Hawaii
Hawaii Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Hawaii requires businesses and government agencies to notify affected residents of a data breach without unreasonable delay under HRS 487N-2. A business that notifies more than 1,000 people at one time must also send written notice to the state Office of Consumer Protection and to the nationwide consumer reporting agencies.
Hawaii requires businesses and government agencies to notify residents when their personal information has been compromised in a data breach. The state's Security Breach of Personal Information law, codified at HRS Chapter 487N, was originally enacted in 2006 and has been updated to reflect modern data security concerns.
Hawaii's law stands out for two reasons. First, it covers both electronic and paper records, not just computerized data. Second, it provides affected individuals with a private right of action, allowing them to sue for actual damages and recover attorney's fees. These provisions make Hawaii's breach notification framework stronger than many other states.
This guide covers the notification requirements, timelines, penalties, and enforcement mechanisms under Hawaii law.
For broader context on Hawaii's overall privacy framework, see the parent guide to Hawaii Data Privacy Laws.
Who Must Comply
Hawaii's breach notification law applies to three categories of entities under HRS 487N-2:
Businesses that own or license personal information of Hawaii residents must notify affected individuals when a breach occurs.
Businesses that conduct business in Hawaii and own or license personal information in any form, whether computerized, paper, or otherwise, must also comply.
Government agencies that collect personal information for specific government purposes have the same notification obligations.
This broad applicability means that any business handling the personal information of Hawaii residents, regardless of where the business is located, must comply with the notification requirements.
What Qualifies as Personal Information
Under HRS 487N-1, "personal information" means an individual's first name or first initial and last name combined with one or more of the following data elements:
- Social Security number
- Driver's license number or Hawaii identification card number
- Account number, credit or debit card number, or access code or password that would allow access to a financial account
The definition excludes publicly available information that is lawfully made available to the general public from federal, state, or local government records.
Proposed Expansion of the Definition
Hawaii legislators have tried across two sessions to widen this definition, and neither attempt has become law.
SB 1038 would add a definition of "specified data element" and expand the definition of personal information. It passed Second Reading in the House as HD 1 on March 19, 2025 and was referred to the Committee on Consumer Protection and Commerce. Its last recorded action was being carried over to the 2026 Regular Session on December 8, 2025, which leaves it dormant rather than formally dead.
The successor measure, SB 3016, moved further in 2026. It adds definitions of "identifier" and "specified data element," amends the definition of personal information for breach notification purposes, and treats telecommunications carriers that comply with certain federal provisions as compliant with the state law. The Senate passed it 25 to 0 on March 10, 2026, and the House Committee on Consumer Protection and Commerce reported it out as HD 1 on March 24, 2026, when it was referred to the Committee on Judiciary and Hawaiian Affairs. Nothing further is recorded on the measure, and it was not enacted.
The practical result for compliance is that the statutory definition (Social Security number, driver's license or Hawaii identification card number, and financial account number with an access code or password) is unchanged.
What Triggers a Notification
A "security breach" under Hawaii law means an incident of unauthorized access to and acquisition of unencrypted or unredacted records or data containing personal information where illegal use of the personal information has occurred, or is reasonably likely to occur, and that creates a risk of harm to a person.
Two key points distinguish Hawaii's trigger:
Risk of harm required. Not every unauthorized access requires notification. The entity must determine that illegal use has occurred or is reasonably likely to occur and that the breach creates a risk of harm.
Encrypted data exception. If the breached records were encrypted, no notification is required unless the encryption key or confidential process was also compromised in the same incident.
Notification Timeline and Requirements
Timeline
Hawaii does not set a specific number of days for notice to the affected people. Instead, the law requires disclosure "without unreasonable delay," consistent with the legitimate needs of law enforcement and any measures necessary to determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system.
This flexible standard gives businesses some room to investigate the breach before notifying, but it also means that the Hawaii Office of Consumer Protection or a court can determine after the fact whether a delay was unreasonable.
Methods of Notification
Under HRS 487N-2(e), a business or government agency may give notice by one of the following methods:
- Written notice to the last available address on record
- Electronic mail notice for people for whom the entity has a valid email address and who have agreed to receive communications electronically, consistent with the federal E-SIGN Act (15 U.S.C. 7001)
- Telephonic notice, provided that contact is made directly with the affected people
- Substitute notice if the cost of direct notice would exceed $100,000, the affected class exceeds 200,000 people, or the business does not have sufficient contact information. Substitute notice requires email notice (if available), conspicuous posting on the business's website, and notification to major statewide media.
Content of Notification
HRS 487N-2(d) requires the notice to be clear and conspicuous, and to describe all five of the following:
- The incident in general terms
- The type of personal information that was subject to the unauthorized access and acquisition
- The general acts of the business or government agency to protect the personal information from further unauthorized access
- A telephone number the person may call for further information and assistance, if one exists
- Advice directing the person to remain vigilant by reviewing account statements and monitoring free credit reports
A notice that names only the categories of data involved does not meet this standard.

Reporting to Regulators and Credit Bureaus
When a business gives notice to more than one thousand persons at one time, HRS 487N-2(f) requires it to notify two further recipients in writing, without unreasonable delay:
- The State of Hawaii's Office of Consumer Protection at the Department of Commerce and Consumer Affairs
- All consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in 15 U.S.C. 1681a(p)
Both notices must cover the timing, distribution, and content of the notice sent to affected people. Two details are easy to get wrong: the trigger is the number of persons notified at one time, not the number of Hawaii residents whose data was involved, and subsection (f) is written to apply to a business.
Government Agency Reports to the Legislature
A separate section, HRS 487N-4, puts a hard deadline on government agencies. An agency must submit a written report to the legislature within twenty days after discovering a security breach. The report must detail the nature of the breach, the number of individuals affected, a copy of the notice that was issued, the number of individuals it was sent to, whether notice was delayed for law enforcement reasons, and any procedures put in place to prevent a recurrence. If a law enforcement agency asks for a delay, the report may be postponed until twenty days after that agency determines notice will no longer impede the investigation or jeopardize national security.
Third-Party Agent Obligations
Any business located in Hawaii, any business that conducts business in Hawaii, and any government agency that maintains or possesses records containing personal information it does not own or license must notify the owner or licensee of the information immediately following discovery of the breach.
Penalties and Enforcement
Civil Penalties
Any business that violates any provision of Chapter 487N faces penalties of up to $2,500 per violation under HRS 487N-3. The Attorney General or the executive director of the Office of Consumer Protection may bring enforcement actions. Subsection (a) ends with a limit that readers often miss: no such action may be brought against a government agency.

Private Right of Action
Hawaii is one of the few states that grants individuals a private right of action for data breach notification violations. Any business that violates Chapter 487N is liable to the injured party for actual damages sustained as a result of the violation. Courts may award reasonable attorney's fees to the prevailing party.
This provision gives Hawaii residents meaningful recourse against businesses. Unlike states where only the Attorney General can act, affected individuals in Hawaii can pursue their own claims in court. The same carve-out applies here as to civil penalties: HRS 487N-3(b) states that no such action may be brought against a government agency, so a person whose data was exposed by a state or county agency cannot sue under this chapter.
Waiver Prohibition
Any waiver of the provisions of HRS 487N-2, the notice section, is contrary to public policy and is void and unenforceable. The anti-waiver clause in subsection (h) is written to cover that section rather than the chapter as a whole. This means businesses cannot include clauses in contracts or terms of service that attempt to waive a consumer's rights under the breach notification law.
HIPAA Safe Harbor
Healthcare providers and health plans that comply with the privacy and security standards of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) are deemed in compliance with Hawaii's notification requirements. This avoids duplicative obligations for HIPAA-covered entities that already maintain breach notification procedures under federal law.

How Hawaii Compares to Other States
Hawaii's breach notification law has several features that set it apart from many other states.
Covers paper records. Many states only require notification for breaches of computerized data. Hawaii covers personal information "in any form," including paper records.
Private right of action against businesses. Most states limit enforcement to the attorney general. Hawaii allows individuals to sue a business directly for actual damages and attorney's fees, though not a government agency.
No specific day count for consumer notice. Unlike states that set 30, 45, or 60-day deadlines, Hawaii uses the "without unreasonable delay" standard for notifying affected people. That provides flexibility but also creates uncertainty. Government agencies do face one hard deadline, but it runs to the legislature rather than to consumers: a written report within twenty days under HRS 487N-4.
Lower per-violation penalty. At $2,500 per violation, Hawaii's penalty is lower than the $500,000 per-breach caps in Alabama and Arizona. The $7,500 per intentional violation figure often quoted for California comes from the California Consumer Privacy Act, not from California's breach notification statute, which lets an injured customer recover damages rather than setting a per-violation penalty.
This article provides general legal information about Hawaii data breach notification laws. It is not legal advice. Laws and regulations change frequently, and this content may not reflect the most recent developments. Consult a qualified attorney licensed in Hawaii for advice about your specific situation.
More Hawaii Laws
Frequently Asked Questions
How quickly must a business notify me of a data breach in Hawaii?
Hawaii law requires notification 'without unreasonable delay' after a breach is discovered. Unlike states that set specific deadlines such as 30 or 45 days, Hawaii uses a flexible standard. The notification timeline must account for law enforcement needs, the time required to determine the scope of the breach, and restoring the integrity of the data system. What counts as unreasonable delay is evaluated on a case-by-case basis.
Can I sue a company for a data breach in Hawaii?
Yes. Hawaii is one of the few states that provides a private right of action for data breach notification violations. Under HRS 487N-3, you can sue a business that violates any provision of the breach notification law and recover actual damages you sustained as a result. The court may also award reasonable attorney's fees to the prevailing party. One limit matters: HRS 487N-3 states that no such action may be brought against a government agency, so a breach at a state or county agency falls outside this remedy.
What information is protected under Hawaii's breach notification law?
Hawaii protects personal information defined as your name combined with a Social Security number, a driver's license or Hawaii identification card number, or a financial account number with an access code or password. The legislature has tried to widen those categories, most recently through SB 3016 in 2026, which passed the Senate and cleared a House committee but was not enacted, so the statutory definition is unchanged.
What penalties do businesses face for failing to report a data breach in Hawaii?
Businesses that violate Hawaii's breach notification law face civil penalties of up to $2,500 per violation. The Attorney General or the executive director of the Office of Consumer Protection can bring enforcement actions. Additionally, affected individuals can bring private lawsuits to recover actual damages and attorney's fees. Neither the penalty action nor the private lawsuit may be brought against a government agency, though an agency must report a breach to the legislature within twenty days under HRS 487N-4.
Does Hawaii's breach notification law cover paper records?
Yes. Hawaii's law is broader than many states because it covers personal information 'in any form,' including both electronic and paper records. This means that a business must notify affected individuals even if the breach involves physical documents rather than computerized data, as long as the breach meets the other statutory requirements.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected and expanded the breach notification requirements: added the duty to notify nationwide consumer reporting agencies alongside the Office of Consumer Protection, listed all five items HRS 487N-2(d) requires in a notice, added telephonic notice as a permitted method, added the twenty-day government agency report to the legislature under HRS 487N-4, noted that neither civil penalties nor the private right of action may be brought against a government agency, and updated the legislative section to cover SB 3016 (2026).
Corrected the state notification trigger to more than 1,000 residents per HRS 487N-2(f), restored the full three-category third-party agent duty, and noted SB 1038 stalled in committee.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Removed two fabricated categories, 'health insurance information' and 'medical or health information', from HRS 487N-1's personal-information definition; the statute currently covers only Social Security number, driver's license/state ID number, and financial account number.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Hawaii Revised Statutes, Chapter 487N: [SECURITY BREACH OF PERSONAL INFORMATION]
§ 487N-2Notice of security breachIn forcecited in 3 of our articles
(a) Any business that owns or licenses personal information of residents of Hawaii, any business that conducts business in Hawaii that owns or licenses personal information in any form (whether computerized, paper, or otherwise), or any government agency that collects personal information for specific government purposes shall provide notice to the affected person that there has been a security breach following discovery or notification of the breach. The disclosure notification shall be made without unreasonable delay, consistent with the legitimate needs of law enforcement as provided in subsection (c) of this section, and consistent with any measures necessary to determine sufficient contact information, determine the scope of the breach, and restore the reasonable integrity, security, and confidentiality of the data system.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at capitol.hawaii.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2019
Opinions citing this section in our collection:
- Silva-Borero v. Equifax, Inc. (District Court, D. Hawaii 2019)“…ntiff fails to state a § 487N-2(b) claim for relief. 3 HRS § 487N-2(e) sets forth various methods by which…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Hawaii Biometric Privacy Laws: Collection, Consent & Penalties (2026), Hawaii Data Privacy Laws: Constitutional Privacy & Consumer Rights (2026)
§ 487N-3Penalties; civil actionIn force
(a) Any business that violates any provision of this chapter shall be subject to penalties of not more than $2,500 for each violation. The attorney general or the executive director of the office of consumer protection may bring an action pursuant to this section. No such action may be brought against a government agency. (b) In addition to any penalty provided for in subsection (a), any business that violates any provision of this chapter shall be liable to the injured party in an amount equal to the sum of any actual damages sustained by the injured party as a result of the violation. The court in any action brought under this section may award reasonable attorneys' fees to the prevailing party. No such action may be brought against a government agency. (c) The penalties provided in this section shall be cumulative to the remedies or penalties available under all other laws of this State. [L 2006, c 135, pt of §2]
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at capitol.hawaii.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2019
Opinions citing this section in our collection:
- Silva-Borero v. Equifax, Inc. (District Court, D. Hawaii 2019)“…breach . . . .” Haw. Rev. Stat. (“HRS”) § 487N-2(b). And HRS § 487N-3(b) provides a private cause of action…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 487N-1DefinitionsIn forcecited in 3 of our articles
. As used in this chapter, unless the context otherwise requires: "Business" means a sole proprietorship, partnership, corporation, association, or other group, however organized, and whether or not organized to operate at a profit. The term includes a financial institution organized, chartered, or holding a license or authorization certificate under the laws of the State, any other state, the United States, or any other country, or the parent or the subsidiary of any such financial institution. The term also includes an entity whose business is records destruction. "Council" means the information privacy and security council established under section 487N-5. "Encryption" or "encrypted" means the use of an algorithmic process to transform data into a form in which the data is rendered unreadable or unusable without the use of a confidential process or key. "Government agency" means any department, division, board, commission, public corporation, or other agency or instrumentality of the State or of any county.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at capitol.hawaii.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- HRS Chapter 487N Security Breach of Personal Information(capitol.hawaii.gov).gov
- HRS 487N-1 definitions including personal information(capitol.hawaii.gov).gov
- HRS 487N-2 notice of security breach requirements(capitol.hawaii.gov).gov
- HRS 487N-3 penalties and private right of action(capitol.hawaii.gov).gov
- Hawaii Office of Consumer Protection security breach notices(cca.hawaii.gov).gov
- SB 1038 expanding personal information definition(capitol.hawaii.gov).gov
- HIPAA Privacy Rule(hhs.gov).gov
- HRS 487N-4 reporting requirements, government agency report to the legislature within twenty days(capitol.hawaii.gov)
- Hawaii SB 3016 (2026) measure status, expanding the personal information definition(capitol.hawaii.gov)
- Hawaii SB 1038 measure status, carried over to the 2026 Regular Session(capitol.hawaii.gov)
- California Civil Code 1798.155, CCPA administrative fines including $7,500 per intentional violation(leginfo.legislature.ca.gov)