There is no federal law on this issue and the state laws that do
exist are patchwork of different standards and requirements. According to
datalossdb.org, in order to request data breach notification reports from governments,
several critieria need to exist.
- The state must have Freedom of
Information or Open Records legislation. - The state must have Breach
Notification legislation - The state must require notifications to a
centralized authority (like an Attorney General, or a Consumer
Protection division).
At this time, only 12 states (Hawaii, Maine, Maryland, Massachusetts, Missouri, New Hampshire, New Jersey, New York, North Carolina, South Carolina, Vermont, and Virginia) meet the
requirements for gathering primary sources. 35 states have data loss
notification legislation, but no centralized reporting. For example, even California which pioneered legislation on data loss reporting has no centralized data loss incident reporting. 4 states have no
data loss notification legislation.

Be the first to comment