Tennessee
Tennessee Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 4 primary sources cited on this page. How we verify our legal content

Tennessee requires businesses to notify affected residents of a data breach no later than 45 days after discovery under Tenn. Code Ann. 47-18-2107. The law applies to any entity conducting business in Tennessee that owns or licenses computerized data containing personal information of state residents.
Tennessee's data breach notification law is codified at Tenn. Code 47-18-2107 within the state's Identity Theft Deterrence Act (Part 21 of the Tennessee Consumer Protection Act). Originally enacted in 2005, the statute received significant amendments in 2016 and 2017 that added a firm 45-day notification deadline and technical encryption requirements.
If your business handles personal information belonging to Tennessee residents, a data breach triggers specific notification obligations. Tennessee stands out among states for granting a private right of action to injured consumers, allowing individuals to sue for both damages and injunctive relief.
This guide covers the full requirements under Tennessee law, including how they connect to the broader Tennessee data privacy laws framework.
Who Must Comply
Tennessee's law applies to any "information holder," which includes any person or business that conducts business in Tennessee and owns or licenses computerized data that includes personal information of Tennessee residents. State agencies and political subdivisions are also covered.
The law also applies to third-party data maintainers. Any entity that maintains computerized data on behalf of another entity must notify the data owner or licensee within 45 days of discovering a breach. The data owner then carries the obligation to notify affected consumers.
Federal Law Exemptions
Section 47-18-2107(i) states that the section "does not apply to any information holder that is subject to" either of the following federal frameworks:
- Title V of the Gramm-Leach-Bliley Act (GLBA) for financial institutions
- Health Insurance Portability and Accountability Act (HIPAA), as expanded by the HITECH Act, for covered healthcare entities and their business associates
Read the exemption carefully: it is status-based. An information holder that is subject to GLBA Title V or HIPAA is outside Section 47-18-2107 altogether, and the statute does not condition that on the entity actually following its federal notification procedures. A covered entity that mishandles a federal notice does not thereby fall back into Tennessee's 45-day duty or the private right of action in subsection (h).
These entities do still owe their federal breach notification obligations, which are enforced under federal law rather than under Section 47-18-2107.
What Triggers Notification
Under Section 47-18-2107, a "breach of system security" means the unauthorized acquisition of computerized data that materially compromises the security, confidentiality, or integrity of personal information maintained by the information holder.
The key term is "materially compromises." Not every unauthorized access triggers notification. The breach must materially affect the security of the personal information, giving entities some latitude to assess whether a technical incident rises to the level of a reportable breach.
Good Faith Exception
A good faith acquisition of personal information by an employee or agent of the information holder is not a breach, provided the information is not used or subject to further unauthorized disclosure.
Encryption Safe Harbor

Tennessee provides an encryption safe harbor tied to a specific federal standard. Under the 2017 amendment (SB 547, Public Chapter 91, effective April 4, 2017), data encrypted in accordance with the Federal Information Processing Standard (FIPS) 140-2 is protected from breach notification requirements, as long as the decryption process or key was not also acquired, released, or used without authorization during the breach.
This is a more specific standard than many states require. FIPS 140-2 is the federal government's standard for cryptographic modules, and it means businesses must use validated encryption methods rather than just any encryption algorithm.
Personal Information That Triggers the Law
Tennessee's definition of personal information is relatively narrow compared to states that have updated their laws in recent years. Under Section 47-18-2107, personal information means an individual's first name or first initial and last name, in combination with any one or more of the following data elements:
- Social Security number
- Driver's license number
- Account, credit card, or debit card number, in combination with any required security code, access code, or password that would permit access to the individual's financial account
What Tennessee's Law Does Not Cover
The definition does not extend to:
- Medical or health information
- Health insurance identification numbers
- Biometric data
- Passport numbers
- Email credentials (usernames with passwords)
- Taxpayer identification numbers (other than SSNs)
Personal information does not include information lawfully made available to the general public from federal, state, or local government records, or information that has been redacted or otherwise made unusable.
