Wyoming Data Breach Notification Law

· About Wyoming Data Breach Notification Law

Key Takeaways

  • Wyoming’s data breach notification law applies to commercial entities and certain other persons that own or license computerized personal information about Wyoming residents, and it requires notice to affected residents as soon as possible after discovery of a breach involving unencrypted personal information.[9][11]
  • The law’s core standard is “most expedient time possible and without unreasonable delay,” but notice may be delayed only to accommodate a legitimate law-enforcement need or to complete a reasonable investigation into the scope of the incident.[1][9][11]
  • Wyoming expanded the definition of personal information in 2015 to include combinations involving medical information, health insurance information, biometric data, usernames or email addresses with passwords or security questions, and similar credentials, not just Social Security numbers and financial account data.[10]
  • Wyoming generally does not require notice to a state agency under the breach-notification statute, but affected individuals must receive a clear notice with specified content, and larger incidents can trigger broader consumer-reporting-agency notice obligations under the state framework.[11]
  • Wyoming also has a separate records-destruction requirement for personal information, requiring reasonable steps to destroy or modify records so the information becomes unreadable or undecipherable when disposal is undertaken.[4]
  • Penalties are enforced through Wyoming’s broader consumer-protection and injunctive-enforcement mechanisms, and violations can expose entities to civil penalties and court orders even though the breach statute itself is mainly a notice regime.[4]

What It Is

Wyoming’s data breach notification regime is codified in Wyo. Stat. §§ 40-12-501 through 40-12-509 and is commonly referred to as the Wyoming Computer Security Breach law.[9][11] It governs notification when a breach of security involving personal information about a Wyoming resident occurs, and it also sits alongside Wyoming’s record-disposal rules that require secure destruction of personal information in records.[4][9]

The statute was originally enacted before the 2015 amendments that broadened the definition of covered information and notice content, and those amendments are the most important substantive expansion in the law’s modern form.[10] The available current sources reviewed here do not show a 2025 or 2026 enacted amendment to the breach-notification text itself, so the law appears to remain in force without a later delaying act or sunset provision.[1][9][11]

Who Must Comply

The law applies to a commercial entity or other person that conducts business in Wyoming and owns or licenses computerized data containing personal information about Wyoming residents.[9][11] The triggering event is not merely possession of data; it is a breach of the security of the system involving information that is unencrypted or otherwise exposed in a way that creates a notification duty.[11]

The statute has extraterritorial reach in the practical sense that it protects Wyoming residents, so an out-of-state company can be covered if it holds information about Wyoming residents and suffers a qualifying breach.[11] The statute does not require the company to be incorporated in Wyoming; it is enough that the business conducts business in Wyoming and maintains the covered information.[9][11]

Common carveouts and limitations include investigations that conclude misuse of the information has not occurred and is not reasonably likely to occur, as well as statutory exceptions tied to the information type and the circumstances of the acquisition.[11] Separate public-records destruction rules may apply to state records and agency retention schedules, but those are not the same as the commercial breach-notification duties discussed here.[8][14]

Core Requirements

  1. Provide prompt resident notice. Covered entities must notify affected Wyoming residents as soon as possible and without unreasonable delay after determining that a breach involving covered personal information has occurred or is reasonably likely to have occurred.[1][9][11]
  1. Use clear and conspicuous notice content. The notice must be understandable and include core facts such as the types of personal information involved, a general description of the breach, the approximate date if reasonably known, and guidance that helps residents protect themselves.[10][11]
  1. Disclose contact and credit-monitoring information where required. Wyoming notice content includes a toll-free number and information that allows the resident to contact the business and locate major consumer reporting agencies’ contact details.[10][11]
  1. Investigate before concluding that notice is unnecessary. If a reasonable and prompt investigation shows the misuse of the affected information has not occurred and is not likely to occur, the notice obligation may not be triggered.[11]
  1. Delay only for narrow reasons. Notice may be delayed if a law-enforcement agency determines that disclosure would impede a criminal investigation or if the entity needs time to determine the scope of the breach and restore system integrity.[1][11]
  1. Securely destroy records containing personal information. When disposing of records, entities must take reasonable steps to destroy, or arrange for destruction of, the personal information so it is unreadable or undecipherable, typically by shredding, erasing, or equivalent methods.[4]

Deadlines and Penalties

| milestone | date | what applies | |---|---:|---| | Breach notice deadline | ongoing | Notify affected Wyoming residents as soon as possible and without unreasonable delay after the breach determination.[1][11] | | Investigation-based no-notice determination | ongoing | If a prompt and reasonable investigation shows misuse is not likely, notice may not be required.[11] | | Records-destruction duty | ongoing | Destroy or render unreadable personal information when disposing of records.[4] |

Wyoming’s breach-notification law does not read like a modern administrative-fine statute with a single breach-specific penalty schedule; instead, exposure generally comes from enforcement under the state’s consumer-protection and injunctive framework.[4] Reported secondary analyses cite civil penalties up to $5,000 per violation under Wyoming consumer-protection enforcement and the possibility of injunctive relief, but the exact theory and maximum exposure depend on the facts and enforcement route.[4]

Other sanctions can include court-ordered compliance, reputational harm, contractual claims, and downstream regulatory scrutiny if the incident also implicates sectoral laws such as insurance or healthcare rules.[4] Because the statute is centered on notice and record security, the biggest operational risk is usually late notice, incomplete notice content, or failure to maintain defensible disposal practices.[10][11]

How to Comply

  1. Map covered data and systems. Identify where Wyoming residents’ personal information is stored, processed, and backed up, including employee, consumer, and vendor environments. Align the data inventory to ISO 27001 asset management and information classification controls.
  1. Define breach triage and legal review. Build a 24/7 incident pathway that routes suspected breaches to security, privacy, and counsel for a documented determination on scope, affected records, and notice trigger. This maps well to NIST CSF 2.0 Detect and Respond functions.
  1. Pre-draft Wyoming notice templates. Prepare resident-notice language that can be populated quickly with breach facts, toll-free contact details, and self-protection guidance, and keep a law-enforcement delay version ready. Templates should be reviewed against the statute’s required content before use.[10][11]
  1. Implement encryption and key-management discipline. Reduce notification exposure by encrypting personal information at rest and in transit, and by ensuring that compromise of encrypted data does not create a notification event unless the key is also compromised or the facts otherwise satisfy the statute.
  1. Harden records destruction and media sanitization. Use approved shredding, wiping, degaussing, and vendor destruction certificates for paper and digital media, with retention exceptions documented. This is where ISO 27001 and NIST media sanitization guidance are directly relevant, and ISO 42001 can help govern AI systems that ingest personal data by enforcing lifecycle and risk controls.
  1. Test vendor and processor obligations. Make sure contracts require rapid incident reporting, cooperation with notices, evidence preservation, and destruction certification. Wyoming liability can arise from data handled by service providers if the business still owns or licenses the data.
  1. Run tabletop exercises. Practice breach determination, resident notice approval, and decision-making on delays, especially for ransomware and cloud incidents. Tabletop testing should include legal, HR, and communications teams because Wyoming notice content has to be accurate and timely.

Related Regulations

  • Wyoming Insurance Data Security Act overlaps for insurers and insurance licensees, creating a sector-specific cybersecurity program and breach-reporting overlay that can be more demanding than the general statute.[4]
  • FTC Act Section 5 can conflict in practice if a company’s privacy disclosures or security program are deceptive or unreasonable, even where state notice timing is technically met.
  • HIPAA Breach Notification Rule may control if the incident involves protected health information, and those federal deadlines and content rules can be stricter than general state law.
  • GLBA Safeguards Rule can overlap for financial institutions and service providers, especially where the breach stems from weak access controls or poor vendor oversight.
  • Colorado Privacy Act and similar state privacy laws can create parallel obligations on data minimization, vendor governance, and consumer rights, though they are not breach-notice statutes.

FAQ

Does Wyoming’s breach law apply to companies outside Wyoming?

Yes. If a company conducts business in Wyoming and holds computerized personal information about Wyoming residents, the statute can apply even if the company is headquartered elsewhere.[9][11] The key question is whose information was compromised, not where the server or office is located.

What counts as personal information in Wyoming?

Wyoming’s definition is broader than a Social Security number alone. It includes a person’s name plus combinations involving driver’s license or account numbers, passwords or security questions, medical information, health insurance information, biometric data, and other specified identifiers.[10] That means incidents involving login credentials or health-related data can trigger the law even when no financial account data is exposed.

Does Wyoming require notice to the attorney general or another state agency?

The breach-notification statute itself does not generally impose a state-agency notice requirement.[11] The primary duty is notice to affected residents, although other laws or sector rules may create separate reporting obligations in a given incident.

Can notice be delayed for a law-enforcement investigation?

Yes, but only in a narrow way. If a law-enforcement agency determines that immediate notice would impede an investigation, the entity may delay resident notice until the agency says disclosure will no longer compromise the matter.[1][11] The delay should be documented and limited to the investigative need.

Does Wyoming require secure destruction of old records?

Yes. Wyoming requires reasonable steps to destroy personal information in records so it becomes unreadable or undecipherable when the records are disposed of.[4] This duty matters for both paper and electronic media and is separate from the breach-notification rule.

Sources

Put it into practice

More compliance guides