There is no federal law on this issue and the state laws that do exist are patchwork of different standards and requirements. According to datalossdb.org, in order to request data breach notification reports from governments, several critieria need to exist.
- The state must have Freedom of Information or Open Records legislation.
- The state must have Breach Notification legislation
- The state must require notifications to a centralized authority (like an Attorney General, or a Consumer Protection division).
At this time, only 12 states (Hawaii, Maine, Maryland, Massachusetts, Missouri, New Hampshire, New Jersey, New York, North Carolina, South Carolina, Vermont, and Virginia) meet the requirements for gathering primary sources. 35 states have data loss notification legislation, but no centralized reporting. For example, even California which pioneered legislation on data loss reporting has no centralized data loss incident reporting. 4 states have no data loss notification legislation.
Comments