If your business discovered tomorrow that customer data had been exposed, the first legal question isn't whether you have to tell anyone — that part is already decided. Every US state, plus the District of Columbia, Guam, and Puerto Rico, has a law requiring notification after certain data breaches, and Canada's federal privacy law imposes its own mandatory reporting duty. What actually trips up business leaders isn't whether notification is required. It's when the clock starts, and who has to be told besides the customer.

Do I Actually Have to Notify Anyone After a Breach?

In almost every case, yes. If your business holds personal information — customer names paired with financial account numbers, health information, government ID numbers, login credentials, and similar data — and that information is accessed or acquired without authorization, some form of notification duty applies. The trigger isn't "we had a security incident." It's a specific legal threshold, and that threshold is where most confusion starts.

What Actually Starts the Clock

In the US, most state laws are triggered by the unauthorized access or acquisition of unencrypted personal information. That word "unencrypted" matters: in most states, if the exposed data was encrypted and the encryption key wasn't also compromised, the notification requirement doesn't apply at all. This is commonly called the encryption safe harbor, and it's one of the few places where a technical control directly changes a legal obligation.

Canada's federal privacy law, PIPEDA, uses a different standard. It requires reporting a "breach of security safeguards" once an organization determines there is a real risk of significant harm to the individuals affected — factors like the sensitivity of the data and the likelihood it will be misused. There's no bright-line "any breach counts" rule in either country; the obligation turns on risk and, in the US, on encryption.

Canada vs. the US: Two Different Clocks

This is where the cross-border patchwork actually bites. In Canada, once an organization determines a breach meets the real-risk threshold, it must report to the Office of the Privacy Commissioner and notify affected individuals "as soon as feasible." PIPEDA doesn't set an exact day count, but regulators expect action within days to weeks, not months. Canadian organizations also have to keep a record of every breach of security safeguards for 24 months — including ones that didn't meet the threshold for reporting — with a brief explanation of why notification wasn't required.

In the US, there is no single federal breach law — each state sets its own rules, and which state's law applies depends on where the affected person lives, not where your business is headquartered. Deadlines vary widely: several states, including California and Colorado, require notification within 30 days; Texas allows 60; many others, including New York and Massachusetts, use an open-ended "without unreasonable delay" standard instead of a fixed number. A business with customers in a dozen states can be looking at a dozen overlapping deadlines from a single breach. We've covered Canada's broader privacy landscape in more detail if PIPEDA compliance is new territory for your business.

Who You Actually Have to Notify

Notifying the affected customers or employees is only the starting point. Depending on the size and location of the breach, businesses may also need to notify:

  • A state Attorney General or regulator — many US states require this once a threshold number of residents is affected, commonly in the 500 to 1,000 range.
  • Nationwide credit reporting agencies — a number of states require this once a separate, usually higher, resident threshold is crossed (commonly 1,000 or more).
  • The Office of the Privacy Commissioner of Canada — required for any breach meeting the real-risk-of-significant-harm threshold, regardless of size.
  • The media — required in some states as a substitute notice method when a large number of affected people can't be reached directly.

Missing one of these secondary obligations is a common and avoidable mistake — most incident response plans focus entirely on the customer-facing notification and skip the regulator and credit bureau steps.

Why This Catches So Many Businesses Off Guard

Two assumptions consistently trip up small and mid-sized businesses. The first is believing a notification law only applies to large companies — a belief we've already dismantled in why "we're too small to be a target" is the most expensive lie in business; notification obligations apply based on the data you hold, not your headcount. The second is assuming a lawyer or cyber insurer will simply "handle it" when the time comes, without any plan built in advance. The deadline clock starts the moment your organization determines a breach meets the legal threshold — it doesn't pause while you find outside counsel for the first time.

What Business Leaders Should Take From This

These are questions worth putting to your legal counsel, IT lead, or insurer before an incident, not during one:

  • Do we know which states or provinces our customer and employee data actually touches?
  • Who inside our organization is authorized to determine that a breach meets the notification threshold, and does our incident response plan name that person?
  • Does our cyber insurance policy cover legal counsel, notification costs, and credit monitoring, or only the direct costs of the incident itself? Insurers increasingly check for this kind of preparedness before quoting a policy.
  • Is sensitive data encrypted where it's technically feasible, given that encryption is one of the only safe harbors most state laws actually offer?

Practical Next Steps

  1. Map where your customers and employees actually live — not just where your business is headquartered.
  2. Identify which state, provincial, and federal laws could apply to the personal data you hold, based on that map.
  3. Build the notification decision into your incident response plan, naming who decides and how quickly.
  4. Identify breach counsel before an incident, not during one — many cyber insurance policies include access to a "breach coach" as part of the coverage.
  5. Confirm your cyber insurance covers legal fees, notification costs, and credit monitoring, not just the technical cleanup.
  6. Keep a breach log for every security incident, reportable or not — a legal requirement in Canada and good practice everywhere else.
  7. Encrypt sensitive data wherever it's practical to do so.

If you're unsure whether your current incident response plan actually addresses notification obligations, a free cybersecurity assessment is a useful starting point for identifying the gaps before they matter.

The Clock Doesn't Wait for You to Be Ready

The fastest way to make a bad day worse is deciding your notification strategy in the middle of a breach, instead of before one. The businesses that handle this well aren't the ones with the most sophisticated legal departments — they're the ones that answered these questions in a calm moment, wrote the answers down, and knew exactly who to call before they ever needed to.


This article is intended for general informational purposes only and does not constitute legal advice. Data breach notification requirements vary by jurisdiction and by the specific facts of an incident, and organizations should consult qualified legal counsel in every state, province, or country where their data subjects are located before making notification decisions.