It’s a Monday. The office administrator can’t get into her email, and when she finally does, the sent folder contains forty messages she didn’t write.
Or: the laptop was in the back of the car outside the hospital, and now it isn’t.
Or: someone calls to say the church’s membership spreadsheet is on a website they’ve never heard of.
Whatever the route, you now stand in a specific place, and the question in the room is not technical. It is: do we have to tell people?
The honest answer is: probably, sometimes, and it depends on facts you don’t have yet. Which is deeply unsatisfying — so this post explains the general shape of how these laws work, so you can recognize the situation and act fast enough to handle it properly.
Everything below is a description of how these rules generally work. It is not legal advice. Requirements vary substantially by state, and you need a lawyer — early.
These laws are not just for corporations
Start here, because this is the assumption that gets churches into trouble.
The National Conference of State Legislatures summarizes the landscape plainly: “All 50 states, the District of Columbia, Guam, Puerto Rico and the Virgin Islands have laws requiring private businesses, and in most states, governmental entities as well, to notify individuals of security breaches of information involving personally identifiable information.”
Nonprofit status is not, by itself, an exemption. These statutes are generally drafted around whoever holds the data rather than around a particular tax classification. Whether a specific state’s law reaches your specific organization is a question with a real answer, and only a lawyer licensed in that state can give it to you. But do not walk into it assuming your 501(c)(3) letter is a shield. It isn’t designed to be one.
What actually triggers a notice
Here is the most useful thing in this article, and the part most people have backwards.
Not every exposure of personal information triggers a notification duty. These laws generally attach to specific, defined categories of data — and a name plus an email address, on its own, very often isn’t one of them.
NCSL describes the common structure: these laws typically contain “definitions of ‘personal information’ (e.g., name combined with SSN, drivers license or state ID, account numbers, etc.); what constitutes a breach (e.g., unauthorized acquisition of data); requirements for notice (e.g., timing or method of notice, who must be notified); and exemptions (e.g., for encrypted information).”
In practice, the categories that most commonly appear across state definitions are a person’s name combined with one or more of:
- Social Security number
- Driver’s license or state identification number
- A financial account, credit card, or debit card number, usually together with whatever code would let someone use it
- In a growing number of states, medical or health insurance information, biometric data such as a fingerprint, or the username and password to an online account
Look at that list against what your church actually holds. Your membership directory of names, addresses, and emails is sensitive and worth protecting — but its exposure may not trigger a statutory notice. Your payroll file, your background-check drawer, and your donation records with bank account details almost certainly could.
That distinction is not a reason to relax. It’s a reason to know precisely where your organization keeps the high-consequence categories, before anything goes wrong.
The obligation usually follows the person, not the church
This surprises people, and it matters for churches more than for most small organizations.
These laws are generally written to protect residents of that state. So the question is usually not “which state is the church in?” but “where do the affected people live?”
A congregation with members who retired to Florida, a college student in another state, and a missionary family supported from a third has, potentially, three sets of rules to satisfy from a single incident. The deadlines may differ. The required content of the letter may differ. Whether a state official has to be told may differ.
You do not need to memorize any of that. You need to know two things: that the number of applicable laws is driven by your people’s addresses, and that your lawyer will need that address list early. Which is a quiet argument for keeping your member records accurate and for not keeping records of people who left twenty years ago.
What the notices generally have in common
Details vary by state — always — but the family resemblance is strong.
A deadline measured in days from discovery. Some states set a specific number of days; others use a reasonableness standard along the lines of the most expedient time possible and without unreasonable delay. These deadlines are not stable, either — California, which used the reasonableness language for more than twenty years, moved to a fixed 30-calendar-day notification deadline effective 1 January 2026, with notice to the Attorney General due within 15 calendar days after individuals are notified. Either way the clock starts near the beginning of the incident, usually well before you understand what happened. This is the single biggest reason to call counsel on day one rather than day ten, and to ask them what the current deadline is in each state where your people live rather than relying on anything you read a year ago.
Required content in the notice. States commonly specify what the letter has to say: what happened, what categories of information were involved, what the organization is doing about it, what the individual can do, and who to contact with questions. Some prescribe the format and the delivery method. This is not a letter to draft yourself from a template you found online.
Notice to a state official. Several states require that the attorney general or a similar office be told, often once the number of affected residents crosses a threshold. California, for example, requires a sample copy of the notice to be submitted to the Attorney General by any organization “required to issue a security breach notification to more than 500 California residents as a result of a single breach of the security system” (Cal. Civ. Code §§ 1798.29(e), 1798.82(f)). Other states set different thresholds, and some set none.
Notice to the credit bureaus. Some states require the nationwide consumer reporting agencies to be notified once the affected population passes a threshold that state sets. Separately, the FTC’s breach response guidance for businesses says that “if Social Security numbers have been stolen, contact the major credit bureaus for additional information or advice,” regardless of whether a statute compels it.
