Skip to content

Data Breach

A data breach is the unauthorized acquisition of information a company held about you. Whether anyone has to tell you depends on which regulator oversees that company, and in one of the main financial regimes the notice goes to the regulator rather than to you.

Last reviewed by Steven Fox, CFP®, EA on

Quick Summary

  • Federal notification duties are sectoral. They attach to particular kinds of company rather than to breaches generally, and two of the financial ones point in opposite directions.
  • Under the FTC's Safeguards Rule, a non-bank financial institution must notify the Federal Trade Commission of an event involving at least 500 consumers within 30 days. That rule requires no notice to consumers at all.
  • Under the SEC's Regulation S-P, a broker-dealer, registered investment adviser, investment company or transfer agent must notify each affected individual as soon as practicable and no later than 30 days.
  • The Safeguards Rule presumes that unauthorized access to unencrypted information was an acquisition, unless the firm has reliable evidence otherwise. So "we found no evidence of misuse" is not an answer to the notice duty.
  • Being in a breach is not identity theft, and a breach letter by itself gives you no statutory rights. The useful steps are the ones you can take without anyone's permission.

Definition

A data breach is the acquisition of information about people by someone not authorized to have it, whether through an intrusion, a misconfiguration, a lost device or an insider. The consumer-facing question is narrower and more useful than the definition: who, if anyone, is required to tell you? The answer is not general. It depends on what kind of business held the data and which regulator sits over it, and the two main financial regimes differ on the most basic point of all, which is whether the notice goes to you or to the government.

Federal notification duties in this area are sectoral: they attach to particular kinds of company rather than to breaches generally, which is a different thing from the common claim that there is no federal law at all. At least three federal rules impose them, two of those squarely on financial firms and pointing in opposite directions. Outside those regimes the obligation is a matter of state law, and state laws differ in what triggers a notice, how quickly it must go out, and what it has to say.

Advanced Explanation

Regime one: the FTC's Safeguards Rule, where the notice goes to the regulator. 16 CFR part 314 applies to financial institutions over which the Commission has jurisdiction, meaning those "not otherwise subject to the enforcement authority of another regulator" under the Gramm-Leach-Bliley Act. The definition is functional rather than a list: an institution is a financial institution if its business is an activity "financial in nature or incidental to such financial activities" as described in section 4(k) of the Bank Holding Company Act. The rule's own examples show how far that reaches, and none of them is a bank: a retailer that issues its own credit card, an automobile dealership that leases cars for terms of at least 90 days, a real estate appraiser, a business that prints and sells checks, and a business that regularly wires money for consumers. Since 13 May 2024, 16 CFR 314.4(j)(1) has required that "upon discovery of a notification event ..., if the notification event involves the information of at least 500 consumers, you must notify the Federal Trade Commission as soon as possible, and no later than 30 days after discovery of the event", on a form on the Commission's own website. The notice must describe the types of information involved, the date range, the number of consumers affected and the event generally.

Read that again for what it does not say. The duty runs to the Commission. The Safeguards Rule contains no obligation to notify the affected consumers, and a firm inside this regime that tells you nothing may be complying with it exactly. Any notice you receive from such a company is coming from state law, from a contract, or from its own choice.

Two mechanical details in that rule are worth more than they look. 16 CFR 314.2(m) defines a notification event as the "acquisition of unencrypted customer information without the authorization of the individual", and then adds the limb that decides most arguments: "Unauthorized acquisition will be presumed to include unauthorized access to unencrypted customer information unless you have reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition of such information." So the burden runs against the firm. "We have no evidence the data was misused" is not a reason to stay silent, because the rule presumes acquisition from access and requires affirmative evidence to rebut it. And 314.4(j)(2) provides that the firm is deemed to know of the event if it is known to "any person, other than the person committing the breach, who is your employee, officer, or other agent", which stops the 30-day clock being restarted by routing the news slowly upwards.

Regime two: the SEC's Regulation S-P, where the notice goes to you. 17 CFR 248.30 applies to "covered institutions", defined as any broker or dealer, any investment company, and any investment adviser or transfer agent registered with the Commission or another appropriate regulatory agency. Under 248.30(a)(4)(iii) such a firm "must provide the notice as soon as practicable, but not later than 30 days, after becoming aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred". Notice must be clear and conspicuous, in writing, and sent by a means designed to ensure the individual can reasonably be expected actually to receive it.

