPRA. | §1798.82(a)(2)(A), as amended by Stats. 2025, Ch. 319 (SB 446), effective 1 January 2026: 'the disclosure required by this subdivision shall be made within 30 calendar days of discovery or notification of the data breach.' Subparagraph (B) permits delay to accommodate legitimate law-enforcement needs under subdivision (c), or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. 30 calendar days is this statute's number — not a 50-state average. | §1798.82(f): if a security breach notification goes to more than 500 California residents as a result of a single breach, electronically submit a single sample copy (excluding personally identifiable information) to the Attorney General within 15 calendar days of notifying affected consumers. 15 calendar days from consumer notice is not the 30 calendar days to the resident. Portal (AG materials): oag.ca.gov/privacy/databreach/reporting. | §1798.82(d)(2)(F) requires the resident notice to include telephone numbers and addresses of the major credit reporting agencies if the breach exposed a social security number or a driver's license or California identification card number. That is notice content, not a separate bureau-filing threshold in the sentences this page fetched. | 8 September 2026 |
| Cal. Civ. Code §1798.29 — agency. Legal requirement only if it applies. Different instrument from §1798.82. | §1798.29(a): 'The disclosure shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subdivision (c), or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.' Last verified 8 September 2026, this agency section still uses that open-ended phrase. It is not §1798.82(a)(2)'s 30 calendar days. Do not paste the customer 30 calendar days onto an agency. | §1798.29(e): sample copy to the Attorney General when more than 500 California residents are notified as a result of a single breach. The 15-calendar-day consumer-to-AG mark in §1798.82(f) is not in the §1798.29(e) sentence this page fetched. | §1798.29(d)(2)(F) is resident-notice content (credit-reporting-agency numbers if SSN or driver's license / California ID exposed), not a bureau-filing threshold in the sentences fetched. | 8 September 2026 |
| N.Y. Gen. Bus. Law §899-aa (SHIELD Act notification). Legal requirement only if it applies. §899-bb is the separate data-security-protections section — not this notice clock. | §899-aa(2), most recent revision fetched 2025-03-28: disclose to any New York resident whose private information was, or is reasonably believed to have been, accessed or acquired without valid authorization. 'The disclosure shall be made in the most expedient time possible and without unreasonable delay, provided that such notification shall be made within thirty days after the breach has been discovered, except for the legitimate needs of law enforcement, as provided in subdivision four of this section.' The thirty-day outer mark is in that sentence. 'Without unreasonable delay' is not converted here into a different number. Subdivision 2(a) is a documented inadvertent-disclosure / not-likely-misuse screen, kept at least five years; if over 500 New York residents, the written determination goes to the attorney general within ten days after the determination. | §899-aa(8)(a): if any New York residents are to be notified, notify the state attorney general, the department of state, the division of state police, and — only if the person or business is a covered entity as defined in 23 NYCRR 500.1 — the department of financial services, as to timing, content, distribution, and approximate number, with a copy of the template, without delaying notice to affected residents. Portal (AG materials): ag.ny.gov/resources/organizations/data-breach-reporting. | §899-aa(8)(b): if more than five thousand New York residents are to be notified at one time, also notify consumer reporting agencies as to timing, content, distribution, and approximate number, without delaying resident notice. | 8 September 2026 |
| Mass. Gen. Laws ch. 93H §3. Legal requirement only if it applies. 201 CMR 17.00 is not this clock. | §3(b): a person or agency that owns or licenses data including personal information about a resident shall provide notice, 'as soon as practicable and without unreasonable delay,' when it knows or has reason to know of a breach of security or that the personal information of such resident was acquired or used by an unauthorized person or used for an unauthorized purpose, to the attorney general, the director of consumer affairs and business regulation, and to such resident. That sentence has no outer day count. This page does not invent one. Notice to the resident 'shall not include the nature of the breach of security or unauthorized acquisition or use, or the number of residents of the commonwealth affected.' | §3(b) always names the attorney general and the director of consumer affairs and business regulation — no numeric resident threshold in that sentence. Official how-to (agency materials): mass.gov/info-details/requirements-for-data-breach-notifications. | §3(b): upon receipt, the director identifies any relevant consumer reporting agency or state agency and forwards those names; the person or agency then provides notice to those identified agencies as soon as practicable and without unreasonable delay. That is a director-identified list, not a numeric 1,000-resident trigger in the sentences fetched. | 8 September 2026 |
