State Data Breach Notification Laws: What Triggers Your Obligation as a CPA
You know about the FTC's 30-day breach notification requirement. You know about reporting to the IRS if taxpayer data is compromised. But there's a third layer of breach notification that many firm owners don't think about until it's too late: state law.
All 50 states, the District of Columbia, Guam, Puerto Rico, and the U.S. Virgin Islands have enacted data breach notification laws. Every single jurisdiction in the country has its own rules about when you must notify people that their data was exposed, how quickly you must do it, and what the notification must contain.
For a CPA firm with clients in a single state, this is manageable. For a firm with clients scattered across five, ten, or twenty states, a single breach can trigger a web of overlapping obligations with different deadlines, different definitions of what constitutes a breach, and different penalties for getting it wrong.
This article won't make you a lawyer. It will give you a working understanding of how state breach notification laws operate, where the biggest variations lie, and what you need to have in place before an incident forces you to figure it all out under pressure.
What Counts as a "Breach" (It's Broader Than You Think)
Most people picture a breach as a dramatic hack: an attacker breaking through your defenses and stealing a database of client records. That's one kind of breach. But under most state laws, the definition is much broader.
A breach typically occurs when personal information is acquired by an unauthorized person, or when there is a reasonable belief that unauthorized acquisition has occurred. This includes:
A phishing attack where an employee's email account is compromised and the attacker has access to messages containing client Social Security numbers. A laptop with unencrypted client files is stolen from a car. A former employee who still has active credentials accesses client records after leaving the firm. A vendor you share data with is breached, and your clients' information is among the exposed records. An employee accidentally emails a client's tax return to the wrong person.
None of these require a sophisticated cyberattack. All of them can trigger notification obligations under state law. The threshold isn't "someone deliberately stole data." It's "personal information was accessed or acquired without authorization, or there's a reasonable basis to believe it was."
The Key Variations Across States
State breach notification laws agree on the basic principle: if personal data is compromised, affected individuals must be notified. They disagree on almost everything else.
Notification Timelines
This is the most operationally important variation. Some states give you a reasonable but unspecified window. Others put a hard number on it.
Florida requires notification within 30 days of determining that a breach occurred. Colorado requires 30 days. California requires notification in the most expedient time possible, without unreasonable delay, and no later than the time the investigation concludes that a breach occurred. New York's SHIELD Act requires notification in the most expedient time possible.
The trend across states is toward shorter windows. Several states that previously had open-ended "without unreasonable delay" language have amended their laws to add specific day counts. When you're managing a breach response, the shortest applicable deadline is the one that drives your timeline.
What Information Triggers the Obligation
States define "personal information" differently. All states include Social Security numbers, driver's license numbers, and financial account numbers. But some go further.
California's definition includes medical information, health insurance information, biometric data, and even email addresses in combination with passwords. New York's SHIELD Act expanded the definition to include biometric information and account security questions. Some states include date of birth in combination with name as a triggering data element.
For CPA firms, the practical implication is significant. Your client files routinely contain Social Security numbers, bank account numbers, dates of birth, and employer identification numbers. Almost any unauthorized access to a client file will trigger notification obligations in the relevant states.
Who Must Be Notified
Beyond the affected individuals, most states require you to notify additional parties:
State Attorney General. Many states require notification to the AG's office, often with a lower threshold than individual notification. Several states require AG notification when the breach affects as few as 25, 250, or 500 residents. Some require notification regardless of the number affected.
Consumer reporting agencies. Some states require notification to credit reporting agencies when breaches exceed certain thresholds, typically 500 or 1,000 affected individuals.
State regulators. In some states, specific industries have additional reporting requirements. As a financial institution under GLBA, your firm may face notification obligations to state banking or financial regulators in addition to the AG's office.
Penalties
Penalties for failure to comply with breach notification requirements vary widely.
California can impose penalties of $2,500 per violation, with each affected individual constituting a separate violation. For a breach affecting 1,000 clients, that's $2.5 million in potential penalties from one state. New York's SHIELD Act allows the AG to seek penalties of up to $5,000 per violation, plus $250,000 in statutory damages. Florida allows fines of $500 per day for the first 30 days of violation, escalating to $1,000 per day thereafter, up to $500,000 per breach.
Beyond statutory penalties, state AGs can pursue enforcement actions that include consent decrees, mandatory security improvements, and ongoing monitoring requirements. These are in addition to any FTC enforcement action.
The Multi-State Problem
This is where the complexity really hits CPA firms. Your client base probably isn't confined to a single state. If you prepare returns for clients in 12 states, a breach of your system could trigger notification obligations in all 12.
Each state has its own:
Timeline for notification. Definition of personal information. Format and content requirements for notification letters. AG notification thresholds and procedures. Penalty structure.
Managing this means that when a breach occurs, someone needs to quickly determine which states are affected, identify the specific requirements in each state, and ensure that all notifications go out within the shortest applicable deadline, with each notification meeting the content requirements of its respective state.
This is one of the primary reasons that breach response plans should include pre-identified legal counsel with experience in multi-state notification. You don't want to be researching 12 different state statutes during the first 48 hours of an active breach response.
How State Laws Interact With Federal Requirements
State breach notification laws operate alongside, not instead of, federal requirements. A single breach can trigger obligations under:
The FTC Safeguards Rule (notification to FTC within 30 days for breaches affecting 500+ consumers). IRS breach reporting (notification to the IRS Identity Protection Specialized Unit and state tax agencies if taxpayer data is involved). State breach notification laws (notification to affected individuals, the state AG, and potentially consumer reporting agencies, in every state where affected individuals reside).
These obligations run in parallel. Meeting the FTC notification requirement doesn't satisfy your state law obligations, and vice versa. You need to comply with each independently.
Some states defer their timelines when a law enforcement investigation is underway, allowing delay if notification would impede an active investigation. But this deferral typically requires documentation from the law enforcement agency.
What Your Notification Must Contain
While the specifics vary by state, most breach notifications must include:
A description of the incident, including the date or date range. The types of personal information that were or may have been compromised. Steps the firm is taking to investigate and remediate the breach. Steps the affected individual can take to protect themselves. Contact information for the firm, including a point of contact for questions. In many states, information about credit monitoring services, sometimes including a requirement that you provide free credit monitoring for affected individuals.
Some states, notably California, specify the format of the notification letter, requiring specific headings and plain-language descriptions. Others are less prescriptive but still expect clear, complete communication.
What You Can Do Today
-
Know where your clients live. Run a report from your practice management software showing the states where your active clients reside. This is your notification footprint. When a breach happens, this list tells you which state laws apply.
-
Identify the shortest applicable timeline. Look at the notification deadlines for the top five states where your clients are concentrated. The shortest deadline becomes your de facto response window for any breach, because you'll need to move at the speed of the strictest requirement.
-
Add multi-state notification to your incident response plan. If your current plan says "notify affected individuals," expand it to include: identify affected states, research specific notification requirements for each state, prepare state-compliant notification letters, and file AG notifications as required.
-
Pre-identify breach counsel. You don't want to find a lawyer who specializes in multi-state breach notification after the breach happens. Identify one now. Many cybersecurity attorneys offer pre-engagement agreements that establish the relationship before you need it.
-
Check your cyber insurance for notification costs. Multi-state breach notification is expensive: legal counsel, notification letter preparation, mailing costs, credit monitoring services. Verify that your cyber insurance covers notification expenses and at what limit.
-
Keep your client contact information current. When you need to notify 500 clients across eight states within 30 days, outdated addresses and email addresses slow you down. Current contact information is a breach response asset.
The Bottom Line
State breach notification laws add a layer of complexity that many firm owners don't appreciate until they're in the middle of a breach response. The requirements are real, the deadlines are short, and the penalties for non-compliance are substantial.
The good news is that preparation eliminates most of the chaos. If you know your notification footprint, have a plan that accounts for multi-state requirements, and have breach counsel identified before you need them, the process becomes manageable. If you wait until the breach happens, you'll be learning state law under the worst possible conditions.
This article completes a three-part regulatory series alongside our breakdowns of the FTC Safeguards Rule and IRS Publication 4557. Together, they cover the full regulatory landscape for CPA firm data security: federal rules, IRS guidance, and state notification obligations.
If tracking requirements across multiple regulatory frameworks feels overwhelming, Kompflow maps your firm's obligations across FTC, IRS, and state-level requirements and tracks your compliance against all of them in one place. But even without a platform, the preparation steps above will put you ahead of most firms in the industry.
The regulations exist. The deadlines are real. And the time to prepare is before you need to.