EnglishEspañol
Montana flag

Montana

Montana Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 4 primary sources cited on this page. How we verify our legal content

Montana Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How long does a business have to notify Montana residents of a data breach?

Montana law requires notification 'without unreasonable delay' but does not set a specific day deadline. The entity may delay notification to determine the scope of the breach and restore system integrity, or to comply with a law enforcement request. Once the reason for the delay no longer exists, notification must happen promptly. The Attorney General determines whether any delay was unreasonable on a case-by-case basis.

Does Montana require businesses to notify the Attorney General after a data breach?

Yes. The Montana Attorney General's Consumer Protection Office must be notified whenever a business provides breach notification to Montana residents. This applies to every breach regardless of the number of affected individuals. Businesses can contact the Consumer Protection Office through the Montana Department of Justice website.

Does encryption protect businesses from Montana's breach notification requirements?

Encryption matters, but not through a key-based safe harbor. Mont. Code 30-14-1704 requires notice only to residents whose unencrypted personal information was acquired, and it defines personal information only where the name or the data elements are not encrypted, so encrypted data falls outside the trigger. Montana does not define encryption, set a standard, or address what happens if an attacker also obtains the decryption key. Unlike many states, Montana's statute contains no encryption-key exception, so an entity whose keys were also taken should consult counsel rather than assume the data still counts as encrypted.

What types of personal information trigger Montana's breach notification law?

Montana's law is triggered when a name is combined with any of the following: Social Security number, driver's license or state/tribal ID number, financial account or credit/debit card number with security code, medical record information, taxpayer identification number, or an identity protection personal identification number issued by the IRS. The inclusion of medical record, tax ID, and IRS identity-protection-PIN data makes Montana's definition broader than many states.

Can individuals sue for a breach notification violation in Montana?

No. Montana's breach notification law does not create a private right of action. Only the Montana Attorney General can enforce the statute under the Unfair Trade Practices and Consumer Protection Act. A court that finds a willful violation may impose civil penalties up to $10,000 per violation under Mont. Code 30-14-142, along with injunctive relief and restitution. Individuals may pursue claims under common law theories, but not under the breach notification statute itself.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected this guide against the current Montana Code: removed a notice-content list and an encryption-key safe harbor that Mont. Code Ann. 30-14-1704 does not contain, restored the statutory requirement that a breach also cause or be reasonably believed to cause loss or injury to a Montana resident, fixed the substitute-notice rules, added the Title 33 insurance carve-out that routes insurer notices to the insurance commissioner, and removed an outdated 30-day MCDPA cure claim.

Corrected the list of personal-information categories that trigger Montana's breach-notification law (removed an invented "health insurance ID" category, added the actual IRS identity-protection PIN category, and fixed the statute citation), updated the state privacy law's cure period from 60 to 30 days to match its 2025 amendment, fixed the Attorney General's civil-penalty citation and clarified it requires a willful violation, corrected how the credit-reporting-agency notification duty is triggered, distinguished state agencies' separate breach-notice statute from the business statute, and replaced a dead Attorney General webpage link.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Mont. Code Ann. 30-14-1704 - Disclosure of Breach(mca.legmt.gov).gov
  2. Mont. Code Ann. 30-14-1702 - Definitions(mca.legmt.gov).gov
  3. Montana AG Office of Consumer Protection(dojmt.gov).gov
  4. Mont. Code Ann. 30-14-103 - Unfair Trade Practices(mca.legmt.gov).gov
  5. Mont. Code Ann. 33-19-321 - Computer security breach (insurance licensees; notice to the commissioner)(mca.legmt.gov)
  6. Mont. Code Ann. 30-14-2817 - Consumer Data Privacy Act enforcement (as amended 2025)(mca.legmt.gov)
  7. Mont. Code Ann. 30-14-2820 - Consumer Data Privacy Act civil penalty and injunction(mca.legmt.gov)
Share: