Skip to content
Rapid Response

      Desks

      This library

      Breach Notification

      The State Clocks and Where They Differ

      Some statutes give a number of days and some give none, and the two kinds interact badly. An organization holding records about residents of a dozen states is governed by the shortest clock in the set, whatever the others allow.

      Breach Notification7 min readState lawState clocks

      Two identical round black-rimmed wall clocks hung side by side on a pale wall, cream dials with red second hands
      Fixed-day statutes look interchangeable until the counting event is read, and then they are not. — 19h00s, Public domain, source.

      The rule in short

      State notification statutes fall into two families. One family sets an outer limit in days, counted either from discovery of the breach or from the determination that a breach occurred. The other family requires notice in the most expedient time possible and without unreasonable delay, with no number at all. Several states in the first family have moved to thirty days, others sit at forty-five or sixty, and the counting event differs even among statutes that share a number.

      The state notification statutes divide into two families that behave very differently under pressure. One family names a number of days and treats it as an outer limit. The other names no number and requires notice in the most expedient time possible and without unreasonable delay. Both kinds are in force at once across any sizeable population of affected residents, and the interaction between them, rather than either one alone, is what governs the schedule.

      The statutes that name a number

      The short end of the range has converged on thirty days. California requires disclosure within thirty calendar days of discovery or notification of the breach. Washington requires notification to affected consumers in the most expedient time possible, without unreasonable delay, and no more than thirty calendar days after the breach was discovered. New York requires notice without unreasonable delay and within thirty days after the breach has been discovered. Maine sets thirty days from the point at which the entity becomes aware of a breach and has identified its scope.

      Above that band sit the forty-five day statutes. Ohio requires disclosure in the most expedient time possible but not later than forty-five days following discovery or notification. Vermont sets the same forty-five days to consumers, counted from discovery or notification. Delaware sits at the long end, requiring notice not later than sixty days after determination of the breach.

      The counting event, which is not always discovery

      Two statutes can share a number and still run on different schedules, because they start from different events. Washington, New York and California count from discovery. Florida counts thirty days from the determination of the breach or from the point at which there is reason to believe a breach occurred, which is a later moment in almost every incident. Delaware likewise counts from determination.

      The gap between discovery and determination is the whole of the investigation, and it is often the largest single block of time in an incident. A statute counting from determination is therefore more generous in fact than its number suggests, and one counting from discovery is less generous. Nothing in the discovery-based statutes suspends the count while the determination is being made; the investigation has to fit inside the period, not precede it.

      StateOuter limit to individualsCounted fromNamed allowance inside the period
      CaliforniaThirty calendar daysDiscovery or notificationLaw enforcement delay; scope and system integrity
      WashingtonThirty calendar daysDiscoveryLaw enforcement delay; scope and system integrity
      FloridaThirty daysDetermination, or reason to believeFifteen further days on written good cause to the regulator
      New YorkThirty daysDiscoveryLegitimate needs of law enforcement
      OhioForty-five daysDiscovery or notificationLegitimate needs of law enforcement
      DelawareSixty daysDetermination of the breachNamed situations altering the obligation

      The statutes that name no number

      A substantial group of states requires disclosure in the most expedient time possible and without unreasonable delay, and stops there. The formula descends from the earliest state statute and has survived amendment in many places even where a number was added elsewhere in the same section. Its practical effect is not leniency. A fixed-day statute at least tells an organization when it is safe; an open-ended one never does, because reasonableness is assessed afterwards against the facts as they developed.

      The open-ended statutes also interact with the numbered ones in a way that is easy to miss. Every numbered statute in this field keeps the expedient-time language alongside the number. Thirty days is a ceiling, not an entitlement. An organization that identified the affected population in four days and notified on the twenty-ninth has satisfied the number and can still be said to have delayed unreasonably. The number does not displace the standard; it caps it.

      Reading an open-ended statute therefore means reading it against practice rather than against a calendar. The reference points available are the numbers other legislatures have chosen and the allowances the same statute grants for scope determination and law enforcement. An organization that finishes its analysis quickly and then holds the letters for reasons unrelated to accuracy has no defense in an open-ended state that it would not also lack in a thirty-day one. What the absence of a number removes is the certainty on the other side: there is no day on which delay becomes safe.

      Two clocks per state, not one

      The deadline for notifying individuals and the deadline for notifying the state regulator are set separately and often differ. Vermont requires a preliminary description to the regulator within fourteen business days while allowing forty-five days to consumers. California allows the sample copy to reach the regulator within fifteen calendar days of notifying consumers, so the regulator clock begins when the consumer notice goes out. Reading one clock and assuming the other matches is a common way to miss a filing.

      Working to the shortest applicable clock

      Because each statute governs the residents of its own state, an incident spanning many states creates many simultaneous obligations rather than one. In operational terms the shortest applicable clock sets the schedule for the whole notification round. Staggering by jurisdiction is possible, but it multiplies the number of drafts in circulation and creates the risk that two versions of the same account reach the public. That sequencing problem is treated in full in handling an incident that crosses many states.

      One qualification is worth stating plainly. Running to the shortest clock is an operational choice rather than a rule of law, and it costs something. A statute allowing sixty days from determination was drafted to let an entity identify its population accurately, and notifying on day twenty-eight to match a neighboring state can mean writing to people whose records turn out not to have been involved. Over-notification has consequences of its own, including a corrective second letter that weakens the first. The choice is between a defensible schedule and an accurate list, and most organizations take the schedule.