Three limbs qualify it. Under (a)(4)(i) the firm need not notify if, after a reasonable investigation, it determines that sensitive customer information "has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience". Under (a)(4)(ii), where the firm cannot identify which individuals were affected, it must notify everyone whose sensitive information sat in the affected system, unless it reasonably determines a particular individual's information was not touched. And under (a)(4)(iii) the notice may be delayed, in stages, only where the Attorney General determines that it poses a substantial risk to national security or public safety. "Sensitive customer information" is defined as any component of customer information whose compromise "could create a reasonably likely risk of substantial harm or inconvenience to an individual identified with the information".

So the same event produces different obligations depending on who lost the data. A car dealership and a registered investment adviser can lose the same file, and the first owes a report to a federal agency while the second owes a letter to you. Neither outcome tells you anything about how serious the incident was.

Regime three: everything else, which is state law and sector rules. Protected health information has its own federal breach notification rule, at 45 CFR part 164, subpart D, headed "Notification in the Case of Breach of Unsecured Protected Health Information". Beyond that, the duty comes from state law, which differs on what information counts, what triggers the notice and how quickly it must arrive, and the applicable law is usually the one of the state where the affected person lives rather than where the company sits.

The thesis that keeps this straight: being in a breach is not identity theft, and a breach letter by itself entitles you to nothing. The strong federal remedies in this area do not key off a company's letter. An extended fraud alert and the blocking of fraudulent information from your credit file both require an identity theft report, meaning a police report of sufficient detail; an initial fraud alert requires only a good-faith suspicion that you have been or are about to become a victim; and a security freeze requires no suspicion at all and is free. That last one is the reason a breach notice is worth acting on even though it grants nothing: the steps with the lowest threshold are the ones you can take unilaterally, and none of them waits for anybody's determination about whether the data has been misused.

Scale, dated and attributed. In the FBI's 2025 Internet Crime Report, personal data breach was reported 67,456 times with reported losses of $1,314,923,988, placing it fourth by complaint count and fourth by loss among all crime types. The report counts a separate and much smaller "data breach" category for computer intrusions against organizations, which is a reminder that a single phrase is doing two jobs even inside one dataset.

How to Remember

Ask who lost it, not what was lost. A non-bank financial company tells the FTC; a brokerage or a registered adviser tells you; everyone else answers to state law. And a letter is news, not a remedy.

Used in a Sentence

“The letter said her account number and date of birth were in the data breach, which is why she froze her credit at all three bureaus that week rather than waiting.”

How It Works

A firm discovers unauthorized access. It determines which regime it sits in, whether the information was encrypted, how many people are involved and whether the data was sensitive. Inside the Safeguards Rule it counts the affected consumers and, at 500 or more, files with the Federal Trade Commission within 30 days of discovery, with the clock starting when any employee or agent other than the intruder knows. Inside Regulation S-P it either determines that the information is not reasonably likely to be used to cause substantial harm or inconvenience, or notifies each affected individual within 30 days, notifying everyone in the affected system where it cannot tell who was touched.

A worked example of the same event under the two rules, because the answers diverge. A firm's client file containing names, addresses, dates of birth and account numbers for 1,400 people is accessed by an intruder. The file was not encrypted, and the firm has no evidence about whether anything was copied.

If the firm is an automobile dealership that leases cars on long terms, which is one of the Safeguards Rule's own examples of a financial institution, 16 CFR part 314 applies. The 314.2(m) presumption means the access is treated as an acquisition, because the firm has no reliable evidence that acquisition did not or could not have occurred. 1,400 exceeds the 500-consumer threshold, so within 30 days of the first day any employee knew, the firm must file a notice with the Federal Trade Commission. Under that rule it owes the 1,400 people nothing.

If the firm is an SEC-registered investment adviser, Regulation S-P applies. The threshold is not a headcount; the question is whether the sensitive customer information is reasonably likely to be used in a way causing substantial harm or inconvenience. Dates of birth and account numbers make that hard to rule out, so the firm must notify each of the 1,400 individuals in writing within 30 days. And if its logs cannot show which of the 1,400 records were reached, (a)(4)(ii) requires it to notify all 1,400 anyway.

Same file, same number of people, same absence of evidence. One regime produces a government filing and 1,400 uninformed people; the other produces 1,400 letters.

Pros and Cons

This is something that happens to you rather than something you choose, so what follows is what the rules deliver and where they leave gaps.

What the rules deliver

  • Under Regulation S-P the notice goes to the affected individual directly, in writing, within 30 days, and by a means designed to ensure it actually arrives.
  • The Safeguards Rule's presumption puts the burden on the firm: unauthorized access to unencrypted information is presumed to be acquisition unless the firm has reliable evidence otherwise.
  • Constructive knowledge through any employee or agent starts the Safeguards Rule clock, so a firm cannot buy time by escalating slowly.
  • Where a covered institution cannot identify who was affected, it must notify everyone whose sensitive information was in the system.
  • The response steps with the lowest thresholds, a security freeze and an initial fraud alert, are available to you without anyone's determination and at no cost.

Where the gaps are

  • The Safeguards Rule requires no notice to consumers at all, so a firm inside that regime can comply fully while telling you nothing.
  • Its threshold is 500 consumers, so a smaller event produces no federal filing either.
  • Regulation S-P's substantial-harm determination is made by the firm, in the first instance, about its own incident.
  • Outside the federal regimes the duty is state law, which differs, so two people affected by the same event can receive different notices at different times.
  • A breach notice confers no statutory rights by itself, and the offer of free monitoring that usually accompanies one detects rather than prevents.
  • You cannot verify what was taken, only what you are told was taken.

People Also Asked

Answers to the most frequently asked questions.

Is a company required to tell me if my data was breached?
It depends entirely on which regulator oversees that company. An SEC-registered investment adviser, broker-dealer, investment company or transfer agent must notify each affected individual within 30 days under 17 CFR 248.30(a)(4), unless it determines after a reasonable investigation that the sensitive information is not reasonably likely to be used in a way causing substantial harm or inconvenience. A non-bank financial institution under the FTC's Safeguards Rule must notify the Federal Trade Commission, not you. Everything else is a matter of state law, which differs.
What does "we have no evidence of misuse" mean in a breach letter?
Under the FTC's Safeguards Rule it is not a reason to withhold a filing. 16 CFR 314.2(m) provides that unauthorized acquisition "will be presumed to include unauthorized access to unencrypted customer information unless you have reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition". The absence of evidence of misuse is not evidence that nothing was taken, and the rule is drafted that way round on purpose. Treat the sentence as reassurance about what the firm knows rather than about your exposure.
Does being in a data breach mean my identity has been stolen?
No. A breach means information about you left a place it was supposed to stay. Identity theft is the use of that information to obtain credit, goods, services or benefits, and it may never happen. The distinction matters because the strongest federal remedies key off an identity theft report or, for an initial fraud alert, a good-faith suspicion that you have been or are about to become a victim, rather than off a letter from a company.
What should I actually do after a breach notice?
Prioritize the steps that need no one's permission. A security freeze at each nationwide credit bureau is free, needs no suspicion of anything, and blocks the specific harm of a new account being opened in your name. An initial fraud alert needs only a good-faith suspicion. Change the password on the affected account and anywhere you reused it, and treat a code arriving unrequested as evidence someone already has that password. The free monitoring usually offered with a notice detects rather than prevents, so it is a supplement rather than the response.
How long does a company have to report a breach?
In the two federal financial regimes, 30 days, but from different starting points and to different recipients. The FTC's Safeguards Rule requires notice to the Commission "as soon as possible, and no later than 30 days after discovery", with discovery dated from the first day any employee or agent other than the intruder knows. The SEC's Regulation S-P requires notice to each affected individual "as soon as practicable, but not later than 30 days" after the firm becomes aware, subject to a delay only where the Attorney General determines the notice poses a substantial risk to national security or public safety.

Have a question a definition can't answer?

Advice-only advisors answer questions like this for a transparent flat fee — no products, no commissions, no asset management.

Find an Advisor