Data & Privacy
What A Breach Notification Law Actually Requires
Companies notify you about breaches because statutes require it, and those statutes define narrowly which data counts, who must be told and how quickly.

A breach notification letter is not a courtesy. Every state has a statute compelling it, and the letter's timing, contents and existence are shaped by what those statutes define as a breach.
The trigger is a defined category of data
Notification duties generally attach to a name combined with a specific identifier such as a government-issued number, a financial account, or credentials that would allow access to an account.
Data outside those categories may be sensitive and still fall outside the statute, which is why a company can lose a large volume of behavioral or location data without a letter going out.
Definitions have widened over time in many states to include biometric templates and health information, so the boundary moves and it is not uniform.
Encryption is usually a safe harbor
Most statutes exempt data that was encrypted, on the reasoning that unreadable data is not meaningfully disclosed.
The exemption typically fails if the keys were taken alongside the data, which is a common outcome when an entire system is compromised rather than a single database file.
This is why companies emphasize encryption in their disclosures. It is a statement about legal exposure as much as a statement about your risk.
Timing is measured from discovery, not from the breach
Clocks generally start when the organization determines that a breach occurred, and many statutes allow a reasonable period for investigation before notice.
Law enforcement can request delay where notice would interfere with an investigation, which lawfully extends the gap between intrusion and letter.
The result is that a letter frequently describes events from months earlier, and the delay is often compliance rather than concealment.
The letter has a required shape
Statutes commonly specify that a notice describe what happened, which categories of data were involved, what the organization is doing, and what recipients can do.
Larger breaches trigger additional duties, including notice to state attorneys general and, above certain thresholds, substitute notice through media because individual letters are impractical.
Offers of credit monitoring are required in some states for certain data types and are voluntary elsewhere, which is why the offers are inconsistent between letters.
Sector rules sit on top of state law
Health information, financial institutions and publicly traded companies each face separate federal regimes with their own definitions, recipients and deadlines.
An organization can therefore be under several obligations at once, notifying regulators on one schedule and individuals on another for the same incident.
Because the requirements differ by state and sector and change regularly, what any specific recipient is owed depends on where they live and what kind of company held the data.
Questions readers ask
What happens if I lose my phone?
If your passkeys synchronise, they are available after signing into your platform account on a new device. If not, you need the recovery path.
Is a passkey the same as biometric login?
No. The biometric unlocks the key locally. Your fingerprint or face is never sent to the site and is not the credential itself.





