International USA Data Breach Legal Rights Email Security

Is Your Email on a US Breach List? What US Law Requires Companies to Tell You

Scan My ShadowSeptember 2, 20263 min read

TL;DR: Unlike the EU, the US has no single federal breach notification law — each state sets its own rules on timing and what companies must disclose. Here's what that means in practice and what to do if you get a breach notice.

👉 See if your data's already leaked — free 30-second check →

Almost every US state has some version of a data breach notification law, but they're not identical. Some require notification "without unreasonable delay," others set a specific day count, and the definition of what counts as a reportable breach varies too. There's no single federal standard tying it all together.

What companies are generally required to do

What they're generally not required to do is tell you exactly how the breach happened, guarantee your data hasn't already been misused, or notify you the moment they discover it — "without unreasonable delay" has left companies real room to interpret their own timelines.

Why some breach emails arrive months later

Investigation time, legal review, and coordinating a public statement all add delay before a notification goes out. In some documented cases, this gap has stretched to months. That's part of why relying solely on official notices means you're often finding out about exposure well after the fact.

What to actually do when you get one

Running your own check regularly closes that gap. A Scan My Shadow report scans your email against 1,500+ breach and public data sources directly, rather than waiting for a company's notification cycle. For a comparison of what similar disclosure laws look like elsewhere, see what GDPR requires companies to tell you. For the practical next step once you know your email is exposed, see what to do if your email appears in a breach.

Frequently Asked Questions

Is there a single US federal breach notification law?

No — there's no single federal law covering all breaches; each state sets its own notification rules, which creates inconsistency in timing and required detail.

How fast are companies required to notify me?

It depends on the state, ranging from a specific number of days to a vaguer 'without unreasonable delay' standard, which gives companies significant discretion.

What if a company never sends me a notification at all?

This does happen, particularly with smaller companies or breaches that fall below a state's reporting threshold — it's part of why independent checking matters.

Do I have any legal recourse if a company delays notifying me?

Recourse varies significantly by state and situation — this isn't something general guidance can answer reliably, so consulting a consumer-rights resource in your state is the right next step for a specific case.

How is this different from GDPR's breach rules?

GDPR sets a much stricter and more uniform standard — companies must notify regulators within 72 hours in most cases — whereas the US patchwork leaves more variation and, often, more delay.

Curious what's already out there about you? Scan My Shadow checks your phone number and email across 1,500+ sources and sends you a clear report — no guesswork, just facts. Start your scan.

Phone + email scan · 1,500+ data sources worldwide · Full report
₹498one-time
Scan My Digital Footprint
Secure payment via Razorpay
  • Results within about 5 minutes
  • Clear, plain-English report
  • Delivered straight to your inbox
  • No login or passwords required
  • Scan data deleted after report is generated