Breach-notification timelines
How long do organisations take to tell regulators about a data breach, and is it getting faster or slower?
Median days to report, by year
Washington: discovery to notice. California: end of breach to notice. The two are different clocks.
Washington: notices after the statutory deadline
| Year | Notices | Median days | 75th pct | 90th pct | Past deadline | Median residents affected |
|---|---|---|---|---|---|---|
| 2015 | 14 | 35 | 95 | 136 | 45% | 2,721 |
| 2016 | 49 | 34 | 54 | 120 | 33% | 1,409 |
| 2017 | 83 | 37 | 57 | 97 | 35% | 1,236 |
| 2018 | 63 | 43 | 84 | 116 | 44% | 1,607 |
| 2019 | 60 | 43 | 70 | 146 | 45% | 1,684 |
| 2020 | 204 | 36 | 74 | 136 | 58% | 1,944 |
| 2021 | 186 | 71 | 144 | 225 | 80% | 1,643 |
| 2022 | 171 | 83 | 183 | 297 | 87% | 1,704 |
| 2023 | 253 | 67 | 130 | 214 | 85% | 2,447 |
| 2024 | 228 | 110 | 213 | 309 | 93% | 1,940 |
| 2025 | 209 | 134 | 232 | 379 | 87% | 2,088 |
| 2026 | 154 | 99 | 188 | 343 | 90% | 2,027 |
Share of notices submitted more than 45 days (before March 2020) or 30 days (since) after the date the organisation reports becoming aware of the breach.
California: days from the end of the breach to the report
| Year | Notices | With a breach date | Median days | 75th pct | 90th pct | Over 30 days |
|---|
Method
The two states record different dates, so their numbers are shown side by side and never combined.
- Washington records the date the organisation says it became aware of the breach and the date it notified the Attorney General. The delay is the days between them, which is the clock the statute uses: notice to the AG is due no more than 45 days after discovery before 1 March 2020 and 30 days after that (RCW 19.255.010). The law allows a delay requested by law enforcement, and “aware” is the organisation's own date, so a notice past the deadline is not by itself a violation. Washington only requires notice to the AG when more than 500 residents are affected.
- California records only the dates of the breach and the date the notice was posted. The delay is the days from the last listed breach date to the report. It includes the time taken to discover the breach, so it is longer than the legal clock and is not a measure of compliance. Notices that list no breach date are counted but left out of the delay figures.
Years are calendar years of the report date (Washington's own annual report runs from 24 July). Medians and percentiles use linear interpolation. Negative delays, which come from data-entry errors, are left out. The current year is partial.
Sources
- Washington Attorney General, Data Breach Notifications (data.wa.gov) (public data)
- California Attorney General, Data Security Breach list (public record)