A reminder that the details of states’ data breach notification laws really do matter. A notification that may be satisfactory in most states may be noncompliant in another state and really cost the firm. From attorneys at BakerHostetler:
One ruling is not a trend. And there can be unique factors at play in regulatory investigations related to large incidents. But a summary judgment ruling in favor of a state in a lawsuit against a telecom shows how not achieving technical compliance with state data breach notification laws in a large incident is a billion-dollar area of risk.
T-Mobile disclosed a security incident in August 2021 that involved 76 million records (approximately 47 million had SSNs). The notification requirement of Washington’s data breach notice law is similar to most states – if there is a notice obligation, the notice has to be provided by sending a letter by regular mail, an email if there is E-Sign consent, or substitute notice (and substitute notice requires a press release, a posting on the company’s website and an email if the company has an email address for the individuals to be notified). Washington’s notification law, like many other states, also has content requirements (e.g., the notice has to include the name of and contact information for the company, the data elements involved and the date of the breach). Washington’s law also provides that if a company has an internal notice procedure and issues notice that meets Washington’s notification time requirement, the company complies with Washington law by following its policy. T-Mobile sent a text message as its method of notice to 361,030 Washington residents.
The Washington Attorney General filed a lawsuit against T-Mobile in January 2025 alleging that T-Mobile committed violations of Washington’s consumer protection law by not providing notice in compliance with the requirements of Washington’s data breach notice law. A Washington state court issued a decision in July 2026 granting summary judgment in favor of Washington. The court determined that T-Mobile’s text message resulted in two separate violations of Washington’s law for each of the 361,030 residents: (1) the method of notice did not meet the substitute notice requirements and (2) the words in the text message did not meet the content requirements. Washington law permits the recovery of a civil penalty of not more than $7,500 for each violation. Using a penalty of just $100 per violation for the 722,060 violations, T-Mobile would face a civil penalty of $72 million (an amount per violation at the top end would impose billions in civil penalties).
Read more at Data Counsel.
h/t JDSupra
