EnglishEspañol
District of Columbia flag

District of Columbia

District of Columbia Data Privacy Laws: Breach Rules & Consumer Rights (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 22 primary sources cited on this page. How we verify our legal content

District of Columbia Data Privacy Laws: Breach Rules & Consumer Rights (2026)

Frequently Asked Questions

Does DC have a comprehensive consumer data privacy law like California or Virginia?

No. As of May 2026, the District of Columbia does not have a comprehensive consumer data privacy law comparable to the California Consumer Privacy Act or the Virginia Consumer Data Protection Act. DC relies on a combination of its breach notification law (D.C. Code Sections 28-3851 through 28-3853), the Consumer Protection Procedures Act (D.C. Code Chapter 39 of Title 28), and the Protecting Students Digital Privacy Act (D.C. Law 21-218), along with federal privacy laws. Legislation is pending in the 26th Council session, including B26-0525 (Personal Health Data Security Amendment Act) and B26-0670 (DC Government Data Privacy and Protection Act of 2026), but neither has passed as of May 2026.

How quickly must businesses notify DC residents and the Attorney General after a data breach?

DC law requires notification in the most expedient time possible and without unreasonable delay. The statute does not set a specific number of days. Written notice to the DC Attorney General is required when a breach affects 50 or more District residents, and that notice must be sent no later than when notice is provided to affected individuals. The Attorney General notification must include the nature of the incident, types of personal information compromised, number of affected residents, remedial actions taken, and any knowledge of foreign country involvement.

What types of data are covered under DC breach notification law after the 2020 amendments?

The 2020 Security Breach Protection Amendment Act (D.C. Law 23-98) significantly expanded DC's definition of personal information. Covered data now includes Social Security numbers, taxpayer identification numbers, passport numbers, driver's license or DC identification numbers, military identification numbers, financial account numbers with access credentials, medical information about dental, medical, or mental health treatment, health insurance policy numbers and subscriber identifiers, biometric data such as fingerprints, voice prints, genetic prints, and retina or iris images used for identity authentication, and genetic information and deoxyribonucleic acid (DNA) profile as a separate covered category.

Are DC government agencies subject to the same data breach notification rules as private businesses?

No. D.C. Code Section 28-3851 specifically excludes the District of Columbia government and its agencies and instrumentalities from the definition of 'person or entity' subject to the breach notification law. DC government agencies are instead subject to separate data governance and privacy policies established by the DC Office of the Chief Technology Officer and other District agencies. However, private contractors handling personal data on behalf of DC government agencies may still be subject to the breach notification requirements for data they maintain, handle, or possess.

What penalties can the DC Attorney General impose for violations of data privacy laws?

Violations of DC's breach notification law are classified as unfair or deceptive trade practices under D.C. Code Section 28-3904. The DC Attorney General can seek civil penalties of up to $5,000 per first violation and up to $10,000 per subsequent violation under D.C. Code Section 28-3909. The Attorney General can also obtain temporary or permanent injunctions, orders requiring corrective action, and consumer restitution without needing to prove damages. The 2023 Blackbaud settlement, in which the AG secured over $355,000 plus data security overhaul commitments, illustrates how these enforcement tools are applied in practice.

Is DC a one-party or two-party consent state for recording conversations?

DC is a one-party consent jurisdiction under D.C. Code § 23-542. You may legally record a phone call or in-person conversation you are participating in without notifying other parties. However, the one-party consent exception does not apply if the recording is made for the purpose of committing a crime, tortious act, or other injurious act under federal or DC law. Violating § 23-542 can result in criminal penalties of up to five years imprisonment and civil liability for the greater of actual damages, $100 per day, or $1,000, plus punitive damages and attorney's fees.

What does the TAKE IT DOWN Act require, and does it apply to DC residents?

Yes, the TAKE IT DOWN Act (Pub. L. 119-12) applies nationwide, including DC residents. Signed into law with bipartisan support, the Act criminalizes publishing nonconsensual intimate visual depictions, including AI-generated deepfakes. As of May 19, 2026, covered online platforms must operate a removal request process and remove flagged content within 48 hours of a valid request. The FTC enforces these platform obligations and may impose civil penalties up to $53,088 per violation. DC residents who are victims of nonconsensual intimate imagery can submit removal requests directly to covered platforms under this federal law.

How can DC residents file a privacy or data breach complaint?

DC residents can file consumer protection and data privacy complaints directly with the DC Office of the Attorney General at oag.dc.gov. The OAG's Consumer and Tenant Response Team handles complaints and has secured millions in consumer restitution through mediation. For federal privacy violations, residents can also file complaints with the FTC at ftc.gov/complaint. For health-related privacy violations involving HIPAA-covered entities, complaints go to the HHS Office for Civil Rights at hhs.gov/hipaa. For student data privacy violations, contact the DC Office of the State Superintendent of Education (OSSE).

What is the status of DC's pending health data privacy bills?

As of May 2026, two health data privacy bills are pending in the DC 26th Council. B26-0525 (Personal Health Data Security Amendment Act of 2025), introduced December 1, 2025, would prohibit geofencing near health facilities, require consent for health data collection and sharing, and establish deletion rights. It received a roundtable hearing March 23, 2026, and remains in committee. An earlier bill, CHIPPA (B25-0930), died in the 25th Council without passing. Neither bill has been enacted into law.

Updates

Corrected the citation for the cumulative rights-and-remedies rule to D.C. Code Section 28-3853(c), cited Section 28-3852.02 for the 18-month identity theft protection duty, dated the Blackbaud settlement to October 2023, and corrected the Google Play settlement's final approval to the August 18, 2026 judgment (April 30, 2026 was the fairness hearing).

Updated the Google Play Store settlement status to reflect final court approval on April 30, 2026 (it previously showed only the November 2025 preliminary approval), and fixed a dead link on the D.C. Code Section 38-831.03 citation.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Added genetic information and DNA profile data, a data element D.C. Code Section 28-3851 lists separately from medical information, to the personal-information definition list, which had omitted it.

Added D.C. Code 28-3851's separate 'genetic information and DNA profile' personal-information category to the KeyTakeaways summary and FAQ answer, which still omitted it after the article body was corrected.

Governing law re-checked for recent changes

May 2026 refresh: Added DC Recording and Wiretap Law section (D.C. Code § 23-542 one-party consent rule, penalties, civil liability). Expanded enforcement section with Google $9.5M location tracking settlement (AG Racine, 2022), Google Play Store $700M settlement (AG Schwalb, 2023), and DC v. Meta/Zuckerberg Cambridge Analytica case status (revived Aug 2025; Zuckerberg motion to dismiss denied May 2026). Added TAKE IT DOWN Act (Pub. L. 119-12) federal overlay sub-section with FTC enforcement live as of May 19, 2026. Updated CHIPPA status: B25-0930 died in 25th Council without passing; added 26th Council bills B26-0525 and B26-0670. Updated $50M enforcement figure to $906.8M total (2025 Impact Report). Added four new FAQ entries on recording consent, TAKE IT DOWN Act, filing complaints, and pending bill status. Updated meta description and KeyTakeaways to reflect TAKE IT DOWN Act and one-party consent additions. Old meta: 'District of Columbia data privacy laws require breach notification under D.C. Code 28-3851 to 28-3853, reasonable security safeguards, and student digital privacy protections.'

Reviewed and approved by an editor

Sources and References

  1. D.C. Code Section 28-3851: Definitions(code.dccouncil.gov).gov
  2. D.C. Code Section 28-3852: Notification of Security Breach(code.dccouncil.gov).gov
  3. D.C. Code Section 28-3852.01: Security Requirements(code.dccouncil.gov).gov
  4. D.C. Code Section 28-3852.02: Remedies(code.dccouncil.gov).gov
  5. D.C. Code Section 28-3853: Enforcement(code.dccouncil.gov).gov
  6. D.C. Law 23-98: Security Breach Protection Amendment Act of 2020(code.dccouncil.gov).gov
  7. D.C. Code Chapter 39: Consumer Protection Procedures Act(code.dccouncil.gov).gov
  8. D.C. Code Section 28-3909: Restraining Prohibited Acts(code.dccouncil.gov).gov
  9. D.C. Law 21-218: Protecting Students Digital Privacy Act of 2016(code.dccouncil.gov).gov
  10. D.C. Code Section 38-831.02: Operator Obligations(code.dccouncil.gov).gov
  11. D.C. Code Section 38-831.04: Student Account Privacy(code.dccouncil.gov).gov
  12. DC AG: Consumer Alert on Online Privacy(oag.dc.gov).gov
  13. DC AG: Blackbaud Settlement(oag.dc.gov).gov
  14. DC AG: CHIPPA Introduction(oag.dc.gov).gov
  15. OSSE: Student Privacy Policy(osse.dc.gov).gov
  16. FTC: Privacy and Security Enforcement(ftc.gov).gov
  17. D.C. Code § 23-542: Interception, Disclosure, and Use of Wire or Oral Communications Prohibited(code.dccouncil.gov).gov
  18. DC Attorney General: AG Racine Announces Google Must Pay $9.5 Million for Deceptive Location Tracking (2022)(oag.dc.gov).gov
  19. DC Attorney General: Schwalb Announces $700 Million Multistate Settlement With Google (2023)(oag.dc.gov).gov
  20. DC Attorney General: AG Racine Sues Mark Zuckerberg for Cambridge Analytica Privacy Failures(oag.dc.gov).gov
  21. DC Attorney General: 2025 Impact Report(oag.dc.gov).gov
  22. DC Council LIMS: B25-0930 Consumer Health Information Privacy Protection Act (25th Council)(lims.dccouncil.gov).gov
  23. In re Google Play Consumer Antitrust Litigation, No. 3:20-cv-05761 (N.D. Cal.): Docket (final judgment entered Aug. 18, 2026)(courtlistener.com)
Share: