West Virginia
West Virginia Data Breach Notification Laws: Reporting Rules & Timelines (2026)

West Virginia requires data breach notification without unreasonable delay under W. Va. Code 46A-2A-102. No fixed day count applies; businesses must act promptly after discovering a breach, with limited delays permitted for investigation or active law enforcement requests.
West Virginia's data breach notification law takes a comparatively narrow approach. Unlike states that have expanded their definitions to cover biometric data, medical records, and login credentials, West Virginia protects only the three most traditional categories of personal information. The law also lacks a fixed notification deadline, instead using the "without unreasonable delay" standard, and does not require any notification to state agencies.
The statute is codified at W.Va. Code 46A-2A-101 (definitions) through 46A-2A-105. Originally enacted in 2008, the law has not been significantly amended since its passage, making it one of the older and less updated breach notification statutes in the country.
For a broader look at West Virginia's privacy framework, see the parent guide to West Virginia Data Privacy Laws.
Who Must Comply
West Virginia's breach notification law applies to any individual or entity that owns or licenses computerized data that includes personal information about West Virginia residents.
This covers businesses of all sizes, nonprofit organizations, and any other entity that maintains a database of personal information. There is no minimum size threshold or revenue requirement.
Third-party service providers are also covered. Any entity that maintains computerized data on behalf of another entity must notify the data owner or licensee when a breach is discovered. The data owner then bears responsibility for consumer notification.
Notably, the law applies to entities that maintain data "as part of a database of personal information regarding multiple individuals." This language suggests that an entity holding personal information about only a single individual may not be subject to the notification requirements.
What Qualifies as Personal Information

West Virginia's definition of personal information is among the narrowest in the country. Under 46A-2A-101, personal information means a resident's first name or first initial and last name combined with any one or more of the following unencrypted, unredacted data elements:
- Social Security number
- Driver's license number or state identification card number
- Financial account number, credit card number, or debit card number combined with any required security code, access code, or password that would permit access to the resident's financial accounts
That is the complete list. West Virginia does not include biometric data, medical records, health insurance information, passport numbers, military IDs, login credentials, or any of the other expanded categories that many states have adopted in recent years.
Personal information does not include information lawfully obtained from publicly available records or from federal, state, or local government records lawfully made available to the general public.
What Triggers the Notification Requirement
A "breach of the security of a system" under West Virginia law means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information.
West Virginia imposes a dual trigger before notification is required:
-
Unauthorized access and acquisition: Both elements must be present. Mere unauthorized access without acquisition, or acquisition without unauthorized access, does not trigger the statute.
-
Risk of harm: The breach must cause the entity to "reasonably believe that the breach of security has caused or will cause identity theft or other fraud to any resident of this state."
This risk-of-harm analysis gives entities significant discretion. If an entity determines after investigation that a breach is unlikely to result in identity theft or fraud, notification is not required. However, the entity should document its analysis in case it is later questioned.
Good-faith acquisition of personal information by an employee or agent of the entity does not constitute a breach, provided the information is not used for an unauthorized purpose or subject to further unauthorized disclosure.
Notification Timeline
West Virginia requires notice "without unreasonable delay" following discovery or notification of the breach.
There is no specific day count. This open-ended standard is less prescriptive than states like Colorado (30 days) or Vermont (45 days), but it also provides less clarity for organizations trying to plan their incident response.
The statute does allow a reasonable delay for two purposes:
- Investigation: An entity may delay notification to take measures necessary to determine the scope of the breach and to restore the reasonable integrity of the data system.
- Law enforcement: If a law enforcement agency determines that notification will impede a criminal or civil investigation, or jeopardize national or homeland security, the entity may delay notification. Notice must be given without unreasonable delay after the agency determines notification will no longer compromise the investigation.
What the Consumer Notice Must Include
West Virginia's statute does specify content requirements for breach notification letters. Under W. Va. Code 46A-2A-102(d), the notice must include:
- To the extent possible, a description of the categories of information reasonably believed to have been accessed or acquired, such as Social Security numbers, driver's license or state ID numbers, and financial data
- A telephone number or website address the individual can use to contact the entity and learn what information it maintained about them
- The toll-free contact telephone numbers and addresses for the major credit reporting agencies, and information on how to place a fraud alert or security freeze
The Federal Trade Commission additionally recommends that breach notifications describe the incident itself, the steps the entity has taken, and recommendations for the consumer such as credit monitoring. Following these additional best practices, beyond what the statute requires, reduces litigation risk and demonstrates good faith.
No Attorney General Notification

West Virginia does not require notification to the Attorney General or any other state agency when a data breach occurs. This makes it one of a shrinking number of states that do not require government notification.
Consumer Reporting Agency Notification
If a breach requires notification to more than 1,000 West Virginia residents, the entity must also notify the nationwide consumer reporting agencies (Equifax, Experian, and TransUnion) without unreasonable delay.
The notice to the credit bureaus must include the timing, distribution, and content of the consumer notification. The purpose is to prepare the agencies for an influx of fraud alert and credit freeze requests.
Methods of Notification
West Virginia allows notification through several methods:
- Written notice sent to the most recent postal address in the entity's records
- Telephonic notice (direct phone call)
- Electronic notice (email), if the entity has an email address for the consumer and the notice is consistent with federal requirements under the E-SIGN Act
Substitute Notice
West Virginia allows substitute notice when direct notification is not feasible. An entity may use substitute notice if it demonstrates that:
- The cost of providing direct notice would exceed $50,000
- The affected class exceeds 100,000 residents
- The entity does not have sufficient contact information
Substitute notice must include any two of the following: email notification (if email addresses are available), conspicuous posting on the entity's website, or notification to major statewide media.
Encryption Safe Harbor

