State Breach Law

Georgia Data Breach Notification Law

O.C.G.A. § 10-1-910 et seq. • Effective 2005-05-05

Georgia requires "most expedient time possible" notification for breaches. While there's no specific day count, delays will be scrutinized. If you're classified as an information broker (businesses that collect and sell data), you have extra reporting requirements.

Notification deadline: Most expedient time possible, without unreasonable delay

Enforcement: Georgia Attorney General, Consumer Protection Division

Overview

Georgia requires businesses to notify affected residents "in the most expedient time possible" after a breach. Information brokers have additional requirements and must notify the Georgia Consumer Protection Division.

Who Must Be Notified

  • Affected Georgia residents
  • Consumer reporting agencies (if 10,000+ residents affected)
  • Consumer Protection Division (for information brokers)

Covered Data Types

Social Security number, Driver's license number, State ID card number, Financial account number with access code, Credit/debit card number with access code

Notification Requirements

  • Written, telephonic, or electronic notice
  • Most expedient time possible without unreasonable delay
  • Substitute notice allowed if cost exceeds $50,000 or 100,000+ affected
  • Information brokers must notify Consumer Protection Division
  • Notify consumer reporting agencies if 10,000+ affected

Is your business exposed?

Exemptions

  • Encrypted data (if key not compromised)
  • Good faith acquisition by employee
  • Publicly available information
  • Entities in compliance with GLBA, HIPAA

Penalties

Subject to unfair or deceptive practices provisions. AG can seek injunctions and penalties under Consumer Protection Act.

If You Experience a Breach

  1. 1.

    Determine if you qualify as an "information broker"

  2. 2.

    Prepare breach notification procedures

  3. 3.

    Know how to contact GA Consumer Protection Division

    GA Consumer Protection

  4. 4.

    Implement reasonable security measures

  5. 5.

    Create notification templates

  6. 6.

    Train employees on breach identification

Official Source

https://consumer.georgia.gov/

Other State Breach Laws

New York, Texas, Florida

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required