The compliance conversation almost always skips this one
Ask most small WordPress site owners about compliance and you'll hear GDPR, maybe CCPA if they're in California or sell to Californians, maybe HIPAA if they're in healthcare. What almost nobody mentions: every US state, plus DC and the major territories, has enacted its own security-breach-notification law. These aren't niche or rarely-enforced — they're the actual legal mechanism that requires you to tell people when their data has been exposed, and they apply far more broadly than CCPA does.
Why this is different from CCPA
CCPA is California-specific and comes with real thresholds: it generally only applies to for-profit businesses that clear roughly $25 million in annual revenue, hold personal data on 100,000+ California residents or households, or derive at least half their revenue from selling personal data. A lot of small stores and sites genuinely fall outside that.
General state breach-notification laws work differently. California's own breach-notification statute, for example, applies to any person or business that owns, licenses, or maintains computerized personal information about a California resident — with no revenue threshold and no minimum record count. A five-person store that exposes 40 customers' card details is covered exactly as fully as a national retailer. Most other states' breach laws follow the same basic shape: they're triggered by the breach itself, not by how big you are.
What actually triggers a notification obligation
Definitions vary by state, but there's a common core. Most breach laws are triggered by unauthorized acquisition of a person's name combined with one or more of a specific list of sensitive data elements — typically a Social Security number, a driver's license or state ID number, or a financial account/credit/debit card number paired with the code or password needed to access it. A growing number of states have expanded that list in recent years to also cover things like biometric data, health information, or an email address paired with its password.
The important word is "combined." Exposing a list of names and email addresses alone typically doesn't trigger these laws in most states. Exposing that same list with Social Security numbers, or a database of stored payment details, very likely does — and exactly which data elements count, and under exactly what conditions, is defined state by state, not nationally.
Why this matters for a WordPress site specifically
This is where it stops being abstract. A compromised WordPress or WooCommerce site that exposes a customer database with billing details, a contact form that collected something sensitive, or an admin export containing Social Security numbers or full payment-card data isn't just a security incident — it's very possibly a legal notification trigger, regardless of whether the business ever thought of itself as handling "regulated" data. "That's an enterprise problem" is exactly the assumption that general state breach laws are built to not care about.
What states typically require once triggered
Requirements vary meaningfully, but the shape repeats: notify the affected individuals, and in many states, notify a state authority as well. Roughly 20 states specify a numeric notification deadline, generally somewhere between 30 and 60 days from discovery; the rest use qualitative language like "without unreasonable delay" instead of a hard number. Separately, around 21 states also require notifying a state agency or attorney general in some or all breach scenarios, on top of notifying the individuals themselves. There is no single national timeline or single national threshold — this is exactly the kind of detail that has to be checked against the specific state in question, not assumed from a general rule of thumb.
The multi-state problem
Here's the part that catches people off guard: if your customers or users span multiple states — which is normal for almost any online store or SaaS-style WordPress site — a single breach can trigger notification obligations under several different state laws simultaneously, each with its own definition of "personal information," its own timeline, and its own notification recipients. A breach doesn't get to pick one state's rules; you have to check every state where an affected person actually lives.
What to actually do about this
- Don't wait for a breach to learn this. Know roughly what categories of sensitive data your site actually collects and stores today — that's the fastest way to estimate your real exposure before anything happens.
- If a breach happens, get legal counsel involved immediately — before drafting any notification, not after. An attorney familiar with breach response can quickly map which states' laws apply based on where your affected users are.
- Treat "which states are my users in" as a real operational question, not an afterthought — it directly determines your notification obligations if something goes wrong.
- Reducing what you store reduces what you have to worry about. A site that never stores Social Security numbers or raw payment details in the first place has a meaningfully smaller breach-notification problem, even before anything happens.
Where this fits with the rest of your compliance picture
State breach-notification laws sit alongside, not instead of, the other compliance areas already covered on this site: GDPR's 72-hour breach rule if you have EU users, CCPA if you're a larger California-facing business, and HIPAA if you handle patient health information. State breach-notification law is the one that applies most broadly of the four, precisely because it isn't gated by revenue, industry, or geography beyond "do you hold data on someone who lives in this state." A general WordPress security plugin can help reduce the odds of a breach happening in the first place — monitoring, hardening, and patching all matter here — but it can't tell you which state notification laws apply once one does. That's a legal question, and it deserves a legal answer.
Whatever your compliance status, know what's actually happening on your site first.
Install free →