EnglishEspañol
Wyoming flag

Wyoming

Wyoming Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 4 primary sources cited on this page. How we verify our legal content

Wyoming Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a Wyoming business notify consumers of a data breach?

Wyoming requires notification 'in the most expedient time possible and without unreasonable delay.' There is no specific day count. The entity must first conduct a good-faith investigation to determine whether personal identifying information has been or will be misused. If misuse has occurred or is reasonably likely, notification must follow as soon as possible. Under Wyo. Stat. 40-12-502(b), notification may be delayed only if a law enforcement agency determines in writing that it may seriously impede a criminal investigation.

Does Wyoming require notification to the Attorney General for data breaches?

No. Wyoming does not require notification to the Attorney General, any state agency, or consumer reporting agencies. Notification obligations are limited to affected individuals. This makes Wyoming one of the least demanding states for government breach reporting.

What types of personal information trigger breach notification in Wyoming?

Wyoming has one of the broadest definitions of personal identifying information in the country. It includes Social Security numbers, driver's license numbers, financial account data, tribal IDs, government-issued IDs, shared secrets or security tokens, username/password combinations, birth or marriage certificates, medical information, health insurance data, biometric data, and taxpayer identification numbers.

Does Wyoming's data breach notification law apply to government agencies?

No. Wyo. Stat. 40-12-502 applies only to individuals and commercial entities conducting business in the state. State agencies are covered by a different statute: Wyo. Stat. 9-21-101(a)(v) requires every executive branch agency to adopt and maintain a data policy that includes breach notification and mitigation procedures. That requirement does not extend to the legislature, the judiciary, the University of Wyoming, or the community colleges.

Does encrypting data exempt a Wyoming business from breach notification?

No. Wyoming's breach notification statute contains no encryption safe harbor, and the word 'encrypt' does not appear in Wyo. Stat. 40-12-501 or 40-12-502. The statute's only data carve-out is redaction: personal identifying information means a name combined with the listed data elements only when those elements are not redacted, and redaction means truncating the data so that no more than five digits remain accessible.

Can individuals sue for data breach notification violations in Wyoming?

No. Wyoming does not provide a private right of action for breach notification violations. Only the Wyoming Attorney General can bring enforcement actions. The AG may seek injunctive relief, compliance orders, and damages. The statute does not specify maximum penalty amounts.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected this guide against the official text of Wyo. Stat. 40-12-501 and 40-12-502: removed an encryption safe harbor Wyoming law does not contain, and fixed the substitute notice, required notice contents, law enforcement delay, third-party custodian and state agency provisions to match the statute.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected the Exceptions section, which had misattributed Wyoming's HIPAA/GLBA breach-notification safe harbors to the wrong statute (40-12-505, which actually governs credit-report exceptions to a security freeze); the safe harbors are actually in 40-12-502(c) and 40-12-502(h). Also corrected the Methods of Notification list, which fabricated an E-SIGN Act condition and a telephonic-notice method not present in the statute; Wyoming's three methods are written notice, electronic mail notice, and substitute notice.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Wyo. Stat. 40-12-501 Definitions(law.justia.com)
  2. Wyo. Stat. 40-12-502 Computer Security Breach Notice(law.justia.com)
  3. Wyo. Stat. 6-3-901 Personal Identifying Information(law.justia.com)
  4. Wyoming Attorney General Privacy(ag.wyo.gov).gov
  5. Wyoming Legislature SF 53 Original Bill(wyoleg.gov).gov
  6. HIPAA Information(hhs.gov).gov
  7. Gramm-Leach-Bliley Act(ftc.gov).gov
  8. Wyo. Stat. 40-12-501 through 40-12-511, Wyoming Legislature official statutes(wyoleg.gov)
  9. Wyo. Stat. 9-21-101 Data policies (state agency breach notification and mitigation procedures)(wyoleg.gov)
Share: