State Agency Protection of Personal Information and Breach Notification
MT State Agency Breach Law
Government records · Breach notification · Data security
Montana state agencies must protect personal information and notify affected people of data breaches without unreasonable delay. Contractors that hold agency data must notify the agency immediately, notify affected individuals, keep a security policy, and file notice copies with the state CISO and the Attorney General.
- Where
- Montana
- Citation
- Mont. Code Ann. 2-6-1501 to 2-6-1504
- Status
- In force
- In force since
- 2015-10-01
- Last amended
- 2025-10-01
- Enforced by
- Montana Department of Administration (chief information security officer); Attorney General receives notice copies
- People can sue
- No
- Penalties
- No specific penalty stated; an agency that notifies after a contractor fails to may recover its reasonable notice costs from the contractor (2-6-1503(2)(b)).
- Applies to
- Montana state agencies in the legislative and executive branches (2-6-1501(8))
- Private third parties that receive personal information from a state agency and maintain it in a computerized system to perform a state agency function (2-6-1503(2), (4))
Security duties
- Agencies and third-party recipients must maintain an information security policy and breach notification procedures.Mont. Code Ann. 2-6-1503(4)
Breach duties
- Third parties holding agency data must notify the agency immediately after discovering a breach and make reasonable efforts to notify affected individuals in the same manner as agencies.Mont. Code Ann. 2-6-1503(2)(a) · Only if: Third party maintains personal information received from a state agency
- Agencies must notify affected persons without unreasonable delay (law enforcement delay permitted).Mont. Code Ann. 2-6-1503(1), (3)
- Simultaneously send an electronic copy of each individual notice, with date and method of distribution, to the state chief information security officer and the AG's consumer protection office.Mont. Code Ann. 2-6-1503(5)
- Agencies must immediately report any security incident to the state chief information security officer.Mont. Code Ann. 2-6-1504
Sources
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Effective dates inferred from history notes (En. Ch. 348, L. 2015; amd. Ch. 227, L. 2023 and Ch. 395, L. 2025) and the default October 1 rule. Content of the 2025 definitional amendment (Ch. 395) not reviewed.
Research reference, not legal advice.