EnglishEspañol
District of Columbia flag

District of Columbia

District of Columbia Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 12 primary sources cited on this page. How we verify our legal content

District of Columbia Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must I notify DC residents after a data breach?

DC law requires notification in the most expedient time possible and without unreasonable delay. Unlike some states that set a specific deadline (such as 30 or 60 days), DC uses a reasonableness standard. You may delay notification only if law enforcement determines it would impede a criminal investigation, or if you need time to determine the scope of the breach and restore data system integrity.

When do I need to notify the DC Attorney General about a breach?

You must notify the DC Attorney General whenever a breach affects 50 or more District of Columbia residents. This is one of the lowest AG notification thresholds in the country. The written notice to the AG must be sent no later than when you notify affected residents. DC Code 28-3852(b-1) lists eleven required items, including the nature of the breach, the types of personal information compromised, the number of affected residents, the cause of the breach, remedial action taken, the date and time frame of the breach, contact information for both the reporting entity and the breached entity, any knowledge of foreign country involvement, and a sample of the notice you will send to residents.

Does DC law require me to offer free identity theft protection after a breach?

Yes, but only when the breach involves Social Security numbers or taxpayer identification numbers. In those cases, you must offer affected DC residents free identity theft protection services for at least 18 months and provide all information necessary for enrollment. This requirement is longer than the 12-month standard used by many states.

Can DC residents sue a company for a data breach?

Yes. DC classifies breach notification violations as unfair or deceptive trade practices under DC Code 28-3904(kk). Affected consumers can file suit in DC Superior Court and recover actual damages, not the treble damages/$1,500-per-violation minimum available for other consumer protection claims, which DC Code 28-3905(k)(2) specifically carves out for 28-3904(kk) violations, plus reasonable attorney fees, punitive damages, and injunctive relief.

Does encryption protect my organization from DC breach notification requirements?

DC provides an encryption safe harbor. If personal information was encrypted or redacted and the unauthorized party did not also obtain the decryption keys or means to undo the redaction, the acquisition does not constitute a breach under DC law, and you are not required to notify. However, if the encryption keys were also compromised, the safe harbor does not apply.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected and expanded the breach-notification detail: the risk-of-harm exclusion now states the required consultation with the DC Attorney General and federal law enforcement, the Attorney General notice list is complete at all eleven statutory items, substitute notice covers national as well as local media, the consumer reporting agency duty notes its Gramm-Leach-Bliley carve-out, and the tailored notice route for username or email credential breaches was added.

Fixed a dead statute link for DC Code 28-3852.02, corrected the personal-information definition to match the statute's actual 'first name, first initial and last name, or any other personal identifier' language (removing an invented phone/address alternative), fixed the consumer-reporting-agency notice threshold to 'more than 1,000' individuals, and added the Attorney General's $5,000/$10,000 per-violation civil penalty authority under DC Code 28-3909(b).

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Corrected the private-right-of-action remedy: DC Code 28-3853(b) classifies ALL breach-notification-subchapter violations (both notification and security-requirement failures) as an unfair trade practice specifically under 28-3904(kk), and 28-3905(k)(2)(A)(ii) limits (kk) violations to actual damages, not the treble damages/$1,500 minimum the article had described.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. DC Code 28-3851 - Definitions(code.dccouncil.gov).gov
  2. DC Code 28-3852 - Notification of security breach(code.dccouncil.gov).gov
  3. DC Code 28-3852.01 - Security requirements(code.dccouncil.gov).gov
  4. DC Code 28-3852.02 - Remedies(code.dccouncil.gov).gov
  5. DC Code 28-3853 - Enforcement(code.dccouncil.gov).gov
  6. DC Code 28-3904 - Unfair or deceptive trade practices(code.dccouncil.gov).gov
  7. DC Code 28-3905 - Complaint procedures(code.dccouncil.gov).gov
  8. D.C. Law 23-98 - Security Breach Protection Amendment Act of 2020(code.dccouncil.gov).gov
  9. DC OAG Consumer Privacy Information(oag.dc.gov).gov
  10. AG Schwalb Blackbaud Data Breach Settlement(oag.dc.gov).gov
  11. Equifax Data Breach Settlement(oag.dc.gov).gov
  12. Uber Data Breach Settlement(oag.dc.gov).gov
  13. 45 C.F.R. 160.103 - HIPAA definitions (genetic information)(ecfr.gov)
Share: