Washington Data Breach Notification Law: What a Small Business Must Do

Under RCW 19.255.010, a business that owns or licenses Washington residents' personal information must notify affected residents within 30 calendar days of discovering a breach, and notify the Attorney General within 30 days if more than 500 Washington residents are affected. Notice is not required when the data was encrypted and the key was not taken, or when the breach is not reasonably likely to cause harm.

By Trella Commercial · Updated October 3, 2026

The short version

  • Who it applies to: any person or business that owns or licenses personal information of Washington residents, wherever the business is located. A vendor that holds your data must tell you about a breach immediately.
  • Deadline: notify affected residents in the most expedient time possible and no more than 30 calendar days after discovering the breach.
  • Attorney General: also notify the Washington Attorney General within 30 days when more than 500 Washington residents are notified.
  • Exceptions: no notice is needed if the data was encrypted to NIST standards and the key was not compromised, or if the breach is not reasonably likely to subject consumers to a risk of harm.
  • In practice, the deadline is hard to meet. Of 1,377 notices filed with the Attorney General for breaches discovered since March 2020, only 17% arrived within 30 days. The median was 78 days.

What counts as a breach?

RCW 19.255.005 defines a breach as the "unauthorized acquisition of data that compromises the security, confidentiality, or integrity of personal information maintained by the person or business." The current definition is not limited to computerized data, so stolen paper files can qualify.

There is one built-in exception. An employee or agent who accesses personal information in good faith for the business's purposes has not caused a breach, as long as the information is not misused or further disclosed.

What counts as personal information?

A first name or first initial and last name, combined with any of the following:

Data elementShare of Washington breach notices that included it
Social Security number63%
Full date of birth65%
Driver's license or Washington ID card number33%
Financial account or card number with its security code, access code, or password46% reported financial or banking information
Medical history, condition, treatment, or diagnosis37%
Health insurance policy or ID number28%
Passport, student, or military ID numberListed separately in the data
Biometric data, or a private key used to sign electronic recordsListed separately in the data

Percentages are from Trella Commercial's analysis of 1,675 notices filed with the Attorney General.

Two more categories count without a name attached:

  • A username or email address together with a password or security question answers that would allow access to an online account.
  • Any of the data elements above, without a name, if they are not encrypted or redacted and would be enough to commit identity theft.

Who has to notify, and who do they notify?

Your roleWhat you must do
You own or license the data (it is your customer, patient, or employee data)Notify each affected Washington resident within 30 days of discovery
More than 500 Washington residents are notified for one breachAlso notify the Attorney General within 30 days
You hold data for another business (a vendor, processor, or IT provider)Notify the data owner immediately after discovering the breach
A vendor holding your data is breachedThe notice duty to your customers generally stays with you as the owner

That last row catches many small businesses. If your payroll company, billing service, or practice management software is breached, the people affected are your customers or employees, and the law looks to you to make sure they are told.

What the notice to residents must say

RCW 19.255.010(6) requires the notice to be written in plain language and to include at least:

  1. The name and contact information of the business reporting the breach
  2. A list of the types of personal information involved
  3. The time frame of exposure, if known, including the date of the breach and the date it was discovered
  4. If the breach exposed personal information, the toll-free numbers and addresses of the major credit reporting agencies

How notice can be delivered

  • Written notice by mail
  • Electronic notice, if it follows the federal E-SIGN Act rules
  • Substitute notice, allowed only if notice would cost more than $250,000, more than 500,000 people would need to be notified, or you do not have enough contact information. Substitute notice requires all three of: email to anyone you have an email address for, a conspicuous posting on your website, and notice to major statewide media.

If the breach involved only usernames or passwords, you may notify people electronically and tell them to change their password and security questions. If the compromised credentials are for an email account you provide, you cannot send the notice to that account; use another method.

What the Attorney General notice must include

When more than 500 Washington residents are notified, the notice to the Attorney General must include:

  • The number of Washington residents affected, or an estimate
  • The types of personal information involved
  • The time frame of exposure, including the date of the breach and the date of discovery
  • A summary of the steps taken to contain the breach
  • A sample copy of the notice sent to residents, without any personal information

If any of this is unknown when notice is due, the notice must be updated later. The Attorney General publishes these notices, which is the dataset behind our Washington breach analysis.

