23andMe Proved That Getting Breached Is Bad — But Notifying Wrong Is Worse
In late 2023, 23andMe disclosed a breach affecting nearly 7 million users. The breach itself was devastating. But the company's notification missteps — delayed disclosures, shifting blame to users, and inconsistent communications across jurisdictions — turned a security incident into an existential crisis. By 2024, the company filed for bankruptcy. Understanding data breach notification requirements isn't optional legal trivia. It's a survival skill for any organization that handles personal data.
If you're a business owner, IT manager, or security professional, this post breaks down exactly what you're required to do when a data breach hits — across federal regulations, all 50 states, and key international frameworks. I've helped organizations navigate these waters, and I can tell you: the notification process trips up far more companies than the breach itself.
What Are Data Breach Notification Requirements?
Data breach notification requirements are legal obligations that mandate organizations to inform affected individuals, regulators, and sometimes credit bureaus when personally identifiable information (PII) is exposed through unauthorized access. Every U.S. state, plus the District of Columbia, Guam, Puerto Rico, and the U.S. Virgin Islands, has its own breach notification law. There is no single federal breach notification statute that covers all industries.
That fragmentation is the problem. You don't comply with one law — you comply with the laws of every jurisdiction where your affected users reside. Miss one, and you're looking at fines, lawsuits, and regulatory action.
The Patchwork: State Laws You Need to Know
All 50 states have enacted breach notification laws, starting with California's SB 1386 in 2003. But the details vary wildly. Here's where the biggest differences show up:
Notification Timelines
Some states set explicit deadlines. Florida requires notification within 30 days. Colorado gives you 30 days as well. Others, like New York and Texas, use vague language like "as expeditiously as possible" or "without unreasonable delay." In my experience, regulators in those states still expect you to act within 30-60 days — they just give themselves more room to second-guess you.
What Triggers Notification
Most states define a breach as unauthorized acquisition of unencrypted personal data. But the definition of "personal data" varies. Some states stick to name plus Social Security number, driver's license, or financial account info. Others — like Illinois and California — include biometric data, health information, and even email addresses combined with passwords. If you've suffered credential theft affecting login credentials, you may trigger notification requirements in states you wouldn't expect.
Who Gets Notified
Every state requires you to notify affected individuals. Most require notification to the state attorney general if the breach exceeds a threshold — often 500 or 1,000 residents. Some states like New York also require notification to the Department of State and Division of State Police. California requires notification to the Office of the Attorney General for breaches affecting over 500 residents.
The National Conference of State Legislatures maintains a comprehensive database of all state breach notification statutes. Bookmark it. You'll need it.
Federal Notification Rules by Sector
While there's no universal federal breach notification law, several sector-specific regulations impose strict requirements:
HIPAA (Healthcare)
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured protected health information (PHI). Breaches affecting 500 or more people must also be reported to HHS and the media. Smaller breaches get logged and reported annually.
GLBA / Safeguards Rule (Financial Services)
The FTC's updated Safeguards Rule, effective since mid-2023, requires non-banking financial institutions to notify the FTC within 30 days of discovering a breach affecting 500 or more consumers. This applies to mortgage brokers, auto dealers, tax preparers, and many others who don't think of themselves as "financial institutions."
FISMA and Federal Agencies
Federal agencies must follow CISA's incident reporting guidelines under FISMA. CISA's cyber incident reporting framework continues to evolve, especially as CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) rules take effect for critical infrastructure entities.
The $4.88M Lesson Most Organizations Learn Too Late
IBM's 2024 Cost of a Data Breach Report pegged the global average cost of a data breach at $4.88 million. But here's the part that doesn't get enough attention: organizations that contained and notified within 200 days spent significantly less than those that dragged past that mark. Speed matters — not just legally, but financially.
I've seen organizations delay notification because they "weren't sure" if data was actually exfiltrated. That hesitation almost always backfires. Regulators and courts don't expect certainty — they expect good-faith, timely action. A threat actor accessing a database of customer records is typically enough to trigger notification, even without confirmed exfiltration.
Your 72-Hour International Obligations
If you handle data belonging to EU residents, GDPR's Article 33 requires notification to the relevant supervisory authority within 72 hours of becoming aware of a breach. Article 34 requires notifying individuals "without undue delay" if the breach poses a high risk to their rights and freedoms.
Canada's PIPEDA requires notification to the Privacy Commissioner and affected individuals for breaches creating a "real risk of significant harm." These international requirements stack on top of your U.S. obligations. If your customer base is global, your notification plan must be too.
Building a Notification-Ready Incident Response Plan
Knowing the law is one thing. Being ready to execute is another. Here's what a notification-ready organization looks like in practice:
1. Pre-Identify Your Jurisdictions
Map where your customers, employees, and users live. This determines which state and international laws apply. Do this before a breach, not during one.
2. Maintain a Current Data Inventory
You can't assess what was exposed if you don't know what you store. A data inventory — covering what data you hold, where it lives, and who has access — is the foundation of every breach assessment.
3. Establish Relationships with Outside Counsel
Breach notification has legal consequences. Have a privacy attorney on retainer or at least identified before an incident. They'll help you navigate multi-state obligations and draft compliant notices.
4. Draft Template Notifications in Advance
Most state statutes specify what a notification must include: description of the incident, types of data exposed, steps the organization is taking, and resources for affected individuals (like credit monitoring). Build templates now. Customize them during the incident.
5. Train Your People
Your employees are your first line of detection. They need to recognize social engineering, phishing attempts, and suspicious access patterns. An untrained workforce delays detection, which delays notification, which increases cost and liability. Investing in cybersecurity awareness training for your team directly shortens your breach detection window.
Phishing remains the number one initial attack vector according to the Verizon Data Breach Investigations Report. That means your notification timeline often starts with whether an employee clicked a malicious link three months ago. Running regular phishing awareness training and simulations helps your organization catch breaches earlier — and comply with notification timelines.
What Happens When You Get It Wrong
The consequences of failing to meet data breach notification requirements are real and escalating:
- State AG enforcement actions: Attorneys general in California, New York, and Texas have been especially aggressive in pursuing companies that delay or botch notifications.
- FTC actions: The FTC has brought cases against companies like CafePress and Drizly for inadequate breach response and notification practices, resulting in consent orders that impose security requirements for decades.
- Class action lawsuits: Plaintiffs' attorneys monitor AG breach databases. A late or incomplete notification is exhibit A in litigation.
- Regulatory fines: GDPR fines for notification failures have reached into the hundreds of millions of euros. State-level fines in the U.S. range from $100 to $750,000 per violation depending on the jurisdiction.
The Zero Trust Connection to Breach Notification
Here's something I don't see discussed enough: adopting a zero trust architecture directly impacts your breach notification posture. When you implement multi-factor authentication, microsegmentation, and least-privilege access, you reduce the blast radius of any single compromise. A smaller blast radius means fewer affected records, fewer jurisdictions triggered, and a simpler notification process.
Zero trust doesn't prevent breaches entirely. Nothing does. But it can turn a reportable incident involving 500,000 records into one involving 500. That difference changes everything — from the cost of credit monitoring to the number of AG offices you have to contact.
Stop Treating Notification as an Afterthought
Every ransomware attack, every phishing simulation failure, every unpatched system is a potential notification event waiting to happen. The organizations that survive breaches with their reputation and finances intact are the ones that planned for notification before they needed it.
Map your obligations. Train your people. Build your playbook. And recognize that data breach notification requirements aren't just legal checkboxes — they're the mechanism that determines whether a security incident stays manageable or becomes a company-ending crisis.
Your breach response plan is only as strong as the humans executing it. Make sure they're prepared.