Georgia
Georgia Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 3 primary sources cited on this page. How we verify our legal content

Georgia requires data collectors and information brokers to notify affected residents of a security breach in the most expedient time possible and without unreasonable delay under O.C.G.A. 10-1-912. The law sets no specific deadline in days and imposes no penalties for late notification.

Georgia's data breach notification law (Ga. Code 10-1-910 through 10-1-912) was enacted in 2005 and then substantially rewritten by Ga. L. 2007, p. 450 (SB 236), the Act that supplied the short title "Georgia Personal Identity Protection Act," added state and local agencies as covered "data collectors," replaced the earlier "immediately" reporting rule for third-party processors with the current 24 hour deadline, and lowered the substitute notice thresholds from $250,000 and 500,000 individuals to $50,000 and 100,000. Neither section has been amended since. While all 50 states now have breach notification laws on the books, Georgia's stands out for what it lacks: no hard notification deadline, no Attorney General reporting requirement, no specific penalties, and no private right of action for affected consumers.
This law binds only information brokers and government data collectors, plus their third-party data processors; most ordinary Georgia businesses that hold customer data for their own purposes have no notification duty under this statute at all. For the entities the law does cover, notification obligations are relatively light compared to neighboring states. For Georgia residents, it means fewer legal protections when their personal data is compromised. This guide breaks down exactly what the law requires, where it falls short, and what reform efforts have looked like.
Who Must Comply
Georgia's breach notification law applies to two categories of entities defined under Ga. Code 10-1-911:
Information brokers are persons or entities that collect and transmit personal information about individuals to third parties for purposes unrelated to the transaction. Think data brokers, consumer reporting companies, and background check services.
Data collectors are state and local government agencies that maintain computerized data containing personal information of individuals. Certain government agencies focused on traffic safety, law enforcement, or licensing are excluded from this definition.
Any person or business that maintains computerized data on behalf of an information broker or data collector also has obligations under the law. These third-party service providers must notify the data owner within 24 hours of discovering a breach.
What Triggers a Notification
A "breach of the security of the system" means the unauthorized acquisition of an individual's electronic data that compromises the security, confidentiality, or integrity of personal information maintained by an information broker or data collector.
The key word is "acquisition." Good-faith access by an employee or agent of the information broker or data collector does not count as a breach, as long as the personal information is not used for an unauthorized purpose or disclosed to an unauthorized third party.
Definition of Personal Information
Under Ga. Code 10-1-911(6), protected personal information means an individual's first name or first initial and last name combined with any one or more of:
- Social Security number
- Driver's license or state identification card number
- Financial account number, credit card number, or debit card number, if usable without additional identifying information, access codes, or passwords
- Account passwords, PINs, or other access codes
The definition also covers standalone data elements (without the name) if the compromised information would be sufficient to perform or attempt identity theft.
Georgia's definition is notably narrow. Unlike states such as Delaware or California, Georgia does not include medical records, health insurance information, biometric data, passport numbers, or taxpayer identification numbers as protected data elements.
Publicly available information from government records is excluded.
Notification Timeline
Georgia requires notification "in the most expedient time possible and without unreasonable delay." The law does not set a specific number of days.
This vague standard gives businesses flexibility, but it also gives consumers little recourse if a company drags its feet. Compare this to Alabama (45 days), Florida (30 days), or Colorado (30 days), which all set firm deadlines.
The notification timeline can account for:
- Measures necessary to determine the scope of the breach
- Steps needed to restore the reasonable integrity of the data system
- Legitimate law enforcement needs (notification may be delayed if law enforcement determines it would impede a criminal investigation)
How Notification Must Be Provided
Entities can notify affected Georgia residents through any of the methods listed in the definition of "notice" at Ga. Code 10-1-911(4):
- Written notice sent to the individual
- Telephone notice to the individual
- Electronic notice that complies with the federal E-SIGN Act (15 U.S.C. 7001)
Substitute Notice
Substitute notice, under Ga. Code 10-1-911(4)(D), is available when direct notification is impractical because:
- The cost of providing notice exceeds $50,000
- The number of affected individuals exceeds 100,000
- The entity does not have sufficient contact information
Substitute notice requires all three of these steps:
- Email notice to affected individuals (if addresses are available)
- Conspicuous posting on the entity's website (if one is maintained)
- Notification through major statewide media
Notice Content
Georgia's statute does not specify what information the notification must contain. This is another gap. Many states require notifications to include a description of the breach, the types of data exposed, steps the consumer can take, and contact information for the company. Georgia leaves the content entirely to the notifying entity's discretion.
Government Agency Notification
Georgia does not require notification to the Attorney General or any other state agency under the general breach notification statute. This is a significant gap. Most states now require some form of government notification, either to the AG or to a designated state agency, so that regulators can monitor breach trends and pursue enforcement when warranted.
The only government-related notification requirement is to consumer reporting agencies (Equifax, Experian, TransUnion) when a breach affects more than 10,000 Georgia residents. In that case, the entity must notify the agencies promptly regarding the timing, distribution, and content of the individual notices.
Encryption Safe Harbor
Georgia provides a clear encryption safe harbor. The notification requirement does not apply to data that was encrypted or redacted at the time of the breach. If the personal information was properly encrypted, even a confirmed unauthorized acquisition does not trigger notification obligations.
The statute does not address scenarios where the encryption key itself is compromised. Some states, like Delaware, explicitly state that the safe harbor does not apply if the encryption key was also acquired. Georgia's law is silent on this point.
Penalties and Enforcement
This is where Georgia's law is weakest.
The general breach notification statute (Ga. Code 10-1-912) contains no specific penalties for failure to notify. It also provides no regulatory enforcement mechanism and no private right of action for affected individuals.
Some legal analyses note that a violation could potentially be treated as an unfair or deceptive practice under Georgia's Fair Business Practices Act (Ga. Code 10-1-390 et seq.), which authorizes civil penalties of up to $2,000 per willful violation when the Attorney General acts administratively (O.C.G.A. 10-1-397), up to $5,000 per violation in a superior court action, and up to $25,000 per violation for violating an injunction (O.C.G.A. 10-1-405). However, the breach notification statute itself does not explicitly incorporate this remedy, and the practical enforcement record is minimal.
Without a private right of action, Georgia residents cannot directly sue a company for failing to provide timely breach notification. Without mandatory AG notification, the Attorney General's office may not even learn about breaches that affect Georgia residents. This creates a significant enforcement vacuum.
The Telecom Exception: Ga. Code 46-5-214
Georgia has a separate, slightly stronger breach notification provision for telecommunications companies. Under Ga. Code 46-5-214, telecom providers must notify Georgia residents when a breach of telephone records occurs that is "reasonably likely to cause quantifiable harm."
Unlike the general statute, violations of 46-5-214 are explicitly classified as unfair or deceptive practices under the Fair Business Practices Act, giving the Attorney General clearer enforcement authority over telecom breaches.
How Georgia Compares to Neighboring States
Georgia's breach notification law is among the weakest in the Southeast. Here is how it stacks up against its neighbors:
| Requirement | Georgia | Alabama | Florida | South Carolina | Tennessee |
|---|---|---|---|---|---|
| Notification deadline | No specific deadline | 45 days | 30 days | Without unreasonable delay | 45 days |
| AG notification | Not required | Required | Required (500+) | Required (1,000+) | Not required |
| Specific penalties | None | Up to $500,000/breach | $1,000/day | $1,000/violation | Not specified |
| Private right of action | No | No | No | No | No |
| Broad PI definition | No | Yes | Yes | No | No |
Alabama's law, enacted in 2018, is particularly instructive. The Alabama Data Breach Notification Act includes a 45-day deadline, mandatory AG notification, penalties up to $500,000 per breach plus $5,000 per day for late notification, and a broader definition of personal information. Georgia's law has seen no comparable update since 2007.
Reform Efforts: SB 111 and What Actually Happened
Georgia's legislature attempted to modernize the state's data privacy framework, but the effort did not survive intact.
In the 2025 legislative session, Senate Bill 111, the Georgia Consumer Privacy Protection Act, passed the Georgia Senate by a vote of 53 to 2. The bill would have created a comprehensive consumer data privacy framework modeled after Virginia's approach, applying to entities with over $25 million in annual revenue processing data of at least 175,000 Georgia residents.
The bill did not make it out of the Georgia House in 2025. The House withdrew and recommitted the bill on March 27, 2025. Georgia's General Assembly runs on a two-year biennium, so the bill carried over into 2026 rather than dying with the session.
Privacy advocates were critical of the bill even before its 2025 stall. The Electronic Privacy Information Center (EPIC) gave the bill a score of 6 out of 10, and the ACLU of Georgia called it potentially "the worst consumer protection act in the country."
In 2026, a House committee replaced SB 111's entire privacy text with an unrelated substitute expanding tax-credit eligibility for rural hospitals. The House passed that substitute 162 to 1 on March 31, 2026, the Senate agreed to it on April 2, 2026, and Governor Kemp signed it into law as Act 462 on May 11, 2026, effective July 1, 2026. The Governor's own signing announcement describes the law solely as a rural hospital tax measure, with no mention of consumer privacy or data breach rules.
No standalone Georgia comprehensive privacy bill has been enacted. Georgia's breach notification law, last amended in 2007, continues to operate without meaningful updates.
Practical Steps for Georgia Residents

If you receive a data breach notification, the Georgia Attorney General's Consumer Protection Division recommends these steps:
- Place a credit freeze with all three major credit bureaus (Equifax: 1-888-766-0008, Experian: 1-888-397-3742, TransUnion: 1-800-680-7289)
- Set fraud alerts on your credit files
- Monitor financial accounts closely for unauthorized transactions
- Change passwords on any accounts that may have been affected
- File an identity theft report at identitytheft.gov if you suspect fraud
You can file a complaint with the Georgia Attorney General at (404) 651-8600 or toll-free at (800) 869-1123.
For a broader overview of Georgia's data privacy landscape, including the state's approach to consumer privacy rights and data protection beyond breach notification, see our Georgia Data Privacy Laws guide.
This article provides general legal information about Georgia's data breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in Georgia for guidance specific to your situation.
More Georgia Laws
Frequently Asked Questions
Does Georgia have a specific deadline for data breach notifications?
No. Georgia requires notification 'in the most expedient time possible and without unreasonable delay,' but the statute does not set a specific number of days. This contrasts with states like Florida (30 days) and Alabama (45 days) that impose firm deadlines.
Do companies have to notify the Georgia Attorney General about a data breach?
No. Georgia's general breach notification statute does not require notification to the Attorney General or any state agency. The only government-related requirement is notifying consumer reporting agencies when more than 10,000 Georgia residents are affected.
What penalties does Georgia impose for failing to notify consumers of a data breach?
Georgia's breach notification statute does not contain specific penalties for non-compliance. There is no private right of action for consumers and no designated enforcement mechanism. Some legal analyses suggest a violation could be treated as an unfair practice under the Fair Business Practices Act, but the practical enforcement record is minimal.
Does Georgia's breach notification law cover medical records or biometric data?
No. Georgia's definition of personal information is limited to name combined with Social Security numbers, driver's license numbers, financial account data with access codes, and account passwords. Medical records, health insurance information, biometric identifiers, and passport numbers are not covered.
Is encrypted data exempt from Georgia's breach notification requirement?
Yes. Georgia provides an encryption safe harbor. If personal information was encrypted or redacted at the time of the breach, the notification requirement does not apply. However, unlike some states, Georgia's law does not address whether the safe harbor still applies if the encryption key was also compromised.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the citation for Georgia's notice methods and substitute notice thresholds, which are set by O.C.G.A. 10-1-911(4) rather than 10-1-912, and added the 2007 amendment (Ga. L. 2007, p. 450 / SB 236) that rewrote both sections.
Corrected a fabricated $100-per-violation Fair Business Practices Act penalty figure (the statute actually authorizes $2,000 to $25,000 per violation depending on the enforcement path), narrowed overbroad statements that all Georgia businesses must notify residents of a breach (the duty applies only to information brokers, government data collectors, and their processors), updated the SB 111 legislative history to report that the bill carried into 2026 and was enacted as an unrelated rural-hospital tax-credit law rather than dying in 2025, corrected the consumer-reporting-agency notification threshold from '10,000 or more' to the statute's own 'more than 10,000,' and replaced a dead Perkins Coie citation with a live NCSL source.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Official Code of Georgia Annotated
§ 10-1-912Notification required upon breach of security regarding personal information.In forcecited in 3 of our articles
(a) Any information broker or data collector that maintains computerized data that includes personal information of individuals shall give notice of any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of this state…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legis.ga.gov
Cited in 3 court opinions in our collectionLatest citing opinion in our collection: 2019
Opinions citing this section in our collection:
- McCONNELL Et Al. v. DEPARTMENT OF LABOR (Court of Appeals of Georgia 2016, 337 Ga. App. 457)“…is of the timing, distribution, and content of the notices. OCGA §10-1-912. See OCGA § 10-1-911 (1) (definition of…”
- In re Equifax, Inc. (District Court, N.D. Georgia 2019, 362 F. Supp. 3d 1295)“…The Court agrees that the absence of any such language in O.C.G.A. § 10-1-912 counsels strongly against inferring a p…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Georgia Biometric Privacy Laws: Collection, Consent & Penalties (2026), Georgia Data Privacy Laws: Breach Notification & Consumer Rights (2026)
§ 10-1-911Definitions.In forcecited in 3 of our articles
As used in this article, the term: (1) "Breach of the security of the system" means unauthorized acquisition of an individual's electronic data that compromises the security, confidentiality, or integrity of personal information of such individual maintained by an information broker or data collect
Official text (excerpt) · last checked 2026-08-04 · Read the full text in our law library · Verify at legis.ga.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2018
Opinions citing this section in our collection:
- McCONNELL Et Al. v. DEPARTMENT OF LABOR (Court of Appeals of Georgia 2016, 337 Ga. App. 457)“…stribution, and content of the notices. OCGA §10-1-912. See OCGA § 10-1-911 (1) (definition of a “breach of the sec…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 46-5-214Action in event of telephone record security breach; notification to Georgia residents; law enforcement exception; violations shall be unfair or deceptive practice in consumer transactions.In force
(a) In the event of a breach of a telephone record concerning a Georgia resident, the telecommunications company must provide notice to the Georgia resident immediately following discovery or notification of the breach if such breach is reasonably likely to cause quantifiable harm to the Georgia…
Official text (excerpt) · last checked 2021-08-17 · Read the full text in our law library
§ 10-1-397Cease and desist orders; civil penalty; judicial relief; receivers.In force
(a) As used in this Code section, the term: (1) "Call" means any communication, message, signal, or transmission. (2) "Telecommunications company" shall have the same meaning as provided in Code Section 46-5-162. (3) "Telecommunications services" shall have the same meaning as provided in Code…
Official text (excerpt) · last checked 2021-08-17 · Read the full text in our law library
Cited in 7 court opinions in our collectionLatest citing opinion in our collection: 2021
Opinions citing this section in our collection:
- State Ex Rel. Doyle v. Frederick J. Hanna & Associates, P.C. (Supreme Court of Georgia 2010, 287 Ga. 289)“…applied to promote its underlying purposes and policies"); OCGA § 10-1-397 (Administrator authorized to issue ceas…”
- Tiismann v. Linda Martin Homes Corp. (Supreme Court of Georgia 2006, 281 Ga. 137)“…e Court of Appeals correctly recognized it as such. Compare OCGA § 10-1-397 (a), which authorizes the administrator…”
- MOORE DAVIS MOTORS, INC. v. Joyner (Court of Appeals of Georgia 2001, 252 Ga. App. 617)“…OCGA § 10-1-393 (b) (7), (9). 6 See OCGA § 10-1-397 (a). 7 OCGA § 10-1…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 10-1-405Civil penalties; individual liability.In force
(a) Any person who violates the terms of an injunction issued under Code Section 10-1-397 shall forfeit and pay to the state a civil penalty of not more than $25,000.00 per violation.…
Official text (excerpt) · last checked 2021-08-17 · Read the full text in our law library
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2022
Opinions citing this section in our collection:
- BROWN v. MEDSCOPE AMERICA CORPORATION (District Court, M.D. Georgia 2022)“…eorgia’s Fair Business Practices Act, specifically O.C.G.A. § 10-1-405(c), only applies to “agents wh…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
United States Code Title 15
§ 7001General rule of validityIn forcecited in 18 of our articles
Notwithstanding any statute, regulation, or other rule of law (other than this subchapter and subchapter II), with respect to any transaction in or affecting interstate or foreign commerce— a signature, contract, or other record relating to such transaction may not be denied legal effect, validity, or enforceability solely because it is in electronic form; and a contract relating to such transaction may not be denied legal effect, validity, or enforceability solely because an electronic signature or electronic record was used in its formation. This subchapter does not— limit, alter, or otherwise affect any requirement imposed by a statute, regulation, or rule of law relating to the rights and obligations of persons under such statute, regulation, or rule of law other than a requirement that contracts or other records be written, signed, or in nonelectronic form; or require any person to agree to use or accept electronic records or electronic signatures, other than a governmental agency with respect to a record other than a contract to which it is a party.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 132 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Metropolitan Regional Information Systems v. American Home Realty Network (2012) applied 15 U.S.C. 7001(a) to hold an electronic assignment process satisfied the signed writing requirement of Copyright Act 204(a). Blatt v. Capital One Auto Finance (2017) held 7001(c) disclosures were not required where the record was delivered on paper.
Opinions citing this section in our collection:
- Metropolitan Regional Information Systems, Inc. v. American Home Realty Network, Inc. (District Court, D. Maryland 2012, 904 F. Supp. 2d 530)✓Subscribers assigned photo copyrights to a real estate database by uploading images under online terms of use; the court relied on E-SIGN, 15 U.S.C. section 7001, to hold those electronic assignments met the Copyright Act signed-writing rule, and denied reconsideration.
- Cutrone v. Mortgage Electronic Registration Systems, Inc. (District Court, E.D. New York 2013, 981 F. Supp. 2d 144)✓Homeowners sued MERS in state court over a second mortgage recording tax on an E-Sign mortgage; MERS removed under 15 U.S.C. section 7001, but the court held that statute gives no private right of action and at most a federal defense, which cannot support removal, and remanded.
- Blatt v. Capital One Auto Finance, Inc. (District Court, M.D. Tennessee 2017, 237 F. Supp. 3d 688)“…legal effect ..solely because it is in electronic form[.]” 15 U.S.C. § 7001 (a)(1).. Furthermore, it mandates that…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Mississippi Data Breach Notification Laws: Reporting Rules & Timelines (2026), Mississippi Data Privacy Laws: Breach Notification & Consumer Rights (2026), Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Ga. Code 10-1-910 through 10-1-912 (Personal Identity Protection Act)(law.justia.com)
- Ga. Code 10-1-912 (Notification Required Upon Breach)(law.justia.com)
- Ga. Code 10-1-911 (Definitions)(law.justia.com)
- Ga. Code 46-5-214 (Telephone Record Security Breach)(law.justia.com)
- Georgia Attorney General: Data Breaches(consumer.georgia.gov).gov
- Georgia Attorney General Consumer Ed: Breach Notification(consumered.georgia.gov).gov
- Georgia SB 111 (2025-2026 Session)(legis.ga.gov).gov
- EPIC: Georgia Privacy Bill Failing Grade(epic.org)
- ACLU of Georgia: Consumer Privacy Bill Report(acluga.org)
- Davis Wright Tremaine: Georgia Breach Summary(dwt.com)
- NCSL: Security Breach Notification Laws (50-state survey)(ncsl.org)
- Ga. L. 2007, p. 450 (SB 236), Georgia Personal Identity Protection Act, as passed(legis.ga.gov)