Law note · West Virginia

Breach of Security of Consumer Information

cite W. Va. Code secs. 46A-2A-101 to 46A-2A-105 stage IMMINENT commencement not set reviewed 2026-08-28

An individual or entity that owns or licenses computerized data including personal information must give notice of a breach of the security of the system, without unreasonable delay, to any West Virginia resident whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person, where the breach causes or is reasonably believed to cause identity theft or other fraud.

Personal information is name plus a Social Security number, driver's license or state ID number, or a financial account number with access credential; health information, biometric data, and genetic data are not folded into this definition, unlike South Dakota's narrower biometric fold-in researched alongside this state. An entity required to notify more than 1,000 persons of a breach must also notify nationwide consumer reporting agencies.

A notice violation is deemed an unfair or deceptive act under West Virginia's general Consumer Credit and Protection Act, but the Attorney General has exclusive authority to bring that action (except against a licensed financial institution, enforced instead by its own primary regulator), which closes the private right of action that West Virginia's general unfair-trade-practices statute, W. Va. Code sec. 46A-6-106, would otherwise open for 'any person who purchases or leases goods or services' suffering an ascertainable loss.

This Act's own codified page carries no separate commencement date beyond its 2008 Regular Session enactment (S.B. 340), so no effective_date is recorded here.

What it asks of an app

  • Notify each affected West Virginia resident of a breach of security involving personal information without unreasonable delay.
  • Notify each nationwide consumer reporting agency if you are required to notify more than 1,000 persons of a breach.
  • Do not rely on this statute to cover a breach of biometric, genetic, or health data alone. It does not fold any of those into personal information.
  • Expect this Act's notice duty to be enforced exclusively by the West Virginia Attorney General (or, for a licensed financial institution, its primary regulator), never by a private plaintiff, even though a violation is deemed an unfair trade practice.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach

Primary source: official West Virginia statute text, W. Va. Code secs. 46A-2A-101 to 46A-2A-105, West Virginia Legislature website

← Back to the example  ·  Lint your app →