Law / United States / District of Columbia
Consumer Security Breach Notification
D.C. Code §§ 28-3851 to 28-3853 (Title 28, Chapter 38, Subchapter II)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 July 2007.
A breach notification rule binding private bodies.
As of 6 September 2026.
What it requires
- If your business conducts business in the District of Columbia and discovers a breach of the security of a system containing a District resident's personal information, notify each affected resident in the most expedient time possible and without unreasonable delay.
- Personal information covered by this duty includes biometric data generated by automatic measurements of biological characteristics, such as a fingerprint, voice print, genetic print, or retina or iris image, when used to authenticate identity.
- If the breach affects 50 or more District residents, also give written notice to the Office of the Attorney General for the District of Columbia, no later than when you notify residents.
- Notifying more than 1,000 people also requires notifying the nationwide consumer reporting agencies of the timing, distribution, and content of the notices.
- A violation of this notification duty is enforced as an unfair or deceptive trade practice and can be brought by a consumer, but recovery for this specific violation is limited to actual damages rather than the treble-damages-or-$1,500-per-violation floor available for other consumer protection violations.
- Information that is lawfully made available to the general public from government records is not personal information for purposes of this duty.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Who enforces it
Enforcement body
Office of the Attorney General for the District of Columbia
What it reaches
Obligation class
Breach notice, Biometric
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Any person or entity conducting business in the District that owns or licenses computerized data containing personal information must notify affected District residents in the most expedient time possible after discovering a breach of the security of the system, and must also notify the Office of the Attorney General in writing if the breach affects 50 or more residents.
Personal information covered by the notification duty includes biometric data such as a fingerprint, voice print, genetic print, or retina or iris image used to authenticate identity. A violation of this notification duty is an unfair or deceptive trade practice under the Consumer Protection Procedures Act.
For this specific violation, though, a consumer's private recovery is limited to actual damages rather than the treble-damages-or-$1,500-per-violation floor available for other violations of that Act. The definition of personal information excludes information that is publicly available from government records. The statute was enacted in 2007 and amended in 2020 by the Security Breach Protection Amendment Act.
When LexLint raises it
processes_biometricsprocesses_voice