Louisiana Database Security Breach Notification Law

· About Louisiana Database Security Breach Notification Law

Key Takeaways

  • Louisiana’s Database Security Breach Notification Law applies to any person doing business in Louisiana, plus agencies and other entities that own, license, or maintain computerized data containing personal information, and it requires notice after discovery of a qualifying breach.[1]
  • Notice to affected Louisiana residents must be given without unreasonable delay and no later than 60 days after discovery, unless law enforcement needs or containment steps justify a delay.[1]
  • The law also requires notice to the Louisiana Attorney General in specified situations, and consumer notice may be by written, electronic, or substitute methods when statutory conditions are met.[1][3]
  • Entities may avoid resident notice if, after a reasonable investigation, they determine there is no reasonable likelihood of harm to Louisiana residents.[1]
  • Louisiana amended the law in 2018 to expand the definition of personal information to include items such as state identification card numbers, passport numbers, and biometric data; no 2025–2026 amendment changing the core breach-notification deadlines appears in the official materials reviewed.[1][9]
  • Violations can trigger attorney general enforcement, civil penalties, and other relief, so the statute is both a notification law and a compliance program requirement.[1][10]

What It Is

Louisiana’s Database Security Breach Notification Law is the state breach-notification statute governing disclosures involving computerized data that contains personal information.[1] It is codified at La. Rev. Stat. § 51:3071 et seq. and is enforced through the Louisiana Attorney General’s consumer protection authority.[1][10]

The statute was enacted before 2018 and was materially amended by Act 382 of 2018, which expanded the personal-information definition; the core notification framework remains in force as of 6 September 2026.[1][9] The official text available from the Louisiana Legislature reflects the operative law, including the 60-day notice deadline and the harm exception.[1]

Key phase-in dates that matter operationally are the 2018 amendment effective date for expanded personal-information scope and the continuing effective date of the notice rules, which are already in force and not awaiting delayed implementation as of the current official materials reviewed.[1][9]

Who Must Comply

The statute applies to any person that conducts business in Louisiana and owns or licenses computerized data including personal information, and to any agency that owns or licenses such data.[1] It also applies to any person or agency that maintains computerized data for another party and discovers that personal information may have been acquired by an unauthorized person through a breach.[1]

The law has an extraterritorial reach because the trigger is the presence of personal information belonging to a Louisiana resident, not the location of the company’s headquarters.[1] If the breach involves Louisiana residents’ personal information, the notice obligation can attach even when the organization is outside Louisiana.[1]

Exemptions are limited. The main express escape hatch is the no reasonable likelihood of harm determination after a reasonable investigation.[1] The statute also permits delayed notification when needed for legitimate law-enforcement purposes or to determine scope, prevent further disclosure, and restore system integrity.[1]

Core Requirements

  1. Determine whether the incident is a covered breach. The law is triggered when personal information was, or is reasonably believed to have been, acquired by an unauthorized person through a breach of security of the system containing the data.[1]
  1. Notify affected Louisiana residents. The entity must notify each Louisiana resident whose personal information was, or is reasonably believed to have been, acquired, using a method authorized by statute.[1]
  1. Meet the timing rule. Notice must be made in the most expedient time possible and without unreasonable delay, and in any event no later than 60 days after discovery, subject to law-enforcement and containment exceptions.[1]
  1. Use an authorized notice method. The statute allows written notice, electronic notice if compliant with federal E-SIGN requirements, and substitute notice when the statutory thresholds are met.[1]
  1. Notify the Attorney General when required. Louisiana requires notice to the Consumer Protection Section of the Attorney General’s Office in connection with resident notices, including information identifying Louisiana citizens affected by the breach.[3]
  1. Consider the harm exception carefully. Resident notice is not required if, after reasonable investigation, the entity determines there is no reasonable likelihood of harm to Louisiana residents.[1]
  1. Protect data before and after a breach. The broader compliance context includes data-destruction and safeguarding practices for personal information; operationally, the breach law should be paired with records-retention and secure-destruction controls so unneeded personal information is not retained indefinitely.[1][11]

Deadlines and Penalties

| milestone | date | what applies | |---|---:|---| | Breach discovered | Day 0 | Start assessing whether personal information of Louisiana residents was acquired by an unauthorized person.[1] | | Resident notice deadline | Within 60 days | Notice must be sent as expeditiously as possible and without unreasonable delay, subject to law-enforcement and containment needs.[1] | | Attorney General notice | As required with resident notice | Notice to the Consumer Protection Section accompanies the breach reporting process.[3] | | 2018 amendment effective | 1 August 2018 | Expanded personal-information scope, including state ID card number, passport number, and biometric data.[9] |