The 45-Day Notification Timeline

Notification must be made no later than 45 days from the discovery or notification of the breach of system security. That deadline came from the 2016 amendment (SB 2005, Public Chapter 692, effective July 1, 2016), which replaced the statute's earlier open-ended timing language with a fixed number of days.
The 2017 amendment is a different change. SB 547 rewrote the encryption provisions, as described above. It did not set the 45-day clock.
Law Enforcement Delay
Notification may be delayed if a law enforcement agency determines that notification will impede a criminal investigation. Once law enforcement determines that notification will no longer compromise the investigation, the information holder must provide notification within 45 days of that determination.
Third-Party Data Holders
When a third party that maintains data on behalf of another entity discovers a breach, the third party must notify the data owner or licensee within 45 days. The data owner then has its own 45-day window to notify affected consumers.
Who Must Be Notified
Affected Individuals
Every Tennessee resident whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person must receive notification.
Consumer Reporting Agencies (1,000+ Threshold)
When an information holder must notify more than 1,000 persons at one time, the holder must also notify, without unreasonable delay, all nationwide consumer reporting agencies (Equifax, Experian, and TransUnion) of the timing, distribution, and content of the consumer notices.
No Mandatory AG Notification
Tennessee's breach notification statute does not require direct notification to the Attorney General for private-sector breaches. This is unusual among states that have modernized their breach notification laws. The Tennessee Attorney General has enforcement authority under the Tennessee Consumer Protection Act but does not receive mandatory breach reports under Section 47-18-2107.
For state agencies, a separate provision (Tenn. Code 8-4-119) requires notification to the Comptroller of the Treasury within five working days of a confirmed or suspected breach.
Methods of Notification
Tennessee permits two primary notification methods:
- Written notice sent to the individual
- Electronic notice, if consistent with the federal E-SIGN Act (15 U.S.C. 7001) or if electronic communication is the entity's primary method of communication with the resident
Substitute Notice
Substitute notice is available when the cost exceeds $250,000, the affected class exceeds 500,000 persons, or the entity lacks sufficient contact information. Substitute notice requires all three of: email notice to available addresses, conspicuous posting on the entity's website, and notification to statewide media.
Your Own Notification Procedures
Subsection (f) of Section 47-18-2107 adds a separate compliance path that businesses often miss. An information holder that maintains its own notification procedures as part of an information security policy for the treatment of personal information, where that policy is otherwise consistent with the timing requirements of the section, is in compliance with the statute when it notifies affected persons in accordance with those policies.
This covers the mechanics of how notice goes out, not the deadline. The policy has to be consistent with the section's timing, so the 45-day clock still governs.
Penalties and Enforcement
Private Right of Action

Tennessee is one of the states that grants a private right of action for breach notification violations. Under Section 47-18-2107, any customer of an information holder (that is a person or business entity, not a state agency) who is injured by a violation may institute a civil action to:
- Recover damages resulting from the violation
- Obtain injunctive relief to enjoin the information holder from further violations
These rights are cumulative, meaning they exist in addition to any other rights and remedies available under law.
Section 47-18-2104 governs how this private action proceeds. The lawsuit must be filed within two years from the date the liability arises; if the information holder concealed the violation, the two-year period runs from when the person discovers it instead. The plaintiff must serve a copy of the complaint, and later any judgment, on the Attorney General. If the court finds the violation involved identity theft committed willfully or knowingly, it may award treble (3x) damages, and the court may award the prevailing plaintiff reasonable attorneys' fees and costs.
Whether a Class Action Is Available Is Unsettled
Tennessee Code 47-18-109(g) bars class action lawsuits seeking damages for an unfair or deceptive act or practice declared to be unlawful by Part 1 of the Consumer Protection Act. That bar is written into Part 1. The breach notification private right of action lives in Part 21 (Section 47-18-2107(h), procedurally governed by Section 47-18-2104), which contains no class action restriction of its own.
The counterargument sits in the same part as the breach statute. Section 47-18-2106(b) provides that "for the purpose of application of the Tennessee Consumer Protection Act, any violation of this part shall be construed to constitute an unfair or deceptive act or practice affecting trade or commerce and subject to the penalties and remedies as provided in that act." A defendant would use that deeming language to argue that a Part 21 breach notification claim is, for Consumer Protection Act purposes, exactly the kind of unfair or deceptive act the Part 1 class action bar reaches.
Treat this as a contested question rather than a settled one. Do not plan a case on the assumption that a class action is available; ask Tennessee counsel how courts are reading Section 47-18-2106(b) against Section 47-18-109(g).
Attorney General Enforcement
The Tennessee Attorney General has authority to enforce the breach notification law under Part 21 of the Tennessee Consumer Protection Act. Under Tenn. Code 47-18-2105(d), a violation is punishable by a civil penalty of whichever amount is greater: $10,000, $5,000 per day for each day a person's identity has been assumed, or 10 times the amount obtained or attempted to be obtained through the identity theft. This penalty is cumulative with other remedies available under the Tennessee Consumer Protection Act, and the AG can also pursue injunctive relief and consumer restitution for violations.
The Tennessee Information Protection Act (TIPA)
Tennessee enacted the Tennessee Information Protection Act (TIPA) in 2023, with an effective date of July 1, 2025. TIPA is a comprehensive consumer privacy law that creates new obligations for data controllers, including requirements around data minimization, purpose limitation, and consumer rights.
TIPA does not replace the breach notification requirements of Section 47-18-2107. The two laws operate independently: TIPA governs how businesses collect and use personal information, while Section 47-18-2107 governs what happens when that information is breached.
This article provides general legal information about Tennessee data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in Tennessee for guidance specific to your situation.
More Tennessee Laws
Frequently Asked Questions
How quickly must a business notify Tennessee residents after a data breach?
Tennessee requires notification no later than 45 days from the discovery or notification of the breach. That deadline was added by the 2016 amendment (SB 2005, Public Chapter 692). If law enforcement requests a delay, notification must occur within 45 days after law enforcement determines that notification will not compromise the investigation.
Can individuals sue for breach notification violations in Tennessee?
Yes. Tennessee grants a private right of action to any customer of an information holder who is injured by a violation. Customers may sue for damages and seek injunctive relief to stop further violations. Whether those claims can proceed as a class action is unsettled: the Consumer Protection Act's class action bar in Section 47-18-109(g) is written into Part 1 while the breach notification action sits in Part 21, but Section 47-18-2106(b) deems any Part 21 violation an unfair or deceptive act subject to the Consumer Protection Act's remedies, which a defendant would invoke to apply the bar.
Does Tennessee require businesses to notify the Attorney General of a data breach?
No. Tennessee's breach notification statute (47-18-2107) does not require direct notification to the Attorney General for private-sector breaches. Consumer reporting agencies must be notified when more than 1,000 persons are affected at one time. State agencies must separately notify the Comptroller of the Treasury within five working days under Tenn. Code 8-4-119.
What encryption standard does Tennessee require for safe harbor protection?
Tennessee ties its encryption safe harbor to the Federal Information Processing Standard (FIPS) 140-2, the federal government's standard for cryptographic modules. Data encrypted in compliance with FIPS 140-2 is excluded from breach notification, provided the decryption key was not also compromised. This encryption rule came from the 2017 amendment (SB 547, Public Chapter 91).
Does Tennessee's breach notification law cover medical or health information?
No. Tennessee's personal information definition only covers SSNs, driver's license numbers, and financial account numbers with security codes. Medical information, health insurance data, biometric data, and email credentials are not covered. Healthcare entities subject to HIPAA are outside Section 47-18-2107 entirely under subsection (i) and have separate federal breach notification obligations.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the GLBA and HIPAA exemption, which is based on being subject to those federal laws rather than on complying with them, reattributed the 45-day notification deadline to the 2016 amendment instead of the 2017 encryption amendment, added the subsection (f) safe harbor for an information holder's own notification procedures, and qualified the class action discussion to reflect the counterargument under Tenn. Code 47-18-2106(b).