| Fla. Stat. §501.171 — Florida Information Protection Act. Legal requirement only if it applies. | §501.171(4)(a): notice to each individual in this state whose personal information was, or the covered entity reasonably believes to have been, accessed as a result of the breach. 'Notice to individuals shall be made as expeditiously as practicable and without unreasonable delay … but no later than 30 days after the determination of a breach or reason to believe a breach occurred' unless a law-enforcement delay under (4)(b) or the written no-likely-harm determination under (4)(c). 'As expeditiously as practicable' is not converted into a number other than the 30-day outer mark the statute states. Clock-start in that sentence is determination of a breach or reason to believe a breach occurred — not California's 'discovery or notification.' | §501.171(3)(a): notice to the Department of Legal Affairs of any breach affecting 500 or more individuals in this state, as expeditiously as practicable, but no later than 30 days after the determination of the breach or reason to believe a breach occurred. A covered entity may receive 15 additional days to provide the individual notice in subsection (4) if good cause for delay is provided in writing to the department within those 30 days. Official consumer explainer (AG materials): myfloridalegal.com/consumer-protection/how-to-protect-yourself-data-security. | §501.171(5): if circumstances require notice of more than 1,000 individuals at a single time, also notify, without unreasonable delay, all nationwide consumer reporting agencies as defined in 15 U.S.C. §1681a(p), of the timing, distribution, and content of the notices. | 8 September 2026 |
| Colo. Rev. Stat. §6-1-716. Legal requirement only if it applies. Not the Colorado Privacy Act (§6-1-1301 et seq.). | §6-1-716(2)(a): when it becomes aware that a security breach may have occurred, conduct in good faith a prompt investigation to determine the likelihood that personal information has been or will be misused. Give notice to affected Colorado residents unless the investigation determines that misuse has not occurred and is not reasonably likely to occur. 'Notice must be made in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred,' consistent with legitimate law-enforcement needs and measures necessary to determine scope and restore reasonable integrity. 'Determination that a security breach occurred' is defined in §6-1-716(1)(c) as the point in time at which there is sufficient evidence to conclude that a security breach has taken place. Thirty days from determination is not thirty days from discovery. | §6-1-716(2)(f)(I): notice to the Colorado attorney general in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination, if the security breach is reasonably believed to have affected five hundred Colorado residents or more, unless the investigation determines that misuse has not occurred and is not likely to occur. Portal (AG materials): coag.gov/data-breach-notification-report-form/. | §6-1-716(2)(d): if required to notify more than one thousand Colorado residents, also notify, in the most expedient time possible and without unreasonable delay, all nationwide consumer reporting agencies of the anticipated date of the notification and the approximate number of residents who are to be notified. That subsection does not require providing names of recipients to the bureau. It does not apply to a covered entity subject to Title V of the Gramm-Leach-Bliley Act. | 8 September 2026 |
| Tex. Bus. & Com. Code §521.053. Legal requirement only if it applies. | §521.053(b): disclose, after discovering or receiving notification of the breach, to any individual whose sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized person. 'The disclosure shall be made without unreasonable delay and in each case not later than the 60th day after the date on which the person determines that the breach occurred, except as provided by Subsection (d) or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system.' The 60th day is this statute's outer mark. 'Without unreasonable delay' is not converted into 30 days. Sixty days is not California's 30 calendar days. | Texas Attorney General Data Breach Reporting page (AG materials, fetched 8 September 2026): Texas law requires electronic submission of the Data Breach Report to the OAG; the Identity Theft Enforcement and Protection Act page on the same site describes reporting a breach that affects 250 or more Texans as soon as practicable but no later than 30 days after determining the breach occurred. Those AG pages describe the filing path. This page does not restate an unseen subsection as if it had been quoted from the code HTML. Portal (AG materials): texasattorneygeneral.gov/consumer-protection/data-breach-reporting. | This page did not fetch a credit-bureau threshold sentence from the official Texas code HTML. It does not invent one. | 8 September 2026 |
| D.C. Code §28-3852. Legal requirement only if it applies. District of Columbia — verified. Not a stand-in for Puerto Rico, the Virgin Islands, Guam, or CNMI. | §28-3852(a): promptly notify any District of Columbia resident whose personal information was included in the breach. 'The notification shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection (d) of this section, and with any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.' No outer day count in that sentence. This page does not invent one. | §28-3852(b-1): in addition to resident notice, promptly provide written notice to the Office of the Attorney General for the District of Columbia if the breach affects 50 or more District residents. Fifty is this statute's AG number — not California's 500, not Florida's 500, not Texas AG materials' 250. | §28-3852(a-1) requires the resident notice to include telephone numbers and addresses for the major consumer reporting agencies, and a statement of the right to obtain a security freeze at no charge under 15 U.S.C. §1681c-1. That is notice content, not a numeric bureau-filing threshold in the sentences fetched. | 8 September 2026 |
201 CMR 17.00 is not the Massachusetts notice clock
Mass. Gen. Laws ch. 93H §3 is the duty to report a known security breach or unauthorized use. 201 CMR 17.00 (Standards for the protection of personal information of residents of the Commonwealth) is the Office of Consumer Affairs and Business Regulation safeguard regulation issued under ch. 93H. Last verified 8 September 2026 against the official mass.gov regulation page: 201 CMR 17.00 establishes minimum standards for a written comprehensive information security program covering paper and electronic records. It is not a substitute for §3's 'as soon as practicable and without unreasonable delay' notice sentence, and this page does not paste 17.00 onto the notification clock. Not legal advice.
CCPA/CPRA is not Cal. Civ. Code §1798.82
Two California regimes. Do not paste one onto the other. Last verified 8 September 2026. Not legal advice.
- Cal. Civ. Code §1798.82 sits in Title 1.81 (Customer Records). It is the person-or-business breach-notification statute. §1798.29 sits in the Information Practices Act and is the agency breach-notification statute. Those are the notice statutes this page treats.
- CCPA/CPRA sits in Title 1.81.5 (Cal. Civ. Code §1798.100 et seq.). §1798.140(d) and (i) define 'business' and 'consumer'. §1798.150 is a private right of action in that title for certain security incidents involving nonencrypted and nonredacted personal information as that title defines it. §1798.150 is not §1798.82. This page does not apply §1798.150 to YOUR facts and does not invent a private-right outcome.
- The which-jurisdictions-apply page on this site is the CCPA/CPRA 'business' threshold map. That threshold is not a GDPR Article 3 test and is not the §1798.82 disclosure duty.
- The signed-in catalog key `ccpa` is labelled CCPA/CPRA readiness (starter subset). Starter controls are Title 1.81.5 consumer-privacy sections (for example 1798.100, 1798.105, 1798.110, 1798.115, 1798.121, 1798.130). They are not §1798.82. The CCPA/CPRA program card records four org-level attestations: 1798.100(a)(3), 1798.115, 1798.121, and 1798.130(a)(6). Those attestations are not a §1798.82 notice.
Multi-state strategy — overlapping duties may all attach
One incident can fire more than one state's statute at once. Filing California does not discharge New York. Meeting Florida's 30-day outer mark does not rewrite Massachusetts' 'as soon as practicable and without unreasonable delay.' This is a strategy note, not a determination that any named statute applies to YOU. Last verified 8 September 2026. Not legal advice.
- Walk residents by state (and the District, if in play). Each statute's personal-information definition and harm screen is its own test. A no-notify decision under Florida §501.171(4)(c) is not a no-notify decision under California §1798.82.
- Do not pick the longest clock and treat it as the only clock. The most protective overlapping duties may all attach. California's 30 calendar days from discovery or notification, New York's thirty days after the breach has been discovered, Florida's 30 days after determination, Colorado's thirty days after determination, and Texas's 60th day after the person determines that the breach occurred are different start events and different marks.
- Attorney-general portals are per-state. A sample copy to the California Attorney General under §1798.82(f) is not New York §899-aa(8)(a) notice to the attorney general, department of state, and division of state police. Do not treat one portal as a nationwide filing desk.
- Credit-bureau notice, where a statute states it, is a third class. New York's more-than-five-thousand trigger is not Florida's more-than-1,000 trigger and not Colorado's more-than-one-thousand trigger.
- HIPAA, SEC Form 8-K Item 1.05, and federal sector rules are different instruments. The SEC cyber-disclosure guide on this site is Form 8-K Item 1.05 and Item 106. The HIPAA breach-notification guide on this site. Filing a state AG does not discharge those. The UK GDPR jurisdiction guide on this site is Articles 33–34 to the Commissioner — a separate leaf from any US-state statute.
- Document the walk, including a no-notification decision. The document-your-decision page on this site is the decision record. This page does not keep YOUR file.
Checklist
This is a question list, not a filing, and not YOUR notice. Walk it with counsel. The which-jurisdictions-apply page on this site is the applicability map. The who-to-notify page on this site is the recipient-class map. The reporting-deadlines page on this site is the statute table.
