State breach laws
US State Breach Notification Estimator
Map notification deadlines and AG duties across affected states, plus rough notification and credit-monitoring cost.
How this is calculated
- For each state you pick, the tool looks up two things from a table compiled from the state statutes: the deadline for notifying residents and any duty to notify the attorney general or another state body. Twelve states are covered; "Other" gives a generic line.
- Strictest deadline: 30 days if California, New York, Florida, Colorado or Washington is selected; 60 days if Texas is the tightest; otherwise "without unreasonable delay".
- Notification cost = affected residents x US$2 (printing, postage, call centre).
- Credit monitoring = residents x US$10-15, added only when Social Security numbers or financial account data are involved.
- Total = notification + monitoring. Colour: red when monitoring applies, amber otherwise.
Constants the tool uses
Unless a value names a study, it is VITI Security's working estimate for budgeting - not taken from a statute or a dated study - so treat it as an adjustable assumption.
- Notification handling per person
- US$2
- Credit or identity monitoring per person (12-24 months)
- US$10-15
- Data types that trigger monitoring
- SSN or financial account data
Worked example
The calculator run on its default inputs:
- States with affected residents
- California; New York; Texas
- Total affected residents
- 10,000 people
- Data types involved
- Social Security numbers
Notification plan across 3 states
$120K-$170K
- Strictest applicable deadline
- 30 days - plan around the strictest state clock, which starts at discovery
- California - 30 calendar days (SB 446, eff. Jan 1, 2026)
- Sample notice to the AG within 15 calendar days of notifying consumers if >500 CA residents
- New York (SHIELD Act) - Within 30 days after discovery (Dec 2024 amendment)
- Notify AG, Dept. of State and State Police for any breach affecting NY residents; DFS too if you are a 23 NYCRR 500 covered entity
- Texas - Within 60 days of determination
- AG within 30 days if ≥250 TX residents affected
- Notification cost (print/mail/handling, ~$2/record)
- $20,000
- Credit monitoring (12-24 mo, ~$10-$15/record)
- $100,000-$150,000
- Estimated total
- $120,000-$170,000
With the defaults (California, New York and Texas; 10,000 residents; Social Security numbers) the strictest clock is 30 days. Notification is 10,000 x US$2 = US$20,000 and monitoring 10,000 x US$10-15 = US$100,000-150,000, so the total is US$120,000-170,000.
Sources
- Cal. Civ. Code 1798.82 - 30 calendar days; sample notice to the AG within 15 days if more than 500 residents
- N.Y. Gen. Bus. Law 899-AA (NY Senate) - 30 days after discovery; AG, Department of State, State Police (and DFS for covered entities)
- Tex. Bus. & Com. Code 521.053 - 60 days to individuals; AG within 30 days if 250 or more Texans
- Fla. Stat. 501.171 - 30 days (15 more for good cause); AG notice at 500 or more
- 815 ILCS 530/10 (Illinois General Assembly) - AG notice when more than 500 Illinois residents are notified
- Pennsylvania Attorney General - reporting a data breach - AG notice alongside individual notice and 12 months of credit monitoring under Act 33 of 2024
- Mass. Gen. Laws ch. 93H s.3 - notice to the AG and the Office of Consumer Affairs and Business Regulation
- RCW 19.255.010 (Washington) - 30 days; AG notice if more than 500 residents
- Colorado Attorney General - data protection laws (C.R.S. 6-1-716) - 30 days after determining a breach; AG notice at 500 or more
- Va. Code 18.2-186.6 - AG notice; AG and consumer reporting agencies above 1,000 people
- O.C.G.A. 10-1-912 (Justia copy; the official code is published through LexisNexis) - consumer reporting agencies above 10,000 residents; no AG notice
- N.J.S.A. 56:8-163 (Justia copy) - report to the Division of State Police before notifying customers
- Conn. Gen. Stat. 36a-701b - at least 24 months of identity-theft services when SSNs are involved
- HIPAA Breach Notification Rule, 45 CFR 164 Subpart D (eCFR) - 60 days; media notice above 500 residents of a state; HHS notice
Sources last checked September 2026.
Limitations
The table covers twelve states; all 50 states have breach laws, and the definition of personal information, the harm threshold and encryption safe harbours differ between them. The cost lines are planning figures, not vendor quotes, and exclude forensics, legal fees and call-centre staffing beyond basic handling. This is an indicative estimate for education and planning, not legal advice. Laws and published figures change, and regulators and courts apply discretion no calculator can model - confirm with a qualified legal or compliance professional before acting on a result.
