Wisconsin
Wisconsin Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 6 primary sources cited on this page. How we verify our legal content

Under Wis. Stat. 134.98, Wisconsin businesses must notify affected individuals of a data breach within 45 days of learning that personal information was acquired without authorization. The deadline runs from when the entity becomes aware, not when the breach occurred, and applies to name-plus-identifier combinations including Social Security numbers and biometric data.
Wisconsin's data breach notification law strikes a balance between consumer protection and business flexibility. While the state includes biometric data and DNA profiles in its definition of personal information, setting it apart from states with narrower definitions, it does not require any notification to state agencies and lacks a private right of action for affected consumers.
The statute is codified at Wis. Stat. 134.98. Originally enacted in 2006, the law has been updated periodically, though it remains more concise than the breach notification statutes of many other states.
For a broader look at Wisconsin's privacy framework, see the parent guide to Wisconsin Data Privacy Laws.
Who Must Comply
Wisconsin's breach notification law applies to any entity whose principal place of business is located in Wisconsin, or any entity that maintains or licenses personal information in the state, if that entity knows that personal information in its possession has been acquired by an unauthorized person.
The law also reaches businesses based outside Wisconsin. Under Wis. Stat. 134.98(2)(b), an entity whose principal place of business is not located in Wisconsin must make reasonable efforts to notify each Wisconsin resident whose personal information it knows was acquired by an unauthorized person. Having no Wisconsin office does not place a company outside the statute.
Under Wis. Stat. 134.98(1)(a), "entity" means a person other than an individual that does any of the following: conducts business in this state and maintains personal information in the ordinary course of business; licenses personal information in this state; maintains a depository account, as defined in Wis. Stat. 815.18(2)(e), for a Wisconsin resident; or lends money to a Wisconsin resident. The last two hooks are easy to overlook: an out-of-state bank or lender is covered simply because it holds accounts for or lends to Wisconsin residents. The definition also expressly includes the state and its agencies, authorities, and institutions, including the legislature and the courts, as well as cities, villages, towns, and counties.
Third-party data custodians are covered, but only in a specific situation. Under Wis. Stat. 134.98(2)(bm), a person that stores personal information about a Wisconsin resident, but does not own or license it, must notify the owner or licensee as soon as practicable only if that storer has not entered into a contract with the person that owns or licenses the information. Because most vendors and service providers do operate under a written contract with the data owner, this statutory duty often does not reach them, and their notification obligations are set by that contract instead. Where the statutory duty does apply, the data owner then bears responsibility for consumer notification.
What Qualifies as Personal Information
Under Wis. Stat. 134.98(1)(b), personal information means an individual's last name and first name or first initial, combined with one or more of the following data elements:
- Social Security number
- Driver's license number or state identification card number
- Financial account number, including a credit or debit card account number, or any security code, access code, or password that would permit access to the individual's financial account
- Deoxyribonucleic acid (DNA) profile, as defined in Wis. Stat. 939.74(2d)(a)
- Unique biometric data, including fingerprint, voice print, retina or iris image, or any other unique physical representation
Note that the financial element is written disjunctively. A name paired with a standalone security code, access code, or password that would permit access to the account is covered on its own, without the account number.
The inclusion of DNA profiles and biometric data distinguishes Wisconsin from states with narrower definitions. However, unlike states such as Washington or Colorado, Wisconsin does not include medical records, health insurance information, passport numbers, military IDs, or login credentials in its definition.
Personal information does not include information that is lawfully obtained from publicly available records or from federal, state, or local government records lawfully made available to the general public.
What Triggers the Notification Requirement
Notification is required when an entity knows that personal information in its possession has been acquired by a person whom the entity has not authorized to acquire the personal information.
Wisconsin's notification trigger includes a risk-of-harm exception. Under Wis. Stat. 134.98(2)(cm)1., an entity is not required to notify if the acquisition of personal information does not create a material risk of identity theft or fraud to the affected individual. Once the entity knows an unauthorized acquisition has occurred and that it creates a material risk of identity theft or fraud, the notification obligation begins.
Wis. Stat. 134.98(2)(cm)2. supplies a second exemption from the duty to notify: notice is not required where the personal information was acquired in good faith by an employee or agent of the entity, if the personal information is used for a lawful purpose of the entity. Note the structure. This is an exemption from the notice requirement rather than a rule that such an acquisition was never unauthorized, and it turns on the affirmative condition that the information is put to a lawful purpose of the entity.
