EnglishEspañol
Michigan flag

Michigan

Michigan Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 10 primary sources cited on this page. How we verify our legal content

Michigan Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a Michigan business notify customers after a data breach?

Under current law (MCL 445.72), Michigan businesses must notify affected residents 'without unreasonable delay.' There is no specific day deadline. Delays are permitted only to determine the scope of the breach or at the request of law enforcement. If SB 360 passes, a firm 45-day outer limit would apply on top of the unreasonable-delay standard.

Does Michigan require businesses to notify the Attorney General about data breaches?

No, current Michigan law does not require notification to the Attorney General. The only mandatory notification beyond affected individuals is to nationwide consumer reporting agencies when a breach affects more than 1,000 Michigan residents. SB 360, pending in the House, would require AG notification for breaches affecting 100 or more residents.

What are the penalties for failing to report a data breach in Michigan?

A person that knowingly fails to provide required breach notification faces civil fines of up to $250 per failure to notify, with aggregate liability capped at $750,000 per breach event. The Michigan Attorney General or a county prosecuting attorney can bring enforcement actions. Filing a false breach notification is a misdemeanor carrying up to 93 days imprisonment.

Does Michigan's breach notification law apply to encrypted data?

No, if the compromised data was properly encrypted and the encryption key was not also accessed or acquired, notification is not required. This encryption safe harbor is one of the most important compliance tools available to Michigan businesses. It provides a strong incentive to encrypt all stored personal information.

Can individuals sue a company for failing to notify them of a data breach in Michigan?

Michigan's Identity Theft Protection Act does not create a private right of action for breach notification failures. Only the Attorney General and county prosecuting attorneys can bring enforcement actions under the statute. However, individuals may pursue claims under other legal theories, such as negligence, if they can demonstrate actual damages from the failure to notify.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected two statutory points: the breach notification duty in MCL 445.72 was added by 2006 PA 566 (applying to breaches on or after July 2, 2006), not by the 2004 Identity Theft Protection Act, and the Michigan Consumer Protection Act's unfair-trade-practice hook reaches MCL 445.71 conduct only, so a failure to notify is not an MCPA violation.

Corrected the substitute-notice triggers to the two the statute authorizes, clarified SB 360 adds a 45-day outer limit on top of the unreasonable-delay standard, and added the GLBA exemption from consumer reporting agency notification.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Identity Theft Protection Act (Act 452 of 2004)(legislature.mi.gov).gov
  2. MCL 445.72 - Security Breach Notification Requirements(legislature.mi.gov).gov
  3. MCL 445.63 - Identity Theft Protection Act Definitions(legislature.mi.gov).gov
  4. MCL 445.72a - Data Destruction Requirements(legislature.mi.gov).gov
  5. Michigan Consumer Protection Act (MCL 445.903)(legislature.mi.gov).gov
  6. Senate Bill 360 of 2025 - Identity Theft Protection Act Amendments(legislature.mi.gov).gov
  7. SB 360 Engrossed Bill Text(legislature.mi.gov).gov
  8. Michigan Attorney General - Consumer Protection(michigan.gov).gov
  9. NIST Cybersecurity Framework 2.0(nist.gov).gov
  10. Federal Interagency Guidance on Response Programs(federalregister.gov).gov
  11. MCL 445.71 - Prohibited Conduct in Trade or Commerce (Identity Theft Protection Act sec. 11)(legislature.mi.gov)
Share: