Wyoming
Wyoming Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 4 primary sources cited on this page. How we verify our legal content

Wyoming requires businesses to notify affected residents of a data breach in the most expedient time possible and without unreasonable delay under Wyo. Stat. 40-12-502. The law sets no fixed day count; entities must investigate promptly and notify as soon as misuse has occurred or is reasonably likely.
Wyoming's data breach notification law applies exclusively to individuals and commercial entities in the private sector. While the state does not impose a fixed notification deadline or require reporting to state agencies, its definition of personal identifying information is surprisingly broad, encompassing categories that many larger states have yet to adopt, including birth and marriage certificates, tribal identification cards, shared security tokens, and health insurance information.
The law is codified at Wyo. Stat. 40-12-501 (definitions) and Wyo. Stat. 40-12-502 (notification requirements). Originally enacted in 2007, the law was significantly amended in 2015, when the legislature expanded the definition of personal identifying information and added specific notice content requirements.
For a broader look at Wyoming's privacy framework, see the parent guide to Wyoming Data Privacy Laws.
Who Must Comply
Wyoming's breach notification law applies to any individual or commercial entity that conducts business in Wyoming and that owns or licenses computerized data containing personal identifying information about Wyoming residents.
The law is specifically limited to the private sector. Government agencies are not covered by this statute. Wyoming state agencies are covered elsewhere instead: Wyo. Stat. 9-21-101(a) requires every executive branch agency to adopt, enforce and maintain a data policy that includes, at subsection (a)(v), processes for identifying and responding to data security incidents, "including breach notification and mitigation procedures." That section expressly excludes the legislature, the judiciary, the University of Wyoming, and the state's community colleges.
Third-party data custodians are also covered. Under Wyo. Stat. 40-12-502(g), a person who maintains computerized data containing personal identifying information on behalf of another business entity must disclose a breach to that entity as soon as practicable following the determination that personal identifying information was, or is reasonably believed to have been, acquired by an unauthorized person. The custodian and the data owner may agree which of them will send the consumer notice, and only a single notice is required for each breach. If they cannot reach an agreement, the party that has the direct business relationship with the Wyoming resident must provide the notice.
What Qualifies as Personal Identifying Information

Wyoming's definition of personal identifying information is among the most comprehensive in the country. Under Wyo. Stat. 40-12-501(a)(vii), personal identifying information means a person's first name or first initial and last name combined with one or more of the data elements specified in Wyo. Stat. 6-3-901(b)(iii) through (xiv), when the data elements are not redacted:
- Social Security number
- Driver's license number
- Financial account number, credit card number, or debit card number combined with any security code, access code, or password permitting access to a financial account
- Tribal identification card
- Federal or state government-issued identification card
- Shared secrets or security tokens known to be used for data-based authentication
- Username or email address combined with a password or security question and answer permitting access to an online account
- Birth or marriage certificate
- Medical information, including medical history, mental or physical condition, or medical treatment or diagnosis by a healthcare professional
- Health insurance information, including policy numbers, subscriber IDs, unique insurer identifiers, and claims history
- Unique biometric data generated from measurements or analysis of human body characteristics for authentication purposes
- Individual taxpayer identification number
The inclusion of birth and marriage certificates, tribal IDs, shared authentication secrets, and health insurance claims history distinguishes Wyoming from the majority of states. The 2015 amendments added many of these expanded categories.
Personal identifying information does not include information contained in federal, state, or local government records or widely distributed media that are lawfully made available to the general public.
What Triggers the Notification Requirement
A "security breach" under Wyoming law means the unauthorized acquisition of computerized data that materially compromises the security, confidentiality, or integrity of personal identifying information and causes, or is reasonably believed to cause, loss or injury to a Wyoming resident.
The trigger involves a two-part analysis:
-
Material compromise: The unauthorized acquisition must materially compromise the security, confidentiality, or integrity of the data. Minor or inconsequential incidents may not meet this threshold.
-
Loss or injury: The breach must cause, or be reasonably believed to cause, loss or injury to a Wyoming resident.
When an entity becomes aware of a potential breach, it must conduct a good-faith, reasonable, and prompt investigation to determine the likelihood that personal identifying information has been or will be misused. If the investigation determines that misuse has occurred or is reasonably likely, notification is required.
Good-faith acquisition of personal identifying information by an employee or agent of the entity does not constitute a breach, provided the information is not used or disclosed in an unauthorized manner.
Notification Timeline
Wyoming requires notice "in the most expedient time possible and without unreasonable delay," consistent with the legitimate needs of law enforcement and with any measures necessary to determine the scope of the breach and restore the reasonable integrity of the computerized data system.
There is no specific day count. This open-ended standard allows entities flexibility for investigation but provides less certainty than states with fixed deadlines.
Wyo. Stat. 40-12-502(b) allows one delay, and it is narrow: notification "may be delayed if a law enforcement agency determines in writing that the notification may seriously impede a criminal investigation." The determination has to be in writing, and a criminal investigation is the only ground the statute names.
What the Consumer Notice Must Include

The 2015 amendments added specific content requirements for breach notifications. The notice must include, at minimum:
- A toll-free number that the individual may use to contact the entity collecting the data, or its agent, and from which the individual may learn the toll-free contact telephone numbers and addresses for the major credit reporting agencies
- The types of personal identifying information that were or are reasonably believed to have been the subject of the breach
- A general description of the breach incident
- The approximate date of the breach, if reasonably determinable at the time of notice
- In general terms, the actions taken by the entity to protect the system from further breaches
- Advice directing the person to remain vigilant by reviewing account statements and monitoring credit reports
- Whether notification was delayed as a result of a law enforcement investigation, if reasonably determinable
The notice must be clear and conspicuous. These content requirements are more detailed than many states with open-ended notification standards.
Methods of Notification
Wyoming allows notification through one of the following methods:
- Written notice
- Electronic mail notice
- Substitute notice, if the entity demonstrates that the cost of notice would exceed the statutory threshold, the affected class exceeds the statutory threshold, or it does not have sufficient contact information (see Substitute Notice below)
Substitute Notice
Wyoming allows substitute notice, but the thresholds differ depending on whether the entity is based in Wyoming:
Wyoming-based entities may use substitute notice if:
- The cost of notice would exceed $10,000
- The affected class exceeds 10,000 persons
- The entity does not have sufficient contact information
Non-Wyoming-based entities may use substitute notice if:
- The cost of notice would exceed $250,000
- The affected class exceeds 500,000 persons
- The entity does not have sufficient contact information
The lower thresholds for Wyoming-based entities reflect the smaller scale of many in-state businesses.
Under Wyo. Stat. 40-12-502(d)(iv), substitute notice "shall consist of all of the following," not a choice among them:
- Conspicuous posting of the notice on the entity's website, if it maintains a public site
- Notification to major statewide media, and that media notice must itself include a toll-free phone number an individual can call to learn whether or not their personal data was included in the breach
Media notification is therefore cumulative. It is required alongside the web posting, not only as a fallback for an entity that has no website. The general definition of substitute notice at Wyo. Stat. 40-12-501(a)(x) also lists electronic mail notice where the entity has email addresses for the affected persons.
No Attorney General Notification

Wyoming does not require notification to the Attorney General or any other state agency when a data breach occurs. There is also no requirement to notify consumer reporting agencies, regardless of the number of affected residents.
This makes Wyoming one of the least demanding states in terms of government reporting obligations.
No Encryption Safe Harbor
Wyoming does not provide an encryption safe harbor. The words "encrypt" and "encrypted" do not appear anywhere in Wyo. Stat. 40-12-501 or 40-12-502, so encrypting the compromised data does not by itself remove the duty to notify.
The carve-out that does exist is redaction. Under Wyo. Stat. 40-12-501(a)(vii), personal identifying information means a name combined with the listed data elements only "when the data elements are not redacted," and Wyo. Stat. 40-12-501(a)(viii) defines redaction as alteration or truncation of the data such that no more than five digits of the data element remain accessible.
Separately, the duty is triggered only where the unauthorized acquisition materially compromises the data and causes, or is reasonably believed to cause, loss or injury to a Wyoming resident, and where a prompt good-faith investigation shows misuse has occurred or is reasonably likely. Strong encryption can be relevant evidence in that investigation, but it is not a statutory exemption.
Exceptions
Under Wyo. Stat. 40-12-502(c), a financial institution that maintains notification procedures subject to the Gramm-Leach-Bliley Act is deemed in compliance with Wyoming's notification requirements if it notifies affected Wyoming customers under its federal obligations. Similarly, under Wyo. Stat. 40-12-502(h), a covered entity or business associate that complies with HIPAA is deemed in compliance with Wyoming's notification requirements if it notifies affected Wyoming customers under its federal obligations.
Enforcement
The Wyoming Attorney General may bring an action in law or equity to address any violation and for other relief that may be appropriate to ensure compliance, recover damages, or both.
There is no private right of action. Individual consumers cannot sue directly under this statute for notification failures.
The statute does not specify maximum penalty amounts, leaving enforcement remedies to the discretion of the courts. The AG may seek injunctive relief, compliance orders, and damages based on the circumstances of each case.
More Wyoming Laws
Frequently Asked Questions
How quickly must a Wyoming business notify consumers of a data breach?
Wyoming requires notification 'in the most expedient time possible and without unreasonable delay.' There is no specific day count. The entity must first conduct a good-faith investigation to determine whether personal identifying information has been or will be misused. If misuse has occurred or is reasonably likely, notification must follow as soon as possible. Under Wyo. Stat. 40-12-502(b), notification may be delayed only if a law enforcement agency determines in writing that it may seriously impede a criminal investigation.
Does Wyoming require notification to the Attorney General for data breaches?
No. Wyoming does not require notification to the Attorney General, any state agency, or consumer reporting agencies. Notification obligations are limited to affected individuals. This makes Wyoming one of the least demanding states for government breach reporting.
What types of personal information trigger breach notification in Wyoming?
Wyoming has one of the broadest definitions of personal identifying information in the country. It includes Social Security numbers, driver's license numbers, financial account data, tribal IDs, government-issued IDs, shared secrets or security tokens, username/password combinations, birth or marriage certificates, medical information, health insurance data, biometric data, and taxpayer identification numbers.
Does Wyoming's data breach notification law apply to government agencies?
No. Wyo. Stat. 40-12-502 applies only to individuals and commercial entities conducting business in the state. State agencies are covered by a different statute: Wyo. Stat. 9-21-101(a)(v) requires every executive branch agency to adopt and maintain a data policy that includes breach notification and mitigation procedures. That requirement does not extend to the legislature, the judiciary, the University of Wyoming, or the community colleges.
Does encrypting data exempt a Wyoming business from breach notification?
No. Wyoming's breach notification statute contains no encryption safe harbor, and the word 'encrypt' does not appear in Wyo. Stat. 40-12-501 or 40-12-502. The statute's only data carve-out is redaction: personal identifying information means a name combined with the listed data elements only when those elements are not redacted, and redaction means truncating the data so that no more than five digits remain accessible.
Can individuals sue for data breach notification violations in Wyoming?
No. Wyoming does not provide a private right of action for breach notification violations. Only the Wyoming Attorney General can bring enforcement actions. The AG may seek injunctive relief, compliance orders, and damages. The statute does not specify maximum penalty amounts.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected this guide against the official text of Wyo. Stat. 40-12-501 and 40-12-502: removed an encryption safe harbor Wyoming law does not contain, and fixed the substitute notice, required notice contents, law enforcement delay, third-party custodian and state agency provisions to match the statute.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected the Exceptions section, which had misattributed Wyoming's HIPAA/GLBA breach-notification safe harbors to the wrong statute (40-12-505, which actually governs credit-report exceptions to a security freeze); the safe harbors are actually in 40-12-502(c) and 40-12-502(h). Also corrected the Methods of Notification list, which fabricated an E-SIGN Act condition and a telephonic-notice method not present in the statute; Wyoming's three methods are written notice, electronic mail notice, and substitute notice.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Wyoming Statutes, Title 40 - Trade and Commerce - Chapter 12: Consumer Protection - Article 5: Credit Freeze Reports
§ 40-12-502Computer security breach; notice to affected persons.In forcecited in 3 of our articles
(a) An individual or commercial entity that conducts business in Wyoming and that owns or licenses computerized data that includes personal identifying information about a resident of Wyoming shall, when it becomes aware of a breach of the security of the system, conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal identifying information has been or will be misused. If the investigation determines that the misuse of personal identifying information about a Wyoming resident has occurred or is reasonably likely to occur, the individual or the commercial entity shall give notice as soon as possible to the affected Wyoming resident. Notice shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system. (b) The notification required by this section may be delayed if a law enforcement agency determines in writing that the notification may seriously impede a criminal investigation.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at wyoleg.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2019
Opinions citing this section in our collection:
- In re Equifax, Inc. (District Court, N.D. Georgia 2019, 362 F. Supp. 3d 1295)“…at "[t]he provisions of this section are not exclusive"); Wyo. Stat. Ann. § 40-12-502 (f) (providing that "[t]he attorney ge…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Wyoming Data Privacy Laws: Breach Notification & Consumer Rights (2026), Wyoming Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 40-12-501Definitions.In forcecited in 3 of our articles
(a) As used in this act: (i) "Breach of the security of the data system" means unauthorized acquisition of computerized data that materially compromises the security, confidentiality or integrity of personal identifying information maintained by a person or business and causes or is reasonably believed to cause loss or injury to a resident of this state. Good faith acquisition of personal identifying information by an employee or agent of a person or business for the purposes of the person or business is not a breach of the security of the data system, provided that the personal identifying information is not used or subject to further unauthorized disclosure; (ii) "Consumer" means any person who is utilizing or seeking credit for personal, family or household purposes; (iii) "Consumer reporting agency" means any person whose business is the assembling and evaluating of information as to the credit standing and credit worthiness of a consumer, for the purposes of furnishing credit reports, for monetary fees and dues to third parties; (iv) "Credit report" means any written or oral report, recommendation or representation of a consumer reporting agency as to the credit…
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at wyoleg.gov
Also relied on in: Wyoming Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
Wyoming Statutes, Title 6 - Crimes and Offenses - Chapter 3: Offenses Against Property - Article 9: Theft of Identity
§ 6-3-901Unauthorized use of personal identifying information; penalties; restitution.In forcecited in 2 of our articles
(a) Every person who willfully obtains personal identifying information of another person, and uses that information for any unlawful purpose, including to obtain, or attempt to obtain, credit, goods, services or medical information in the name of the other person without the consent of that person is guilty of theft of identity. (b) As used in this section "personal identifying information" means the name or any of the following data elements of an individual person: (i) Address; (ii) Telephone number; (iii) Social security number; (iv) Driver's license number; (v) Account number, credit card number or debit card number in combination with any security code, access code or password that would allow access to a financial account of the person; (vi) Tribal identification card; (vii) Federal or state government issued identification card; (viii) Shared secrets or security tokens that are known to be used for data based authentication; (ix) A username or email address, in combination with a password or security question and answer that would permit access to an online account; (x) A birth or marriage certificate; (xi) Medical information, meaning a person’s medical…
Official text (excerpt) · last checked 2026-09-02 · Read the full text in our law library · Verify at wyoleg.gov
Cited in 4 court opinions in our collectionLatest citing opinion in our collection: 2022
Opinions citing this section in our collection:
- Hampton v. State (Wyoming Supreme Court 2006, 141 P.3d 129)“…Stevens' personal identifying information in violation of Wyo. Stat. Ann. § 6-3-901 (a) (LexisNexis 2005 & Supp.2006). [4…”
- Rodgers v. State (Wyoming Supreme Court 2011, 265 P.3d 235)“…validity of his conviction for felony identity theft under Wyo. Stat. Ann. § 6-3-901 (LexisNexis 2011). The statute defines…”
- Ronald D. Allaback v. The State of Wyoming (Wyoming Supreme Court 2014, 318 P.3d 827)“…ed guilty to three counts of identity theft in violation of Wyo. Stat. Ann. § 6-3-901(a)(c)(ii) (LexisNexis 2013). The distri…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Wyoming Identity Theft Laws: Penalties and the Factual Innocence Petition
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Wyo. Stat. 40-12-501 Definitions(law.justia.com)
- Wyo. Stat. 40-12-502 Computer Security Breach Notice(law.justia.com)
- Wyo. Stat. 6-3-901 Personal Identifying Information(law.justia.com)
- Wyoming Attorney General Privacy(ag.wyo.gov).gov
- Wyoming Legislature SF 53 Original Bill(wyoleg.gov).gov
- HIPAA Information(hhs.gov).gov
- Gramm-Leach-Bliley Act(ftc.gov).gov
- Wyo. Stat. 40-12-501 through 40-12-511, Wyoming Legislature official statutes(wyoleg.gov)
- Wyo. Stat. 9-21-101 Data policies (state agency breach notification and mitigation procedures)(wyoleg.gov)