Every state has a notification law, and they are not the same
What it is
A legal duty to tell affected people, and often a regulator, after personal information you hold has been acquired by somebody who should not have it. Every US state has such a law, and so do the EU and UK under the GDPR.
Does it apply to you
- You hold personal information about residents of a state, which for a website with a contact form means you probably do.
- An incident meets that state’s definition of a breach. The definitions differ, particularly on whether encrypted data counts and on whether a risk-of-harm assessment can excuse notice.
What being wrong costs
Obligations run to the residents of each state your affected people live in, so a single incident can trigger several different notification regimes with different deadlines and different content requirements. Under the GDPR, notification to a supervisory authority is generally required within 72 hours of becoming aware. Delay is often the part that attracts penalties, rather than the incident itself.
What it demands
- Knowing what personal information you hold and where, before an incident, because that determines who you notify.
- Detecting an incident at all. A duty that starts when you become aware is a duty nobody can discharge without monitoring.
- Notifying within the applicable window, with the content each jurisdiction requires.
What WebSpark does
- The data a site holds is defined and minimal: form submissions with a declared retention, and nothing else. A short, known inventory is what makes a notification decision answerable in hours rather than weeks.
- Retention is enforced by the storage, so old submissions are deleted rather than accumulating into a larger incident.
- Monitoring covers the platform, and your data processing agreement sets the terms on which we notify you.
What you can show
- A current inventory of what the site holds and for how long.
- A data processing agreement with breach notification terms in writing.
What stays yours
- Notifying affected people and regulators. That is the controller obligation and it stays with you.
- Personal information you hold elsewhere, which is usually the larger part of the inventory.
Sources
- Security Breach Notification LawsNational Conference of State Legislatures
- Regulation (EU) 2016/679, Articles 33 and 34EUR-Lex, Publications Office of the European Union
WebSpark describes obligations and evidences what a site does. It does not provide legal advice, and this page is not a substitute for a lawyer who knows your business.