EnglishEspañol
Tennessee flag

Tennessee

Tennessee Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 4 primary sources cited on this page. How we verify our legal content

Tennessee Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a business notify Tennessee residents after a data breach?

Tennessee requires notification no later than 45 days from the discovery or notification of the breach. That deadline was added by the 2016 amendment (SB 2005, Public Chapter 692). If law enforcement requests a delay, notification must occur within 45 days after law enforcement determines that notification will not compromise the investigation.

Can individuals sue for breach notification violations in Tennessee?

Yes. Tennessee grants a private right of action to any customer of an information holder who is injured by a violation. Customers may sue for damages and seek injunctive relief to stop further violations. Whether those claims can proceed as a class action is unsettled: the Consumer Protection Act's class action bar in Section 47-18-109(g) is written into Part 1 while the breach notification action sits in Part 21, but Section 47-18-2106(b) deems any Part 21 violation an unfair or deceptive act subject to the Consumer Protection Act's remedies, which a defendant would invoke to apply the bar.

Does Tennessee require businesses to notify the Attorney General of a data breach?

No. Tennessee's breach notification statute (47-18-2107) does not require direct notification to the Attorney General for private-sector breaches. Consumer reporting agencies must be notified when more than 1,000 persons are affected at one time. State agencies must separately notify the Comptroller of the Treasury within five working days under Tenn. Code 8-4-119.

What encryption standard does Tennessee require for safe harbor protection?

Tennessee ties its encryption safe harbor to the Federal Information Processing Standard (FIPS) 140-2, the federal government's standard for cryptographic modules. Data encrypted in compliance with FIPS 140-2 is excluded from breach notification, provided the decryption key was not also compromised. This encryption rule came from the 2017 amendment (SB 547, Public Chapter 91).

Does Tennessee's breach notification law cover medical or health information?

No. Tennessee's personal information definition only covers SSNs, driver's license numbers, and financial account numbers with security codes. Medical information, health insurance data, biometric data, and email credentials are not covered. Healthcare entities subject to HIPAA are outside Section 47-18-2107 entirely under subsection (i) and have separate federal breach notification obligations.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the GLBA and HIPAA exemption, which is based on being subject to those federal laws rather than on complying with them, reattributed the 45-day notification deadline to the 2016 amendment instead of the 2017 encryption amendment, added the subsection (f) safe harbor for an information holder's own notification procedures, and qualified the class action discussion to reflect the counterargument under Tenn. Code 47-18-2106(b).

Corrected the consumer-reporting-agency notification threshold to 'more than 1,000 persons' rather than '1,000 or more,' added the Attorney General's specific civil-penalty amounts under 47-18-2105(d), added the two-year filing deadline and attorneys'-fees provision that govern a private lawsuit under 47-18-2104, corrected an overstated claim that the state's class-action bar limits breach-notification lawsuits, and removed an inaccurate 'immediately' standard from the 45-day notice deadline.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Tenn. Code 47-18-2107 - Release of Personal Consumer Information(law.justia.com)
  2. Tennessee Attorney General - Consumer Laws(tn.gov).gov
  3. Tennessee Comptroller - Data Breach Online Submission(comptroller.tn.gov).gov
  4. NIST FIPS 140-2 Standard(csrc.nist.gov).gov
  5. Tennessee AG - TIPA Guidelines(tn.gov).gov
  6. Tennessee General Assembly - SB 2005 (2016), Public Chapter 692, 45-day breach notification deadline(wapp.capitol.tn.gov)
  7. Tennessee General Assembly - SB 547 (2017), Public Chapter 91, encryption amendment(wapp.capitol.tn.gov)
Share: