District of Columbia
District of Columbia Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Businesses that collect personal information about District of Columbia residents must notify affected individuals in the most expedient time possible and without unreasonable delay after a qualifying breach, under D.C. Code 28-3852. Organizations reaching 50 or more affected DC residents must also notify the Attorney General.
The District of Columbia has one of the more aggressive data breach notification laws in the country. While many states set AG reporting thresholds at 250, 500, or even 1,000 affected residents, DC triggers that obligation at just 50 people. Combined with a private right of action that allows consumers to pursue actual damages, attorney fees, and punitive damages, plus a mandatory 18-month identity theft protection requirement for SSN breaches, the District gives residents real tools to hold organizations accountable.
This guide covers every key provision of DC's breach notification framework, from who must comply and what triggers a notification to enforcement mechanisms and consumer remedies. For the broader picture of DC privacy protections, see the parent guide on District of Columbia Data Privacy Laws.
The Governing Statute: DC Code 28-3851 Through 28-3853
DC's breach notification requirements are found in Subchapter II of Chapter 38 of Title 28 of the DC Code. The original law was enacted in 2007 and significantly strengthened by the Security Breach Protection Amendment Act of 2020 (D.C. Law 23-98), which took effect on June 17, 2020.
The subchapter now contains six sections:
- DC Code 28-3851: Definitions
- DC Code 28-3852: Notification of security breach
- DC Code 28-3852.01: Security requirements
- DC Code 28-3852.02: Remedies (identity theft protection)
- DC Code 28-3852.03: Rulemaking authority
- DC Code 28-3853: Enforcement
The 2020 amendment expanded the definition of personal information, added mandatory security requirements, created the AG notification obligation, and established remedies for breaches involving Social Security numbers.
Who Must Comply
The law applies to any person or entity that conducts business in the District of Columbia and owns or licenses computerized or other electronic data that includes personal information of DC residents. It also applies to entities that maintain, handle, or otherwise possess such data on behalf of the data owner.
DC government agencies are excluded from the definition of "person or entity" under the statute, though they may be subject to separate data protection requirements.
If you are a third-party service provider holding personal information on behalf of another organization, you must notify the data owner or licensee when you discover a breach. The data owner then bears the responsibility for notifying affected residents.
What Counts as Personal Information

DC Code 28-3851 defines personal information broadly. It includes an individual's first name or initial and last name, or phone number, or address, combined with any of the following data elements:
- Social Security number
- Driver's license or DC identification card number
- Passport number
- Taxpayer identification number
- Military ID number
- Financial account number (credit or debit card number with any required security code, access code, or password)
- Medical information (any data about dental, medical, or mental health treatment or diagnosis by a health care provider)
- Genetic information (as defined under HIPAA at 45 C.F.R. 160.103)
- Health insurance information (policy number or subscriber ID combined with a unique identifier used by the insurer)
- Biometric data (fingerprints, voice prints, retina or iris images, or other unique biological characteristics used for authentication)
- Email address combined with a password, security question answer, or other authenticating data
This is one of the broader definitions among US jurisdictions. The inclusion of biometric data, genetic information, medical records, and email credentials goes well beyond the name-plus-SSN model that older state laws used.
Publicly available information lawfully accessible from federal, state, or local government records is excluded.
What Triggers a Notification
A notification obligation arises when there is a "breach of the security of the system," defined as the unauthorized acquisition of computerized or other electronic data, or any equipment or device storing such data, that compromises the security, confidentiality, or integrity of personal information.
Three situations are excluded from the definition:
- Good-faith employee access. If an employee or agent accesses personal information in the course of their duties and does not use or disclose it in an unauthorized way, that is not a breach.
- Encrypted or redacted data. Acquisition of data that has been rendered secure through encryption or redaction is not a breach, unless the encryption keys or redaction methods were also compromised.
- No risk of harm. After a good-faith investigation, if the entity reasonably determines that the acquired information is unlikely to cause harm to the affected individuals, notification is not required.