- Which states' (or the District's) residents are in the affected set? This page does not run that census.
- For each candidate statute, is the dataset personal information / private information / sensitive personal information as that statute defines it? Do not paste California's list onto Massachusetts.
- Was there unauthorized acquisition (or, in New York, access or acquisition) of computerized data as that statute defines breach? Encryption plus key? This page does not find it.
- Does that statute have a risk-of-harm, misuse, or substantial-risk screen? Counsel applies that test. A documented no-likely-harm decision in one state is not a decision in another.
- Individual notice: quote that statute's timing words. Do not convert 'without unreasonable delay' into 30 days. Do not treat determination as discovery.
- Attorney-general or department notice: different threshold, sometimes a different clock (California's 15 calendar days from consumer notice; New York whenever any resident is notified; Massachusetts always with the resident).
- Credit-bureau notice: only where the cited section states it, at that section's number.
- Does CCPA/CPRA Title 1.81.5 also sit on the facts? That is a different regime from §1798.82. The obligation-map `ccpa` in-scope mark is not that determination.
- Who is authorised to file, and who is not. A named human files. The product does not. This page does not file.
Glossary
These are teaching labels for this page. They are not legal conclusions about YOUR facts.
| Term | How this page uses it |
|---|---|
| All 50 states | Last verified 8 September 2026, every state has a data-breach notification law. Alabama's Data Breach Notification Act of 2018 is the official chapter that completed that map. This table is still not the 50-state code. |
| §1798.82 | California customer-records breach notification. 30 calendar days from discovery or notification as of 1 January 2026 (SB 446). Not CCPA/CPRA. Not §1798.29. |
| §1798.29 | California agency breach notification. Still 'most expedient time possible and without unreasonable delay' in the text fetched. Not the customer 30 calendar days. |
| CCPA/CPRA | Cal. Civ. Code §1798.100 et seq. (Title 1.81.5), including §1798.150. Different regime from §1798.82. |
| SHIELD Act | New York Stop Hacks and Improve Electronic Data Security Act. §899-aa is notification. §899-bb is data-security protections. Do not collapse them. |
| Without unreasonable delay | Open-ended timing words in several statutes. Not 30 days. Not 45 days. Not 60 days. A statute that also states an outer mark (New York thirty days; Texas 60th day) is quoted as both. |
| Determination | Florida and Colorado start language for their 30-day outer marks. Colorado defines it as sufficient evidence to conclude a security breach has taken place. Not California's discovery or notification. |
| Risk-of-harm | A family of screens (substantial risk, misuse not reasonably likely, identity theft or other financial harm, substantial harm). Not a uniform trigger. Not GDPR Article 33(1)'s 'unlikely to result in a risk.' |
| 201 CMR 17.00 | Massachusetts written-information-security-program regulation. Not Mass. Gen. Laws ch. 93H §3's notice clock. |
Where this shows up in ShipReady Metrics
The signed-in app does not decide that any US-state statute applies, does not start a notification clock, does not file with an attorney general, residents, or credit bureaus, and does not have a 50-state reporting ladder. None of the surfaces below is a §1798.82 disclosure, a New York §899-aa notice, or an instruction to submit a filing.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organization has classified as CRA-in-scope. That is one product tracker for the CRA actively-exploited ladder. It is not a US-state clock, not an AG filing, and not a resident notice. It tracks a clock the organization already recorded. It is not a determination that CRA applies. A named human still submits.
CCPA/CPRA is a bundled framework in the catalog (`ccpa`, labelled CCPA/CPRA readiness — a starter subset, not the full statute, and not Cal. Civ. Code §1798.82). The obligation map lists frameworks the organization has marked in-scope. That in-scope mark is not a determination that CCPA/CPRA applies, not a 50-state applicability opinion, and not a legal opinion that a breach-notification statute has been triggered. The CCPA/CPRA program card records four org-level attestations (1798.100(a)(3), 1798.115, 1798.121, 1798.130(a)(6)). Those rows are not a §1798.82 pack. The cyber risk register lives under Security. None of those surfaces files with a state attorney general, a resident, or a credit bureau.
