Cybersecurity Is a Legal (Not Just Technical) Issue
In years past, cybersecurity was generally considered an administrative or IT issue, and data breaches were often viewed as a problem for those departments. However, as more and more of our lives and personal information have migrated to the digital space, and as more states have adopted protections for that data, cybersecurity has become a compliance issue for legal departments.
Data breaches routinely lead to:
- Mandatory consumer notifications. See e.g. Civ. Code § 1798.82(a) (requiring notice to consumer “in the most expedient time possible and without unreasonable delay” if the consumer’s personal data is included in a data breach); Fla. Stat. Ann. § 501.171(4) (requiring notice to consumer “as expeditiously as practicable and without unreasonable delay” if breach may result in “identity theft or financial harm”).
- Regulatory investigations and fines/penalties. See e.g. Rev. Stat. Ann. § 6-1-1311 (giving Colorado State Attorney General authority to investigate data breaches and issue civil penalties); Tex. Bus. & Com. Code Ann. § 521.151 (authorizing Texas attorney general to investigate claims and recover civil penalties of “at least $2,000 but not more than $50,000 for each violation”).
- Breach of contract or indemnity claims. See e.g. Travelers Indem. Co. of Am. v. Portal Healthcare Sols., LLC, 35 F. Supp. 3d 765, 767 (E.D. Va. 2014), aff’d sub nom. Travelers Indem. Co. of Am. v. Portal Healthcare Sols., L.L.C., 644 F. App’x 245 (4th Cir. 2016) (determining insurer had duty to defend insured in data breach suit); Paul Fire & Marine Ins. Co. v. Rosen Millennium, Inc., 337 F. Supp. 3d 1176, 1181 (M.D. Fla. 2018) (determining insurer did not have duty to defend data breach suit).
- Class actions. See e.g. Miller v. Syracuse Univ., 662 F. Supp. 3d 338 (N.D.N.Y. 2023) (class action by university students for breach of personal information); Olson v. Ferrara Candy Co., 2025 IL App (1st) 241126, __ N.E.3d __ (Ill. Nov. 26, 2025) (employees bringing class action for breach of their personal information); Attias v. CareFirst, Inc., 344 F.R.D. 38 (D.D.C. 2023) (certifying classes for breach of contract and violation of consumer protection acts of Maryland and Virginia).
- Reputational harm. See generally Angelo A. Stio III, Jan Levine, William Gibson, Standing and the Emerging Law of Data Breach Class Actions, N.J. Law., April 2015, at 70 (“Corporations that fail to address cybersecurity run the risk of reputational harm, loss of intellectual property, exposure to regulatory actions, civil litigation and loss of time and resources.”
A Patchwork of Laws
While there are federal laws regulating data security, those laws generally have limited applicability and no private enforcement. See e.g. 17 C.F.R. § 229.106 (providing that publicly traded companies must report cybersecurity threats to the government). To bridge the gap, all 50 states, and the District of Columbia, have enacted data privacy laws. The problem, however, is that the laws are far from uniform. While they share common characteristics, the way each state law handles those characteristics differs.
For example, while all states generally require a notice to the consumer in the most egregious cases, some states do not require notice if there is no likelihood of harm. Compare Va. Code Ann. § 18.2-186.6(B) (requiring disclosure only where the data holder reasonably believes the breach will cause identify theft or fraud); 9 V.S.A. § 2435(d)(1) (providing no disclosure requirement where the “misuse of personally identifiable information or login credentials is not reasonably possible”) with Minn. Stat. Ann. § 325E.61 (requiring disclosure regardless of consideration of harm); Cal. Civ. Code § 1798.82(a) (same).
Likewise, states have different definitions of “personal information,” with varying degrees of broadness. See e.g. Minn. Stat. Ann. § 325E.61(e) (personal information only includes an individual’s name, together with social security number, driver’s license number, account number or credit card number and password); N.J. Stat. Ann.
§ 56:8-161 (same but including user names and email addresses); Or. Rev. Stat. Ann. § 646A.602 (same as New Jersey, but also including information about a consumer’s physical identifying characteristics (like fingerprints), health insurance information, and medical history.)
States also have different requirements regarding whether notice must be given to state agencies and the timing of that notice. See e.g. Me. Rev. Stat. Ann. tit. 10, § 1348 (requiring notice to Attorney General or state regulators, but affixing no hard time frame); Kan. Stat. Ann. § 50-7a02 (requiring notice to consumer and consumer reporting agencies but not to state agencies); 16 La. Admin. Code Pt III, 701 (requiring notice to the Attorney General within 10 days of notice to consumer); N.J. Stat. Ann. § 56:8-163(c)(1) (requiring notice to Department of Law and Public Safety before notice to consumer); Okla. Stat. Ann. tit. 24, § 163(E)(1) (requiring notice to Attorney General within 60 days of notice to consumer, subject to exceptions).
The upshot of this patchwork of laws is that an entity that experiences a data breach should take stock of where the affected individuals may reside and seek legal counsel regarding that forum’s data privacy laws.
List of State Data Privacy and Disclosure Laws
| Alabama | Ala. Code § 8-38-2 | Missouri | § 407.1500(1)(9), RSMo . |
| Alaska | Alaska Stat. § 45.48.090 | Montana | Mont. Code Ann. § 30-14-1704 |
| Arizona | A.R.S. § 18-551 | Nebraska | Neb. Rev. St. § 87-802 |
| Arkansas | Ark. Code Ann. § 4-110-103 | Nevada | NRS 603A.040 |
| California | Cal. Civ. Code § 1798.82 | New Hampshire | N.H. RSA § 359-C:19 |
| Colorado | Colo. Rev. Stat. Ann. § 6-1-716 | New Jersey | N.J.S.A. 56:8-161 |
| Connecticut | Conn. Gen. Stat. Ann. § 36a-701b | New Mexico | NMSA 1978, § 57-12C-2 |
| Delaware | 6 Del. C. § 12B-101 | New York | N.Y. Gen. Bus. Law § 899-aa |
| District of Columbia | D.C. Code § 28-3851 | North Carolina | N.C.G.S. §§ 14-113.20 , 75-61 , and 75-65 |
| Florida | § 501.171, Fla. Stat . | North Dakota | N.D.C.C. § 51-30-01 |
| Georgia | O.C.G.A. § 10-1-911 | Ohio | Ohio R.C. 1349.19 |
| Hawaii | HRS § 487N-1 | Oklahoma | Okla. Stat. tit. 24, § 162 |
| Idaho | Idaho Code § 28-51-104 | Oregon | ORS 646A.602 |
| Illinois | 815 ILCS 530/5 | Pennsylvania | 73 Pennsylvania Statutes § 2302 |
| Indiana | Ind. Code § 24-4.9-2-10 | Rhode Island | R.I. Gen. Laws § 11-49.3-3 |
| Iowa | Iowa Code Ann. § 715C.1 | South Carolina | S.C. Code Ann. § 39-1-90 |
| Kansas | K.S.A. 50-7a01 | South Dakota | SDCL 22-40-19 |
| Kentucky | KRS 365.732 | Tennessee | T.C.A. § 47-18-2107 |
| Louisiana | La. R.S. 51:3073 | Texas | Tex. Bus. & Com. Code Ann. § 521.002 |
| Maine | 10 M.R.S. § 1347 | Utah | Utah Code § 13-44-102 |
| Maryland | Md. Code Ann., Com. Law § 14-3501 | Vermont | 9 V.S.A. § 2430 |
| Massachusetts | M.G.L. c. 93H, § 1 | Virginia | Va. Code Ann. § 18.2-186.6 |
| Michigan | MCL 445.63 | Washington | RCW 19.255.005 |
| Minnesota | Minn. Stat. Ann. § 325E.61 | West Virginia | W. Va. Code § 46A-2A-101 |
| Mississippi | Miss. Code Ann. § 75-24-29 | Wisconsin | Wis. Stat. § 134.98 |
|
Source: Thomas-Reuters – Westlaw |
Wyoming | Wyo. Stat. Ann. §§ 6-3-901 and 40-12-501 | |