Exceptions and special cases

SituationRule
Data was encryptedNo notice needed if it was encrypted to NIST standards, unless the key or other means to decrypt it was also acquired
No real riskNo notice needed if the breach is not reasonably likely to subject consumers to a risk of harm
Law enforcement asks you to waitNotice can be delayed if a law enforcement agency determines it would impede a criminal investigation, then given once it will not
You follow your own written proceduresA business with its own notification procedures, as part of an information security policy, complies if those procedures meet the law's timing requirements
HIPAA covered entitiesDeemed compliant for protected health information if they follow the federal HITECH notice rules, but must still notify the Attorney General

Deciding that a breach is "not reasonably likely" to cause harm is a judgment call with real consequences. Make it with a breach attorney and document why.

What happens if you get it wrong?

Under RCW 19.255.040, the Attorney General can enforce the law in court, and a violation is treated as an unfair or deceptive act under the Consumer Protection Act for that purpose. Consumers injured by a violation can also sue for damages directly under the breach law.

For card data, RCW 19.255.020 adds a narrow rule: a processor or a business that handles more than six million card transactions a year can be liable to banks for reasonable card reissuance costs if its lack of reasonable care caused the breach. Encryption or a current PCI DSS compliance validation is a defense.

A 30-day timeline that works

The 30 days start at discovery, not at the end of the investigation. A practical sequence:

  1. Day 0: Call your cyber insurer's breach hotline or your broker. Preserve evidence and contain the incident.
  2. First week: The insurer's breach attorney engages forensic investigators to determine what data was accessed and whose.
  3. Weeks two and three: Identify affected people and their states, draft the notice, and arrange mailing, call center, and credit monitoring if offered.
  4. By day 30: Mail resident notices and, if more than 500 Washington residents are affected, file with the Attorney General.

If your customers live in more than one state, each state's law applies to its residents. Idaho, for example, has no fixed deadline and no Attorney General filing for private businesses. See the comparison table in our complete cyber insurance guide.

How cyber insurance pays for compliance

The law applies whether or not you are insured. A cyber policy's breach response coverage typically pays for the breach attorney, forensic investigation, notification letters, a call center, and credit monitoring, and its regulatory and privacy liability coverage responds to Attorney General inquiries and lawsuits. Check that breach response costs are not subject to a low sublimit, and whether the policy requires you to use its panel of vendors. More on what policies include: cyber liability insurance.

Common questions

How long does a business have to report a data breach in Washington?

No more than 30 calendar days after the breach is discovered, and sooner if possible. RCW 19.255.010 requires notice "in the most expedient time possible, without unreasonable delay," with limited exceptions such as a law enforcement request or the time needed to determine the scope of the breach and restore the integrity of the system.

When do I have to notify the Washington Attorney General?

When a single breach requires notice to more than 500 Washington residents. The Attorney General notice is due within the same 30 days and must include the number affected, the types of information, the time frame, the containment steps, and a sample of the consumer notice.

Does Washington's breach law apply to businesses outside Washington?

Yes. It applies to any person or business that owns or licenses personal information of Washington residents. In the Attorney General's data, 71% of the organizations that filed notices and listed a state were based outside Washington.

Do I have to notify people if the stolen laptop was encrypted?

Not if the data was encrypted to the standard the law requires and the encryption key or password was not also compromised. If the key was taken with the device, notice is required.

Does the law cover paper records?

The current definition of a breach refers to unauthorized acquisition of "data" that compromises personal information, without limiting it to computerized data. Treat stolen or exposed paper files containing personal information as a potential breach and get advice before deciding notice is not required.

Sources

This page is general information, not legal advice. After a breach, work with a breach attorney, usually provided through your cyber policy. Statutes checked October 2026.

More in this guide

Find out what your current policies actually cover.

Send us what you have. We review it line by line against your leases and contracts, and tell you plainly what is missing. Free, and no obligation.