This material is general public information for educational purposes only. It should not be used as legal, financial, or tax advice, and no attorney-client relationship is created by reading it. Federal, state, and local rules may vary and may change over time. A qualified professional can review specific circumstances.
Key Facts
- Federal level: The FTC Act declares unfair methods of competition and unfair or deceptive acts or practices unlawful and empowers the FTC to prevent them under 15 U.S.C. § 45.
- Federal level: GLBA requires each financial institution to respect customer privacy and protect the security and confidentiality of customers’ nonpublic personal information under 15 U.S.C. § 6801.
- Federal level: The GLBA Safeguards Rule requires an information security program based on a risk assessment and includes encryption in transit and at rest where applicable under 16 CFR Part 314.
- Federal level: The GLBA Safeguards Rule requires FTC notification no later than 30 days after discovery for notification events involving at least 500 consumers under 16 CFR Part 314.
- Federal level: HIPAA breach notification defines “breach” and presumes a breach unless the covered entity demonstrates low probability using a risk assessment under 45 CFR Part 164 Subpart D.
- Federal level: HIPAA requires individual notice after a breach of unsecured protected health information without unreasonable delay and no later than 60 calendar days after discovery under 45 CFR Part 164 Subpart D.
- Federal level: HIPAA requires media notification for breaches involving more than 500 residents of a State or jurisdiction under 45 CFR Part 164 Subpart D.
- State level: California requires disclosure of a security breach to California residents within 30 calendar days of discovery or notification, with allowed law-enforcement delays under California Civil Code § 1798.82.
- State level: New York’s SHIELD Act requires reasonable safeguards for private information, including disposal, and states that it does not create a private right of action under New York General Business Law § 899-bb.
- National overview: Federal damages claims generally require Article III standing based on concrete harm, and speculative future harms must be certainly impending under TransUnion LLC v. Ramirez and Clapper v. Amnesty International USA.
Last reviewed: May 2026. Legal rules, forms, deadlines, and procedures can change by jurisdiction, agency, and court system.
- The federal enforcement baseline often starts with the FTC Act
- How the FTC describes practical security planning for business
- Financial sector example GLBA and the Safeguards Rule
- GLBA sets a continuing privacy and security obligation for covered financial institutions
- The Safeguards Rule translates that policy into program, risk, and encryption requirements
- A federal breach notification deadline example GLBA’s 500 consumer threshold and 30 day timing
- A compact comparison of breach notification timing examples
- Health sector example HIPAA breach notification focuses on a “breach” definition and a low probability exception
- State examples California’s breach notice statute and New York’s reasonable safeguards requirement
- California 30 day resident disclosure plus allowed law enforcement delays
- New York reasonable safeguards and no private right of action
- Court system angle standing limits can affect data breach and privacy damages cases
- Putting the pieces together how professionals often frame compliance
- Sources
Data privacy and security obligations often feel like they “move” because they come from multiple sources at once. In the U.S., controlling rules can differ based on who holds the data, what kind of information it involves, and where affected individuals live.
A helpful way to understand the patchwork is to separate three questions: (1) which federal statute or regulation governs the data-holder relationship, (2) whether a state breach-security law also applies, and (3) how federal courts handle damages claims when standing is disputed.
The federal enforcement baseline often starts with the FTC Act
Federal law gives the FTC a broad enforcement pathway for unfair methods of competition and unfair or deceptive acts or practices. The statutory text declares these conduct types unlawful and empowers the FTC to prevent them under 15 U.S.C. § 45.
How the FTC describes practical security planning for business
The FTC’s business guidance frames a data security plan around five principles—TAKE STOCK, SCALE DOWN, LOCK IT, PITCH IT, and PLAN AHEAD—and it describes that statutes like GLBA and the FTC Act may require reasonable security for sensitive information in applicable contexts. That guidance appears in Protecting Personal Information: A Guide for Business.
Financial sector example GLBA and the Safeguards Rule
GLBA sets a continuing privacy and security obligation for covered financial institutions
GLBA includes an express policy that each financial institution has an affirmative and continuing obligation to protect the security and confidentiality of customers’ nonpublic personal information. That obligation appears in 15 U.S.C. § 6801.
The Safeguards Rule translates that policy into program, risk, and encryption requirements
For FTC-jurisdiction financial institutions, the GLBA Safeguards Rule requires a comprehensive information security program tailored to the institution and based on a risk assessment. The rule also requires protecting customer information by encryption in transit and at rest as described in 16 CFR Part 314.
A federal breach notification deadline example GLBA’s 500 consumer threshold and 30 day timing
Federal rules can also include explicit notice timing. Under the GLBA Safeguards Rule, when a notification event involves the information of at least 500 consumers, an institution must notify the FTC “no later than 30 days after discovery” as stated in 16 CFR Part 314. The rule also includes effective-date language stating that § 314.4(j) is effective as of May 13, 2024 under the same eCFR Part 314 text.
A compact comparison of breach notification timing examples
| Framework (example scope) | Notice trigger concept supported by the rule | Timing language supported by the rule |
|---|---|---|
| GLBA Safeguards Rule (FTC-jurisdiction financial institutions) | Notification event involving information of at least 500 consumers | Notify the FTC no later than 30 days after discovery |
| HIPAA Breach Notification Rule (covered entities and business associates) | Breach of unsecured protected health information | Individual notice in no case later than 60 calendar days after discovery |
| California Civil Code § 1798.82 (California residents) | Unauthorized breach of the security of the system involving computerized personal information | Disclosure to California residents within 30 calendar days of discovery or notification |
Health sector example HIPAA breach notification focuses on a “breach” definition and a low probability exception
HIPAA’s breach-notification rule uses both a definition of “breach” and a risk-assessment concept that affects how breach presumption works. The regulation defines a breach as acquisition, access, use, or disclosure of protected health information in a manner not permitted that compromises security or privacy, and it presumes a breach unless the covered entity or business associate demonstrates low probability based on a risk assessment of specified factors under 45 CFR Part 164 Subpart D.
HIPAA’s notification duties also include specific timing and communication modes, including individual notice “without unreasonable delay and in no case later than 60 calendar days after discovery.” The same eCFR Part 164 Subpart D text also includes a media-notification requirement for breaches involving more than 500 residents of a state or jurisdiction under the HIPAA rule.
The U.S. Department of Health and Human Services provides an official summary page that tracks the regulation’s breach definition and risk-assessment concept for HIPAA breach notification, as described on HHS’s Breach Notification Rule page.
State examples California’s breach notice statute and New York’s reasonable safeguards requirement
California 30 day resident disclosure plus allowed law enforcement delays
California’s data breach notice statute applies to an entity that owns or licenses computerized data including personal information, and it includes a timing rule that requires disclosure to California residents within 30 calendar days of discovery or notification under California Civil Code § 1798.82. The statute also allows delaying notification to accommodate legitimate law-enforcement needs, including when a law enforcement agency determines that notification will impede a criminal investigation, while requiring prompt notice after the agency determines it will not compromise the investigation.
California’s statute also defines “breach of the security of the system” in terms of unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information, and it includes an exclusion for certain good-faith employee or agent acquisition if no further unauthorized disclosure occurs under the same Civil Code section. State breach laws can also change on effective dates, and the California legislative text for § 1798.82 includes an amendment note indicating an effective date of January 1, 2026.
New York reasonable safeguards and no private right of action
New York’s SHIELD Act requires covered persons or businesses that own or license computerized data including private information of New York residents to develop, implement, and maintain reasonable safeguards to protect security, confidentiality, and integrity, including disposal of data under New York General Business Law § 899-bb. The same statute states that it does not create a private right of action under § 899-bb(2)(e).
Court system angle standing limits can affect data breach and privacy damages cases
Even when a statute or regulation creates an obligation, federal damages claims in court generally require plaintiffs to satisfy Article III standing. In TransUnion LLC v. Ramirez, the Supreme Court held that only plaintiffs concretely harmed by a defendant’s statutory violation have Article III standing to seek damages against a private defendant in federal court.
Standing doctrine also limits speculative “future” injury theories. In Clapper v. Amnesty International USA, the Supreme Court described threatened injury as needing to be “certainly impending” and rejected the idea that plaintiffs can manufacture standing by incurring costs based on hypothetical future harm.
Putting the pieces together how professionals often frame compliance
Because the rules come from multiple federal and state sources, many organizations treat “data privacy and security” as a mapping problem rather than a single checklist. This article’s examples illustrate how controlling duties can depend on the data-holder category and statutory trigger—such as GLBA Safeguards Rule encryption and notice timing for certain 500-consumer events, HIPAA’s breach definition and low-probability risk assessment concept, and California’s 30-day disclosure timing for resident breach notices.
Lawyers often connect these themes to other privacy, confidentiality, and technology concerns. For related discussion in this site’s archive, see technology raises significant privacy concerns and for a consumer-facing framing of personal information harms, see invasion of the personal information snatchers. For confidentiality concepts that often matter when attorneys handle sensitive information, this site also covers questions about the attorney-client privilege.
The key legal takeaway is that the most binding requirements come from the statute or regulation that actually applies, while federal court procedure can still narrow what plaintiffs can recover through damages by requiring concrete harm under Article III.