The 45-Day Notification Deadline

Wisconsin requires entities to provide notice within a reasonable time, not to exceed 45 days after the entity learns of the unauthorized acquisition of personal information.
The 45-day clock begins when the entity learns of the acquisition, not when the breach itself occurred. The statute emphasizes that notification must occur within a "reasonable time," meaning that 45 days is the outer limit, not the target.
A law enforcement agency may request a delay in notification to protect an investigation or homeland security. During such a delay, the entity may not provide notice of or publicize the breach except as authorized by the law enforcement agency. The notification process begins at the end of the delay period.
What the Consumer Notice Must Include
Wisconsin's statute requires that the notice "indicate that the entity knows of the unauthorized acquisition of personal information pertaining to the subject of the personal information."
Beyond this basic requirement, the statute does not prescribe specific content elements. This is less detailed than many states, which require inclusion of credit reporting agency contact information, FTC contact details, and specific remediation steps.
However, the DATCP guidance recommends that notifications include:
- A description of the incident
- The types of personal information involved
- Steps the entity has taken to address the breach
- Contact information for the entity
- Recommendations for consumers to protect themselves
- Contact information for the credit reporting agencies and the FTC
Methods of Notification
Wisconsin allows notification through two primary methods:
- Mail sent to the last known address of the affected individual
- A method the entity has previously used to communicate with the individual
If the entity cannot with reasonable diligence determine the mailing address and has not previously communicated with the individual, it must provide notice by a method reasonably calculated to provide actual notice to the individual.
No Attorney General Notification

Wisconsin does not require notification to the Attorney General, DATCP, or any other state agency when a data breach occurs. This places Wisconsin among a diminishing number of states that do not mandate government notification.
Consumer Reporting Agency Notification
If, as the result of a single incident, an entity is required to notify 1,000 or more individuals, the entity must also notify the nationwide consumer reporting agencies (Equifax, Experian, and TransUnion) without unreasonable delay. The threshold is met at exactly 1,000 notices, not only above it.
The notice to the credit bureaus must include the timing, distribution, and content of the consumer notifications. This requirement aligns with most other states' consumer reporting agency notification provisions.
Encryption Safe Harbor

Wisconsin provides an encryption safe harbor. The notification requirements apply only to personal information that has not been "encrypted, redacted, or altered in a manner that renders the personal information unreadable."
If the compromised data was properly encrypted or rendered unreadable at the time of the unauthorized acquisition, notification is not required.
Federal Regulation Safe Harbors
Wisconsin provides specific safe harbors under Wis. Stat. 134.98(3m):
Financial institutions: An entity subject to and in compliance with the privacy and security requirements of the Gramm-Leach-Bliley Act (15 U.S.C. 6801-6827), or a person with contractual obligations to such an entity, is exempt from Wisconsin's notification requirements if it maintains a policy addressing breaches of information security.
Healthcare entities: An entity described in 45 CFR 164.104(a) that is in compliance with HIPAA security and privacy requirements (45 CFR Part 164) is exempt from the notification requirements.
These safe harbors are broader than those in many states, which often require federally regulated entities to still comply with certain state-specific requirements.
Effect on Civil Claims
Wisconsin includes an important provision in Wis. Stat. 134.98(4): failure to comply with the notification requirements is not negligence or a breach of any duty, but may be used as evidence of negligence or a breach of a legal duty in a civil action.
This means that while there is no standalone private right of action under the breach notification statute, a failure to notify could potentially strengthen a plaintiff's case in a separate negligence or breach-of-duty claim.
Enforcement and Penalties
Wis. Stat. 134.98 does not establish a civil forfeiture or other dollar-amount penalty for noncompliance, and the statute does not name a specific enforcement agency. The only stated consequence for a failure to notify is the evidentiary provision in subsection (4).
There is no private right of action that allows individual consumers to sue directly under this statute, though the evidentiary provision in subsection (4) may support related civil claims.
DATCP maintains guidance documents for businesses on complying with the notification requirements and provides consumer resources for individuals affected by data breaches.
More Wisconsin Laws
Frequently Asked Questions
How quickly must a Wisconsin business notify consumers of a data breach?
Wisconsin requires notification within a reasonable time, not to exceed 45 days after the entity learns of the unauthorized acquisition of personal information. The clock starts when the entity becomes aware of the breach, not when the breach itself occurred. Law enforcement may request a temporary delay to protect an investigation or homeland security.
Does Wisconsin require notification to the Attorney General for data breaches?
No. Wisconsin does not require notification to the Attorney General, DATCP, or any other state agency. However, if a single incident requires notifying 1,000 or more individuals, the entity must notify the nationwide consumer reporting agencies (Equifax, Experian, and TransUnion) about the timing, distribution, and content of consumer notices. The threshold is met at exactly 1,000 notices.
What types of personal information trigger breach notification in Wisconsin?
Wisconsin protects an individual's name combined with Social Security numbers, driver's license or state ID numbers, financial account numbers or any security code, access code, or password that would permit access to a financial account, DNA profiles, and unique biometric data such as fingerprints, voice prints, and retina or iris images. The inclusion of DNA and biometric data is broader than many states, though Wisconsin does not cover medical records, login credentials, or passport numbers.
Does Wisconsin's breach notification law apply to businesses located outside the state?
Yes. Under Wis. Stat. 134.98(2)(b), an entity whose principal place of business is not in Wisconsin must make reasonable efforts to notify Wisconsin residents whose personal information it knows was acquired without authorization. The definition of entity also reaches a business that maintains a depository account for a Wisconsin resident or lends money to one, which brings in many out-of-state banks and lenders.
Can individuals sue for data breach notification violations in Wisconsin?
No. Wisconsin does not provide a private right of action under the breach notification statute. However, the law specifies that failure to comply may be used as evidence of negligence or breach of duty in a separate civil action. The statute does not establish a civil forfeiture or other specific dollar-amount penalty for noncompliance.
Are HIPAA-covered healthcare entities exempt from Wisconsin's breach notification law?
Yes. Wisconsin provides a safe harbor for healthcare entities that comply with HIPAA security and privacy requirements under 45 CFR Part 164. Similarly, financial institutions complying with the Gramm-Leach-Bliley Act are also exempt, provided they maintain a policy addressing breaches of information security.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the credit-bureau notification threshold to 1,000 or more individuals, replaced an inaccurate definition of "entity" with the statutory one, and added Wisconsin's coverage of out-of-state businesses along with fixes to the financial-account, third-party storage, and good-faith provisions.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Corrected two errors: the article claimed a $10,000-per-violation civil forfeiture and named Attorney General/DATCP enforcement authority, neither of which appears in Wis. Stat. 134.98 (confirmed against the full statute text and the official Wisconsin Legislature site); and corrected the claim that the breach-notification trigger has no risk-of-harm component, when 134.98(2)(cm)1. exempts entities from notifying when a breach creates no material risk of identity theft or fraud.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Wisconsin Statutes, Chapter 134: Miscellaneous Trade Regulations
§ 134.98Notice of unauthorized acquisition of personal information.In forcecited in 5 of our articles
(1) Definitions. In this section: (a) 1. “Entity” means a person, other than an individual, that does any of the following: a. Conducts business in this state and maintains personal information in the ordinary course of business. b. Licenses personal information in this state. c. Maintains for a resident of this state a depository account as defined in s. 815.18 (2) (e). d. Lends money to a resident of this state. 2. “Entity” includes all of the following: a. The state and any office, department, independent agency, authority, institution, association, society, or other body in state government created or authorized to be created by the constitution or any law, including the legislature and the courts. b. A city, village, town, or county. (am) “Name” means an individual’s last name combined with the individual’s first name or first initial. (b) “Personal information” means an individual’s last name and the individual’s first name or first initial, in combination with and linked to any of the following elements, if the element is not publicly available information and is not encrypted, redacted, or altered in a manner that renders the element unreadable: 1.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at docs.legis.wisconsin.gov
Cited in 5 court opinions in our collectionLatest citing opinion in our collection: 2025
In the courts (editorial summary, independently checked):Federal courts that analyzed Wis. Stat. 134.98 under Wisconsin implied right of action doctrine found no private suit. Fox, Yvonne v. Iowa Health System (2019) and Negron v. Ascension Health (2025) dismissed 134.98 counts, while In re Equifax, Inc. (2019) had let one proceed only absent Wisconsin authority.
Opinions citing this section in our collection:
- In re Target Corp. Customer Data Security Breach Litigation (District Court, D. Minnesota 2014, 66 F. Supp. 3d 1154)✓Hackers stole card and personal data from about 110 million Target shoppers in 2013 and consumers sued over delayed breach notice; the court noted Wis. Stat. 134.98 is silent on enforcement and, absent authority barring private suits, declined to dismiss the Wisconsin claim.
- In re Equifax, Inc. (District Court, N.D. Georgia 2019, 362 F. Supp. 3d 1295)✓Hackers exploited an unpatched Apache Struts flaw to take personal data on about 147 million people from Equifax, disclosed seven weeks later; the court read Wis. Stat. 134.98(4) as not barring private suit and, treating the statute as silent, let the Wisconsin claim proceed.
- Fox, Yvonne v. Iowa Health System (District Court, W.D. Wisconsin 2019)✓Patients sued UnityPoint Health after its email system was hacked in 2017 and 2018, exposing health data and Social Security numbers; the court held Wis. Stat. 134.98 creates no private right of action, relying on subsection (4), and dismissed the Wisconsin notification claim.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Wisconsin Data Privacy Laws: Breach Notification & Consumer Rights (2026), Wisconsin Biometric Privacy Laws: Collection, Consent & Penalties (2026), Wisconsin Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
Code of Federal Regulations Title 45
§ 164.104Applicability.In force
(a) Except as otherwise provided, the standards, requirements, and implementation specifications adopted under this part apply to the following entities: (1) A health plan. (2) A health care clearinghouse. (3) A health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter. (b) Where provided, the standards, requirements, and implementation specifications adopted under this part apply to a business associate.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 17 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- United States v. Yazzie (District Court, D. New Mexico 2014, 998 F. Supp. 2d 1044)“…enforcement directly.” 707 F.Supp.2d at 1259 (quoting 45 C.F.R. § 164.104 ). The Court also concluded that the pl…”
- Tapia v. City of Albuquerque (District Court, D. New Mexico 2014, 10 F. Supp. 3d 1323)“…enforcement directly.” 707 F.Supp.2d at 1259 (quoting 45 C.F.R. § 164.104 ). The Court also concluded that the pl…”
- Kerns v. Board of Com'rs of Bernalillo County (District Court, D. New Mexico 2010, 707 F. Supp. 2d 1190)“…formation, and does not restrain law-enforcement directly. 45 C.F.R. § 164.104 . See United States v. Prentice,…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Wisconsin Statutes, Chapter 939: Crimes
§ 939.74Time limitations on prosecutions.In forcecited in 4 of our articles
(1) Except as provided in subs. (2) and (2d) and s. 946.88 (1), prosecution for a felony must be commenced within 6 years and prosecution for a misdemeanor or for adultery within 3 years after the commission thereof. Within the meaning of this section, a prosecution has commenced when a warrant or summons is issued, an indictment is found, or an information is filed. (2) Notwithstanding that the time limitation under sub. (1) has expired: (a) 1. A prosecution under s. 940.01, 940.02, 940.03, 940.05, 940.225 (1), 948.02 (1), or 948.025 (1) (a), (b), (c), or (d) may be commenced at any time. 2. A prosecution for an attempt to commit a violation of s. 940.01, 940.05, 940.225 (1), or 948.02 (1) may be commenced at any time. (am) A prosecution under s. 940.06 may be commenced within 15 years after the commission of the violation. (ap) A prosecution under s. 940.11 (2) may be commenced within the applicable time under sub. (1) or within 6 years of the date the corpse was discovered or identified, whichever is later. (ar) A prosecution for a violation of s. 940.225 (2) may be commenced within 20 years after the commission of the violation. A prosecution for a violation of s.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at docs.legis.wisconsin.gov
Cited in 26 court opinions in our collectionLatest citing opinion in our collection: 2022
Opinions citing this section in our collection:
- State v. Joel M. Hurley (Wisconsin Supreme Court 2015, 361 Wis. 2d 529)“…(1) (a), (b), (c), or (d) "may be commenced at any time." Wis. Stat. § 939.74 (2)(a)(l) (2011 — 12). A prosecution un…”
- State v. Sweat (Wisconsin Supreme Court 1997, 208 Wis. 2d 409)“…tions that applies in the underlying criminal proceedings, Wis. Stat. § 939.74 , [2] including its tolling provisions…”
- State v. McGuire (Wisconsin Supreme Court 2010, 328 Wis. 2d 289)“…are subject to the six-year statute of limitations under Wis. Stat. § 939.74 (1) (2007-08), 1 the statute of limita…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Wisconsin Statute of Limitations: Filing Deadlines by Case Type
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Wis. Stat. 134.98 Notice of Unauthorized Acquisition(docs.legis.wisconsin.gov).gov
- DATCP Data Breach Notification Law Guidance(datcp.wi.gov).gov
- DATCP Data Breach Consumer Guide(datcp.wi.gov).gov
- Wisconsin State Law Library Privacy Law(wilawlibrary.gov).gov
- HIPAA Information(hhs.gov).gov
- Gramm-Leach-Bliley Act(ftc.gov).gov