ATTORNEY ON CALL · 24/7
212 300 5196
FROM THE DEFENSE DESK / UNCATEGORIZED
4 AUG 2026 · 8 MIN READ · BY TODD A. SPODEK
★★★★★1,100+ FIVE-STAR GOOGLE REVIEWS
SUPER LAWYERS · 2020-25AVVO · “SUPERB”SECOND GENERATION · SINCE 1976
AS SEEN ON NETFLIX · CNN · FOX NEWS · NY POST

Nearly all U.S. states have laws that require notification when personal information has been compromised, but “compromised” means different things in different places. State breach statutes are some of the most important laws governing the duty to notify, and they most commonly establish notification obligations triggered by unauthorized access to or unauthorized acquisition (or compromise) of personal information. While this generally means that “compromise” does alone is enough to trigger notification obligations, it does not necessarily mean that compromise alone is enough to prove a breach notification lawsuit.

At the federal level, the FTC frequently pursues companies for allegedly “unreasonable cybersecurity practices,” based on its authority under the Federal Trade Commission Act to investigate and protect against “unfair or deceptive acts or practices in or affecting commerce.” FTC investigations and enforcement actions are common following a data breach, and they can result in substantial fines and injunctions. Like breach notification obligations under state law, data breach victims will often rely on the FTC’s authority as well. The FTC has established its authority to intervene following a breach on the basis that a company failed to adopt “adequate” or “reasonable” measures to protect consumer information, and it has also established authority to intervene in cases where companies failed to fulfill their notification obligations.

Many sources beyond state breach statutes and the FTC impose notification obligations for data security failures. Companies must comply with all applicable laws, and breach notification obligations are among many obligations under state law, federal law, and other legal mechanisms (such as engagement agreements).

A common misconception is that federal law establishes a uniform breach notification deadline across the country. While there are several federal statutes and regulations with breach notification components, there is no generally applicable federal statute that imposes a nationwide deadline or requirements. Instead, the criteria for determining the deadline and methods for notifying the appropriate parties are set forth by a combination of state law, federal law, sector-specific rules, contract terms, and guidance issued by the government.

Which jurisdiction’s clock and regulator notice apply after a breach?

The applicable jurisdiction after a data breach, and the duration of the applicable clock, depends on several factors, and the applicable clock can range from 48 hours to unlimited depending on the circumstances involved. Texas, California, and others have unique requirements:

California

California’s statute imposes unique requirements upon companies and agencies as well. For example:

“Where the security breach involves more than 500 California residents, the business or agency shall notify the Attorney General of California. In addition, if the security breach involves California residents’ Social Security numbers, driver’s license numbers, or account numbers, the entity shall notify the person or person’s representative and make an offer to provide appropriate identity-theft prevention and mitigation services at no cost for not less than 12 months.”

General Data Protection Regulation (GDPR)

The EU’s General Data Protection Regulation (GDPR) may apply to organizations outside of Europe as well. As outlined by the U.S. Department of Justice:

“The protections of the GDPR apply to: (i) Any business or organization located in Europe (regardless of location of the data subject), and (ii) Any business or organization located outside of Europe if it is processing the personal data of data subjects in the European Union or European Economic Area (i.e., EU or EEA residents) in connection with the offering of goods or services to them, or if the organization is monitoring their behavior in the European Union or European Economic Area.”

As a result, if a data breach involves a data subject located in the EU or EEA, affected companies may have a duty to notify, or not notify, under the GDPR, and they could potentially face substantial regulatory penalties.

Texas

Texas’s statute establishes two different notification timeframes for breach notification:

  • Notice to affected persons: “A covered entity shall notify an individual or individual’s representative as required by this subsection not later than the 60th day after determining that the event has occurred.”
  • Notice to the state Attorney General: “If a security breach affects 250 or more residents of this state, the covered entity shall notify the attorney general. The notice shall be delivered via mail or electronic means no later than the 60th day after the date of determination as defined in Section 521.053(c).”

GDPR

GDPR Article 33 generally requires supervisory-authority notification “without undue delay and, where feasible, not later than 72 hours after having become aware of it.”

Spodek Law Group keeps an attorney on call around the clock, which is the whole point of a number you can ring at two in the morning.

How can a claimant estimate value when breach demands reach millions but recoveries do not?

Data-breach class actions are common. When data breaches compromise a large number of individuals’ personal data, these individuals are often represented by a small number of law firms in an attempt to secure a substantial class-action settlement. In these class actions, the monetary value demanded often runs into the millions, with plaintiffs’ lawyers and data-breach claimants combining claimed damages for failure to safeguard personal data, statutory damages (where applicable), attorney fees, and investigative costs. This process frequently includes attempts to include claims for financial losses and alleged “economic harm” to consumers who have lost control of their data. Plaintiffs’ lawyers will also seek to prove the plaintiff is entitled to “presumed damages” where possible, while noting other reasons that might justify awarding damages. While the number of affected individuals is large, the amount an actual individual recovers can be minimal. However, the demand value of the case is often very high.

Here are two other examples of how plaintiffs may build their claims for damages in these lawsuits.

Theory 1: Computer Fraud and Abuse Act (CFAA)

A plaintiff’s CFAA theory may be that the company failed to prevent unauthorized access to a “protected computer.” One of the key elements for civil recovery under the CFAA is a $5,000 loss threshold. In a CFAA action, the party alleging damages must provide evidence of “loss,” and “loss,” as defined by the statute, “includes any reasonable cost of responding to an offense, including the cost of obtaining a damage assessment for the offense, and includes costs incurred by the victim.” This definition allows the plaintiff or his or her counsel to use calculations that include “reasonable response costs,” and this may include calculations for cost to investigate and remediate the intrusion.

Theory 2: California’s Comprehensive Computer Data Access and Fraud Act

California’s Comprehensive Computer Data Access and Fraud Act prohibits unauthorized access to “personal, private, or otherwise protected computer data,” and prohibits a computer’s “unauthorized access.” A plaintiff’s counsel will use California’s computer-access statute to try to recover damages from the defendant without requiring an actual loss. California’s computer-access statute allows the plaintiff to recover injunctive and compensatory damages. And, as mentioned above, the statute allows for the plaintiff to recover attorney fees and, for a willful violation where oppression, fraud, or malice is proved by clear and convincing evidence, punitive damages.

Understanding and Managing Multimillion-Dollar Damage Demands

Multimillion-dollar damage demands in data breach class actions are common, and they have an intent to secure a favorable settlement. However, multimillion-dollar damage demands, in the aggregate, do not establish that any actual damages are owed. They also do not establish what actual damages might have been recoverable if a lawsuit proceeded to verdict. As a result, a well-informed defense strategy for a data breach class action will focus on defending against the underlying allegations while also scrutinizing the calculations of the damages that plaintiffs’ lawyers have claimed.

How do law-firm breach duties differ for current clients, former clients, and privileged files?

Here are examples of how the breach notification considerations we have discussed apply specifically to lawyers and law firms in certain situations:

Current Clients

Law firms’ current clients have protections under Model Rule 1.4, which establishes:

“A lawyer shall promptly inform the client or each client of competent representation of all matters reasonably involving the client’s interests, including: . . . (iii) all material developments in the representation.”

In order to fulfill this duty, if a law firm experiences a data breach, it will generally have a duty to notify any affected current clients.

However, law firms also have a duty to take appropriate steps to protect their clients’ personal information. This includes protecting against “unauthorized access” and other “threats to cybersecurity.” And, while the duty to protect client information is the same under Model Rule 1.4 and Model Rule 1.6, the duty to notify current clients about data breaches will most likely arise under Model Rule 1.4.

Former Clients

With respect to former clients, Model Rule 1.9(c) establishes the following obligations:

“A lawyer who has formerly represented a client in a matter shall not use information relating to the representation of the client to the disadvantage of the client unless the client gives informed consent, the disclosure is impliedly authorized in compliance with Paragraph (b), or the disclosure is otherwise permitted or required by law.”

And, more generally: “A lawyer who has formerly represented a client in a matter shall not use or reveal information relating to the representation of the client that could be embarrassing, damaging, or otherwise detrimental to the client or the client’s relationship with another person or entity, unless the client gives informed consent, the disclosure is impliedly authorized in compliance with Paragraph (b), or the disclosure is otherwise permitted or required by law.”

As a result, Model Rule 1.9(c) does not itself impose any breach-notification requirement for law firms. But, as the ABA explains in Formal Opinion 483:

“The lack of a specific rule under the Model Rules regarding breach notification in relation to former clients does not preclude the potential obligation to notify former clients as potentially advisable in appropriate circumstances . . . . Given the nature of the information contained within lawyers’ files (whether paper or electronic), former clients may be entitled to a similar notification in appropriate circumstances.”

Privileged Files

Does attorney-client privilege apply to hacked files?

The answer to that is no, not necessarily, and not always. In some cases, it will; in others, it will not. For example, courts around the country have reached different results on the question of whether unauthorized hacking waives attorney-client privilege. The U.S. Court of Appeals for the Fifth Circuit held that “unauthorized access does not establish a waiver of attorney-client privilege” in In re: Am. Online Servs. Inc. Privacy Litigation, and some other courts have taken a similar view.

What about inadvertently disclosed protected materials?

While a protective order usually governs what happens when a party inadvertently discloses protected materials (and in practice, these orders generally preserve the confidentiality of inadvertently disclosed materials), the same rules that apply to privilege when the material is intentionally disclosed in a lawsuit may apply when it is inadvertently disclosed.

Talk It Through With a Lawyer

Every case turns on its own facts. Todd Spodek is the managing partner of Spodek Law Group, a second generation firm his father opened in 1976, and the firm takes federal criminal and white collar matters nationwide. Call 888 348 8028 to talk it through.

LEGAL INFORMATION, NOT LEGAL ADVICE · STATUTES CHANGE - VERIFY CURRENT LAW · ATTORNEY ADVERTISING
THE AUTHOR'S RECORD · PRIOR RESULTS DO NOT GUARANTEE A SIMILAR OUTCOME
Acquitted.
$26M MONEY LAUNDERING
Dismissed.
RICO · 10-YEAR MINIMUM FACED
Six months.
$12M PONZI · YEARS ASKED
ALL RESULTS →
★★★★★VERIFIED CLIENT · FEDERAL CASE · 2022 · VIA GOOGLE REVIEWS
"By the time our free consultation was over, we left at ease."
1,100+ FIVE-STAR GOOGLE REVIEWS →
RISK FREE · CONFIDENTIAL · 24/7

Reading is good. Calling is better.

Answered within 24 hours, guaranteed. Some stories are better told out loud -

212 300 5196
AFTER YOU REACH OUT
01A person answers - not a service. Day or night. 02Free, confidential consultation - ask us anything, regardless of how long it takes. 03Strategy starts the same day - and you hold the senior partner's cell number.
★★★★★1,100+ FIVE-STAR GOOGLE REVIEWS
READ THEM →
INTAKE · PRIVILEGED & CONFIDENTIAL
24/7
01
02
03
04
05
ANSWERED WITHIN 24 HOURS, GUARANTEED OR CALL 212 300 5196
EVERYTHING YOU SHARE IS PROTECTED BY ATTORNEY-CLIENT PRIVILEGE FROM THE FIRST WORD.