Law / United States / District of Columbia

District of Columbia

United States law applies in District of Columbia District of Columbia is a state of the United States, whose 28 researched instruments are listed on the United States page, not here. The law of District of Columbia, described on this page below, applies here too.

1 of 6 named instruments researched to a stage, across one of the six areas of law we track: 1 in force. As of 6 September 2026.

  1. AI law none researched
  2. Privacy law 1
  3. Scraping law none researched
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law1 instrument, 1 in force

Research summary (132 words)

The District of Columbia has no comprehensive consumer data-protection act of the kind most states have enacted; the federal sectoral posture recorded in the national document applies unmodified.

The District's own contribution is a Consumer Security Breach Notification law that requires prompt notice to affected residents and, above a 50-resident threshold, to the Attorney General, and whose definition of covered personal information expressly reaches biometric identifiers including a voice print.

The Consumer Protection Procedures Act, the basis of the Attorney General's Meta and TikTok suits, carries no independent data-handling duty of its own; it supplies the enforcement mechanism and private right of action for a breach-notice violation, and expressly caps a consumer's private recovery for that one violation type to actual damages rather than the treble-damages-or-statutory-minimum floor it gives every other violation.

Breach notification

Consumer Security Breach Notification

D.C. Code §§ 28-3851 to 28-3853 (Title 28, Chapter 38, Subchapter II)official text, D.C. Law Library (code.dccouncil.gov)

In force since 1 July 2007. Binds private bodies.

What this law does

Any person or entity conducting business in the District that owns or licenses computerized data containing personal information must notify affected District residents in the most expedient time possible after discovering a breach of the security of the system, and must also notify the Office of the Attorney General in writing if the breach affects 50 or more residents.

Personal information covered by the notification duty includes biometric data such as a fingerprint, voice print, genetic print, or retina or iris image used to authenticate identity. A violation of this notification duty is an unfair or deceptive trade practice under the Consumer Protection Procedures Act.

For this specific violation, though, a consumer's private recovery is limited to actual damages rather than the treble-damages-or-$1,500-per-violation floor available for other violations of that Act. The definition of personal information excludes information that is publicly available from government records. The statute was enacted in 2007 and amended in 2020 by the Security Breach Protection Amendment Act.

What it requires

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.