The encryption safe harbor is significant. If your organization encrypts personal information at rest and in transit, and an unauthorized party gains access to the encrypted data but not the decryption keys, you are not required to notify.
Notification Timeline and Requirements
When to Notify
DC Code 28-3852 requires notification "in the most expedient time possible and without unreasonable delay." The statute does not set a hard deadline measured in calendar days, unlike states that specify 30, 45, or 60 days.
The timeline must be consistent with:
- The legitimate needs of law enforcement (notification can be delayed if law enforcement determines it would impede a criminal investigation)
- Measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system
Once any law enforcement delay is lifted, notification must proceed as soon as possible.
What the Notice Must Include
Written breach notifications to affected DC residents must contain:
- A description of the categories of personal information that were, or are reasonably believed to have been, compromised
- Contact information for the notifying entity
- Phone numbers for major consumer reporting agencies
- Information about how to place a security freeze on credit reports
- Contact information for the Federal Trade Commission and the DC Office of the Attorney General
- Guidance on identity theft prevention from the FTC and the AG
Methods of Notice
Notification can be delivered through:
- Written notice sent to the last known postal address of the affected individual
- Electronic notice if the entity has a valid email address and the individual has consented to electronic communication
- Substitute notice if the cost of direct notice would exceed $50,000, the affected group exceeds 100,000 individuals, or the entity lacks sufficient contact information (substitute notice requires email to known addresses, conspicuous website posting, and notification to major DC-area media outlets)
The 50-Resident AG Notification Threshold

One of DC's most distinctive provisions is its low threshold for notifying the Attorney General. Under DC Code 28-3852(b-1), when a breach affects 50 or more District residents, the entity must send written notice to the Office of the Attorney General.
For comparison, many states set this threshold at 250 or 500, and some have no AG notification requirement at all. DC's low bar means that even a relatively small breach involving personal information of DC residents will require a formal report to the AG.
The AG notice must be provided "in the most expedient manner possible, without unreasonable delay" and no later than the time at which notice is sent to affected residents. The notice to the AG must include:
- The nature of the breach
- The types of personal information compromised
- The number of DC residents affected
- The cause of the breach, if known
- Remedial actions taken or planned
- The date and time frame of the breach
- The address of corporate headquarters if the entity is located outside the District
When 1,000 or more individuals are notified, the entity must also inform nationwide consumer reporting agencies about the timing, distribution, and content of the notifications.
Mandatory Identity Theft Protection

DC Code 28-3852.02 requires that when a breach includes or is reasonably believed to include a Social Security number or taxpayer identification number, the entity must offer each affected DC resident identity theft protection services at no cost for at least 18 months.
The entity must also provide all information necessary for residents to enroll in those services. This is not optional or discretionary. Any breach involving SSNs or taxpayer IDs automatically triggers this obligation.
This 18-month requirement is longer than the 12-month standard that many states use, giving DC residents an extended period of monitoring after their most sensitive identifiers are compromised.
Data Security Requirements
The 2020 amendment added DC Code 28-3852.01, which imposes affirmative security obligations. Any entity that possesses personal information of DC residents must "implement and maintain reasonable security safeguards, including procedures and practices that are appropriate to the nature of the personal information."
This standard requires organizations to consider the sensitivity of the data and the size and complexity of their operations when designing security measures. The law does not prescribe specific technical controls, instead using the "reasonable" standard common in data security regulation.
Third-Party Service Providers
When entities engage third-party service providers that will handle personal information, they must execute written agreements requiring those providers to maintain reasonable security procedures and practices appropriate to the nature of the data.
Records Destruction
When destroying physical or digital records containing personal information, entities must take reasonable steps to prevent unauthorized access. Factors to consider include the sensitivity of the records, the size of the business, available technology, and the cost of destruction methods.
