EnglishEspañol
Wisconsin flag

Wisconsin

Wisconsin Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 6 primary sources cited on this page. How we verify our legal content

Wisconsin Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a Wisconsin business notify consumers of a data breach?

Wisconsin requires notification within a reasonable time, not to exceed 45 days after the entity learns of the unauthorized acquisition of personal information. The clock starts when the entity becomes aware of the breach, not when the breach itself occurred. Law enforcement may request a temporary delay to protect an investigation or homeland security.

Does Wisconsin require notification to the Attorney General for data breaches?

No. Wisconsin does not require notification to the Attorney General, DATCP, or any other state agency. However, if a single incident requires notifying 1,000 or more individuals, the entity must notify the nationwide consumer reporting agencies (Equifax, Experian, and TransUnion) about the timing, distribution, and content of consumer notices. The threshold is met at exactly 1,000 notices.

What types of personal information trigger breach notification in Wisconsin?

Wisconsin protects an individual's name combined with Social Security numbers, driver's license or state ID numbers, financial account numbers or any security code, access code, or password that would permit access to a financial account, DNA profiles, and unique biometric data such as fingerprints, voice prints, and retina or iris images. The inclusion of DNA and biometric data is broader than many states, though Wisconsin does not cover medical records, login credentials, or passport numbers.

Does Wisconsin's breach notification law apply to businesses located outside the state?

Yes. Under Wis. Stat. 134.98(2)(b), an entity whose principal place of business is not in Wisconsin must make reasonable efforts to notify Wisconsin residents whose personal information it knows was acquired without authorization. The definition of entity also reaches a business that maintains a depository account for a Wisconsin resident or lends money to one, which brings in many out-of-state banks and lenders.

Can individuals sue for data breach notification violations in Wisconsin?

No. Wisconsin does not provide a private right of action under the breach notification statute. However, the law specifies that failure to comply may be used as evidence of negligence or breach of duty in a separate civil action. The statute does not establish a civil forfeiture or other specific dollar-amount penalty for noncompliance.

Are HIPAA-covered healthcare entities exempt from Wisconsin's breach notification law?

Yes. Wisconsin provides a safe harbor for healthcare entities that comply with HIPAA security and privacy requirements under 45 CFR Part 164. Similarly, financial institutions complying with the Gramm-Leach-Bliley Act are also exempt, provided they maintain a policy addressing breaches of information security.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the credit-bureau notification threshold to 1,000 or more individuals, replaced an inaccurate definition of "entity" with the statutory one, and added Wisconsin's coverage of out-of-state businesses along with fixes to the financial-account, third-party storage, and good-faith provisions.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Corrected two errors: the article claimed a $10,000-per-violation civil forfeiture and named Attorney General/DATCP enforcement authority, neither of which appears in Wis. Stat. 134.98 (confirmed against the full statute text and the official Wisconsin Legislature site); and corrected the claim that the breach-notification trigger has no risk-of-harm component, when 134.98(2)(cm)1. exempts entities from notifying when a breach creates no material risk of identity theft or fraud.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Wis. Stat. 134.98 Notice of Unauthorized Acquisition(docs.legis.wisconsin.gov).gov
  2. DATCP Data Breach Notification Law Guidance(datcp.wi.gov).gov
  3. DATCP Data Breach Consumer Guide(datcp.wi.gov).gov
  4. Wisconsin State Law Library Privacy Law(wilawlibrary.gov).gov
  5. HIPAA Information(hhs.gov).gov
  6. Gramm-Leach-Bliley Act(ftc.gov).gov
Share: