In the News: Lauren Godfrey Shares Guidance on Navigating Expanding State Breach Notification Requirements
Constangy Cyber Team partner Lauren Godfrey authored an article for The Legal Intelligencer discussing how states have continued to strengthen breach notification statutes and expand attorney general reporting requirements. This means that organizations now face increased risk of penalties if they delay consumer and regulatory notifications when a cybersecurity incident occurs.
Lauren provided insight into state-specific reporting requirements as it pertains to deadlines for regulatory and consumer disclosure. She also highlighted recent enforcement trends and the enforcement authority of state attorneys general. Additionally, Lauren shared practical lessons for organizations, including viewing breach notification obligations as a critical component of incident response rather than a post-investigation task.
“As states adopt shorter deadlines and regulators place greater emphasis on prompt disclosure, long notification timelines can transform a cybersecurity incident into a broader regulatory enforcement matter,” said Lauren. “Organizations that fail to prioritize timely reporting may find that the most expensive consequence of a breach is not the intrusion itself but the time it took in telling regulators and affected individuals about it.”
To view the full article, subscribers may click here.