Mintz Matrix Updated – Data Breach Laws in All 50 States
With the recent enactment of data breach notification laws in South Dakota and Alabama, all 50 US states now have laws regulating data breach notification. We’ve updated the Mintz Matrix (maintained by the Mintz Privacy Team for nearly 10 years) to provide you with the latest information.
Managing the differing requirements remains a challenge, and points to the need for updated incident response plans. As an example, the chart below outlines the different timelines for notification. The Mintz Matrix contains information on all of these, and more.
Breach Notification Timeline
Time After Discovery of Breach | Action Required |
10 Calendar Days |
|
14 Business Days |
|
15 Business Days |
|
30 Calendar Days |
|
45 Calendar Days |
|
60 Calendar Days |
|
90 Calendar Days |
|
Most expedient time and without unreasonable delay |
|
As soon as possible |
|
Days After Confirmation of Breach | Action Required |
45 Calendar Days |
|
Author
Cynthia J. Larose
Member / Co-Chair, Privacy & Cybersecurity Practice
Cynthia J. Larose is Chair of the firm's Privacy & Cybersecurity Practice, a Certified Information Privacy Professional-US (CIPP-US), and a Certified Information Privacy Professional-Europe (CIPP-E). She works with clients in various industries to develop comprehensive information security programs on the front end, and provides timely counsel when it becomes necessary to respond to a data breach.