Federal Compliance Safe Harbor
Organizations that comply with the data security requirements of the Gramm-Leach-Bliley Act (Title V), HIPAA, or the HITECH Act are deemed to satisfy DC's security requirements automatically. This safe harbor applies to the security provisions only. It does not exempt organizations from the separate notification requirements, and entities that qualify for the security safe harbor must still notify the AG when 50 or more DC residents are affected by a breach.
Enforcement and Penalties
Unfair or Deceptive Trade Practice Classification
DC Code 28-3853 classifies any violation of the breach notification subchapter as an unfair or deceptive trade practice under DC Code 28-3904(kk). This is a powerful enforcement mechanism because it opens up all the remedies available under DC's Consumer Protection Procedures Act.
Private Right of Action
DC residents have a private right of action under DC Code 28-3905(k). Consumers injured by a violation of the breach notification law can file suit in DC Superior Court and recover:
- Actual damages, not the treble damages/$1,500-per-violation minimum otherwise available for Consumer Protection Procedures Act claims. DC Code 28-3853(b) classifies any violation of the breach notification subchapter, including both the Section 28-3852 notification duties and the Section 28-3852.01 security requirements, as an unfair or deceptive trade practice specifically under Section 28-3904(kk), and Section 28-3905(k)(2)(A)(ii) carves out (kk) violations from the general treble-damages rule, limiting them to actual damages
- Reasonable attorney fees
- Punitive damages in appropriate cases
- Injunctive relief to stop ongoing violations
- Any other relief the court determines proper
This combination of guaranteed actual-damages recovery and attorney fee shifting still creates a meaningful incentive for private enforcement, even when individual losses from a breach are relatively small.
Attorney General Enforcement
The DC Attorney General can bring enforcement actions in DC Superior Court seeking injunctive relief and restitution. The AG is not required to prove damages to obtain an injunction, and no bond is required. The AG's office has actively pursued data breach enforcement actions.
Recent enforcement actions include a settlement of over $350,000 against software firm Blackbaud in a multistate action involving a ransomware attack that exposed personal information of nonprofits and schools. DC also participated in the $600 million Equifax settlement and a $148 million Uber settlement over delayed breach notification.
Cumulative Remedies
The statute specifies that the rights and remedies available under the breach notification law are cumulative to each other and to any other rights and remedies available under law. This means consumers can pursue claims under both the breach notification statute and any other applicable laws simultaneously.
Federal Compliance and Preemption
Entities that comply with the breach notification provisions of the Gramm-Leach-Bliley Act or HIPAA are deemed to be in compliance with DC's resident notification requirements under DC Code 28-3852. However, this safe harbor does not exempt those entities from the AG notification requirement. Even HIPAA-covered entities must notify the DC Attorney General when a breach affects 50 or more DC residents.
There is no federal preemption of DC's breach notification law. The federal safe harbor provisions are additive, not preemptive, meaning organizations must still meet DC-specific requirements that go beyond federal mandates.
This article provides general legal information about District of Columbia data breach notification laws and is not legal advice. Data breach notification requirements involve time-sensitive obligations and potential penalties. Consult a licensed attorney in the District of Columbia for guidance on your specific situation.
Frequently Asked Questions
How quickly must I notify DC residents after a data breach?
DC law requires notification in the most expedient time possible and without unreasonable delay. Unlike some states that set a specific deadline (such as 30 or 60 days), DC uses a reasonableness standard. You may delay notification only if law enforcement determines it would impede a criminal investigation, or if you need time to determine the scope of the breach and restore data system integrity.
When do I need to notify the DC Attorney General about a breach?
You must notify the DC Attorney General whenever a breach affects 50 or more District of Columbia residents. This is one of the lowest AG notification thresholds in the country. The written notice to the AG must be sent no later than when you notify affected residents and must include the nature of the breach, types of personal information compromised, number of affected residents, cause of the breach, remedial actions taken, and the date and time frame of the breach.
Does DC law require me to offer free identity theft protection after a breach?
Yes, but only when the breach involves Social Security numbers or taxpayer identification numbers. In those cases, you must offer affected DC residents free identity theft protection services for at least 18 months and provide all information necessary for enrollment. This requirement is longer than the 12-month standard used by many states.
Can DC residents sue a company for a data breach?
Yes. DC classifies breach notification violations as unfair or deceptive trade practices under DC Code 28-3904(kk). Affected consumers can file suit in DC Superior Court and recover actual damages, not the treble damages/$1,500-per-violation minimum available for other consumer protection claims, which DC Code 28-3905(k)(2) specifically carves out for 28-3904(kk) violations, plus reasonable attorney fees, punitive damages, and injunctive relief.
Does encryption protect my organization from DC breach notification requirements?
DC provides an encryption safe harbor. If personal information was encrypted or redacted and the unauthorized party did not also obtain the decryption keys or means to undo the redaction, the acquisition does not constitute a breach under DC law, and you are not required to notify. However, if the encryption keys were also compromised, the safe harbor does not apply.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Governing law re-checked for recent changes
Corrected the private-right-of-action remedy: DC Code 28-3853(b) classifies ALL breach-notification-subchapter violations (both notification and security-requirement failures) as an unfair trade practice specifically under 28-3904(kk), and 28-3905(k)(2)(A)(ii) limits (kk) violations to actual damages, not the treble damages/$1,500 minimum the article had described.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 6 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Code of the District of Columbia, Title 28: Commercial Instruments and Transactions. - Chapter 38: Consumer Protections. - Subchapter II: Consumer Security Breach Notification.
§ 28-3851Definitions.In forcecited in 4 of our articles
For purposes of this subchapter, the term: (A) "Breach of the security of the system" means unauthorized acquisition of computerized or other electronic data or any equipment or device storing such data that compromises the security, confidentiality, or integrity of personal information maintained by the person or entity who conducts business in the District of Columbia. (B) The term "breach of the security of the system" does not include: (i) A good-faith acquisition of personal information by an employee or agency of the person or entity for the purposes of the person or entity if the personal information is not used improperly or subject to further unauthorized disclosure; (ii) Acquisition of data that has been rendered secure, including through encryption or redaction of such data, so as to be unusable by an unauthorized third party unless any information obtained has the potential to compromise the effectiveness of the security protection preventing unauthorized access; or (iii) Acquisition of personal information of an individual that the person or entity reasonably determines, after a reasonable investigation and consultation with the Office of the Attorney General for…
Official text (excerpt) · as of 2026-07-30 · Read the full section at github.com
Also relied on in: District of Columbia Data Privacy Laws: Breach Rules & Consumer Rights (2026), District of Columbia Biometric Privacy Laws: Collection, Consent & Penalties (2026), DC Employee Monitoring Laws: Notice, GPS, and Privacy Rules (2026)
§ 28-3852Notification of security breach.In forcecited in 4 of our articles
(a) Any person or entity who conducts business in the District of Columbia, and who, in the course of such business, owns or licenses computerized or other electronic data that includes personal information, and who discovers a breach of the security of the system, shall promptly notify any District of Columbia resident whose personal information was included in the breach. The notification shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection (d) of this section, and with any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
Official text (excerpt) · as of 2026-07-30 · Read the full section at github.com
§ 28-3853Enforcement.In forcecited in 3 of our articles
(a) [Repealed]. (b) A violation of this subchapter, or any rule issued pursuant to the authority of this subchapter, is an unfair or deceptive trade practice pursuant to § 28-3904(kk). (c) The rights and remedies available under this section are cumulative to each other and to any other rights and remedies available under law.
Official text (excerpt) · as of 2026-07-30 · Read the full section at github.com
Code of the District of Columbia, Title 28: Commercial Instruments and Transactions. - Chapter 39: Consumer Protection Procedures.
