Montana
Montana Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 4 primary sources cited on this page. How we verify our legal content

Montana requires businesses that experience a data breach to notify affected residents without unreasonable delay under Mont. Code Ann. 30-14-1704. No fixed-day deadline applies; the standard is flexible, but the Montana Attorney General determines whether any delay was unreasonable on a case-by-case basis.
If your business stores personal information belonging to Montana residents, a data breach triggers specific legal obligations under Montana's breach notification statute. Mont. Code Ann. 30-14-1704 through 30-14-1706 sets out who must notify, what triggers the duty, and how quickly you need to act. Montana enacted its original breach notification law in 2005, and the legislature has amended it several times to expand the definition of personal information and tighten notification requirements.
This guide covers the full scope of Montana's breach notification requirements, including what personal information triggers the law, who must be notified, the timeline, penalties, exemptions, and how the Montana Consumer Data Privacy Act (MCDPA) interacts with breach obligations.
Who Must Comply With Montana's Breach Notification Law
Montana's law applies to any person or business that conducts business in Montana and owns or licenses computerized data that includes personal information. It also applies to any person or business that maintains computerized data containing personal information that it does not own. This captures both data owners and third-party service providers such as cloud hosting companies or payment processors.
When a third-party data maintainer discovers a breach, it must notify the data owner or licensee "as soon as the discovery is made." The data owner then carries the primary responsibility to notify affected consumers and the Attorney General.
Government Entities
Montana state agencies (executive and legislative branch bodies) are not covered by the business breach statute at all. They follow a separate law, Mont. Code Ann. 2-6-1501 through 2-6-1504, which similarly requires notice without unreasonable delay but also requires simultaneous notice to the state's chief information security officer. Local governments and political subdivisions are not defined as "state agencies" under that statute, and it is not clear that Montana's business breach law extends to them either. A local government entity with questions about its own obligations should consult counsel.
Insurance Licensees
Montana's definition of "business" at Mont. Code Ann. 30-14-1702(1)(b) expressly excludes "industries regulated under Title 33," the insurance code. Insurance licensees and insurance-support organizations instead follow Mont. Code Ann. 33-19-321, a parallel breach statute carrying the same "without unreasonable delay" standard and the same personal-information categories.
The difference that matters is which regulator receives the filing. Under 33-19-321(5), the simultaneous electronic copy of the notification goes to the insurance commissioner, not to the Attorney General's consumer protection office. An insurer that follows the general business track would report to the wrong agency.
What Qualifies as a Breach
Under Mont. Code 30-14-1704(4)(a), a "breach of the security of the data system" means the unauthorized acquisition of computerized data that materially compromises the security, confidentiality, or integrity of personal information maintained by the person or business "and causes or is reasonably believed to cause loss or injury to a Montana resident."
That is a two-part test, and both halves must be satisfied. Material compromise alone is not enough; the statute also requires loss or injury, actual or reasonably believed, to a Montana resident. The definition sits in the breach statute itself, not in the general definitions at 30-14-1702, which do not define the term at all and carry a different, broader "personal information" definition written for the record-destruction provisions.
Good Faith Exception
A good faith acquisition of personal information by an employee or agent of the entity does not constitute a breach, provided the personal information is not used for an unauthorized purpose or subject to further unauthorized disclosure.
Encryption
Montana's duty runs only to residents whose unencrypted personal information was or is reasonably believed to have been acquired, and 30-14-1704(4)(b)(i) reaches a name plus a listed data element only "when either the name or the data elements are not encrypted." Data that was encrypted therefore falls outside the trigger.
Montana does not define "encrypted," set an encryption standard, or address what happens when an attacker also obtains the decryption key. Many other states write an explicit key-acquisition exception into their breach statutes. Montana's does not contain one. An entity whose encryption keys were taken alongside the data should treat the question as unsettled and consult counsel rather than assume the data still counts as encrypted for purposes of the statute.
Personal Information That Triggers Notification
Montana's definition of personal information is broader than many states. Under Mont. Code Ann. 30-14-1704(4)(b), personal information means an individual's first name or first initial and last name combined with any one or more of the following:
- Social Security number
- Driver's license number, state ID card number, or tribal ID number
- Account number or credit or debit card number combined with any required security code, access code, or password that would permit access to the account
- Medical record information
- Taxpayer identification number
- Identity protection personal identification number issued by the IRS
The inclusion of medical records, taxpayer identification numbers, and IRS identity protection PINs makes Montana's definition notably broader than states that only cover financial account data and SSNs.
Personal information does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.

Notification Timeline
Montana requires notification "without unreasonable delay." Unlike states such as Indiana (45 days) or Colorado (30 days), Montana does not impose a specific day count. The standard is flexible but carries real enforcement risk if the Attorney General determines a delay was unreasonable.
When Delay Is Permitted
A delay in notification is reasonable if it is necessary to:
- Determine the scope of the breach and restore the reasonable integrity of the data system
- Comply with a request from law enforcement that notification would impede a criminal investigation
When a delay occurs for law enforcement purposes, notification must be made without unreasonable delay after law enforcement determines disclosure no longer compromises the investigation.
Who Must Be Notified
Affected Individuals
Every Montana resident whose unencrypted personal information was or is reasonably believed to have been acquired by an unauthorized person must be notified.

Montana does not prescribe what the notice must say. Mont. Code 30-14-1704(5) governs only the method of notice, written, electronic, telephonic, or substitute, and no subsection of the statute sets out required content. That is unusual among state breach laws, many of which mandate specific disclosures.
Because the statute is silent, notice content in Montana is a matter of practice rather than a legal requirement. Notices commonly describe the categories of information involved, give a contact for questions, and suggest steps such as reviewing account statements and obtaining free credit reports. Pointing the reader to a credit reporting agency is optional, and it carries a consequence described in the next section.
Montana Attorney General
The Montana Attorney General's Consumer Protection Office must be notified of any breach affecting Montana residents. Under Mont. Code 30-14-1704(8), the business must simultaneously submit an electronic copy of the notification to the AG's consumer protection office, along with a statement of the date and method of distribution.
This is a mandatory requirement for every breach that triggers consumer notification, regardless of the number of affected residents. Insurance licensees and insurance-support organizations are the exception: they file the same copy with the insurance commissioner under 33-19-321(5) instead.
Consumer Reporting Agencies
Under Mont. Code Ann. 30-14-1704(7), if the notice given to individuals suggests, indicates, or implies that they may obtain a copy of their file from a consumer credit reporting agency, the business must coordinate with that agency on the timing, content, and distribution of the notice. The coordination may not unreasonably delay notice to affected individuals.
This obligation is conditional and entirely within the sender's control. It attaches only because the business chose to point readers toward a credit reporting agency. A notice that says nothing about obtaining a credit file does not trigger the coordination duty at all.
How to Provide Notification
Montana permits the following notification methods:
- Written notice sent by mail to the last known address of the individual
- Electronic notice, if the notice is consistent with the federal E-SIGN Act's provisions on electronic records and signatures, 15 U.S.C. 7001
- Telephone notification
Substitute Notice
Substitute notice is available when:
- The cost of notification would exceed $250,000
- The affected class exceeds 500,000 individuals
- The entity does not have sufficient contact information
Substitute notice is not a three-part checklist. Mont. Code 30-14-1704(5)(b) joins the first two items with "and" and the second and third with "or":
- Email notice when the entity has an email address for the subject persons, and
- Conspicuous posting of the notice on the entity's website page, if it maintains one, or
- Notification to applicable local or statewide media
A purely local outlet satisfies the third item. The statute says "applicable local or statewide media," not major statewide outlets.
Enforcement and Penalties

Montana's breach notification law is enforced by the Attorney General under the Montana Unfair Trade Practices and Consumer Protection Act. Violations of the breach notification statute constitute unfair or deceptive trade practices under Mont. Code 30-14-103.
The Attorney General may seek:
- Injunctive relief to stop ongoing violations
- Civil penalties up to $10,000 per violation under Mont. Code 30-14-142, if a court finds the violation was willful, or for violating an injunction
- Restitution for affected consumers
There is no private right of action for breach notification violations. Only the Attorney General can bring enforcement actions under this statute.
How the MCDPA Interacts With Breach Notification
The Montana Consumer Data Privacy Act (MCDPA), effective October 1, 2024, created a comprehensive privacy framework for Montana. However, the MCDPA does not contain its own breach notification requirements. Businesses subject to the MCDPA must still follow Mont. Code 30-14-1704 for breach notification.
The MCDPA does add relevant obligations that affect breach preparedness:
- Data security requirement: Controllers must implement reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data at issue.
- Data minimization: Controllers must limit data collection to what is adequate, relevant, and reasonably necessary for the disclosed purpose.
- Sensitive data consent: Biometric data, precise geolocation, and other sensitive categories require explicit consumer consent before processing.
The MCDPA is enforced separately by the Attorney General, with civil penalties up to $7,500 per violation under Mont. Code Ann. 30-14-2820.
Do not assume a right to cure. Section 30-14-2820(2) makes a violator liable "following the 30-day period described in 30-14-2817(3)," but the current text of Mont. Code Ann. 30-14-2817, as amended in 2025, contains no cure period at all. Its subsection (3) now covers civil investigative demands. The cross-reference points at a provision that no longer exists, so a cure opportunity cannot be relied on.
This article provides general legal information about Montana data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in Montana for guidance specific to your situation.
More Montana Laws
Frequently Asked Questions
How long does a business have to notify Montana residents of a data breach?
Montana law requires notification 'without unreasonable delay' but does not set a specific day deadline. The entity may delay notification to determine the scope of the breach and restore system integrity, or to comply with a law enforcement request. Once the reason for the delay no longer exists, notification must happen promptly. The Attorney General determines whether any delay was unreasonable on a case-by-case basis.
Does Montana require businesses to notify the Attorney General after a data breach?
Yes. The Montana Attorney General's Consumer Protection Office must be notified whenever a business provides breach notification to Montana residents. This applies to every breach regardless of the number of affected individuals. Businesses can contact the Consumer Protection Office through the Montana Department of Justice website.
Does encryption protect businesses from Montana's breach notification requirements?
Encryption matters, but not through a key-based safe harbor. Mont. Code 30-14-1704 requires notice only to residents whose unencrypted personal information was acquired, and it defines personal information only where the name or the data elements are not encrypted, so encrypted data falls outside the trigger. Montana does not define encryption, set a standard, or address what happens if an attacker also obtains the decryption key. Unlike many states, Montana's statute contains no encryption-key exception, so an entity whose keys were also taken should consult counsel rather than assume the data still counts as encrypted.
What types of personal information trigger Montana's breach notification law?
Montana's law is triggered when a name is combined with any of the following: Social Security number, driver's license or state/tribal ID number, financial account or credit/debit card number with security code, medical record information, taxpayer identification number, or an identity protection personal identification number issued by the IRS. The inclusion of medical record, tax ID, and IRS identity-protection-PIN data makes Montana's definition broader than many states.
Can individuals sue for a breach notification violation in Montana?
No. Montana's breach notification law does not create a private right of action. Only the Montana Attorney General can enforce the statute under the Unfair Trade Practices and Consumer Protection Act. A court that finds a willful violation may impose civil penalties up to $10,000 per violation under Mont. Code 30-14-142, along with injunctive relief and restitution. Individuals may pursue claims under common law theories, but not under the breach notification statute itself.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected this guide against the current Montana Code: removed a notice-content list and an encryption-key safe harbor that Mont. Code Ann. 30-14-1704 does not contain, restored the statutory requirement that a breach also cause or be reasonably believed to cause loss or injury to a Montana resident, fixed the substitute-notice rules, added the Title 33 insurance carve-out that routes insurer notices to the insurance commissioner, and removed an outdated 30-day MCDPA cure claim.
