This content is for informational and educational purposes only and is not legal, financial, or tax advice. No attorney-client relationship is created by reading or using this article. Federal, state, and local rules may differ and may change without notice. A qualified professional can review specific circumstances. The author and publisher assume no liability for actions taken based on this content.
Key Facts
- Federal level: Federal criminal identity theft provisions in 18 U.S.C. § 1028 cover certain transfers, possessions, or uses of another person’s “means of identification” without lawful authority with intent tied to unlawful activity.
- Federal level: 18 U.S.C. § 1028A adds an extra term of imprisonment when the identification-related conduct occurs during and in relation to an enumerated felony violation.
- Federal level: Under 15 U.S.C. § 1681c-2, a consumer reporting agency must block identity-theft-related information within 4 business days after receiving specified proof.
- Federal level: The FTC Act, 15 U.S.C. § 45, makes unfair or deceptive acts or practices in or affecting commerce unlawful and empowers the FTC to prevent them.
- Federal level: HIPAA breach notification rules in 45 CFR Part 164 Subpart D presume a breach unless a “low probability” standard is met based on listed risk assessment factors, and require individual notice within 60 calendar days after discovery.
- Federal level: The GLBA Safeguards Rule in 16 CFR Part 314 imposes certain notice obligations for FTC-jurisdiction financial institutions for certain security notification events involving at least 500 consumers.
- National overview: State breach notification laws exist in all states plus DC, Puerto Rico, and the Virgin Islands, but details like what must be included and how notices work can vary by state.
Last reviewed: May 2026. Legal rules, forms, deadlines, and procedures can change by jurisdiction, agency, and court system.
- Why “personal information theft” shows up in privacy discussions
- The federal criminal track tied to “means of identification”
- Aggravated identity theft as an enhanced federal penalty
- The consumer reporting track blocking identity theft information
- The FTC Act track unfair or deceptive acts or practices
- How FTC privacy and security guidance ties “promises” to obligations
- HIPAA breach notification presumed breach with a “low probability” demonstration
- GLBA Safeguards Rule notification FTC jurisdiction financial institutions
- Where state law fits, and how the tracks differ in real life
- Sources
Why “personal information theft” shows up in privacy discussions
The phrase “personal information theft” often functions as a plain-language label for identity theft and other misuse of information that can identify a specific person, rather than describing one single federal statute. The legal landscape often breaks into separate “tracks,” including federal criminal statutes, federal consumer-protection and consumer-reporting rules, and industry-specific breach notification requirements that depend on the type of data and who holds it. For broader background on privacy concerns in technology, see the archive article technology raises significant privacy concerns.
The federal criminal track tied to “means of identification”
Federal criminal identity theft concepts focus on a “means of identification,” which federal law defines to include “any name or number” that may be used to identify a specific individual. Under 18 U.S.C. § 1028, that definition includes identifiers such as a Social Security number and an official driver’s license or identification number. The statute also reaches certain conduct connected to identification materials and, in the relevant clause, criminalizes knowingly transferring, possessing, or using another person’s “means of identification” without lawful authority when done with intent to commit, to aid or abet, or in connection with unlawful activity (see 18 U.S.C. § 1028&edition=prelim)).
Aggravated identity theft as an enhanced federal penalty
Aggravated identity theft is not a standalone definition of a “kind” of information theft so much as an enhanced federal sentencing layer for certain circumstances. Under 18 U.S.C. § 1028A, the law adds an additional term of imprisonment when a person, during and in relation to an enumerated felony violation, knowingly transfers, possesses, or uses another person’s means of identification without lawful authority. A common confusion is treating the aggravated provision as a standalone definition; instead, it builds on the underlying identification-related criminal conduct and attaches the extra penalty when the statutory felony-condition applies.
The consumer reporting track blocking identity theft information
Federal law also addresses identity theft in the credit and consumer-reporting system through an information-blocking requirement. Under 15 U.S.C. § 1681c-2, a consumer reporting agency must block reporting of information in a consumer’s file that the consumer identifies as information resulting from alleged identity theft. The rule sets a specific timing requirement: blocking must happen “not later than 4 business days” after the agency receives specified proof, which includes a copy of an identity theft report. This is a distinct legal mechanism from criminal prosecution and it targets what appears in consumer reports.
The FTC Act track unfair or deceptive acts or practices
Federal consumer-protection authority provides a different enforcement model from the criminal identity theft statutes. The FTC Act declares that “unfair or deceptive acts or practices” in or affecting commerce are unlawful and empowers the FTC to prevent those practices (see 15 U.S.C. § 45&edition=prelim)). In the data-and-privacy context, this statutory framework can become relevant when business conduct about data practices is alleged to be unfair or deceptive under the FTC Act.
How FTC privacy and security guidance ties “promises” to obligations
FTC guidance on privacy and security explains how the FTC expects businesses to treat privacy and security commitments in the FTC Act framework. On FTC privacy and security guidance, the FTC states that if a company makes privacy promises, the FTC Act requires the company to live up to those claims. The FTC also describes a security obligation even when the company does not make specific claims, stating that there is an obligation to maintain security appropriate in light of the nature of the data the business possesses.
HIPAA breach notification presumed breach with a “low probability” demonstration
For certain health-related data, federal breach notification obligations come from HIPAA’s breach notification rule. Under 45 CFR Part 164 Subpart D, a breach is generally presumed unless the covered entity or business associate demonstrates that there is a “low probability” that protected health information has been compromised, using a risk assessment based on listed factors. The regulation also sets a timing rule for individuals: notification to affected individuals must be provided “without unreasonable delay and in no case later than 60 calendar days after discovery of a breach.”
GLBA Safeguards Rule notification FTC jurisdiction financial institutions
For certain financial institutions and consumer/customer information, the GLBA Safeguards Rule sets a separate regulatory framework for security and, in specified circumstances, notification to the FTC. Under 16 CFR Part 314, the rule implements standards for developing, implementing, and maintaining reasonable safeguards to protect customer information, and it includes notification obligations for certain “notification events.” The notification timing provided in the rule is specific: for a notification event involving at least 500 consumers, the financial institution must notify the FTC “as soon as possible, and no later than 30 days after discovery of the event,” subject to the rule’s scope and exceptions.
Where state law fits, and how the tracks differ in real life
State law can add additional breach notification requirements, and state rules typically work alongside federal frameworks rather than replacing them. The FTC explains that all states plus the District of Columbia, Puerto Rico, and the Virgin Islands have enacted breach notification legislation requiring notification of security breaches involving personal information, and it notes that state breach notification laws typically specify what information must or must not be provided in breach notices (see FTC breach response guide). As a result, the same underlying personal information theft incident can trigger different duties depending on the data type and the holder’s legal obligations, and the content and timing of required notices can vary by state.
| Legal track | Controlling authority | What it addresses | Timing or mechanism emphasized in the rule |
|---|---|---|---|
| Criminal identity theft | 18 U.S.C. § 1028; enhanced by 18 U.S.C. § 1028A | Identification-related conduct without lawful authority | Aggravated identity theft adds an additional term of imprisonment when the statutory felony condition applies |
| Consumer reporting | 15 U.S.C. § 1681c-2 | Identity-theft-related information appearing in consumer reports | Consumer reporting agency must block within 4 business days after receiving specified proof |
| Health data breach notice (HIPAA) | 45 CFR Part 164 Subpart D | Breach notification for unsecured protected health information | Notification to individuals within 60 calendar days after discovery; presumed breach unless “low probability” standard is met |
| Financial data breach notice / security notification | 16 CFR Part 314 | Safeguards and notification events for FTC-jurisdiction financial institutions | For certain events involving at least 500 consumers, FTC notice no later than 30 days after discovery |
| State breach notices | State breach-notification statutes (varies) | Additional notification duties for certain security incidents | State details (including what must be included) differ by state |
A practical way to read the rules is to treat “personal information theft” as a topic umbrella and then ask which system the facts touch: a criminal-identity-theft prosecution, a consumer-reporting-block requirement, or a breach-notification/security obligation tied to a particular regulated industry or data type.