Washington
Washington Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 12 primary sources cited on this page. How we verify our legal content

Washington businesses must notify affected consumers within 30 days of discovering a data breach under RCW 19.255.010, and must also notify the Attorney General when a single breach requires notifying more than 500 Washington residents. The deadline applies regardless of business size, and the clock starts on the date of discovery, not when the breach occurred.
Washington state has one of the most comprehensive data breach notification laws in the United States. Its 30-day notification deadline is among the shortest nationally, its definition of personal information is among the broadest, and it is one of the few states where individual consumers have a private right of action to sue for notification violations.
The core statute for private entities is RCW 19.255.010. A parallel statute, RCW 42.56.590, governs state and local government agencies. The law was originally enacted in 2005 and was significantly strengthened by HB 1071, signed by Governor Jay Inslee on May 7, 2019, with the new requirements taking effect March 1, 2020.
For a broader look at Washington's privacy framework, see the parent guide to Washington Data Privacy Laws.
Who Must Comply
Washington's breach notification law applies to any person or business that conducts business in the state and owns or licenses computerized data that includes personal information about Washington residents.
There is no minimum size threshold. Any business, regardless of size, that handles personal information of Washington residents must comply.
Government agencies at the state and local level are covered under the separate statute RCW 42.56.590, which imposes substantially similar obligations.
Third-party service providers that maintain data on behalf of another business must notify the data owner or licensee immediately following discovery of a breach. The data owner then bears responsibility for consumer and AG notification.
What Qualifies as Personal Information
Washington's definition of personal information is among the broadest in the country. Under RCW 19.255.005, the definition has three separate branches, and only the first of them requires the resident's name.
Branch one: a name plus a data element. A resident's first name or first initial and last name in combination with any one or more of the following:
- Social Security number
- Driver's license number or Washington identification card number
- Account number or credit or debit card number, combined with any required security code, access code, or password that would permit access to a financial account, or any other numbers or information that can be used to access a financial account
- Full date of birth
- Private key that is unique to an individual and used to authenticate or sign an electronic record
- Student, military, or passport identification number
- Health insurance policy number or health insurance identification number
- Any information about a consumer's medical history or mental or physical condition, or about a health care professional's medical diagnosis or treatment of the consumer
- Biometric data generated by automatic measurements of an individual's biological characteristics, such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns used to identify a specific individual
Branch two: account credentials, with no name required. A user name or email address in combination with a password or security questions and answers that would permit access to an online account is personal information on its own. The resident's name does not have to be part of the breached data.
Branch three: those same data elements without a name. Any of the branch-one data elements, or any combination of them, without the consumer's first name or first initial and last name, if encryption, redaction, or other methods have not rendered them unusable and they would enable a person to commit identity theft against the consumer.
The inclusion of date of birth, student, military and passport ID numbers, health insurance information, and medical history makes Washington's list of data elements substantially broader than most states, and branches two and three widen the law further by dropping the name requirement that most state breach statutes treat as mandatory. The 2019 amendments through HB 1071 added several of these categories.
Personal information does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.
What Triggers the Notification Requirement
A breach of the security system under Washington law is the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the entity.
Three conditions must be met for notification to be required:
- Personal information was, or is reasonably believed to have been, acquired by an unauthorized person
- The personal information was not secured (i.e., not encrypted or otherwise rendered unusable)
- The breach is reasonably likely to subject consumers to a risk of harm
The risk-of-harm analysis gives entities some discretion, but the standard is whether harm is "reasonably likely," not whether it has already occurred. Good-faith acquisition of personal information by an employee or agent of the entity does not constitute a breach, provided the information is not used or disclosed in an unauthorized manner.
The 30-Day Notification Deadline

Washington requires notification in the most expedient time possible and without unreasonable delay, but no later than 30 days after the breach was discovered.
This 30-day deadline, introduced by HB 1071, is one of the shortest in the country. Before the 2019 amendments, the deadline was 45 days.
The clock starts from the date the breach was discovered, not from the date the breach itself occurred. However, organizations should not delay their investigation as a means of avoiding the timeline.
Law enforcement may request a delay in notification if it would impede a criminal investigation. The entity must provide notification promptly after law enforcement determines notification will no longer compromise the investigation.
What the Consumer Notice Must Include
Washington law specifies required content for breach notification letters. Under RCW 19.255.010(6)(b), the notice must include all four of the following:
- The name and contact information of the reporting person or business
- A list of the types of personal information that were or are reasonably believed to have been the subject of the breach
- A time frame of exposure, if known, including the date of the breach and the date of the discovery of the breach
- The toll-free telephone numbers and addresses of the major credit reporting agencies, if the breach exposed personal information
The credit reporting agency item is not limited to financial data or Social Security numbers. The statute conditions it on the breach having exposed personal information, which is the same condition that requires the notice in the first place, so in practice it belongs in every consumer notice.
The notice must be written in plain language. Beyond those four required items, entities are encouraged, though not strictly required, to also include a description of the incident, steps taken to address the breach, and recommendations for consumers to protect themselves.
Attorney General Notification
When a breach affects more than 500 Washington residents, the entity must notify the Washington Attorney General's office within the same 30-day window.
The AG notification is submitted via an online Data Breach Notification Web Form. The notice must include:
- The number of Washington consumers affected or potentially affected
- A list of the types of personal information breached
- The time frame of exposure (if known)
- A summary of steps taken to contain the breach
- A sample copy of the security breach notification sent to consumers
The AG's office maintains a public Data Breach Notifications Directory on its website, listing all reported breaches.
Substitute Notice
Washington allows substitute notice when direct notification is not feasible. An entity may use substitute notice if:
- The cost of providing direct notice would exceed $250,000
- The affected class exceeds 500,000 people
- The entity does not have sufficient contact information
Substitute notice must include all of the following: email notification (if email addresses are available), conspicuous posting on the entity's website, and notification to major statewide media.
Encryption Safe Harbor

Washington provides an encryption safe harbor. If the personal information was secured (encrypted, redacted, or otherwise rendered unusable) at the time of the breach, notification is not required.
The definition of "secured" means encrypted in a manner that meets or exceeds the National Institute of Standards and Technology (NIST) standard, or is otherwise modified so that the personal information is rendered unreadable, unusable, or undecipherable by an unauthorized person.
If the encryption key was also compromised in the breach, the safe harbor does not apply.
Interaction with Federal Regulations
Washington addresses federal overlap in RCW 19.255.030, and the two routes it creates work differently.
Under RCW 19.255.030(1), a covered entity under HIPAA is deemed to have complied with all of chapter 19.255 with respect to protected health information if it has complied with section 13402 of the federal HITECH Act. That entity still notifies the Washington Attorney General, but it does so on the HITECH timeline, expressly notwithstanding the 30-day timeline in RCW 19.255.010(7).
Under RCW 19.255.030(2), a financial institution regulated by the Office of the Comptroller of the Currency, the Federal Deposit Insurance Corporation, the National Credit Union Administration, or the Federal Reserve System is deemed to have complied with the chapter as to "sensitive customer information" if it notifies affected consumers under the federal interagency guidelines establishing information security standards. This route carries no equivalent override of the state clock: the statute says the institution shall notify the attorney general pursuant to RCW 19.255.010, in addition to notifying its primary federal regulator.
A separate and narrower provision, RCW 19.255.010(5), covers an entity's own internal policy rather than federal law. A person or business that maintains its own notification procedures as part of an information security policy for the treatment of personal information, and that is otherwise consistent with the timing requirements of that section, complies by notifying affected persons in accordance with those policies. It is conditioned on the entity's own procedures matching the statutory timing, so it is not a route to a longer deadline.
Enforcement and Private Right of Action

Washington's breach notification law is enforced under RCW 19.255.040. This section splits enforcement into two distinct tracks:
Attorney General Enforcement: Under RCW 19.255.040(2), the attorney general may bring an action treating a violation as an unfair or deceptive act in trade or commerce. The statute expressly provides that an action to enforce the chapter may not be brought under RCW 19.86.090, the Consumer Protection Act's general private-action provision. The AG can seek injunctive relief, civil penalties, and restitution.
Private Right of Action: RCW 19.255.040(3)(a) gives consumers their own standalone remedy, separate from the CPA's general track: any consumer injured by a violation of the chapter may institute a civil action to recover damages. Because the statute bars routing a chapter claim through RCW 19.86.090, the treble-damages multiplier, the $25,000 cap, and the attorney's-fee provision that apply to general Consumer Protection Act claims do not automatically apply to this action. The statute's own text authorizes recovery of:
- Actual damages sustained
This private right of action still makes Washington one of the more plaintiff-friendly states for breach notification enforcement, since most states give consumers no lawsuit at all. Consumers do not need to wait for the AG to act; they can pursue claims independently.
Government Agency Requirements
State and local government agencies in Washington are governed by RCW 42.56.590, which mirrors the private-sector requirements. Government agencies must:
- Notify affected residents within 30 days of discovery
- Notify the AG when more than 500 residents are affected
- Provide the same content in their notification letters
Government agencies may also delay notification to affected consumers for up to an additional 14 days beyond the 30-day deadline, to allow the notice to be translated into the primary language of the affected consumers, under RCW 42.56.590(8).
More Washington Laws
Frequently Asked Questions
How quickly must a Washington business notify consumers of a data breach?
Washington requires notification within 30 days of discovering a data breach. This deadline was shortened from 45 days to 30 days by HB 1071, which took effect March 1, 2020. The clock starts from the date the breach was discovered, not from the date the breach itself occurred. Law enforcement may request a delay if notification would impede a criminal investigation.
When must the Washington Attorney General be notified of a data breach?
Entities must notify the Washington Attorney General within 30 days when a breach affects more than 500 Washington residents. The notification is submitted via an online web form on the AG's website. The notice must include the number of affected residents, types of personal information compromised, time frame of exposure, steps taken to contain the breach, and a sample copy of the consumer notification.
Can individuals sue for data breach notification violations in Washington?
Yes. Washington is one of the few states that provides a private right of action for breach notification violations. Under RCW 19.255.040(3)(a), a consumer injured by a violation may bring a civil action to recover damages. This is a standalone remedy: the statute expressly states that an action to enforce the chapter may not be brought under RCW 19.86.090, the Consumer Protection Act's general treble-damages provision, so the $25,000 treble-damages cap that applies to other Washington consumer claims does not automatically apply to a breach notification lawsuit.
What types of personal information are protected under Washington's breach notification law?
Washington has one of the broadest definitions of personal information in the country. RCW 19.255.005(2)(a) sets out three branches. The first is a resident's name combined with a data element such as a Social Security number, driver's license number, financial account data, full date of birth, student, military or passport ID number, health insurance ID, medical history, or biometric data such as a fingerprint or eye retina scan. The second is a user name or email address with a password or security question answers, which counts on its own with no name attached. The third covers those same data elements without a name, where they were not rendered unusable and would enable identity theft. The definition was significantly expanded by HB 1071 in 2019.
Does Washington's breach notification law apply to government agencies?
Yes. Washington has two parallel statutes. RCW 19.255 covers private businesses and individuals, while RCW 42.56.590 covers state and local government agencies. Both impose the same 30-day notification deadline and the same AG reporting requirements. Government agencies do have one accommodation private businesses do not: they may delay consumer notification up to 14 additional days to translate the notice into the primary language of affected consumers, under RCW 42.56.590(8).
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the personal information definition to include the two branches that require no name, added the required time frame of exposure to the consumer notice contents, and replaced the federal interaction section with the actual deemed-compliance rules of RCW 19.255.030 for HIPAA covered entities and federally regulated financial institutions.
Corrected the description of Washington's breach-notification lawsuit: consumers sue under a standalone damages provision (RCW 19.255.040) that the statute expressly excludes from the Consumer Protection Act's treble-damages track, not under the $25,000 treble-damages CPA claim the page previously described. Also fixed an unsupported reference to Office of the Chief Information Officer guidelines, added the agency-only 14-day translation extension, and corrected the personal-information definition's citation from RCW 19.255.010 to RCW 19.255.005.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected the dollar figure for Washington's breach-notification private right of action. The private right of action itself is real (RCW 19.255.040(3)(a), which routes into RCW 19.86 as an unfair/deceptive act), but the remedy is not a flat '$1,000 punitive damages' figure -- that number appears nowhere in RCW 19.255.010, .040, or the Consumer Protection Act. The actual enhanced remedy under RCW 19.86.090 is court-discretionary treble damages capped at $25,000, plus costs and attorney's fees.
Corrected two substitute-notice and safe-harbor claims: substitute notice under RCW 19.255.010 requires email, website posting, AND statewide media notice together, not just the first two; and the internal-procedures safe harbor applies to an entity's own compliant notification policy, not specifically to HIPAA or GLBA compliance.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Revised Code of Washington
§ 19.255.010Personal information—Notice of security breaches.In forcecited in 5 of our articles
(1) Any person or business that conducts business in this state and that owns or licenses data that includes personal information shall disclose any breach of the security of the system to any resident of this state whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person and the personal information was not secured. Notice is not required if the breach of the security of the system is not reasonably likely to subject consumers to a risk of harm. The breach of secured personal information must be disclosed if the information acquired and accessed is not secured during a security breach or if the confidential process, encryption key, or other means to decipher the secured information was acquired by an unauthorized person. (2) Any person or business that maintains or possesses data that may include personal information that the person or business does not own or license shall notify the owner or licensee of the information of any breach of the security of the data immediately following discovery, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at app.leg.wa.gov
Cited in 5 court opinions in our collectionLatest citing opinion in our collection: 2024
In the courts (editorial summary, independently checked):Guy v. Convergent Outsourcing (2023) held RCW 19.255.010(2) reaches only a business that maintains data it does not own or license, and that a subsection (1) claim needs a Washington resident plaintiff. Krefting v. Kaye-Smith (2023) applied the 30-day notice window in subsection (8) without deciding whether it creates a tort duty.
Opinions citing this section in our collection:
- Sarah Nunley v. Chelan-Douglas Health District (Court of Appeals of Washington 2024)✓After hackers took patient records from a health district, the court reversed dismissal of a negligence suit and cited the breach notification statute's notice duty and damages remedy as evidence of Washington policy supporting a common law duty to safeguard personal data.
- In re Sony Gaming Networks & Customer Data Security Breach Litigation (District Court, S.D. California 2014, 996 F. Supp. 2d 942)“…sufficient. The court agrees. With respect to a claim under RCW 19.255.010, it is not enough for Mr. Grigsby to ha…”
- In re Premera Blue Cross Customer Data Security Breach Litigation (District Court, D. Oregon 2016, 198 F. Supp. 3d 1183)“…(2) violation of the Washington Data Breach Disclosure Law, RCW § 19.255.010; 3 (3) negligence; 4 (4) breach of ex…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Washington Security Camera Laws: Rules for Home and Business Surveillance (2026), Data Breach Notification Deadlines by Country (2026 Comparison Table), Washington Data Privacy Laws: My Health My Data Act & More (2026)
§ 19.255.005Definitions.In forcecited in 2 of our articles
The definitions in this section apply throughout this chapter unless the context clearly requires otherwise. (1) "Breach of the security of the system" means unauthorized acquisition of data that compromises the security, confidentiality, or integrity of personal information maintained by the person or business. Good faith acquisition of personal information by an employee or agent of the person or business for the purposes of the person or business is not a breach of the security of the system when the personal information is not used or subject to further unauthorized disclosure.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
Cited in 13 court opinions in our collectionLatest citing opinion in our collection: 2024
Opinions citing this section in our collection:
- Greek Islands Cuisine Inc v. YourPeople Inc (District Court, E.D. Washington 2024)“…10 RCW 19.255.005(2)(a).…”
- Doe v. Fred Hutchinson Cancer Center (District Court, W.D. Washington 2024)“…tion of the Washington Data 8 Breach Disclosure Law, see RCW 19.255.005 et seq.; and (10) violation of the Wash…”
- Aleshire v. Fred Hutchinson Cancer Center (District Court, W.D. Washington 2024)“…tion of the Washington Data 8 Breach Disclosure Law, see RCW 19.255.005 et seq.; and (10) violation of the Wash…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 19.255.040Consumer protection.In force
(1) Any waiver of the provisions of this chapter is contrary to public policy, and is void and unenforceable. (2) The attorney general may bring an action in the name of the state, or as parens patriae on behalf of persons residing in the state, to enforce this chapter. For actions brought by the attorney general to enforce this chapter, the legislature finds that the practices covered by this chapter are matters vitally affecting the public interest for the purpose of applying the consumer protection act, chapter 19.86 RCW. For actions brought by the attorney general to enforce this chapter, a violation of this chapter is not reasonable in relation to the development and preservation of business and is an unfair or deceptive act in trade or commerce and an unfair method of competition for purposes of applying the consumer protection act, chapter 19.86 RCW. An action to enforce this chapter may not be brought under RCW 19.86.090. (3)(a) Any consumer injured by a violation of this chapter may institute a civil action to recover damages. (b) Any person or business that violates, proposes to violate, or has violated this chapter may be enjoined.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2024
Opinions citing this section in our collection:
- Sarah Nunley v. Chelan-Douglas Health District (Court of Appeals of Washington 2024)“…ice requirement have a cause of action to recover damages. RCW 19.255.040(3)(a). There are numerous other…”
- Guy v. Convergent Outsourcing Inc (District Court, W.D. Washington 2023)“…chapter [to] institute a civil action to recover damages.” RCW 19.255.040(3)(a). 22 Convergent argues tha…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 42.56.590Personal information—Notice of security breaches.In force
(1) Any agency that owns or licenses data that includes personal information shall disclose any breach of the security of the system to any resident of this state whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person and the personal information was not secured. Notice is not required if the breach of the security of the system is not reasonably likely to subject consumers to a risk of harm. The breach of secured personal information must be disclosed if the information acquired and accessed is not secured during a security breach or if the confidential process, encryption key, or other means to decipher the secured information was acquired by an unauthorized person. (2) Any agency that maintains or possesses data that may include personal information that the agency does not own or license shall notify the owner or licensee of the information of any breach of the security of the data immediately following discovery, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
Cited in 7 court opinions in our collectionLatest citing opinion in our collection: 2024
Opinions citing this section in our collection:
- Wa Federation Of State Employees, Resps V. Freedom Foundation, App (Court of Appeals of Washington 2022)“…(Wash. 2019). One provision of SHB 1071 amended RCW 42.56.590, which requires that agencie…”
- Wa Education Association, V. Dept.of Retirement Systems (Court of Appeals of Washington 2022)“…Bill (SHB) 1071 went into effect. This legislation amended RCW 42.56.590 to require any public agency that owns,…”
- Wash. Pub. Emps. Ass'n v. Wash. State Ctr. for Childhood Deafness & Hearing Loss (Washington Supreme Court 2019)“…requiring agencies to notify persons of security breaches. RCW 42.56.590. While this definition exists for a spe…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 19.86.090Civil action for damages—Treble damages authorized—Action by governmental entities.In forcecited in 5 of our articles
Any person who is injured in his or her business or property by a violation of RCW 19.86.020, 19.86.030, 19.86.040, 19.86.050, or 19.86.060, or any person so injured because he or she refuses to accede to a proposal for an arrangement which, if consummated, would be in violation of RCW 19.86.030, 19.86.040, 19.86.050, or 19.86.060, may bring a civil action in superior court to enjoin further violations, to recover the actual damages sustained by him or her, or both, together with the costs of the suit, including a reasonable attorney's fee. In addition, the court may, in its discretion, increase the award of damages up to an amount not to exceed three times the actual damages sustained: PROVIDED, That such increased damage award for violation of RCW 19.86.020 may not exceed twenty-five thousand dollars: PROVIDED FURTHER, That such person may bring a civil action in the district court to recover his or her actual damages, except for damages which exceed the amount specified in RCW 3.66.020, and the costs of the suit, including reasonable attorney's fees.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at app.leg.wa.gov
Cited in 529 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Hangman Ridge Training Stables, Inc. v. Safeco Title Insurance (Washington Supreme Court 1986, 105 Wash. 2d 778)“…izens would be encouraged to bring suit to enforce the CPA. RCW 19.86.090, as amended, first in 1971 and again in…”
- Washington State Physicians Insurance Exchange & Ass'n v. Fisons Corp. (Washington Supreme Court 1993, 122 Wash. 2d 299)“…any trade or commerce are hereby declared unlawful. *312 RCW 19.86.090 creates a private right of action by pr…”
- Bowers v. Transamerica Title Insurance (Washington Supreme Court 1983, 100 Wash. 2d 581)“…d its discretion in awarding attorney fees of $42,805 under RCW 19.86.090. We hold that: 1. An escrow agent i…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: MHMDA Business Compliance (Washington), MHMDA Consumer Rights (Washington), What Is MHMDA? WA My Health My Data Act
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- RCW 19.255.010 Personal Information Notice of Security Breaches(app.leg.wa.gov).gov
- RCW 42.56.590 Government Agency Breach Notification(app.leg.wa.gov).gov
- Chapter 19.255 RCW Full Text(app.leg.wa.gov).gov
- Washington AG Data Breach Notification Laws(atg.wa.gov).gov
- Washington AG HB 1071 FAQ(atg.wa.gov).gov
- Washington AG Data Breach Notifications Directory(atg.wa.gov).gov
- Washington AG Data Breach Resource Center(atg.wa.gov).gov
- Washington AG Identity Theft Guide for Businesses(atg.wa.gov).gov
- HB 1071 Bill Summary(app.leg.wa.gov).gov
- HIPAA Information(hhs.gov).gov
- Gramm-Leach-Bliley Act(ftc.gov).gov
- RCW 19.255.005 - Personal Information Definitions(app.leg.wa.gov).gov
- RCW 19.255.030 Federal Law, Covered Entities, Financial Institutions(app.leg.wa.gov)