What does Georgia's Personal Identity Protection Act require after a breach?

Quick answer: It requires notice to affected Georgia residents in the most expedient time possible and without unreasonable delay once a breach is confirmed (O.C.G.A. Sec. 10-1-910 et seq.). A breach affecting 10,000 or more Georgia residents also requires notice to the Georgia Attorney General.

Georgia's Personal Identity Protection Act (PIPA), codified at O.C.G.A. Sec. 10-1-910 through 10-1-912, requires a business that experiences a data breach to notify affected Georgia residents in the most expedient time possible and without unreasonable delay once the breach is confirmed. A data breach, under the statute, generally means unauthorized access to unencrypted personal information, such as a Social Security number, driver's license number, or financial account number paired with a name.

The statute does not set a fixed number of days for notifying individuals, unlike some other states. Instead it uses the "most expedient time possible" and "without unreasonable delay" standard, which is judged against how long the investigation into the scope of the breach reasonably takes. Notification can be delayed if a law enforcement agency determines that early notice would interfere with a criminal investigation, but the delay lasts only as long as that agency requests.

A second threshold applies to larger breaches. When a breach affects 10,000 or more Georgia residents, the business must also notify the Georgia Attorney General, in addition to notifying the individuals themselves. Smaller breaches, affecting fewer than 10,000 residents, trigger the individual notice duty without the separate Attorney General notice.

For example, a Savannah property management company that stores tenant applications, including Social Security numbers, on an internal server discovers that an employee's login credentials were used to access and download that file. If 200 Georgia tenants are affected, the company must notify those 200 individuals without unreasonable delay, but the Attorney General notice threshold is not triggered. If the same company instead managed a statewide portfolio and the breach touched 15,000 applicants, both the individual notices and the Attorney General notice would apply.

Meeting these notice duties is often expensive: forensic investigation to scope the breach, a mailing or email vendor for notifications, and sometimes credit monitoring offered to affected individuals. Cyber liability insurance is the coverage built to pay for that response. Does Georgia law require my business to carry cyber liability insurance? explains that PIPA creates the notice duty without mandating insurance to fund it. Typical premium ranges are covered in how much cyber liability insurance costs for a Georgia small business, and the Georgia cyber liability insurance page has more on how policies structure breach-response coverage. A coverage review can walk through what a specific business's current policy would and would not pay for under a PIPA-triggered breach.