What a business must tell you when your personal information is exposed, which laws require it, what the notice must say, and what a person whose data was breached can actually claim.
There is no general federal data breach law. Notification is required by the statutes of every state, which apply according to the residence of the people whose information was exposed, and by federal rules for particular sectors: health information under the HIPAA breach notification rule, financial institutions under the Gramm-Leach-Bliley safeguards rule and the banking regulators, and public companies under securities disclosure rules. A single breach therefore often triggers several overlapping obligations with different definitions, deadlines and recipients.
The state statutes share a shape. They apply to unauthorized acquisition of defined personal information - typically a name combined with a Social Security number, driver's licence number, financial account number with access code, and increasingly medical, biometric and login credentials; they require notice to affected residents within a period after discovery, in a form that describes what happened, what information was involved, what the business is doing and what the person can do; and many require notice to the state attorney general and to the credit bureaus once the number affected passes a threshold. Encrypted data is usually exempt if the key was not also taken. Some states also require the business to offer credit monitoring or identity protection services for a period.
What a person can recover is less settled than what they must be told. Notification statutes mostly give enforcement to the attorney general; a private claim, where it exists, usually runs through negligence, breach of contract, the state consumer protection statute, or a specific privacy statute such as California's, which allows statutory damages for a breach caused by a failure to maintain reasonable security. Courts continue to divide on whether the risk of future misuse, without actual fraud, is an injury a plaintiff can sue on, and the Supreme Court has held that exposure without concrete harm does not by itself confer standing in federal court.
A person who receives a breach notice should act on it - freeze their credit, change the affected credentials, and keep the letter - rather than wait to see whether fraud follows, because the letter is the evidence of when they knew. Whether to sue is a question for a lawyer who handles these cases, and the honest answer is usually that individual claims are small and class actions are slow; a business that has discovered a breach needs counsel immediately, since the notification deadlines run from discovery and the analysis of which states' and which sectors' rules apply is itself the first legal task.
Choose your state. Each link opens the directory page for the city in that state with the most currently published law firms in this practice area; a +n beside the city is how many other cities in the state also have one. The list is generated when this page loads, so a state whose listings have lapsed drops out rather than becoming a dead link.