Maximum penalties and sanctions depend on enforcement action under Louisiana law and are not stated as a single fixed penalty schedule in the breach-notification text itself.[1] The Attorney General may seek injunctive relief and civil penalties under the enforcement provisions applicable to the chapter, and noncompliance can also create litigation and regulatory risk.[1][10]

How to Comply

  1. Map the data. Identify where Louisiana residents’ personal information is collected, stored, transmitted, and shared, and classify which systems are in scope under La. Rev. Stat. § 51:3071 et seq.[1]
  1. Build a breach triage workflow. Create a documented process to determine whether unauthorized acquisition occurred, whether personal information was involved, and whether the harm exception could apply.[1]
  1. Set a 60-day legal clock. Use incident-response tooling to start the notification timetable at discovery and track the deadline to resident and regulator notices.[1][3]
  1. Align controls to ISO 27001. Use ISO 27001 for asset inventory, access control, incident management, supplier management, and evidence retention, because those controls support fast breach containment and defensible investigations.
  1. Use NIST CSF 2.0 for incident response. Map detection, analysis, containment, recovery, and communications to the NIST CSF 2.0 functions so legal, security, and privacy teams share one response cadence.
  1. Adopt ISO 42001 where AI systems process personal information. If AI systems ingest or infer Louisiana residents’ personal data, use ISO 42001 to govern data lineage, oversight, and operational accountability around automated processing.
  1. Pre-build notice templates. Keep resident and Attorney General notice drafts ready, with fields for affected populations, timing, incident summary, and contact information, so counsel can finalize them quickly.[3]
  1. Test and audit annually. Run breach-notification tabletop exercises and periodic audits to confirm the organization can complete investigation, legal review, and notifications inside the statutory window.[1][10]

Related Regulations

The Louisiana Consumer Data Privacy Law overlaps because it adds broader privacy rights and governance duties, but it does not replace breach-notification obligations; the Louisiana privacy statute expressly preserves compliance with the breach law.[14]

The HIPAA Breach Notification Rule may apply when protected health information is involved, creating separate federal timing and reporting duties in addition to Louisiana notice obligations.

The GLBA Safeguards Rule can overlap for financial institutions, especially where customer information security controls and incident response are concerned, but it is sector-specific and does not displace Louisiana resident notice requirements.

The FTC Act, Section 5 can overlap through unfair or deceptive practices exposure if breach-response statements, privacy notices, or security representations are inaccurate.

The Louisiana Insurance Data Security Law may apply to licensed insurers and can require regulator notification in parallel with the general breach statute.[12]

FAQ

Does Louisiana’s breach law apply to companies outside Louisiana?

Yes, if the company owns, licenses, or maintains computerized data that includes personal information of Louisiana residents and a covered breach occurs.[1] The statute is triggered by the affected residents and the data relationship, not by the company’s state of incorporation.[1]

When does the 60-day notice clock start?

The clock starts on discovery of the breach.[1] The law requires notice as quickly as possible and without unreasonable delay, and in any case within 60 days unless law-enforcement or containment needs justify a delay.[1]

Is Attorney General notice required?

Yes, Louisiana requires notice to the Consumer Protection Section of the Attorney General’s Office in connection with resident breach notification, including the names of affected Louisiana citizens.[3] The official guidance should be checked for the exact filing format and operational details.[3][10]

What counts as personal information in Louisiana?

The statute covers unencrypted computerized personal information and, after the 2018 amendment, includes items such as state identification card numbers, passport numbers, and biometric data in addition to traditional identifiers.[1][9] Organizations should not assume the definition is limited to Social Security numbers.[1]

Can an organization skip notice if no one seems harmed?

Potentially yes, but only after a reasonable investigation supporting a conclusion that there is no reasonable likelihood of harm to Louisiana residents.[1] That decision should be documented carefully because it may be scrutinized later by regulators or plaintiffs.[1]

Does the law still change in 2025–2026?

The official materials reviewed show the core Louisiana breach-notification rules still in force in 2026, with no newly effective 2025–2026 amendment altering the main 60-day notice framework identified here.[1][10] A broader Louisiana privacy law took effect in 2027 planning discussions, but it does not replace this breach-notification statute.[8][14]

Sources

Put it into practice

More compliance guides