The short version
- Who it applies to: any person or business that owns or licenses personal information of Washington residents, wherever the business is located. A vendor that holds your data must tell you about a breach immediately.
- Deadline: notify affected residents in the most expedient time possible and no more than 30 calendar days after discovering the breach.
- Attorney General: also notify the Washington Attorney General within 30 days when more than 500 Washington residents are notified.
- Exceptions: no notice is needed if the data was encrypted to NIST standards and the key was not compromised, or if the breach is not reasonably likely to subject consumers to a risk of harm.
- In practice, the deadline is hard to meet. Of 1,377 notices filed with the Attorney General for breaches discovered since March 2020, only 17% arrived within 30 days. The median was 78 days.
What counts as a breach?
RCW 19.255.005 defines a breach as the "unauthorized acquisition of data that compromises the security, confidentiality, or integrity of personal information maintained by the person or business." The current definition is not limited to computerized data, so stolen paper files can qualify.
There is one built-in exception. An employee or agent who accesses personal information in good faith for the business's purposes has not caused a breach, as long as the information is not misused or further disclosed.
What counts as personal information?
A first name or first initial and last name, combined with any of the following:
| Data element | Share of Washington breach notices that included it |
|---|---|
| Social Security number | 63% |
| Full date of birth | 65% |
| Driver's license or Washington ID card number | 33% |
| Financial account or card number with its security code, access code, or password | 46% reported financial or banking information |
| Medical history, condition, treatment, or diagnosis | 37% |
| Health insurance policy or ID number | 28% |
| Passport, student, or military ID number | Listed separately in the data |
| Biometric data, or a private key used to sign electronic records | Listed separately in the data |
Percentages are from Trella Commercial's analysis of 1,675 notices filed with the Attorney General.
Two more categories count without a name attached:
- A username or email address together with a password or security question answers that would allow access to an online account.
- Any of the data elements above, without a name, if they are not encrypted or redacted and would be enough to commit identity theft.
Who has to notify, and who do they notify?
| Your role | What you must do |
|---|---|
| You own or license the data (it is your customer, patient, or employee data) | Notify each affected Washington resident within 30 days of discovery |
| More than 500 Washington residents are notified for one breach | Also notify the Attorney General within 30 days |
| You hold data for another business (a vendor, processor, or IT provider) | Notify the data owner immediately after discovering the breach |
| A vendor holding your data is breached | The notice duty to your customers generally stays with you as the owner |
That last row catches many small businesses. If your payroll company, billing service, or practice management software is breached, the people affected are your customers or employees, and the law looks to you to make sure they are told.
What the notice to residents must say
RCW 19.255.010(6) requires the notice to be written in plain language and to include at least:
- The name and contact information of the business reporting the breach
- A list of the types of personal information involved
- The time frame of exposure, if known, including the date of the breach and the date it was discovered
- If the breach exposed personal information, the toll-free numbers and addresses of the major credit reporting agencies
How notice can be delivered
- Written notice by mail
- Electronic notice, if it follows the federal E-SIGN Act rules
- Substitute notice, allowed only if notice would cost more than $250,000, more than 500,000 people would need to be notified, or you do not have enough contact information. Substitute notice requires all three of: email to anyone you have an email address for, a conspicuous posting on your website, and notice to major statewide media.
If the breach involved only usernames or passwords, you may notify people electronically and tell them to change their password and security questions. If the compromised credentials are for an email account you provide, you cannot send the notice to that account; use another method.
What the Attorney General notice must include
When more than 500 Washington residents are notified, the notice to the Attorney General must include:
- The number of Washington residents affected, or an estimate
- The types of personal information involved
- The time frame of exposure, including the date of the breach and the date of discovery
- A summary of the steps taken to contain the breach
- A sample copy of the notice sent to residents, without any personal information
If any of this is unknown when notice is due, the notice must be updated later. The Attorney General publishes these notices, which is the dataset behind our Washington breach analysis.
Exceptions and special cases
| Situation | Rule |
|---|---|
| Data was encrypted | No notice needed if it was encrypted to NIST standards, unless the key or other means to decrypt it was also acquired |
| No real risk | No notice needed if the breach is not reasonably likely to subject consumers to a risk of harm |
| Law enforcement asks you to wait | Notice can be delayed if a law enforcement agency determines it would impede a criminal investigation, then given once it will not |
| You follow your own written procedures | A business with its own notification procedures, as part of an information security policy, complies if those procedures meet the law's timing requirements |
| HIPAA covered entities | Deemed compliant for protected health information if they follow the federal HITECH notice rules, but must still notify the Attorney General |
Deciding that a breach is "not reasonably likely" to cause harm is a judgment call with real consequences. Make it with a breach attorney and document why.
What happens if you get it wrong?
Under RCW 19.255.040, the Attorney General can enforce the law in court, and a violation is treated as an unfair or deceptive act under the Consumer Protection Act for that purpose. Consumers injured by a violation can also sue for damages directly under the breach law.
For card data, RCW 19.255.020 adds a narrow rule: a processor or a business that handles more than six million card transactions a year can be liable to banks for reasonable card reissuance costs if its lack of reasonable care caused the breach. Encryption or a current PCI DSS compliance validation is a defense.
A 30-day timeline that works
The 30 days start at discovery, not at the end of the investigation. A practical sequence:
- Day 0: Call your cyber insurer's breach hotline or your broker. Preserve evidence and contain the incident.
- First week: The insurer's breach attorney engages forensic investigators to determine what data was accessed and whose.
- Weeks two and three: Identify affected people and their states, draft the notice, and arrange mailing, call center, and credit monitoring if offered.
- By day 30: Mail resident notices and, if more than 500 Washington residents are affected, file with the Attorney General.
If your customers live in more than one state, each state's law applies to its residents. Idaho, for example, has no fixed deadline and no Attorney General filing for private businesses. See the comparison table in our complete cyber insurance guide.
How cyber insurance pays for compliance
The law applies whether or not you are insured. A cyber policy's breach response coverage typically pays for the breach attorney, forensic investigation, notification letters, a call center, and credit monitoring, and its regulatory and privacy liability coverage responds to Attorney General inquiries and lawsuits. Check that breach response costs are not subject to a low sublimit, and whether the policy requires you to use its panel of vendors. More on what policies include: cyber liability insurance.