Washington
Washington Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Washington businesses must notify affected consumers and the Attorney General within 30 days of discovering a data breach under RCW 19.255.010. The deadline applies regardless of business size, and the clock starts on the date of discovery, not when the breach occurred.
Washington state has one of the most comprehensive data breach notification laws in the United States. Its 30-day notification deadline is among the shortest nationally, its definition of personal information is among the broadest, and it is one of the few states where individual consumers have a private right of action to sue for notification violations.
The core statute for private entities is RCW 19.255.010. A parallel statute, RCW 42.56.590, governs state and local government agencies. The law was originally enacted in 2005 and was significantly strengthened by HB 1071, signed by Governor Jay Inslee on May 7, 2019, with the new requirements taking effect March 1, 2020.
For a broader look at Washington's privacy framework, see the parent guide to Washington Data Privacy Laws.
Who Must Comply
Washington's breach notification law applies to any person or business that conducts business in the state and owns or licenses computerized data that includes personal information about Washington residents.
There is no minimum size threshold. Any business, regardless of size, that handles personal information of Washington residents must comply.
Government agencies at the state and local level are covered under the separate statute RCW 42.56.590, which imposes substantially similar obligations.
Third-party service providers that maintain data on behalf of another business must notify the data owner or licensee immediately following discovery of a breach. The data owner then bears responsibility for consumer and AG notification.
What Qualifies as Personal Information
Washington's definition of personal information is among the broadest in the country. Under RCW 19.255.010, personal information means a resident's first name or first initial and last name combined with any of the following unencrypted data elements:
- Social Security number
- Driver's license number or state identification card number
- Account number, credit card number, or debit card number combined with any required security code, access code, or password
- Full date of birth
- Private key that is unique to an individual and used to authenticate or sign an electronic record
- Student identification number
- Military identification card number
- Passport number
- Health insurance policy number or health insurance identification number
- Medical history or information about mental or physical conditions, diagnoses, or treatment
- Biometric data generated from measurements or analysis of human body characteristics (such as fingerprint, retina, or iris images)
- Username or email address combined with a password or security questions and answers that permit access to an online account
The inclusion of date of birth, student IDs, military IDs, passport numbers, health insurance information, and full medical records makes Washington's definition substantially broader than most states. The 2019 amendments through HB 1071 added several of these categories.
Personal information does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.
What Triggers the Notification Requirement
A breach of the security system under Washington law is the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the entity.
Three conditions must be met for notification to be required:
- Personal information was, or is reasonably believed to have been, acquired by an unauthorized person
- The personal information was not secured (i.e., not encrypted or otherwise rendered unusable)
- The breach is reasonably likely to subject consumers to a risk of harm
The risk-of-harm analysis gives entities some discretion, but the standard is whether harm is "reasonably likely," not whether it has already occurred. Good-faith acquisition of personal information by an employee or agent of the entity does not constitute a breach, provided the information is not used or disclosed in an unauthorized manner.
The 30-Day Notification Deadline

Washington requires notification in the most expedient time possible and without unreasonable delay, but no later than 30 days after the breach was discovered.
This 30-day deadline, introduced by HB 1071, is one of the shortest in the country. Before the 2019 amendments, the deadline was 45 days.
The clock starts from the date the breach was discovered, not from the date the breach itself occurred. However, organizations should not delay their investigation as a means of avoiding the timeline.
Law enforcement may request a delay in notification if it would impede a criminal investigation. The entity must provide notification promptly after law enforcement determines notification will no longer compromise the investigation.
What the Consumer Notice Must Include
Washington law specifies required content for breach notification letters. The notice must include:
- The name and contact information of the reporting entity
- A list of the types of personal information that were or are reasonably believed to have been the subject of the breach
- The toll-free telephone numbers and addresses of the major credit reporting agencies (if the breach exposed financial data, Social Security numbers, or other data relevant to credit monitoring)
The notice must be written in plain language. Entities are encouraged, though not strictly required, to also include a description of the incident, steps taken to address the breach, and recommendations for consumers to protect themselves.
Attorney General Notification
When a breach affects more than 500 Washington residents, the entity must notify the Washington Attorney General's office within the same 30-day window.
The AG notification is submitted via an online Data Breach Notification Web Form. The notice must include:
- The number of Washington consumers affected or potentially affected
- A list of the types of personal information breached
- The time frame of exposure (if known)
- A summary of steps taken to contain the breach
- A sample copy of the security breach notification sent to consumers
The AG's office maintains a public Data Breach Notifications Directory on its website, listing all reported breaches.
Substitute Notice
Washington allows substitute notice when direct notification is not feasible. An entity may use substitute notice if:
- The cost of providing direct notice would exceed $250,000
- The affected class exceeds 500,000 people
- The entity does not have sufficient contact information
Substitute notice must include all of the following: email notification (if email addresses are available), conspicuous posting on the entity's website, and notification to major statewide media.
Encryption Safe Harbor

Washington provides an encryption safe harbor. If the personal information was secured (encrypted, redacted, or otherwise rendered unusable) at the time of the breach, notification is not required.
The definition of "secured" means encrypted in a manner that meets or exceeds the National Institute of Standards and Technology (NIST) standard, or is otherwise modified so that the personal information is rendered unreadable, unusable, or undecipherable by an unauthorized person.
If the encryption key was also compromised in the breach, the safe harbor does not apply.
Interaction with Federal Regulations
Entities that maintain their own notification procedures as part of an information security policy for the treatment of personal information, and that are otherwise consistent with this law's timing requirements, are deemed in compliance with Washington's notification requirements if they notify affected persons in accordance with those internal policies. The statute does not condition this safe harbor on compliance with HIPAA, the Gramm-Leach-Bliley Act, or any other federal law.
However, these entities must still comply with the 30-day AG notification requirement when more than 500 Washington residents are affected.
Enforcement and Private Right of Action

Washington's breach notification law is enforceable under the Consumer Protection Act (RCW 19.86). This has two important implications:
Attorney General Enforcement: The Washington Attorney General can bring enforcement actions treating violations as unfair or deceptive acts. The AG can seek injunctive relief, civil penalties, and restitution.
Private Right of Action: Unlike most states, Washington allows individual consumers injured by a notification violation to bring a civil lawsuit under RCW 19.255.040 and the Consumer Protection Act. Consumers may recover:
- Actual damages sustained
- Treble damages at the court's discretion, capped at $25,000 under RCW 19.86.090
- Costs and reasonable attorney's fees
This private right of action makes Washington one of the more plaintiff-friendly states for breach notification enforcement. Consumers do not need to wait for the AG to act; they can pursue claims independently.
Government Agency Requirements
State and local government agencies in Washington are governed by RCW 42.56.590, which mirrors the private-sector requirements. Government agencies must:
- Notify affected residents within 30 days of discovery
- Notify the AG when more than 500 residents are affected
- Provide the same content in their notification letters
Government agencies are additionally required to maintain procedures and practices consistent with guidelines developed by the Office of the Chief Information Officer.
More Washington Laws
Frequently Asked Questions
How quickly must a Washington business notify consumers of a data breach?
Washington requires notification within 30 days of discovering a data breach. This deadline was shortened from 45 days to 30 days by HB 1071, which took effect March 1, 2020. The clock starts from the date the breach was discovered, not from the date the breach itself occurred. Law enforcement may request a delay if notification would impede a criminal investigation.
When must the Washington Attorney General be notified of a data breach?
Entities must notify the Washington Attorney General within 30 days when a breach affects more than 500 Washington residents. The notification is submitted via an online web form on the AG's website. The notice must include the number of affected residents, types of personal information compromised, time frame of exposure, steps taken to contain the breach, and a sample copy of the consumer notification.
Can individuals sue for data breach notification violations in Washington?
Yes. Washington is one of the few states that provides a private right of action for breach notification violations. Violations are treated as unfair or deceptive acts under the Consumer Protection Act (RCW 19.86). Consumers can sue to recover actual damages, and courts may award treble damages capped at $25,000 at their discretion, plus costs and reasonable attorney's fees.