§ 28-3904Unfair or deceptive trade practices.In forcecited in 2 of our articles
It shall be a violation of this chapter for any person to engage in an unfair or deceptive trade practice, whether or not any consumer is in fact misled, deceived, or damaged thereby, including to: (a) represent that goods or services have a source, sponsorship, approval, certification, accessories, characteristics, ingredients, uses, benefits, or quantities that they do not have; (b) represent that the person has a sponsorship, approval, status, affiliation, certification, or connection that the person does not have; (c) represent that goods are original or new if in fact they are deteriorated, altered, reconditioned, reclaimed, or second hand, or have been used; (d) represent that goods or services are of particular standard, quality, grade, style, or model, if in fact they are of another; (e) misrepresent as to a material fact which has a tendency to mislead; (e-1) represent that a transaction confers or involves rights, remedies, or obligations which it does not have or involve, or which are prohibited by law; (f) fail to state a material fact if such failure tends to mislead; (f-1) use innuendo or ambiguity as to a material fact, which has a tendency to mislead; (g)…
Official text (excerpt) · as of 2026-07-30 · Read the full section at github.com
§ 28-3905Complaint procedures.In force
(a) A case is begun by filing with the Department a complaint plainly describing a trade practice and stating the complainant’s (and, if different, the consumer’s) name and address, the name and address (if known) of the respondent, and such other information as the Director may require. The complaint must be in or reduced by the Director to writing. The filing of a complaint with the Department shall toll the periods for limitation of time for bringing an action as set out in section 12-301 until the complaint has been resolved through an administrative order, consent decree, or dismissal in accordance with this section or until an opportunity to arbitrate has been provided in Chapter 5 of Title 50. (1) Except as provided in paragraph (2) of this subsection, the Director shall investigate each such complaint and determine: (A) What trade practice actually occurred; and (B) Whether the trade practice which occurred violates any statute, regulation, rule of common law, or other law of the District of Columbia. (2) The Director may, in his or her discretion, decline to prosecute certain cases as necessary to manage the Department’s caseload and control program costs.
Official text (excerpt) · as of 2026-07-30 · Read the full section at github.com
Code of Federal Regulations Title 45
§ 160.103Definitions.In forcecited in 5 of our articles
Except as otherwise provided, the following definitions apply to this subchapter: Act means the Social Security Act. Administrative simplification provision means any requirement or prohibition established by: (1) 42 U.S.C. 1320d-1320d-4, 1320d-7, 1320d-8, and 1320d-9; (2) Section 264 of Pub. L. 104-191; (3) Sections 13400-13424 of Public Law 111-5; or (4) This subchapter. ALJ means Administrative Law Judge. ANSI stands for the American National Standards Institute. Business associate: (1) Except as provided in paragraph (4) of this definition, business associate means, with respect to a covered entity, a person who: (i) On behalf of such covered entity or of an organized health care arrangement (as defined in this section) in which the covered entity participates, but other than in the capacity of a member of the workforce of such covered entity or arrangement, creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter, including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, patient safety activities listed at 42 CFR 3.20, billing,…
Official text (excerpt) · as of 2026-07-28 · Read the full section at ecfr.gov
Also relied on in: Does a Failed Drug Test Show Up on Your Record?, When Is a Business Associate Agreement Required? (2026), South Dakota Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- DC Code 28-3851 - Definitions(code.dccouncil.gov).gov
- DC Code 28-3852 - Notification of security breach(code.dccouncil.gov).gov
- DC Code 28-3852.01 - Security requirements(code.dccouncil.gov).gov
- DC Code 28-3852.02 - Remedies(code.dccouncil.gov).gov
- DC Code 28-3853 - Enforcement(code.dccouncil.gov).gov
- DC Code 28-3904 - Unfair or deceptive trade practices(code.dccouncil.gov).gov
- DC Code 28-3905 - Complaint procedures(code.dccouncil.gov).gov
- D.C. Law 23-98 - Security Breach Protection Amendment Act of 2020(code.dccouncil.gov).gov
- DC OAG Consumer Privacy Information(oag.dc.gov).gov
- AG Schwalb Blackbaud Data Breach Settlement(oag.dc.gov).gov
- Equifax Data Breach Settlement(oag.dc.gov).gov
- Uber Data Breach Settlement(oag.dc.gov).gov