Wyoming
Wyoming Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Wyoming requires businesses to notify affected residents of a data breach in the most expedient time possible and without unreasonable delay under Wyo. Stat. 40-12-502. The law sets no fixed day count; entities must investigate promptly and notify as soon as misuse has occurred or is reasonably likely.
Wyoming's data breach notification law applies exclusively to individuals and commercial entities in the private sector. While the state does not impose a fixed notification deadline or require reporting to state agencies, its definition of personal identifying information is surprisingly broad, encompassing categories that many larger states have yet to adopt, including birth and marriage certificates, tribal identification cards, shared security tokens, and health insurance information.
The law is codified at Wyo. Stat. 40-12-501 (definitions) and Wyo. Stat. 40-12-502 (notification requirements). Originally enacted in 2007, the law was significantly amended in 2015 by Senate Files 35 and 36, which expanded the definition of personal identifying information and added specific notice content requirements.
For a broader look at Wyoming's privacy framework, see the parent guide to Wyoming Data Privacy Laws.
Who Must Comply
Wyoming's breach notification law applies to any individual or commercial entity that conducts business in Wyoming and that owns or licenses computerized data containing personal identifying information about Wyoming residents.
The law is specifically limited to the private sector. Government agencies are not covered by this statute, making Wyoming one of the few states where public entities have no statutory breach notification obligations under this particular law.
Third-party data custodians are also covered. If a person or entity that maintains computerized data containing personal identifying information on behalf of another entity discovers a breach, it must notify the data owner or licensee in the most expedient time possible. The data owner then bears responsibility for consumer notification.
What Qualifies as Personal Identifying Information

Wyoming's definition of personal identifying information is among the most comprehensive in the country. Under Wyo. Stat. 40-12-501(a)(vii), personal identifying information means a person's first name or first initial and last name combined with one or more of the data elements specified in Wyo. Stat. 6-3-901(b)(iii) through (xiv), when the data elements are not redacted:
- Social Security number
- Driver's license number
- Financial account number, credit card number, or debit card number combined with any security code, access code, or password permitting access to a financial account
- Tribal identification card
- Federal or state government-issued identification card
- Shared secrets or security tokens known to be used for data-based authentication
- Username or email address combined with a password or security question and answer permitting access to an online account
- Birth or marriage certificate
- Medical information, including medical history, mental or physical condition, or medical treatment or diagnosis by a healthcare professional
- Health insurance information, including policy numbers, subscriber IDs, unique insurer identifiers, and claims history
- Unique biometric data generated from measurements or analysis of human body characteristics for authentication purposes
- Individual taxpayer identification number
The inclusion of birth and marriage certificates, tribal IDs, shared authentication secrets, and health insurance claims history distinguishes Wyoming from the majority of states. The 2015 amendments added many of these expanded categories.
Personal identifying information does not include information contained in federal, state, or local government records or widely distributed media that are lawfully made available to the general public.
What Triggers the Notification Requirement
A "security breach" under Wyoming law means the unauthorized acquisition of computerized data that materially compromises the security, confidentiality, or integrity of personal identifying information and causes, or is reasonably believed to cause, loss or injury to a Wyoming resident.
The trigger involves a two-part analysis:
-
Material compromise: The unauthorized acquisition must materially compromise the security, confidentiality, or integrity of the data. Minor or inconsequential incidents may not meet this threshold.
-
Loss or injury: The breach must cause, or be reasonably believed to cause, loss or injury to a Wyoming resident.
When an entity becomes aware of a potential breach, it must conduct a good-faith, reasonable, and prompt investigation to determine the likelihood that personal identifying information has been or will be misused. If the investigation determines that misuse has occurred or is reasonably likely, notification is required.
Good-faith acquisition of personal identifying information by an employee or agent of the entity does not constitute a breach, provided the information is not used or disclosed in an unauthorized manner.
Notification Timeline
Wyoming requires notice "in the most expedient time possible and without unreasonable delay," consistent with the legitimate needs of law enforcement and with any measures necessary to determine the scope of the breach and restore the reasonable integrity of the computerized data system.
There is no specific day count. This open-ended standard allows entities flexibility for investigation but provides less certainty than states with fixed deadlines.
Law enforcement may request a delay in notification if it would impede a criminal investigation or jeopardize homeland security. Notification must proceed once the law enforcement agency determines it will no longer compromise the investigation.
What the Consumer Notice Must Include

The 2015 amendments added specific content requirements for breach notifications. The notice must include, at minimum:
- The types of personal identifying information that were or are reasonably believed to have been the subject of the breach
- A general description of the breach incident
- The approximate date of the breach, if reasonably determinable at the time of notice
- In general terms, the actions taken by the entity to protect the system from further breaches
- Advice directing the person to remain vigilant by reviewing account statements and monitoring credit reports
- Whether notification was delayed as a result of a law enforcement investigation, if reasonably determinable
- Toll-free contact telephone numbers and addresses for the major credit reporting agencies
The notice must be clear and conspicuous. These content requirements are more detailed than many states with open-ended notification standards.
Methods of Notification
Wyoming allows notification through one of the following methods:
- Written notice
- Electronic mail notice
- Substitute notice, if the entity demonstrates that the cost of notice would exceed the statutory threshold, the affected class exceeds the statutory threshold, or it does not have sufficient contact information (see Substitute Notice below)
Substitute Notice
Wyoming allows substitute notice, but the thresholds differ depending on whether the entity is based in Wyoming:
Wyoming-based entities may use substitute notice if:
- The cost of notice would exceed $10,000
- The affected class exceeds 10,000 persons
- The entity does not have sufficient contact information
Non-Wyoming-based entities may use substitute notice if:
- The cost of notice would exceed $250,000
- The affected class exceeds 500,000 persons
- The entity does not have sufficient contact information
Substitute notice requires email notification (if addresses are available) and conspicuous posting on the entity's website. If the entity does not have a website, substitute notice must include notification to major statewide media.
The lower thresholds for Wyoming-based entities reflect the smaller scale of many in-state businesses.
No Attorney General Notification

Wyoming does not require notification to the Attorney General or any other state agency when a data breach occurs. There is also no requirement to notify consumer reporting agencies, regardless of the number of affected residents.
This makes Wyoming one of the least demanding states in terms of government reporting obligations.
Encryption Safe Harbor
Wyoming provides an encryption safe harbor. The notification requirements apply only when the data was "not encrypted, redacted, or otherwise rendered unreadable." If the compromised data was properly encrypted at the time of the breach, notification is not required.
Exceptions
Under Wyo. Stat. 40-12-502(c), a financial institution that maintains notification procedures subject to the Gramm-Leach-Bliley Act is deemed in compliance with Wyoming's notification requirements if it notifies affected Wyoming customers under its federal obligations. Similarly, under Wyo. Stat. 40-12-502(h), a covered entity or business associate that complies with HIPAA is deemed in compliance with Wyoming's notification requirements if it notifies affected Wyoming customers under its federal obligations.
Enforcement
The Wyoming Attorney General may bring an action in law or equity to address any violation and for other relief that may be appropriate to ensure compliance, recover damages, or both.
There is no private right of action. Individual consumers cannot sue directly under this statute for notification failures.
The statute does not specify maximum penalty amounts, leaving enforcement remedies to the discretion of the courts. The AG may seek injunctive relief, compliance orders, and damages based on the circumstances of each case.
More Wyoming Laws
Frequently Asked Questions
How quickly must a Wyoming business notify consumers of a data breach?
Wyoming requires notification 'in the most expedient time possible and without unreasonable delay.' There is no specific day count. The entity must first conduct a good-faith investigation to determine whether personal identifying information has been or will be misused. If misuse has occurred or is reasonably likely, notification must follow as soon as possible. Law enforcement may request a delay to protect an investigation.
Does Wyoming require notification to the Attorney General for data breaches?
No. Wyoming does not require notification to the Attorney General, any state agency, or consumer reporting agencies. Notification obligations are limited to affected individuals. This makes Wyoming one of the least demanding states for government breach reporting.
What types of personal information trigger breach notification in Wyoming?
Wyoming has one of the broadest definitions of personal identifying information in the country. It includes Social Security numbers, driver's license numbers, financial account data, tribal IDs, government-issued IDs, shared secrets or security tokens, username/password combinations, birth or marriage certificates, medical information, health insurance data, biometric data, and taxpayer identification numbers.
Does Wyoming's data breach notification law apply to government agencies?
No. Wyoming's breach notification statute applies only to individuals and commercial entities conducting business in the state. Government agencies are not covered by this particular law, making Wyoming one of the few states where public entities have no statutory breach notification obligations under the data breach notification statute.
Can individuals sue for data breach notification violations in Wyoming?
No. Wyoming does not provide a private right of action for breach notification violations. Only the Wyoming Attorney General can bring enforcement actions. The AG may seek injunctive relief, compliance orders, and damages. The statute does not specify maximum penalty amounts.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the Exceptions section, which had misattributed Wyoming's HIPAA/GLBA breach-notification safe harbors to the wrong statute (40-12-505, which actually governs credit-report exceptions to a security freeze); the safe harbors are actually in 40-12-502(c) and 40-12-502(h). Also corrected the Methods of Notification list, which fabricated an E-SIGN Act condition and a telephonic-notice method not present in the statute; Wyoming's three methods are written notice, electronic mail notice, and substitute notice.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 4 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Wyoming Statutes, Title 40 - Trade and Commerce - Chapter 12: Consumer Protection - Article 5: Credit Freeze Reports
§ 40-12-501Definitions.In forcecited in 3 of our articles
(a) As used in this act: (i) "Breach of the security of the data system" means unauthorized acquisition of computerized data that materially compromises the security, confidentiality or integrity of personal identifying information maintained by a person or business and causes or is reasonably believed to cause loss or injury to a resident of this state. Good faith acquisition of personal identifying information by an employee or agent of a person or business for the purposes of the person or business is not a breach of the security of the data system, provided that the personal identifying information is not used or subject to further unauthorized disclosure; (ii) "Consumer" means any person who is utilizing or seeking credit for personal, family or household purposes; (iii) "Consumer reporting agency" means any person whose business is the assembling and evaluating of information as to the credit standing and credit worthiness of a consumer, for the purposes of furnishing credit reports, for monetary fees and dues to third parties; (iv) "Credit report" means any written or oral report, recommendation or representation of a consumer reporting agency as to the credit…
Official text (excerpt) · as of 2026-07-30 · Read the full section at wyoleg.gov
Also relied on in: Wyoming Biometric Privacy Laws: Collection, Consent & Penalties (2026), Wyoming Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
§ 40-12-502Computer security breach; notice to affected persons.In forcecited in 2 of our articles
(a) An individual or commercial entity that conducts business in Wyoming and that owns or licenses computerized data that includes personal identifying information about a resident of Wyoming shall, when it becomes aware of a breach of the security of the system, conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal identifying information has been or will be misused. If the investigation determines that the misuse of personal identifying information about a Wyoming resident has occurred or is reasonably likely to occur, the individual or the commercial entity shall give notice as soon as possible to the affected Wyoming resident. Notice shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system. (b) The notification required by this section may be delayed if a law enforcement agency determines in writing that the notification may seriously impede a criminal investigation.
Official text (excerpt) · as of 2026-07-30 · Read the full section at wyoleg.gov
§ 40-12-505Exceptions.In force
(a) Notwithstanding W.S. 40-12-503, a consumer reporting agency may furnish a consumer's credit report to a third party if: (i) The purpose of the credit report is to: (A) Use the credit report for purposes permitted under 15 U.S.C. § 1681b(c); (B) Review the consumer's account with the third party, including for account maintenance or monitoring, credit line increases or other upgrades or enhancements; (C) Collect on a financial obligation owed by the consumer to the third party requesting the credit report; (D) Collect on a financial obligation owed by the consumer to another person; or (E) The third party requesting the credit report is a subsidiary, affiliate, agent, assignee or prospective assignee of the person holding the consumer's account or to whom the consumer owes a financial obligation. (b) The consumer's request for a security freeze does not prohibit the consumer reporting agency from disclosing the consumer's credit report for other than credit related purposes consistent with the definition of credit report in W.S. 40-12-501(a).
Official text (excerpt) · as of 2026-07-30 · Read the full section at wyoleg.gov
Wyoming Statutes, Title 6 - Crimes and Offenses - Chapter 3: Offenses Against Property - Article 9: Theft of Identity
§ 6-3-901Unauthorized use of personal identifying information; penalties; restitution.In force
(a) Every person who willfully obtains personal identifying information of another person, and uses that information for any unlawful purpose, including to obtain, or attempt to obtain, credit, goods, services or medical information in the name of the other person without the consent of that person is guilty of theft of identity. (b) As used in this section "personal identifying information" means the name or any of the following data elements of an individual person: (i) Address; (ii) Telephone number; (iii) Social security number; (iv) Driver's license number; (v) Account number, credit card number or debit card number in combination with any security code, access code or password that would allow access to a financial account of the person; (vi) Tribal identification card; (vii) Federal or state government issued identification card; (viii) Shared secrets or security tokens that are known to be used for data based authentication; (ix) A username or email address, in combination with a password or security question and answer that would permit access to an online account; (x) A birth or marriage certificate; (xi) Medical information, meaning a person’s medical…
Official text (excerpt) · as of 2026-07-30 · Read the full section at wyoleg.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Wyo. Stat. 40-12-501 Definitions(law.justia.com)
- Wyo. Stat. 40-12-502 Computer Security Breach Notice(law.justia.com)
- Wyo. Stat. 6-3-901 Personal Identifying Information(law.justia.com)
- Wyoming Attorney General Privacy(ag.wyo.gov).gov
- Wyoming Legislature SF 53 Original Bill(wyoleg.gov).gov
- HIPAA Information(hhs.gov).gov
- Gramm-Leach-Bliley Act(ftc.gov).gov