West Virginia Consumer Credit and Protection Act
· About West Virginia Consumer Credit and Protection Act
Key Takeaways
- West Virginia’s breach-notification law applies to any individual or entity that owns or licenses computerized personal information and to certain data processors that maintain it for others, requiring notice to affected West Virginia residents after a qualifying breach.[2][5]
- The law covers unencrypted and unredacted personal information and also reaches encrypted data when the encryption key is compromised or the data is acquired in unencrypted form.[2][6]
- Notice must be given without unreasonable delay after discovery or notification of the breach, and the statute allows limited delays only for legitimate law-enforcement needs or to restore system integrity.[5][14]
- If a breach affects more than 1,000 residents, the entity must also notify consumer reporting agencies, and notices must include credit bureau contact information and guidance on fraud alerts or security freezes.[5][6]
- The West Virginia Attorney General may enforce the statute, and the civil penalty in the statute is capped at $150,000 per breach or series of similar breaches discovered in a single investigation.[13]
- As of 6 September 2026, the official code still reflects the breach-notification framework in W. Va. Code §§ 46A-2A-101 to 46A-2A-105; the 2026 legislative activity found in public bill texts appears to concern a different privacy proposal and does not show a replacement of the breach-notification article.[5][7][10][15]
What It Is
The relevant West Virginia data-breach regime sits in Article 2A of Chapter 46A of the West Virginia Consumer Credit and Protection Act, titled Notice of Breach of Security of Computerized Personal Information.[5][8] It is enforced through the state’s consumer-protection framework and gives the Attorney General civil enforcement authority.[13]
The article’s operative text defines “breach of the security of a system” as unauthorized access and acquisition of computerized data that compromises the security or confidentiality of personal information and creates a reasonable belief of identity theft or other fraud risk to a West Virginia resident.[2][6]
The current official code materials available in 2026 show the breach-notification article in force, with the statute applying to breaches discovered or notified on or after its effective date; the code text also indicates that the timing rules are tied to discovery or notification of the breach.[5][14] No 2025–2026 enactment identified in the available official materials displaces Article 2A, although 2026 bill activity includes a separate consumer financial privacy proposal that is not the breach-notification law itself.[7][15]
Who Must Comply
The law applies to an individual or entity that owns or licenses computerized data including personal information, and also to an individual or entity that maintains computerized data for another owner or licensee.[5][6] The maintainer must notify the owner or licensee promptly if it discovers unauthorized access and acquisition of the personal information.[5][6]
The statute reaches West Virginia residents whose unencrypted and unredacted personal information was, or is reasonably believed to have been, accessed and acquired by an unauthorized person and where the event causes or is reasonably believed to cause identity theft or other fraud.[2][5]
The law has extraterritorial effects in the practical sense that an out-of-state company must comply if it owns, licenses, or maintains data affecting West Virginia residents.[5][6] The law’s notice duty is triggered by the resident’s status and the location of the impacted information, not by where the company is headquartered.[5]
The code materials surfaced here do not identify a broad exemption for small businesses, sector-specific exceptions, or a general carve-out for nonprofits.[5][13] One notable limitation is that a licensed financial institution is treated differently for enforcement, with the statute stating that violations are enforceable exclusively by the institution’s primary functional regulator.[13]
Core Requirements
- Prompt breach notice to residents. An owner or licensee of computerized data must notify affected West Virginia residents after discovering a breach involving unencrypted and unredacted personal information that was or is reasonably believed to have been accessed and acquired by an unauthorized person.[5][6]
- Notice to the owner when acting as a processor. A person or entity that merely maintains computerized data for another must notify the owner or licensee of the information as soon as practicable after discovery if the data was or is reasonably believed to have been accessed by an unauthorized person.[5][6]
- Use permitted notice methods. The statute allows written, telephonic, or electronic notice, and permits substitute notice when the cost of direct notice exceeds $50,000, the affected class exceeds 100,000 residents, or sufficient contact information is unavailable.[2][5]
- Include required content in the notice. The notice must describe, to the extent possible, the categories of information believed to have been accessed or acquired and provide contact details for the entity and for the major consumer reporting agencies, including how to place a fraud alert or security freeze.[5][6]
- Notify consumer reporting agencies in large breaches. If more than 1,000 residents are notified at one time, the entity must also notify all nationwide consumer reporting agencies without unreasonable delay.[6]
- Avoid unnecessary delay. Notice may be delayed only to accommodate law enforcement needs or to determine the scope of the breach and restore system integrity, and the delay must not exceed what is reasonably necessary.[14]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | Breach discovered or notified | immediately upon discovery | Notice obligations are triggered when the breach is discovered or the entity is notified of it.[5][14] | | Resident notice | without unreasonable delay | Affected residents must be notified promptly, subject only to limited lawful delay.[5][14] | | Owner notice by processor | as soon as practicable | A maintainer of data must notify the owner or licensee promptly after discovering unauthorized access.[5][6] | | Credit bureau notice | when more than 1,000 residents are notified | Consumer reporting agencies must be notified for large-scale incidents.[6] |
The statute provides for civil penalties up to $150,000 per breach of the security of the system or series of similar breaches discovered in a single investigation.[13] Enforcement is through the West Virginia Attorney General, except where the statute directs exclusive enforcement by the primary functional regulator for a licensed financial institution.[13]
Other sanctions can include injunctive relief and enforcement actions under the state consumer-protection framework, which makes breach response and documentation critical even where a civil penalty is not imposed.[13]
How to Comply
- Build a breach-response playbook. Map detection, triage, legal review, and notice approval into a written incident plan that aligns with ISO 27001 incident-management controls and NIST CSF 2.0 Govern/Respond functions.
- Inventory personal information and data flows. Identify where Social Security numbers, driver’s license numbers, state ID numbers, account data, and access credentials are stored, transferred, and backed up so breach scoping is defensible.
- Classify encryption and key management gaps. Because encrypted data can still be reportable if accessed in unencrypted form or if the encryption key is compromised, key separation and logging matter as much as encryption itself.[6]
- Pre-draft notice templates. Prepare resident, owner, and credit bureau notices with the statutory content already inserted, including fraud alert and security freeze instructions.
- Set a 72-hour internal escalation target. The West Virginia statute says “without unreasonable delay,” so a short internal deadline helps preserve room for legal review and law-enforcement coordination.
- Test vendor and processor clauses. Contracts with service providers should require immediate breach escalation, cooperation on forensic review, and preservation of evidence consistent with incident-response controls in ISO 27001.
- Document decisions. Keep a breach log showing when the event was discovered, why any delay was necessary, and when each notice was sent; that record is central to demonstrating reasonableness.
- Use privacy governance only where it fits. ISO 42001 is not a substitute for breach notification, but its AI governance controls help if automated systems handle personal data or support detection and triage.
Related Regulations
West Virginia’s breach-notification rules overlap with the New York SHIELD Act in that both require reasonable safeguards and breach notices, but West Virginia’s article is narrower and focused on incident notice rather than a broad security-program mandate.
The law also overlaps with the federal GLBA/FTC Safeguards framework for financial institutions and service providers, although West Virginia expressly leaves certain financial-institution enforcement to the primary functional regulator.[13]
It can conflict operationally with HIPAA, because healthcare entities may need to coordinate state breach notice with federal breach-notification timing and content rules, while avoiding inconsistent communications.
The statute overlaps with the California Consumer Privacy Act / CPRA only at the level of incident governance; California is a broader consumer-privacy regime, while West Virginia’s article is a breach-notice law.
For multistate operators, the law should be read alongside the NIST Cybersecurity Framework 2.0 as a control baseline, but NIST is guidance rather than a legal obligation.
FAQ
Does West Virginia’s breach-notification law apply to companies outside West Virginia?
Yes. If an out-of-state company owns, licenses, or maintains computerized personal information affecting West Virginia residents, it can be subject to the statute.[5][6] The trigger is the resident impact and the nature of the data, not the company’s headquarters.
What counts as personal information under the law?
The official text focuses on unencrypted and unredacted computerized personal information and specifically references data such as Social Security numbers, driver’s license or state ID numbers, and financial data.[5][6] The exact statutory list matters, so breach teams should treat any combination of identifiers and account data as potentially reportable until counsel rules otherwise.
Is there a fixed deadline for notice?
The statute does not set a hard number of hours or days for resident notice; instead, it requires notice without unreasonable delay.[5][14] That standard allows limited delay for law enforcement or system-restoration needs, but it does not permit open-ended deferral.
Do encrypted breaches still have to be reported?
Sometimes yes. If encrypted information is accessed and acquired in an unencrypted form, or if the encryption key is compromised and the event is likely to cause identity theft or fraud, notice is required.[6] Encryption therefore reduces risk, but it does not automatically eliminate the reporting obligation.
Are there penalties for failing to comply?
Yes. The statute authorizes civil penalties up to $150,000 per breach or series of similar breaches discovered in a single investigation and empowers the Attorney General to enforce the article.[13] In practice, poor notice timing, weak documentation, and inaccurate notice content can all increase enforcement exposure.
Did West Virginia change this law in 2025 or 2026?
The official code materials available here still show the breach-notification article in Chapter 46A, Article 2A, with no identified replacement or repeal in 2025–2026.[5][7][10][15] Separate 2026 bill texts concern a different consumer financial privacy proposal, so compliance teams should treat those as distinct legislation unless and until enacted.
Sources
- West Virginia Code, Chapter 46A, Article 2A
- West Virginia Code § 46A-2A-101
- West Virginia Code § 46A-2A-102
- West Virginia Code § 46A-2A-103
- West Virginia Code § 46A-2A-104
- West Virginia Legislature bill text, HB 2987 (2025)
- West Virginia Legislature bill text, HB 4868 (2026)
- PrivacyOn, Privacy Laws in West Virginia
Put it into practice
- Generate the policy: Virginia CDPA policy generator (generatepolicy.com)
- Buy the policy pack: State Privacy Law Checklist (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)