How long do I have to notify Hawaii residents after a data breach?
Without unreasonable delay
Do I have to notify the Hawaii Attorney General?
Yes — if more than 1,000 Hawaii residents are affected, written notice to the Office of Consumer Protection
Does Hawaii require notification to nationwide consumer reporting agencies?
Yes — if more than 1,000 residents, notify nationwide CRAs
Is encrypted data exempt from Hawaii's breach notification requirement?
Yes — Hawaii has an encryption safe harbor. Breaches of properly encrypted personal information generally do not trigger notification, provided the encryption key was not also compromised.
Can Hawaii residents sue me directly for a data breach?
Yes — Hawaii allows a private right of action. Affected residents may sue for actual damages and, in some cases, statutory damages or attorneys' fees. Class actions are common.
What counts as 'personal information' under Hawaii law?
First name/initial + last name with SSN, DL/HI ID, account number/credit/debit + access code
What are the penalties for failing to comply with Hawaii's breach notification law?
Up to $2,500 per violation; private right of action for actual damages