Is Your Email on a US Breach List? What US Law Requires Companies to Tell You
TL;DR: Unlike the EU, the US has no single federal breach notification law — each state sets its own rules on timing and what companies must disclose. Here's what that means in practice and what to do if you get a breach notice.
👉 See if your data's already leaked — free 30-second check →
Almost every US state has some version of a data breach notification law, but they're not identical. Some require notification "without unreasonable delay," others set a specific day count, and the definition of what counts as a reportable breach varies too. There's no single federal standard tying it all together.
What companies are generally required to do
- Notify affected individuals once a breach involving personal data is confirmed, though the exact timeline depends on the state.
- Describe what was exposed — usually at least the categories of data involved, like email, password hashes, or payment details.
- Sometimes notify state regulators if the breach affects a large enough number of residents.
What they're generally not required to do is tell you exactly how the breach happened, guarantee your data hasn't already been misused, or notify you the moment they discover it — "without unreasonable delay" has left companies real room to interpret their own timelines.
Why some breach emails arrive months later
Investigation time, legal review, and coordinating a public statement all add delay before a notification goes out. In some documented cases, this gap has stretched to months. That's part of why relying solely on official notices means you're often finding out about exposure well after the fact.
What to actually do when you get one
- Change the password on that account immediately, and anywhere else you reused it
- Turn on two-factor authentication if it wasn't already active
- Watch for follow-up phishing that references the breach to seem credible
- Don't wait for official notices to check — breach databases are often updated well before companies send their letters
Running your own check regularly closes that gap. A Scan My Shadow report scans your email against 1,500+ breach and public data sources directly, rather than waiting for a company's notification cycle. For a comparison of what similar disclosure laws look like elsewhere, see what GDPR requires companies to tell you. For the practical next step once you know your email is exposed, see what to do if your email appears in a breach.
Frequently Asked Questions
Is there a single US federal breach notification law?
No — there's no single federal law covering all breaches; each state sets its own notification rules, which creates inconsistency in timing and required detail.
How fast are companies required to notify me?
It depends on the state, ranging from a specific number of days to a vaguer 'without unreasonable delay' standard, which gives companies significant discretion.
What if a company never sends me a notification at all?
This does happen, particularly with smaller companies or breaches that fall below a state's reporting threshold — it's part of why independent checking matters.
Do I have any legal recourse if a company delays notifying me?
Recourse varies significantly by state and situation — this isn't something general guidance can answer reliably, so consulting a consumer-rights resource in your state is the right next step for a specific case.
How is this different from GDPR's breach rules?
GDPR sets a much stricter and more uniform standard — companies must notify regulators within 72 hours in most cases — whereas the US patchwork leaves more variation and, often, more delay.
Curious what's already out there about you? Scan My Shadow checks your phone number and email across 1,500+ sources and sends you a clear report — no guesswork, just facts. Start your scan.
- Results within about 5 minutes
- Clear, plain-English report
- Delivered straight to your inbox
- No login or passwords required
- Scan data deleted after report is generated