Hawaii Revised Statutes Chapter 487N - Security Breach of Personal Information
· About Hawaii Revised Statutes Chapter 487N - Security Breach of Personal Information
Key Takeaways
- Hawaii Revised Statutes Chapter 487N applies to businesses that own or license personal information of Hawaii residents, businesses that conduct business in Hawaii and hold personal information, and government agencies that collect personal information for specific government purposes.[1][2]
- Notice is required without unreasonable delay after discovery or notification of a security breach, unless a law-enforcement delay is justified.[1][2]
- If more than 1,000 Hawaii residents are notified, the business must also notify the Hawaii Office of Consumer Protection and the nationwide consumer reporting agencies.[1][13]
- The statute’s penalty for businesses is up to $2,500 per violation, and the law also authorizes civil actions.[8]
- Government agencies have separate reporting duties, including a written report to the legislature within 20 days after discovery of a breach.[7]
- A 2026 bill would expand the definition of personal information, but the available legislative materials show it as proposed/amended bill text, not confirmed enacted law as of the current record.[2][3][11]
What It Is
Hawaii Revised Statutes Chapter 487N is the state’s breach-notification law for security breaches involving personal information.[1][5] It is enforced through the state’s consumer-protection framework, including the Office of Consumer Protection for large-notification events, and through statutory civil penalties for noncompliance.[1][8][13]
The current version in the available codified materials traces to the long-standing breach-notification framework and has not been shown in the gathered sources to have an enacted 2025–2026 replacement text.[5][12] However, 2026 session materials show an active bill to broaden the definition of personal information and related terms, so compliance teams should treat the definition question as an area of live legislative risk rather than a settled expansion.[2][3][11]
For timing, the law requires notice after discovery or notification of a breach, and government-agency reporting must occur within 20 days of discovery.[1][7] The sources gathered do not indicate a new enacted delayed effective date in 2025–2026 that overrides the existing notice framework.[5][12]
Who Must Comply
The law applies to any business that owns or licenses personal information of Hawaii residents, any business that conducts business in Hawaii and owns or licenses personal information in any form, and any government agency that collects personal information for specific governmental purposes.[1][2]
The statute’s reach is effectively extraterritorial for companies outside Hawaii if they own or license personal information of Hawaii residents or conduct business in Hawaii while holding such information.[1][13] That means a company does not need to be headquartered in Hawaii to fall within the law.
The codified definition of personal information historically focuses on a resident’s name combined with data elements such as Social Security number, driver’s license number, or financial account information, while legislative materials in 2026 propose expanding that definition.[1][2][3] Publicly available information lawfully made available from government records is excluded in the 2026 bill text, and good-faith employee acquisition for a legitimate business purpose is not a security breach if it is not misused or further disclosed.[3][6]
Core Requirements
- Provide resident notice promptly. A covered entity must notify affected persons after discovery or notification of a security breach, without unreasonable delay, unless law enforcement requests a delay.[1][2]
- Use an appropriate notice method. Notice may be written, electronic, or telephonic, and substitute notice is permitted when direct notice is impracticable under the statute’s conditions.[4]
- Include required content in the notice. The notice must describe the incident, identify the type of personal information involved, and explain actions taken to protect the information.[4]
- Notify state authorities and credit bureaus when the breach is large. If more than 1,000 individuals are affected, the business must notify the Hawaii Office of Consumer Protection and nationwide consumer reporting agencies.[4][13]
- Maintain breach response documentation. Government agencies must prepare a written report to the legislature within 20 days after discovery, including the nature of the breach, the number of individuals affected, the notice used, and mitigation steps.[7]
- Avoid prohibited handling of personal information. Good-faith internal acquisition for legitimate business purposes is excluded from the breach definition only if it is not used for an unauthorized purpose and not further disclosed.[6]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | Resident notice after discovery | Without unreasonable delay | Notice to affected individuals after a breach is discovered or reported.[1][2] | | Government-agency legislative report | 20 days after discovery | Written report to the legislature describing the breach and response.[7] | | Large-breach state and CRA notice | When 1,000+ individuals are affected | Notice to the Hawaii Office of Consumer Protection and nationwide consumer reporting agencies.[4][13] |
The maximum statutory business penalty identified in the codified source is not more than $2,500 for each violation.[8] The statute also authorizes civil action, which means private litigation exposure may accompany regulatory enforcement.[8]
How to Comply
- Map Hawaii data holdings. Identify whether the organization owns or licenses personal information of Hawaii residents, including data held by third parties and processors.
- Classify datasets against the statutory trigger. Build a Hawaii-specific breach matrix for the existing definition of personal information and track the 2026 proposal separately so incident triage does not rely on an outdated definition.[1][2][3]
- Align incident response to ISO 27001 and NIST CSF 2.0. Use ISO 27001 for governance, asset inventory, logging, access control, and supplier oversight; use NIST CSF 2.0 to structure Detect, Respond, and Recover workflows.
- Create a breach-notice decision tree. Include the “without unreasonable delay” standard, law-enforcement delay handling, threshold-based state and CRA notices, and approved notice channels.[1][4]
- Pre-draft notice templates and approval paths. Ensure templates contain the incident description, data categories, and remediation steps, with legal review for accuracy and consistency with forensic findings.[4]
- Set executive and legal escalation SLAs. Large incidents should trigger immediate notice routing, because the law’s timing standard is measured by unreasonable delay, not by a fixed number of days for resident notice.[1][2]
- Test third-party coordination. Contracts with processors, cloud vendors, and response firms should require rapid breach reporting, evidence preservation, and cooperation for Hawaii-specific notices.
- Use ISO 42001 for AI-assisted response controls where relevant. If AI is used in triage, classification, or notice drafting, apply ISO 42001-style oversight, human review, and output validation so the organization can defend accuracy and accountability.
Related Regulations
- Hawaii consumer protection law overlaps because major breach notices go to the Office of Consumer Protection, making the privacy incident also a consumer-protection event.[4][13]
- HIPAA may conflict or overlap for health data, because a single incident can trigger both HIPAA breach rules and Hawaii breach notice duties depending on the data set.
- GLBA may overlap for financial institutions, which often have separate federal privacy and incident-response obligations that can run in parallel with Hawaii notice duties.
- California Civil Code breach-notice rules are similar but not identical, so multi-state businesses should avoid using one uniform template without state-specific tailoring.
- Washington data breach law overlaps for companies with Pacific-region footprints and different state thresholds, making coordinated incident triage essential.
FAQ
Does Hawaii Chapter 487N apply to companies outside Hawaii?
Yes, if they own or license personal information of Hawaii residents or conduct business in Hawaii while holding such information.[1][13] The law is triggered by the data relationship, not only by the company’s headquarters.
Does the law require notice to affected people after every cyber incident?
No, only after a security breach as defined by the statute.[6] Good-faith internal access for a legitimate business purpose is excluded if there is no unauthorized use or further disclosure.[6]
How fast must notice go out?
The statute requires notice after discovery or notification of the breach without unreasonable delay.[1][2] That means the timing depends on the facts, including forensic validation, containment, and any lawful delay request by law enforcement.
What happens if more than 1,000 people are affected?
The business must also notify the Hawaii Office of Consumer Protection and the nationwide consumer reporting agencies.[4][13] That additional escalation makes large incidents materially more complex than routine individual notices.
Are there penalties for noncompliance?
Yes. The codified penalty provision states that a business violating the chapter is subject to penalties of not more than $2,500 for each violation.[8] The statute also permits civil action, which increases litigation exposure.[8]
Did Hawaii expand the definition of personal information in 2025 or 2026?
The gathered materials show a 2026 bill aimed at expanding the definition, but those sources identify it as bill text and testimony rather than confirmed enacted law.[2][3][11] Compliance teams should treat that as proposed or pending unless the final enrolled act and effective date are confirmed in the official session law.
Sources
- Hawaii Revised Statutes Chapter 487N (codified chapter)
- Hawaii Revised Statutes § 487N-1 Definitions
- Hawaii Revised Statutes § 487N-2 Notice of security breach
- Hawaii Revised Statutes § 487N-3 Penalties; civil action
- Hawaii Revised Statutes § 487N-4 Reporting requirements
- 2026 Hawaii Senate Bill 3016 PDF
- 2026 Hawaii Senate Bill 3016 HD1 text
- 2026 testimony on SB3016
- DataGuidance Hawaii jurisdiction overview
- DataBreachCost Hawaii breach notification overview
Put it into practice
- Generate the policy: Privacy policy generator (generatepolicy.com)
- Buy the policy pack: State Privacy Law Checklist (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)