EnglishEspañol
Washington flag

Washington

Washington Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 12 primary sources cited on this page. How we verify our legal content

Washington Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a Washington business notify consumers of a data breach?

Washington requires notification within 30 days of discovering a data breach. This deadline was shortened from 45 days to 30 days by HB 1071, which took effect March 1, 2020. The clock starts from the date the breach was discovered, not from the date the breach itself occurred. Law enforcement may request a delay if notification would impede a criminal investigation.

When must the Washington Attorney General be notified of a data breach?

Entities must notify the Washington Attorney General within 30 days when a breach affects more than 500 Washington residents. The notification is submitted via an online web form on the AG's website. The notice must include the number of affected residents, types of personal information compromised, time frame of exposure, steps taken to contain the breach, and a sample copy of the consumer notification.

Can individuals sue for data breach notification violations in Washington?

Yes. Washington is one of the few states that provides a private right of action for breach notification violations. Under RCW 19.255.040(3)(a), a consumer injured by a violation may bring a civil action to recover damages. This is a standalone remedy: the statute expressly states that an action to enforce the chapter may not be brought under RCW 19.86.090, the Consumer Protection Act's general treble-damages provision, so the $25,000 treble-damages cap that applies to other Washington consumer claims does not automatically apply to a breach notification lawsuit.

What types of personal information are protected under Washington's breach notification law?

Washington has one of the broadest definitions of personal information in the country. RCW 19.255.005(2)(a) sets out three branches. The first is a resident's name combined with a data element such as a Social Security number, driver's license number, financial account data, full date of birth, student, military or passport ID number, health insurance ID, medical history, or biometric data such as a fingerprint or eye retina scan. The second is a user name or email address with a password or security question answers, which counts on its own with no name attached. The third covers those same data elements without a name, where they were not rendered unusable and would enable identity theft. The definition was significantly expanded by HB 1071 in 2019.

Does Washington's breach notification law apply to government agencies?

Yes. Washington has two parallel statutes. RCW 19.255 covers private businesses and individuals, while RCW 42.56.590 covers state and local government agencies. Both impose the same 30-day notification deadline and the same AG reporting requirements. Government agencies do have one accommodation private businesses do not: they may delay consumer notification up to 14 additional days to translate the notice into the primary language of affected consumers, under RCW 42.56.590(8).

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the personal information definition to include the two branches that require no name, added the required time frame of exposure to the consumer notice contents, and replaced the federal interaction section with the actual deemed-compliance rules of RCW 19.255.030 for HIPAA covered entities and federally regulated financial institutions.

Corrected the description of Washington's breach-notification lawsuit: consumers sue under a standalone damages provision (RCW 19.255.040) that the statute expressly excludes from the Consumer Protection Act's treble-damages track, not under the $25,000 treble-damages CPA claim the page previously described. Also fixed an unsupported reference to Office of the Chief Information Officer guidelines, added the agency-only 14-day translation extension, and corrected the personal-information definition's citation from RCW 19.255.010 to RCW 19.255.005.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected the dollar figure for Washington's breach-notification private right of action. The private right of action itself is real (RCW 19.255.040(3)(a), which routes into RCW 19.86 as an unfair/deceptive act), but the remedy is not a flat '$1,000 punitive damages' figure -- that number appears nowhere in RCW 19.255.010, .040, or the Consumer Protection Act. The actual enhanced remedy under RCW 19.86.090 is court-discretionary treble damages capped at $25,000, plus costs and attorney's fees.

Corrected two substitute-notice and safe-harbor claims: substitute notice under RCW 19.255.010 requires email, website posting, AND statewide media notice together, not just the first two; and the internal-procedures safe harbor applies to an entity's own compliant notification policy, not specifically to HIPAA or GLBA compliance.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. RCW 19.255.010 Personal Information Notice of Security Breaches(app.leg.wa.gov).gov
  2. RCW 42.56.590 Government Agency Breach Notification(app.leg.wa.gov).gov
  3. Chapter 19.255 RCW Full Text(app.leg.wa.gov).gov
  4. Washington AG Data Breach Notification Laws(atg.wa.gov).gov
  5. Washington AG HB 1071 FAQ(atg.wa.gov).gov
  6. Washington AG Data Breach Notifications Directory(atg.wa.gov).gov
  7. Washington AG Data Breach Resource Center(atg.wa.gov).gov
  8. Washington AG Identity Theft Guide for Businesses(atg.wa.gov).gov
  9. HB 1071 Bill Summary(app.leg.wa.gov).gov
  10. HIPAA Information(hhs.gov).gov
  11. Gramm-Leach-Bliley Act(ftc.gov).gov
  12. RCW 19.255.005 - Personal Information Definitions(app.leg.wa.gov).gov
  13. RCW 19.255.030 Federal Law, Covered Entities, Financial Institutions(app.leg.wa.gov)
Share: