Skip to Content

Continuing Changes in State Data Breach Notice Laws

on Monday, 28 September 2026 in Technology & Intellectual Property Update: Arianna C. Goldstein, Editor

States are continuing to modify, update, and tailor their data breach notification requirements. These changes (generally) fall into three categories:

  • Narrowing the scope of exceptions to the definition of a breach;
  • Expanding the definition of personally identifiable data (PII); and,
  • Requiring notice to the Attorney General (“AG”) for the state where the affected people reside.

Two examples of such changes include amendments to the Delaware and Oklahoma breach notice laws.

Delaware

Delaware enacted HB 381[1] which amends the state notification requirement to require:

  • Notice to the Delaware Attorney General (“DAG”) within sixty (60) days of the breach even when an organization cannot identify affected Delaware residents; and
  • Narrows the safe-harbor for institutions covered by the Gramm-Leach-Bliley Act (GLBA).

An organization may avoid notifying the DAG office with “substitute notice.” 

The early reporting requirement is in addition to the DAG notice required if the class affected exceeds 500 individuals.

The legislation is unclear, however, as to what effect this may have on out-of-state organizations. Any organization that may have Delaware residents in their databases should now include notice to the DAG within sixty (60) days of the incident in their response procedures. Organizations cannot delay notice to DAG until the investigation, and the data-mining review are complete.

Financial organizations should also reassess their notice requirements to the DAG’s office given the new statutory language.

Oklahoma

The Oklahoma legislature at the beginning of 2026 revised its data breach notification law.  In summary, the bill [2] does the following:

  • Expands the definition of PII to include government issued identification, unique electronic identifiers, and biometric data;
  • Notice to the Oklahoma AG (“OAG”) office is now required for all breaches affecting 500 or more individuals within sixty (60) days of the breach; and
  • Entities governed by GLBA, HIPAA, or other regulations will need to provide notice to the OAG when the number of affected individuals is equal to or greater than 500 affected individuals.

Other States

In addition to the above:

  • California’s SB 446[3], effected as of 2026 replaced flexible language (“disclosure to be made in the most expedient time possible and without unreasonable delay”) with a strict 30-day notice requirement; and
  • New York[4] in 2025 shortened its reporting timeline to their state AG office.

Conclusions

Organizations should continually assess their notification obligations and update their risk assessments to include the identification and location of stored PII. The timeline for notification obligations must also be continually reassessed to ensure organizations know and understand their notice requirements given the narrowing of the exceptions under these breach notice laws.

1700 Farnam Street | Suite 1500 | Omaha, NE 68102 | 402.344.0500

Law Firm Website Design