Regime one: the FTC's Safeguards Rule, where the notice goes to the regulator. 16 CFR part 314 applies to financial institutions over which the Commission has jurisdiction, meaning those "not otherwise subject to the enforcement authority of another regulator" under the Gramm-Leach-Bliley Act. The definition is functional rather than a list: an institution is a financial institution if its business is an activity "financial in nature or incidental to such financial activities" as described in section 4(k) of the Bank Holding Company Act. The rule's own examples show how far that reaches, and none of them is a bank: a retailer that issues its own credit card, an automobile dealership that leases cars for terms of at least 90 days, a real estate appraiser, a business that prints and sells checks, and a business that regularly wires money for consumers. Since 13 May 2024, 16 CFR 314.4(j)(1) has required that "upon discovery of a notification event ..., if the notification event involves the information of at least 500 consumers, you must notify the Federal Trade Commission as soon as possible, and no later than 30 days after discovery of the event", on a form on the Commission's own website. The notice must describe the types of information involved, the date range, the number of consumers affected and the event generally.
Read that again for what it does not say. The duty runs to the Commission. The Safeguards Rule contains no obligation to notify the affected consumers, and a firm inside this regime that tells you nothing may be complying with it exactly. Any notice you receive from such a company is coming from state law, from a contract, or from its own choice.
Two mechanical details in that rule are worth more than they look. 16 CFR 314.2(m) defines a notification event as the "acquisition of unencrypted customer information without the authorization of the individual", and then adds the limb that decides most arguments: "Unauthorized acquisition will be presumed to include unauthorized access to unencrypted customer information unless you have reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition of such information." So the burden runs against the firm. "We have no evidence the data was misused" is not a reason to stay silent, because the rule presumes acquisition from access and requires affirmative evidence to rebut it. And 314.4(j)(2) provides that the firm is deemed to know of the event if it is known to "any person, other than the person committing the breach, who is your employee, officer, or other agent", which stops the 30-day clock being restarted by routing the news slowly upwards.
Regime two: the SEC's Regulation S-P, where the notice goes to you. 17 CFR 248.30 applies to "covered institutions", defined as any broker or dealer, any investment company, and any investment adviser or transfer agent registered with the Commission or another appropriate regulatory agency. Under 248.30(a)(4)(iii) such a firm "must provide the notice as soon as practicable, but not later than 30 days, after becoming aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred". Notice must be clear and conspicuous, in writing, and sent by a means designed to ensure the individual can reasonably be expected actually to receive it.
Three limbs qualify it. Under (a)(4)(i) the firm need not notify if, after a reasonable investigation, it determines that sensitive customer information "has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience". Under (a)(4)(ii), where the firm cannot identify which individuals were affected, it must notify everyone whose sensitive information sat in the affected system, unless it reasonably determines a particular individual's information was not touched. And under (a)(4)(iii) the notice may be delayed, in stages, only where the Attorney General determines that it poses a substantial risk to national security or public safety. "Sensitive customer information" is defined as any component of customer information whose compromise "could create a reasonably likely risk of substantial harm or inconvenience to an individual identified with the information".
So the same event produces different obligations depending on who lost the data. A car dealership and a registered investment adviser can lose the same file, and the first owes a report to a federal agency while the second owes a letter to you. Neither outcome tells you anything about how serious the incident was.
Regime three: everything else, which is state law and sector rules. Protected health information has its own federal breach notification rule, at 45 CFR part 164, subpart D, headed "Notification in the Case of Breach of Unsecured Protected Health Information". Beyond that, the duty comes from state law, which differs on what information counts, what triggers the notice and how quickly it must arrive, and the applicable law is usually the one of the state where the affected person lives rather than where the company sits.
The thesis that keeps this straight: being in a breach is not identity theft, and a breach letter by itself entitles you to nothing. The strong federal remedies in this area do not key off a company's letter. An extended fraud alert and the blocking of fraudulent information from your credit file both require an identity theft report, meaning a police report of sufficient detail; an initial fraud alert requires only a good-faith suspicion that you have been or are about to become a victim; and a security freeze requires no suspicion at all and is free. That last one is the reason a breach notice is worth acting on even though it grants nothing: the steps with the lowest threshold are the ones you can take unilaterally, and none of them waits for anybody's determination about whether the data has been misused.
Scale, dated and attributed. In the FBI's 2025 Internet Crime Report, personal data breach was reported 67,456 times with reported losses of $1,314,923,988, placing it fourth by complaint count and fourth by loss among all crime types. The report counts a separate and much smaller "data breach" category for computer intrusions against organizations, which is a reminder that a single phrase is doing two jobs even inside one dataset.