Corrected the list of personal-information categories that trigger Montana's breach-notification law (removed an invented "health insurance ID" category, added the actual IRS identity-protection PIN category, and fixed the statute citation), updated the state privacy law's cure period from 60 to 30 days to match its 2025 amendment, fixed the Attorney General's civil-penalty citation and clarified it requires a willful violation, corrected how the credit-reporting-agency notification duty is triggered, distinguished state agencies' separate breach-notice statute from the business statute, and replaced a dead Attorney General webpage link.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Montana Code Annotated, Title 30
§ 30-14-1704Computer Security BreachIn forcecited in 4 of our articles
30-14-1704. Computer security breach. (1) Any person or business that conducts business in Montana and that owns or licenses computerized data that includes personal information shall disclose any breach of the security of the data system following discovery or notification of the breach to any resident of Montana whose unencrypted personal information was or is reasonably believed to have been acquired by an unauthorized person. The disclosure must be made without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection (3), or consistent with any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. (2) Any person or business that maintains computerized data that includes personal information that the person or business does not own shall notify the owner or licensee of the information of any breach of the security of the data system immediately following discovery if the personal information was or is reasonably believed to have been acquired by an unauthorized person.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at mca.legmt.gov
Also relied on in: Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026), Montana Biometric Privacy Laws: Collection, Consent & Penalties (2026), Montana Identity Theft Laws: Penalties and the Identity Theft Passport
§ 30-14-1702DefinitionsIn force
30-14-1702. Definitions. As used in 30-14-1701 through 30-14-1705, 30-14-1712, and 30-14-1713, unless the context requires otherwise, the following definitions apply: (1) (a) "Business" means a sole proprietorship, partnership, corporation, association, or other group, however organized and whether or not organized to operate at a profit, including a financial institution organized, chartered, or holding a license or authorization certificate under the law of this state, any other state, the United States, or any other country or the parent or the subsidiary of a financial institution. The term includes an entity that destroys records. The term also includes industries regulated by the public service commission or under Title 30, chapter 10. (b) The term does not include industries regulated under Title 33. (2) "Customer" means an individual who provides personal information to a business for the purpose of purchasing or leasing a product or obtaining a service from the business.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mca.legmt.gov
§ 30-14-103Unlawful PracticesIn force
30-14-103. Unlawful practices. Unfair methods of competition and unfair or deceptive acts or practices in the conduct of any trade or commerce are unlawful.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mca.legmt.gov
Cited in 50 court opinions in our collectionLatest citing opinion in our collection: 2024
Opinions citing this section in our collection:
- Plath v. Schonrock (Montana Supreme Court 2003, 314 Mont. 101)“…nacted, it was the Legislature's intent that in construing § 30-14-103, MCA, “due consideration and weight [should]…”
- Anderson v. Recontrust Co. (Montana Supreme Court 2017, 2017 MT 313)“…Montana Department of Justice to “make rules interpreting” § 30-14-103, MCA, “consistent with” FTC and federal cour…”
- Jacobson v. Bayview Loan Servicing, LLC (Montana Supreme Court 2016, 383 Mont. 257)“…of trade or commerce in violation of 15 U.S.C. § 1692e and § 30-14-103, MCA. ¶30 Bayview argues that the Distric…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Mont. Code Ann. 30-14-1704 - Disclosure of Breach(mca.legmt.gov).gov
- Mont. Code Ann. 30-14-1702 - Definitions(mca.legmt.gov).gov
- Montana AG Office of Consumer Protection(dojmt.gov).gov
- Mont. Code Ann. 30-14-103 - Unfair Trade Practices(mca.legmt.gov).gov
- Mont. Code Ann. 33-19-321 - Computer security breach (insurance licensees; notice to the commissioner)(mca.legmt.gov)
- Mont. Code Ann. 30-14-2817 - Consumer Data Privacy Act enforcement (as amended 2025)(mca.legmt.gov)
- Mont. Code Ann. 30-14-2820 - Consumer Data Privacy Act civil penalty and injunction(mca.legmt.gov)