How long do I have to notify Montana residents after a data breach?
Without unreasonable delay
Do I have to notify the Montana Attorney General?
Yes — written notice to the AG simultaneously with consumer notice
Does Montana require notification to nationwide consumer reporting agencies?
Yes — if more than 1,000 residents, notify nationwide CRAs
Is encrypted data exempt from Montana's breach notification requirement?
Yes — Montana has an encryption safe harbor. Breaches of properly encrypted personal information generally do not trigger notification, provided the encryption key was not also compromised.
Can Montana residents sue me directly for a data breach?
Yes — Montana allows a private right of action. Affected residents may sue for actual damages and, in some cases, statutory damages or attorneys' fees. Class actions are common.
What counts as 'personal information' under Montana law?
First name/initial + last name with SSN, DL/state ID, account number/credit/debit + access code, medical info, taxpayer ID
What are the penalties for failing to comply with Montana's breach notification law?
Civil enforcement by AG; private right of action under Montana Consumer Protection Act