EnglishEspañol
West Virginia flag

West Virginia

West Virginia Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 6 primary sources cited on this page. How we verify our legal content

West Virginia Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a West Virginia business notify consumers of a data breach?

West Virginia requires notification 'without unreasonable delay' after discovering a breach. There is no specific day count. The entity may delay notification to investigate the scope of the breach and restore system integrity, or if law enforcement determines that notification would impede an investigation. This open-ended standard provides flexibility but less clarity than states with fixed deadlines.

Does West Virginia require notification to the Attorney General for data breaches?

No. West Virginia does not require notification to the Attorney General or any other state agency. However, if a breach requires notification to more than 1,000 people, the entity must notify the nationwide consumer reporting agencies (Equifax, Experian, and TransUnion) about the timing, distribution, and content of the consumer notification. That credit-bureau duty does not apply to an entity subject to Title V of the Gramm-Leach-Bliley Act.

What types of personal information trigger breach notification in West Virginia?

West Virginia has one of the narrower definitions among U.S. states. Only three categories of data trigger notification when combined with a name: Social Security numbers, driver's license or state ID numbers, and financial account numbers (credit/debit cards) combined with any required security code or password. The law does not cover biometric data, medical records, login credentials, or passport numbers.

Can individuals sue for data breach notification violations in West Virginia?

No. West Virginia does not provide a private right of action for breach notification violations. Enforcement belongs to the Attorney General, with one exception: under 46A-2A-104(c), a violation by a licensed financial institution is enforceable exclusively by that institution's primary functional regulator. Civil penalties are capped at $150,000 per breach or series of related breaches and require a showing of repeated and willful violations.

Does West Virginia's law require notification if the breached data was encrypted?

Usually not, but the safe harbor has limits. The general notification duty applies only to unencrypted and unredacted personal information, so data that was properly encrypted or redacted (truncated to no more than the last four digits) at the time of the breach ordinarily does not trigger notice. However, 46A-2A-102(b) still requires notice if the encrypted information is accessed and acquired in an unencrypted form, or if the breach involves a person with access to the encryption key, and the entity reasonably believes identity theft or other fraud has resulted or will result.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the encryption safe harbor, which is not absolute under W. Va. Code 46A-2A-102(b), added the Gramm-Leach-Bliley exemption from the credit-bureau notice, noted that violations by licensed financial institutions are enforced by their primary functional regulator rather than the Attorney General, and clarified that the substitute-notice conditions are alternatives.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected two compliance-relevant errors: West Virginia's breach notification law DOES specify required notice content under W. Va. Code 46A-2A-102(d) (it does not leave this unregulated), and substitute notice requires any TWO of three methods, not all three.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. W.Va. Code 46A-2A-101 Definitions(code.wvlegislature.gov).gov
  2. W.Va. Code 46A-2A-102 Notice of Breach(code.wvlegislature.gov).gov
  3. W.Va. Code 46A-2A-103 Procedures Deemed in Compliance(code.wvlegislature.gov).gov
  4. W.Va. Code Article 46A-2A Full Article(code.wvlegislature.gov).gov
  5. West Virginia Attorney General(ago.wv.gov).gov
  6. FTC Data Breach Response Guide(ftc.gov).gov
  7. W. Va. Code 46A-2A-104 Violations (Attorney General enforcement; financial-institution exception)(code.wvlegislature.gov)
Share: