EnglishEspañol
Hawaii flag

Hawaii

Hawaii Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Hawaii Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a business notify me of a data breach in Hawaii?

Hawaii law requires notification 'without unreasonable delay' after a breach is discovered. Unlike states that set specific deadlines such as 30 or 45 days, Hawaii uses a flexible standard. The notification timeline must account for law enforcement needs, the time required to determine the scope of the breach, and restoring the integrity of the data system. What counts as unreasonable delay is evaluated on a case-by-case basis.

Can I sue a company for a data breach in Hawaii?

Yes. Hawaii is one of the few states that provides a private right of action for data breach notification violations. Under HRS 487N-3, you can sue a business that violates any provision of the breach notification law and recover actual damages you sustained as a result. The court may also award reasonable attorney's fees to the prevailing party. One limit matters: HRS 487N-3 states that no such action may be brought against a government agency, so a breach at a state or county agency falls outside this remedy.

What information is protected under Hawaii's breach notification law?

Hawaii protects personal information defined as your name combined with a Social Security number, a driver's license or Hawaii identification card number, or a financial account number with an access code or password. The legislature has tried to widen those categories, most recently through SB 3016 in 2026, which passed the Senate and cleared a House committee but was not enacted, so the statutory definition is unchanged.

What penalties do businesses face for failing to report a data breach in Hawaii?

Businesses that violate Hawaii's breach notification law face civil penalties of up to $2,500 per violation. The Attorney General or the executive director of the Office of Consumer Protection can bring enforcement actions. Additionally, affected individuals can bring private lawsuits to recover actual damages and attorney's fees. Neither the penalty action nor the private lawsuit may be brought against a government agency, though an agency must report a breach to the legislature within twenty days under HRS 487N-4.

Does Hawaii's breach notification law cover paper records?

Yes. Hawaii's law is broader than many states because it covers personal information 'in any form,' including both electronic and paper records. This means that a business must notify affected individuals even if the breach involves physical documents rather than computerized data, as long as the breach meets the other statutory requirements.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected and expanded the breach notification requirements: added the duty to notify nationwide consumer reporting agencies alongside the Office of Consumer Protection, listed all five items HRS 487N-2(d) requires in a notice, added telephonic notice as a permitted method, added the twenty-day government agency report to the legislature under HRS 487N-4, noted that neither civil penalties nor the private right of action may be brought against a government agency, and updated the legislative section to cover SB 3016 (2026).

Corrected the state notification trigger to more than 1,000 residents per HRS 487N-2(f), restored the full three-category third-party agent duty, and noted SB 1038 stalled in committee.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Removed two fabricated categories, 'health insurance information' and 'medical or health information', from HRS 487N-1's personal-information definition; the statute currently covers only Social Security number, driver's license/state ID number, and financial account number.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. HRS Chapter 487N Security Breach of Personal Information(capitol.hawaii.gov).gov
  2. HRS 487N-1 definitions including personal information(capitol.hawaii.gov).gov
  3. HRS 487N-2 notice of security breach requirements(capitol.hawaii.gov).gov
  4. HRS 487N-3 penalties and private right of action(capitol.hawaii.gov).gov
  5. Hawaii Office of Consumer Protection security breach notices(cca.hawaii.gov).gov
  6. SB 1038 expanding personal information definition(capitol.hawaii.gov).gov
  7. HIPAA Privacy Rule(hhs.gov).gov
  8. HRS 487N-4 reporting requirements, government agency report to the legislature within twenty days(capitol.hawaii.gov)
  9. Hawaii SB 3016 (2026) measure status, expanding the personal information definition(capitol.hawaii.gov)
  10. Hawaii SB 1038 measure status, carried over to the 2026 Regular Session(capitol.hawaii.gov)
  11. California Civil Code 1798.155, CCPA administrative fines including $7,500 per intentional violation(leginfo.legislature.ca.gov)
Share: