Government Command Center 14 items
State Data Breach Notification Compliance Checklist
Guides a public agency's response when personal information is compromised, covering breach determination, notification content, timing, and regulator reporting under state law.
State Breach Notification StatutesState PII DefinitionsState AG Notice Requirements
Free PDF · enter your email to download.
Breach Determination
- Was 'personal information' as defined by the applicable state statute involved? *
- Was the data unencrypted, or was the encryption key also compromised? *
- Has a risk-of-harm analysis been conducted where the statute permits? *
- Have all states of residence of affected individuals been identified (multi-state analysis)? *
Notification Timing
- Is notice to affected residents provided within the statutory deadline (e.g., without unreasonable delay / a fixed day count)? *
- Was any law-enforcement delay request documented? *
- Date breach discovered: *
Notice Content & Method
- Does the notice include the required content (description, data types, date, contact, and remediation steps)? *
- Was notice delivered by an approved method (written, electronic, or substitute notice)? *
- Is credit monitoring / identity theft protection offered where required? *
Regulator & Third-Party Reporting
- Was the state attorney general or other regulator notified where required? *
- Were consumer reporting agencies notified when the affected count exceeds the statutory threshold? *
- Were data owners notified if the agency was acting as a data maintainer/processor? *
- Is documentation of the breach and response retained per statute? *
Download the full State Data Breach Notification Compliance Checklist checklist
Get it as a clean, printable PDF — free.
