Data Breach Notification Law: A Comprehensive Guide
67 questions
67 questions on data breach notification law, answered and cited by the UpLaw editorial team.
- Can a company be sued over its security marketing claims after a breach?
- Can a data breach jeopardize a company's trade secrets?
- Can a data breach plaintiff recover the cost of credit monitoring they bought themselves?
- Can an individual sue under HIPAA after a health data breach?
- Can our contracts define “personal data” more broadly than the breach statutes do?
- Can the FTC bring an enforcement action over a company's data security?
- Can we notify residents of different states on different schedules?
- Can we send the same breach notification letter to everyone in the country?
- Do breach notification laws cover paper records?
- Does full-disk encryption satisfy the breach notification safe harbor?
- Does reporting a breach to the FBI let us delay notifying customers?
- Do we have to file anything if we decide a breach does not require notification?
- Do we have to notify the credit bureaus after a breach?
- Do we have to offer free credit monitoring after a breach?
- How can a breach notice be delivered, and when is substitute notice allowed?
- How does HIPAA's risk assessment differ from a state risk-of-harm analysis?
- How does the GDPR define a personal data breach, and how is that broader than U.S. law?
- How do you notify someone that their email password was breached without sending the notice to the compromised account?
- How is materiality determined for SEC cybersecurity disclosure?
- How quickly must a company notify individuals of a data breach?
- How should a vendor negotiate a breach notification clause in a customer contract?
- If our state's deadline is 45 days, can we take all 45 days to notify?
- Is a ransomware attack a reportable data breach if we restored from backup and nothing was stolen?
- Is it a breach if an employee accesses personal information without authorization?
- Is there a federal data breach notification law in the United States?
- Should a company file an immaterial cyber incident under Item 1.05?
- Should a defendant move to dismiss a removed breach class action for lack of standing?
- What are HIPAA's breach notification deadlines?
- What are HIPAA's exceptions to the definition of a breach?
- What are the GDPR penalties for failing to report a breach?
- What are the legal risks of paying a ransomware demand?
- What claims do plaintiffs bring after a data breach?
- What conditions must be met before a company can rely on the encryption safe harbor?
- What counts as “personal information” under state breach notification statutes?
- What did TransUnion v. Ramirez hold, and how does it apply to data breaches?
- What does Item 106 of Regulation S-K require?
- What does the FTC Safeguards Rule require, and when must a breach be reported to the FTC?
- What do large consumer data breach settlements typically look like?
- What has to be in a data breach notification letter?
- What is a “breach of the security of the system” under California law?
- What is a hybrid entity, and why does it matter for breach response?
- What is Article III standing and why does it decide data breach cases?
- What is the 36-hour banking regulator notification rule?
- What is the CCPA private right of action for data breaches?
- What is the difference between an “acquisition” and an “access” breach standard, and why does it matter?
- What is the economic loss doctrine and why is it the key defense in breach cases?
- What is the GDPR's 72-hour breach notification rule?
- What is the McMorris test for standing in data breach cases?
- What is the risk-of-harm threshold, and who applies it?
- What new categories have states added to the definition of personal information?
- What should a business associate agreement say about breach notification timing?
- What should a company do about preserving evidence after discovering a breach?
- What should a company know about cyber insurance before a breach?
- What single decision most determines how bad a data breach will be?
- When do we have to notify a state attorney general about a data breach?
- When is a data breach considered “discovered” for purposes of starting the notification clock?
- When must a public company file an 8-K about a cybersecurity incident?
- When must individuals be told about a breach under the GDPR?
- Which breach notification deadline usually hits first?
- Which European regulator do we notify if we have no EU establishment?
- Which state passed the first data breach notification law, and why does its approach still matter?
- Which states have no risk-of-harm exception to breach notification?
- Who counts as a “financial institution” under the Gramm-Leach-Bliley Act?
- Why do courts often order production of the post-breach forensic report?
- Why does it matter whether breached data appeared on the dark web?
- Why is class certification contested in data breach cases even after a huge breach?
- Why is the encryption safe harbor the most valuable provision in breach notification law?