Corrected the consumer-reporting-agency notification threshold to 'more than 1,000 persons' rather than '1,000 or more,' added the Attorney General's specific civil-penalty amounts under 47-18-2105(d), added the two-year filing deadline and attorneys'-fees provision that govern a private lawsuit under 47-18-2104, corrected an overstated claim that the state's class-action bar limits breach-notification lawsuits, and removed an inaccurate 'immediately' standard from the 45-day notice deadline.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Tennessee Code Annotated
§ 47-18-2107Release of personal consumer information.In forcecited in 3 of our articles
(a) As used in this section: (1) “Breach of system security”: (A) Means the acquisition of the information set out in subdivision (a)(1)(A)(i) or (a)(1)(A)(ii) by an unauthorized person that materially compromises the security, confidentiality, or integrity of personal information maintained by…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library
Also relied on in: Tennessee Data Privacy Laws: TIPA Consumer Rights Guide (2026), Tennessee Biometric Privacy Laws: Collection, Consent & Penalties (2026)
United States Code Title 15
§ 7001General rule of validityIn forcecited in 18 of our articles
Notwithstanding any statute, regulation, or other rule of law (other than this subchapter and subchapter II), with respect to any transaction in or affecting interstate or foreign commerce— a signature, contract, or other record relating to such transaction may not be denied legal effect, validity, or enforceability solely because it is in electronic form; and a contract relating to such transaction may not be denied legal effect, validity, or enforceability solely because an electronic signature or electronic record was used in its formation. This subchapter does not— limit, alter, or otherwise affect any requirement imposed by a statute, regulation, or rule of law relating to the rights and obligations of persons under such statute, regulation, or rule of law other than a requirement that contracts or other records be written, signed, or in nonelectronic form; or require any person to agree to use or accept electronic records or electronic signatures, other than a governmental agency with respect to a record other than a contract to which it is a party.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 132 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Metropolitan Regional Information Systems v. American Home Realty Network (2012) applied 15 U.S.C. 7001(a) to hold an electronic assignment process satisfied the signed writing requirement of Copyright Act 204(a). Blatt v. Capital One Auto Finance (2017) held 7001(c) disclosures were not required where the record was delivered on paper.
Opinions citing this section in our collection:
- Metropolitan Regional Information Systems, Inc. v. American Home Realty Network, Inc. (District Court, D. Maryland 2012, 904 F. Supp. 2d 530)✓Subscribers assigned photo copyrights to a real estate database by uploading images under online terms of use; the court relied on E-SIGN, 15 U.S.C. section 7001, to hold those electronic assignments met the Copyright Act signed-writing rule, and denied reconsideration.
- Cutrone v. Mortgage Electronic Registration Systems, Inc. (District Court, E.D. New York 2013, 981 F. Supp. 2d 144)✓Homeowners sued MERS in state court over a second mortgage recording tax on an E-Sign mortgage; MERS removed under 15 U.S.C. section 7001, but the court held that statute gives no private right of action and at most a federal defense, which cannot support removal, and remanded.
- Blatt v. Capital One Auto Finance, Inc. (District Court, M.D. Tennessee 2017, 237 F. Supp. 3d 688)“…legal effect ..solely because it is in electronic form[.]” 15 U.S.C. § 7001 (a)(1).. Furthermore, it mandates that…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Mississippi Data Breach Notification Laws: Reporting Rules & Timelines (2026), Mississippi Data Privacy Laws: Breach Notification & Consumer Rights (2026), Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Tenn. Code 47-18-2107 - Release of Personal Consumer Information(law.justia.com)
- Tennessee Attorney General - Consumer Laws(tn.gov).gov
- Tennessee Comptroller - Data Breach Online Submission(comptroller.tn.gov).gov
- NIST FIPS 140-2 Standard(csrc.nist.gov).gov
- Tennessee AG - TIPA Guidelines(tn.gov).gov
- Tennessee General Assembly - SB 2005 (2016), Public Chapter 692, 45-day breach notification deadline(wapp.capitol.tn.gov)
- Tennessee General Assembly - SB 547 (2017), Public Chapter 91, encryption amendment(wapp.capitol.tn.gov)