Wisconsin
Wisconsin Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Under Wis. Stat. 134.98, Wisconsin businesses must notify affected individuals of a data breach within 45 days of learning that personal information was acquired without authorization. The deadline runs from when the entity becomes aware, not when the breach occurred, and applies to name-plus-identifier combinations including Social Security numbers and biometric data.
Wisconsin's data breach notification law strikes a balance between consumer protection and business flexibility. While the state includes biometric data and DNA profiles in its definition of personal information, setting it apart from states with narrower definitions, it does not require any notification to state agencies and lacks a private right of action for affected consumers.
The statute is codified at Wis. Stat. 134.98. Originally enacted in 2006, the law has been updated periodically, though it remains more concise than the breach notification statutes of many other states.
For a broader look at Wisconsin's privacy framework, see the parent guide to Wisconsin Data Privacy Laws.
Who Must Comply
Wisconsin's breach notification law applies to any entity whose principal place of business is located in Wisconsin, or any entity that maintains or licenses personal information in the state, if that entity knows that personal information in its possession has been acquired by an unauthorized person.
The term "entity" is defined broadly to include corporations, business trusts, estates, partnerships, limited liability companies, associations, organizations, joint ventures, governments, governmental subdivisions, agencies, and any other legal or commercial entity.
Third-party data custodians are also covered. If a person or entity that stores personal information on behalf of another entity, but does not own or license that information, learns of an unauthorized acquisition, it must notify the data owner or licensee as soon as practicable. The data owner then bears responsibility for consumer notification.
What Qualifies as Personal Information
Under Wis. Stat. 134.98(1)(b), personal information means an individual's last name and first name or first initial, combined with one or more of the following data elements:
- Social Security number
- Driver's license number or state identification card number
- Financial account number, credit card number, or debit card number combined with any required security code, access code, or password
- Deoxyribonucleic acid (DNA) profile, as defined in Wis. Stat. 939.74(2d)(a)
- Unique biometric data, including fingerprint, voice print, retina or iris image, or any other unique physical representation
The inclusion of DNA profiles and biometric data distinguishes Wisconsin from states with narrower definitions. However, unlike states such as Washington or Colorado, Wisconsin does not include medical records, health insurance information, passport numbers, military IDs, or login credentials in its definition.
Personal information does not include information that is lawfully obtained from publicly available records or from federal, state, or local government records lawfully made available to the general public.
What Triggers the Notification Requirement
Notification is required when an entity knows that personal information in its possession has been acquired by a person whom the entity has not authorized to acquire the personal information.
Wisconsin's notification trigger includes a risk-of-harm exception. Under Wis. Stat. 134.98(2)(cm)1., an entity is not required to notify if the acquisition of personal information does not create a material risk of identity theft or fraud to the affected individual. Once the entity knows an unauthorized acquisition has occurred and that it creates a material risk of identity theft or fraud, the notification obligation begins.
Good-faith acquisition of personal information by an employee or agent of the entity is not an unauthorized acquisition, provided the information is not used or disclosed in an unauthorized manner.
The 45-Day Notification Deadline

Wisconsin requires entities to provide notice within a reasonable time, not to exceed 45 days after the entity learns of the unauthorized acquisition of personal information.
The 45-day clock begins when the entity learns of the acquisition, not when the breach itself occurred. The statute emphasizes that notification must occur within a "reasonable time," meaning that 45 days is the outer limit, not the target.
A law enforcement agency may request a delay in notification to protect an investigation or homeland security. During such a delay, the entity may not provide notice of or publicize the breach except as authorized by the law enforcement agency. The notification process begins at the end of the delay period.
What the Consumer Notice Must Include
Wisconsin's statute requires that the notice "indicate that the entity knows of the unauthorized acquisition of personal information pertaining to the subject of the personal information."
Beyond this basic requirement, the statute does not prescribe specific content elements. This is less detailed than many states, which require inclusion of credit reporting agency contact information, FTC contact details, and specific remediation steps.
However, the DATCP guidance recommends that notifications include:
- A description of the incident
- The types of personal information involved
- Steps the entity has taken to address the breach
- Contact information for the entity
- Recommendations for consumers to protect themselves
- Contact information for the credit reporting agencies and the FTC
Methods of Notification
Wisconsin allows notification through two primary methods:
- Mail sent to the last known address of the affected individual
- A method the entity has previously used to communicate with the individual
If the entity cannot with reasonable diligence determine the mailing address and has not previously communicated with the individual, it must provide notice by a method reasonably calculated to provide actual notice to the individual.
No Attorney General Notification

Wisconsin does not require notification to the Attorney General, DATCP, or any other state agency when a data breach occurs. This places Wisconsin among a diminishing number of states that do not mandate government notification.
Consumer Reporting Agency Notification
If a single breach requires notification to more than 1,000 individuals, the entity must also notify the nationwide consumer reporting agencies (Equifax, Experian, and TransUnion) without unreasonable delay.
The notice to the credit bureaus must include the timing, distribution, and content of the consumer notifications. This requirement aligns with most other states' consumer reporting agency notification provisions.
Encryption Safe Harbor

Wisconsin provides an encryption safe harbor. The notification requirements apply only to personal information that has not been "encrypted, redacted, or altered in a manner that renders the personal information unreadable."
If the compromised data was properly encrypted or rendered unreadable at the time of the unauthorized acquisition, notification is not required.
Federal Regulation Safe Harbors
Wisconsin provides specific safe harbors under Wis. Stat. 134.98(3m):
Financial institutions: An entity subject to and in compliance with the privacy and security requirements of the Gramm-Leach-Bliley Act (15 U.S.C. 6801-6827), or a person with contractual obligations to such an entity, is exempt from Wisconsin's notification requirements if it maintains a policy addressing breaches of information security.
Healthcare entities: An entity described in 45 CFR 164.104(a) that is in compliance with HIPAA security and privacy requirements (45 CFR Part 164) is exempt from the notification requirements.
These safe harbors are broader than those in many states, which often require federally regulated entities to still comply with certain state-specific requirements.
Effect on Civil Claims
Wisconsin includes an important provision in Wis. Stat. 134.98(4): failure to comply with the notification requirements is not negligence or a breach of any duty, but may be used as evidence of negligence or a breach of a legal duty in a civil action.
This means that while there is no standalone private right of action under the breach notification statute, a failure to notify could potentially strengthen a plaintiff's case in a separate negligence or breach-of-duty claim.
Enforcement and Penalties
Wis. Stat. 134.98 does not establish a civil forfeiture or other dollar-amount penalty for noncompliance, and the statute does not name a specific enforcement agency. The only stated consequence for a failure to notify is the evidentiary provision in subsection (4).
There is no private right of action that allows individual consumers to sue directly under this statute, though the evidentiary provision in subsection (4) may support related civil claims.
DATCP maintains guidance documents for businesses on complying with the notification requirements and provides consumer resources for individuals affected by data breaches.
More Wisconsin Laws
Frequently Asked Questions
How quickly must a Wisconsin business notify consumers of a data breach?
Wisconsin requires notification within a reasonable time, not to exceed 45 days after the entity learns of the unauthorized acquisition of personal information. The clock starts when the entity becomes aware of the breach, not when the breach itself occurred. Law enforcement may request a temporary delay to protect an investigation or homeland security.
Does Wisconsin require notification to the Attorney General for data breaches?
No. Wisconsin does not require notification to the Attorney General, DATCP, or any other state agency. However, if a single breach requires notification to more than 1,000 individuals, the entity must notify the nationwide consumer reporting agencies (Equifax, Experian, and TransUnion) about the timing, distribution, and content of consumer notices.
What types of personal information trigger breach notification in Wisconsin?
Wisconsin protects an individual's name combined with Social Security numbers, driver's license or state ID numbers, financial account data (with access codes), DNA profiles, and unique biometric data such as fingerprints, voice prints, and retina or iris images. The inclusion of DNA and biometric data is broader than many states, though Wisconsin does not cover medical records, login credentials, or passport numbers.
Can individuals sue for data breach notification violations in Wisconsin?
No. Wisconsin does not provide a private right of action under the breach notification statute. However, the law specifies that failure to comply may be used as evidence of negligence or breach of duty in a separate civil action. The statute does not establish a civil forfeiture or other specific dollar-amount penalty for noncompliance.
Are HIPAA-covered healthcare entities exempt from Wisconsin's breach notification law?
Yes. Wisconsin provides a safe harbor for healthcare entities that comply with HIPAA security and privacy requirements under 45 CFR Part 164. Similarly, financial institutions complying with the Gramm-Leach-Bliley Act are also exempt, provided they maintain a policy addressing breaches of information security.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Governing law re-checked for recent changes
Corrected two errors: the article claimed a $10,000-per-violation civil forfeiture and named Attorney General/DATCP enforcement authority, neither of which appears in Wis. Stat. 134.98 (confirmed against the full statute text and the official Wisconsin Legislature site); and corrected the claim that the breach-notification trigger has no risk-of-harm component, when 134.98(2)(cm)1. exempts entities from notifying when a breach creates no material risk of identity theft or fraud.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 3 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Code of Federal Regulations Title 45
§ 164.104Applicability.In force
(a) Except as otherwise provided, the standards, requirements, and implementation specifications adopted under this part apply to the following entities: (1) A health plan. (2) A health care clearinghouse. (3) A health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter. (b) Where provided, the standards, requirements, and implementation specifications adopted under this part apply to a business associate.
Official text (excerpt) · as of 2026-07-28 · Read the full section at ecfr.gov
Wisconsin Statutes, Chapter 134: Miscellaneous Trade Regulations
§ 134.98Notice of unauthorized acquisition of personal information.In forcecited in 4 of our articles
(1) Definitions. In this section: (a) 1. “Entity” means a person, other than an individual, that does any of the following: a. Conducts business in this state and maintains personal information in the ordinary course of business. b. Licenses personal information in this state. c. Maintains for a resident of this state a depository account as defined in s. 815.18 (2) (e). d. Lends money to a resident of this state. 2. “Entity” includes all of the following: a. The state and any office, department, independent agency, authority, institution, association, society, or other body in state government created or authorized to be created by the constitution or any law, including the legislature and the courts. b. A city, village, town, or county. (am) “Name” means an individual’s last name combined with the individual’s first name or first initial. (b) “Personal information” means an individual’s last name and the individual’s first name or first initial, in combination with and linked to any of the following elements, if the element is not publicly available information and is not encrypted, redacted, or altered in a manner that renders the element unreadable: 1.
Official text (excerpt) · as of 2026-07-29 · Read the full section at docs.legis.wisconsin.gov
Also relied on in: Wisconsin Data Privacy Laws: Breach Notification & Consumer Rights (2026), Wisconsin Biometric Privacy Laws: Collection, Consent & Penalties (2026), Wisconsin Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
Wisconsin Statutes, Chapter 939: Crimes
§ 939.74Time limitations on prosecutions.In forcecited in 4 of our articles
(1) Except as provided in subs. (2) and (2d) and s. 946.88 (1), prosecution for a felony must be commenced within 6 years and prosecution for a misdemeanor or for adultery within 3 years after the commission thereof. Within the meaning of this section, a prosecution has commenced when a warrant or summons is issued, an indictment is found, or an information is filed. (2) Notwithstanding that the time limitation under sub. (1) has expired: (a) 1. A prosecution under s. 940.01, 940.02, 940.03, 940.05, 940.225 (1), 948.02 (1), or 948.025 (1) (a), (b), (c), or (d) may be commenced at any time. 2. A prosecution for an attempt to commit a violation of s. 940.01, 940.05, 940.225 (1), or 948.02 (1) may be commenced at any time. (am) A prosecution under s. 940.06 may be commenced within 15 years after the commission of the violation. (ap) A prosecution under s. 940.11 (2) may be commenced within the applicable time under sub. (1) or within 6 years of the date the corpse was discovered or identified, whichever is later. (ar) A prosecution for a violation of s. 940.225 (2) may be commenced within 20 years after the commission of the violation. A prosecution for a violation of s.
Official text (excerpt) · as of 2026-07-29 · Read the full section at docs.legis.wisconsin.gov
Also relied on in: Wisconsin Statute of Limitations: Filing Deadlines by Case Type
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Wis. Stat. 134.98 Notice of Unauthorized Acquisition(docs.legis.wisconsin.gov).gov
- DATCP Data Breach Notification Law Guidance(datcp.wi.gov).gov
- DATCP Data Breach Consumer Guide(datcp.wi.gov).gov
- WI Legislative Council Records Containing Personal Information(docs.legis.wisconsin.gov).gov
- Wisconsin State Law Library Privacy Law(wilawlibrary.gov).gov
- HIPAA Information(hhs.gov).gov
- Gramm-Leach-Bliley Act(ftc.gov).gov