Primary sources (last verified 8 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Cal. Civ. Code §1798.82 (Legislative Counsel, including Stats. 2025, Ch. 319, SB 446, effective 1 January 2026) and §1798.29 are legal requirements only if they apply. N.Y. Gen. Bus. Law §899-aa (NYSenate Open Legislation, most recent revision 2025-03-28) is a legal requirement only if it applies; §899-bb is a different section. Mass. Gen. Laws ch. 93H §3 (malegislature.gov) is a legal requirement only if it applies; 201 CMR 17.00 is the OCABR safeguard regulation, not the notice clock. Fla. Stat. §501.171 (Florida Senate, 2024 statutes including 2025C) is a legal requirement only if it applies. Tex. Bus. & Com. Code §521.053(b) (Texas legislative HTML) is a legal requirement only if it applies. Colo. Rev. Stat. §6-1-716 (official CRS PDF via the Colorado General Assembly) is a legal requirement only if it applies. D.C. Code §28-3852 (code.dccouncil.gov) is a legal requirement only if it applies. Alabama Code Chapter 38 (Data Breach Notification Act of 2018, §§8-38-1 to 8-38-12) is cited from the official ALISON chapter listing; this page did not fetch the body of §8-38-5 and does not invent a 45-day Alabama clock. Attorney General pages actually fetched — California oag.ca.gov/privacy/databreach/reporting, New York ag.ny.gov/resources/organizations/data-breach-reporting, Massachusetts mass.gov/info-details/requirements-for-data-breach-notifications, Florida myfloridalegal.com/consumer-protection/how-to-protect-yourself-data-security, Texas texasattorneygeneral.gov/consumer-protection/data-breach-reporting, Colorado coag.gov/data-breach-notification-report-form/, Alabama alabamaag.gov/data-breach-notification/ — are AG materials, not the statute. These are the instruments this page treats, not a complete 50-state code. The UK GDPR jurisdiction guide on this site is Articles 33–34 to the Commissioner. The SEC cyber-disclosure guide on this site is Form 8-K Item 1.05 and Item 106. The HIPAA breach-notification guide on this site. The Canada PIPEDA jurisdiction guide on this site is PIPEDA ss. 10.1–10.3 and SOR/2018-64. A dedicated Australia NDB, India DPDP / CERT-In, and UAE/Dubai guide is not on this site yet. Naming them is not a link. Not legal advice.
The which-jurisdictions-apply page on this site is the applicability map. The who-to-notify page on this site is the recipient-class map. The reporting-deadlines page on this site is the statute table of clocks. The reporting-decision-tree page on this site is the branching tree. The regulator-customer-individual page on this site is the three-stream comparison. The prepare-regulatory-report page on this site is the field checklist. The document-your-decision page on this site is the decision record. The supporting-evidence page on this site is the evidentiary record. The failure-to-report-consequences page on this site is the maxima table. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The GDPR breach-notification guide on this site is the jurisdiction treatment of Articles 33–34. The NIS2 incident-reporting guide on this site. The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. The CRA Article 14 reporting guide on this site.
Frequently asked questions
Which US state breach-notification laws might apply?
This page cannot tell you. Last verified 8 September 2026, all 50 states have a data-breach notification law. Individual, attorney-general, and credit-bureau notices are different recipient classes. The table is a representative high-variance comparison, not a restatement of every statute. Counsel maps YOUR residents, YOUR dataset, and each statute's words. Not legal advice.
Is this legal advice?
No. It is a US-state jurisdiction guide distilled from official statute text this page fetched and from Attorney General portals labelled as AG materials, not the statute. Whether any named section applies, whether personal information as that section defines it was acquired, whether a risk-of-harm screen is met, and whether a clock has started are legal questions for counsel on your facts. This page does not start a reporting clock.
Does ShipReady file with state AGs?
No. The signed-in app does not file with an attorney general, residents, or credit bureaus, does not start a US-state notification clock, and does not have a 50-state reporting ladder. Compliance → CRA reporting tracks the Article 14 ladder from recorded awareness for findings the org classified as CRA-in-scope — one product tracker, not a state AG filing. The obligation map is frameworks marked in-scope, not a 50-state applicability opinion. A named human still submits.
Does notifying California discharge New York?
No. Filing California does not discharge New York. One incident can fire more than one state's statute. Individual, AG, and credit-bureau notices are different recipient classes with different thresholds. That is a strategy note, not a determination that either statute applies to YOU. Not legal advice.
Is CCPA the same as Cal. Civ. Code §1798.82?
No. §1798.82 (and agency §1798.29) are breach-notification statutes. CCPA/CPRA is Title 1.81.5, Cal. Civ. Code §1798.100 et seq., including §1798.150. The catalog key `ccpa` is CCPA/CPRA readiness (starter subset) — consumer-privacy controls, not a §1798.82 notice. Not legal advice.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.