      Working to the shortest clock also has a definitional consequence. The threshold question of whether the facts amount to a breach must be answered on that compressed schedule, which is why the analysis described in the definitions that decide whether a breach occurred is done in parallel with the forensic work rather than after it.

      The delays the statutes actually permit

      Three allowances recur. The first is law enforcement: notice may be delayed where an agency determines that notification would impede a criminal investigation, and the clock resumes on the agency's say-so rather than the organization's. The mechanics of that request are set out in delaying notice at the request of law enforcement. The second is scope and integrity: several statutes allow the time reasonably necessary to determine the scope of the breach and to restore the reasonable integrity of the data system. The third is narrower and appears in Florida, which permits fifteen additional days if written good cause is provided to the regulator inside the original thirty.

      None of these is self-executing. Each depends on a record made at the time: the identity of the officer who asked for the delay, the reason the scope could not yet be determined, the good-cause letter that was actually sent. Where the record is thin, the allowance is difficult to invoke later, and the organization is left defending a plain reading of the number. Regulator filings and their own thresholds are treated separately in the counts that trigger a filing with a state regulator.

      Points to carry away

      • California, Washington, Florida, Maine and New York all now run outer limits of thirty days.
      • Ohio and Vermont set forty-five days, and Delaware sets sixty.
      • The counting event differs: some statutes run from discovery, others from the determination that a breach occurred.
      • Every fixed-day statute is layered on top of a duty to act without unreasonable delay, so the number is a ceiling and not a target.
      • Statutes commonly allow time needed to determine the scope of the breach and restore the integrity of the system.
      • Notice to the regulator can be due on a different clock from notice to individuals in the same state.

      Questions readers ask

      Which state deadline governs when an incident touches many states?

      Each state governs its own residents, so no single deadline governs the incident. In practice the shortest applicable clock sets the operational schedule, because a single coordinated notification round is easier to defend than a staggered one and because the content requirements largely overlap. Where a state adds an element the others do not, the usual approach is to build one notice containing the union of required elements rather than to draft a separate letter for each jurisdiction, unless a state's own wording forbids the additions.

      Does the clock stop while forensic work continues?

      Not as a general matter. Several statutes expressly allow the time reasonably necessary to determine the scope of the breach and to restore the reasonable integrity of the data system, but that is an allowance inside the period rather than a suspension of it. Washington and California both frame it that way. An investigation that has not identified every affected record does not excuse silence past the outer limit; it usually means notice goes out on what is known, with supplementary notice as more becomes clear.

      What starts the clock in a statute that names no number?

      The duty attaches on discovery or notification of the breach and requires notice in the most expedient time possible and without unreasonable delay. There is no fixed endpoint, which cuts both ways. It permits a longer period where the facts genuinely require one, and it offers no safe harbor at any point, because reasonableness is judged after the fact against what the organization knew and when. Regulators reading such a statute tend to measure delay against the date the incident was first detected.

      Sources

      1. California Civil Code section 1798.82Sets disclosure within thirty calendar days of discovery or notification, with an allowance for law enforcement and scope determination.
      2. RCW 19.255.010 — Washington notice of security breachesRequires consumer notice in the most expedient time possible and no more than thirty calendar days after discovery.
      3. Florida Statutes section 501.171Runs thirty days from determination of the breach rather than from discovery, and allows fifteen additional days on written good cause.
      4. New York General Business Law section 899-aaRequires notice without unreasonable delay and within thirty days after the breach has been discovered.
      5. Ohio Revised Code section 1349.19Sets the most expedient time possible but not later than forty-five days following discovery or notification.
      6. 9 V.S.A. section 2435 — Vermont security breach noticeSets forty-five days to consumers and a separate fourteen business day preliminary notice to the regulator.
      7. Delaware Code title 6, chapter 12BSets sixty days after determination of the breach, with named situations that alter the obligation.

      Rapid Response Law is a publication, not a law firm. This article states general rules and cites its sources; it is not advice about any particular case, and the law differs by state and changes over time.

      More in Breach Notification

      Breach Notification

      Notifying a Regulator and the Threshold That Triggers It

      Most states require a filing with the attorney general once a set number of that state's residents must be notified. Five hundred is the most common figure, but the clock attached to it varies: some states measure from discovery, one measures from the date consumer notice goes out, and one requires a preliminary description long before consumers hear anything. Consumer reporting agencies form a third tier with higher counts and different content.

      6 min readState law

      Breach Notification

      The Sixty-Day Rule for Health Information

      A covered entity must notify each affected individual without unreasonable delay and in no case later than sixty calendar days after discovery of a breach of unsecured protected health information. Discovery is defined by knowledge attributed across the workforce, not by the moment senior management is briefed. Breaches touching five hundred or more individuals require contemporaneous notice to the Secretary and notice to prominent media; smaller ones are logged and reported annually.

      7 min readFederal law

      Breach Notification

      Substitute Notice When People Cannot Be Reached

      Where direct notice is not feasible, most state statutes permit a substitute consisting of email where addresses are held, a conspicuous posting on the entity's own website, and notification to major statewide media. The gateway is fixed: cost above two hundred fifty thousand dollars, an affected class above five hundred thousand, or insufficient contact information. The federal health rule uses a different gateway entirely, turning on whether contact details fail for ten or more individuals.

      6 min readState law