Navigating the laws of data breach notification systems in the US can get confusing. Each state is responsible for setting its own standards leaving very little room for nation-wide guidelines. Even the very definition of what a data breach is can vary from state to state. Most states agree however that immediate notification without unreasonable delay is required but “unreasonable delay” can mean 45 days all the way up to 90 days. Between law enforcement investigation and methods of notification, in the event of a breach it could take several weeks or even months for those affected to be notified.

Infographic by: digitalguardian.com