What types of personal information are protected under Washington's breach notification law?
Washington has one of the broadest definitions of personal information in the country. It includes Social Security numbers, driver's license numbers, financial account data, full date of birth, student IDs, military IDs, passport numbers, health insurance IDs, medical records and history, biometric data such as fingerprints or retina scans, and username/password combinations. The definition was significantly expanded by HB 1071 in 2019.
Does Washington's breach notification law apply to government agencies?
Yes. Washington has two parallel statutes. RCW 19.255 covers private businesses and individuals, while RCW 42.56.590 covers state and local government agencies. Both impose the same 30-day notification deadline and the same AG reporting requirements. Government agencies must additionally follow guidelines developed by the Office of the Chief Information Officer.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the dollar figure for Washington's breach-notification private right of action. The private right of action itself is real (RCW 19.255.040(3)(a), which routes into RCW 19.86 as an unfair/deceptive act), but the remedy is not a flat '$1,000 punitive damages' figure -- that number appears nowhere in RCW 19.255.010, .040, or the Consumer Protection Act. The actual enhanced remedy under RCW 19.86.090 is court-discretionary treble damages capped at $25,000, plus costs and attorney's fees.
Corrected two substitute-notice and safe-harbor claims: substitute notice under RCW 19.255.010 requires email, website posting, AND statewide media notice together, not just the first two; and the internal-procedures safe harbor applies to an entity's own compliant notification policy, not specifically to HIPAA or GLBA compliance.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 2 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Revised Code of Washington
§ 19.255.010Personal information—Notice of security breaches.In forcecited in 4 of our articles
(1) Any person or business that conducts business in this state and that owns or licenses data that includes personal information shall disclose any breach of the security of the system to any resident of this state whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person and the personal information was not secured. Notice is not required if the breach of the security of the system is not reasonably likely to subject consumers to a risk of harm. The breach of secured personal information must be disclosed if the information acquired and accessed is not secured during a security breach or if the confidential process, encryption key, or other means to decipher the secured information was acquired by an unauthorized person. (2) Any person or business that maintains or possesses data that may include personal information that the person or business does not own or license shall notify the owner or licensee of the information of any breach of the security of the data immediately following discovery, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person.
Official text (excerpt) · as of 2026-07-29 · Read the full section at app.leg.wa.gov
Also relied on in: Washington Security Camera Laws: Rules for Home and Business Surveillance (2026), Data Breach Notification Deadlines by Country (2026 Comparison Table), Washington Data Privacy Laws: My Health My Data Act & More (2026)
§ 42.56.590Personal information—Notice of security breaches.In force
(1) Any agency that owns or licenses data that includes personal information shall disclose any breach of the security of the system to any resident of this state whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person and the personal information was not secured. Notice is not required if the breach of the security of the system is not reasonably likely to subject consumers to a risk of harm. The breach of secured personal information must be disclosed if the information acquired and accessed is not secured during a security breach or if the confidential process, encryption key, or other means to decipher the secured information was acquired by an unauthorized person. (2) Any agency that maintains or possesses data that may include personal information that the agency does not own or license shall notify the owner or licensee of the information of any breach of the security of the data immediately following discovery, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person.
Official text (excerpt) · as of 2026-07-29 · Read the full section at app.leg.wa.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- RCW 19.255.010 Personal Information Notice of Security Breaches(app.leg.wa.gov).gov
- RCW 42.56.590 Government Agency Breach Notification(app.leg.wa.gov).gov
- Chapter 19.255 RCW Full Text(app.leg.wa.gov).gov
- Washington AG Data Breach Notification Laws(atg.wa.gov).gov
- Washington AG HB 1071 FAQ(atg.wa.gov).gov
- Washington AG Data Breach Notifications Directory(atg.wa.gov).gov
- Washington AG Data Breach Resource Center(atg.wa.gov).gov
- Washington AG Identity Theft Guide for Businesses(atg.wa.gov).gov
- HB 1071 Bill Summary(app.leg.wa.gov).gov
- HIPAA Information(hhs.gov).gov
- Gramm-Leach-Bliley Act(ftc.gov).gov