West Virginia provides an encryption safe harbor. The notification requirements apply only to "unencrypted and unredacted" personal information. If the compromised data was encrypted or redacted at the time of the breach, notification is not required.
The statute defines "redact" as alteration or truncation of data such that no more than the last four digits of a Social Security number, driver's license number, state ID number, or account number is accessible.
Enforcement and Penalties
The West Virginia Attorney General has exclusive enforcement authority over the breach notification law. Violations are treated as unfair or deceptive acts or practices under the West Virginia Consumer Credit and Protection Act.
There is no private right of action. Individual consumers cannot sue directly for notification failures under this statute.
Penalties are subject to specific caps:
- No civil penalty may be assessed unless the court finds a course of repeated and willful violations
- Civil penalties cannot exceed $150,000 per breach or series of related breaches discovered in a single investigation
The $150,000 cap and the requirement to show repeated, willful conduct make West Virginia's penalty structure more lenient than most states. Single-incident failures, even if negligent, may not result in civil penalties.
More West Virginia Laws
Frequently Asked Questions
How quickly must a West Virginia business notify consumers of a data breach?
West Virginia requires notification 'without unreasonable delay' after discovering a breach. There is no specific day count. The entity may delay notification to investigate the scope of the breach and restore system integrity, or if law enforcement determines that notification would impede an investigation. This open-ended standard provides flexibility but less clarity than states with fixed deadlines.
Does West Virginia require notification to the Attorney General for data breaches?
No. West Virginia does not require notification to the Attorney General or any other state agency. However, if a breach requires notification to more than 1,000 West Virginia residents, the entity must notify the nationwide consumer reporting agencies (Equifax, Experian, and TransUnion) about the timing, distribution, and content of the consumer notification.
What types of personal information trigger breach notification in West Virginia?
West Virginia has one of the narrower definitions among U.S. states. Only three categories of data trigger notification when combined with a name: Social Security numbers, driver's license or state ID numbers, and financial account numbers (credit/debit cards) combined with any required security code or password. The law does not cover biometric data, medical records, login credentials, or passport numbers.
Can individuals sue for data breach notification violations in West Virginia?
No. West Virginia does not provide a private right of action for breach notification violations. Only the Attorney General can bring enforcement actions. Civil penalties are capped at $150,000 per breach or series of related breaches and require a showing of repeated and willful violations.
Does West Virginia's law require notification if the breached data was encrypted?
No. West Virginia provides an encryption safe harbor. The notification requirements apply only to unencrypted and unredacted personal information. If the data was properly encrypted or redacted (truncated to no more than the last four digits) at the time of the breach, notification is not required.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected two compliance-relevant errors: West Virginia's breach notification law DOES specify required notice content under W. Va. Code 46A-2A-102(d) (it does not leave this unregulated), and substitute notice requires any TWO of three methods, not all three.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 3 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
West Virginia Code
§ 101Definitions.In forcecited in 5 of our articles
As used in this article: (1) "Breach of the security of a system" means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information maintained by an individual or entity as part of a database of personal information regarding multiple individuals and that causes the individual or entity to reasonably believe that the breach of security has caused or will cause identity theft or other fraud to any resident of this state. Good faith acquisition of personal information by an employee or agent of an individual or entity for the purposes of the individual or the entity is not a breach of the security of the system, provided that the personal information is not used for a purpose other than a lawful purpose of the individual or entity or subject to further unauthorized disclosure.
Official text (excerpt) · as of 2026-07-30 · Read the full section at code.wvlegislature.gov
Also relied on in: West Virginia Data Privacy Laws: Breach Notification & Consumer Rights (2026), West Virginia Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 102Notice of breach of security of computerized personal information.In forcecited in 5 of our articles
(a) An individual or entity that owns or licenses computerized data that includes personal information shall give notice of any breach of the security of the system following discovery or notification of the breach of the security of the system to any resident of this state whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person and that causes, or the individual or entity reasonably believes has caused or will cause, identity theft or other fraud to any resident of this state. Except as provided in subsection (e) of this section or in order to take any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the system, the notice shall be made without unreasonable delay.
Official text (excerpt) · as of 2026-07-30 · Read the full section at code.wvlegislature.gov
§ 103Procedures deemed in compliance with security breach notice requirements.In forcecited in 3 of our articles
(a) An entity that maintains its own notification procedures as part of an information privacy or security policy for the treatment of personal information and that are consistent with the timing requirements of this article shall be deemed to be in compliance with the notification requirements of this article if it notifies residents of this state in accordance with its procedures in the event of a breach of security of the system. (b) A financial institution that responds in accordance with the notification guidelines prescribed by the Federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice is deemed to be in compliance with this article. (c) An entity that complies with the notification requirements or procedures pursuant to the rules, regulation, procedures or guidelines established by the entity's primary or functional regulator shall be in compliance with this article.
Official text (excerpt) · as of 2026-07-30 · Read the full section at code.wvlegislature.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- W.Va. Code 46A-2A-101 Definitions(code.wvlegislature.gov).gov
- W.Va. Code 46A-2A-102 Notice of Breach(code.wvlegislature.gov).gov
- W.Va. Code 46A-2A-103 Substitute Notice(code.wvlegislature.gov).gov
- W.Va. Code Article 46A-2A Full Article(code.wvlegislature.gov).gov
- West Virginia Attorney General(ago.wv.gov).gov
- FTC Data Breach Response Guide(ftc.gov).gov