And an encryption exemption that is worth real money. This is the most actionable point in the whole area of law. Many state statutes are written around unencrypted personal information. California’s, for example, requires disclosure to a resident “whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person” — and also where encrypted information was acquired along with the encryption key or security credential (Cal. Civ. Code §§ 1798.29(a), 1798.82(a)). So encryption is not a blanket exemption anywhere, and the details differ by state. Ask your lawyer how it works in the states that apply to you.
Encryption means the data is stored scrambled, readable only with a key. Turning on full-disk encryption on your laptops is free — it’s built into Windows and macOS — and it takes about ten minutes per machine. It will not stop a phished mailbox. But a laptop stolen from a car is one of the most common ways a small organization loses data, and encryption can be the difference between a stolen laptop and a notifiable breach. That is an extraordinary return on ten minutes, and it is a genuine, concrete reason to do it this month rather than someday.
The first days: what to do so that you can comply
Whether you’ll owe notice is a question for later. What you do in the first hours decides whether you’ll be able to answer it.
Preserve everything. Do not clean up. The instinct — reset the machine, delete the bad messages, wipe it and start fresh — destroys the only record of what happened. The FTC’s guidance for businesses is direct: “Do not destroy any forensic evidence in the course of your investigation and remediation,” and “don’t turn any machines off until the forensic experts arrive.” Disconnect an affected computer from the network by unplugging the cable or switching off Wi-Fi, but leave it running and leave it alone.
Stop the bleeding without destroying the evidence. Change passwords from a different device, sign out all active sessions, and turn on multi-factor authentication if it wasn’t already on. Preserving evidence does not mean leaving the door open.
Write down the timeline as it happens. A plain notebook or a single document. When you first noticed something. Who reported it. What time. What you did and when. Who you called. Your lawyer will need this, your insurer will need this, and memory reconstructed three weeks later is not good enough. Start it in the first ten minutes.
Call your lawyer before you call anyone else you’re tempted to call. Not because you’ve done something wrong, but because the deadline has probably already begun, and because counsel can often direct the investigation in a way that protects the organization. Ask specifically about a legal hold — an instruction to stop any routine deletion of records that might be relevant.
Call your insurer the same day. Read this twice: many policies impose their own notice deadlines that are shorter than the law’s, and some require you to use their approved forensic and legal panel. Calling them late, or hiring your own investigator first, can jeopardize coverage on a policy you’ve been paying for. If you have cyber liability coverage, the hotline number is the most valuable thing in the policy.
Report it. If money moved or fraud was attempted, report to the FBI at ic3.gov immediately. The Bureau’s Recovery Asset Team froze $507,042,623 across 3,574 domestic cases in 2025, and that process works far better inside the first 24 to 72 hours. Point affected individuals to identitytheft.gov, which walks them through recovery steps at no cost.
Say less publicly, sooner privately. Do not speculate from the pulpit about what happened. Do tell your board chair and your leadership immediately.
Notifying well is a trust-building act
There’s a fear underneath all of this: that telling the congregation will destroy confidence in the church’s leadership.
The pattern runs the other way.
Congregations are generally forgiving about incidents. People understand that criminals exist, that a determined attack can succeed against anyone, and that ministry staff are not security professionals. What congregations do not forgive is finding out later that leadership knew and said nothing. The first is a misfortune. The second is a character question, and it is the one that ends tenures.
A good notification is short and specific: here’s what happened, here’s what information was involved, here’s what we’ve done, here’s what we recommend you do, here’s who to call with questions, and here’s the change we’re making so it doesn’t happen again. No hedging, no passive voice, no “an incident may have occurred.” Take responsibility for the response even where you couldn’t have prevented the event.
Handled that way, a breach notification is one of the clearer demonstrations a church can give that it treats people’s information as a trust rather than an asset. That’s not spin. It’s just what integrity looks like on a bad week.
What to do this week
Turn on full-disk encryption on every laptop your organization owns — BitLocker or device encryption on Windows, FileVault on Mac. Ten minutes a machine, no cost, and in many states it changes the legal character of a stolen laptop.
Then write two phone numbers on the same card and put it where your leadership can find it: your attorney, and your insurance carrier’s claims line. Add whether you have cyber liability coverage at all — if nobody in the room knows, that’s this week’s second task, and it’s a five-minute email to your broker.
Preparing before anything happens is far cheaper than improvising afterwards. MissionDefend’s free assessment asks straightforward questions about how your organization handles email, donations, member data, and accounts, then returns a baseline score and a ranked list of what to fix first — including whether you’d be able to answer the questions above on the worst morning of the year.
No spam and no sales calls — just one email when it’s live.
Related reading
- the pastoral message that goes out inside a day
- the carrier deadline nobody reads until it matters
- the one-page plan that makes compliance possible
MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.
Sources: National Conference of State Legislatures, Security Breach Notification Laws; California Office of the Attorney General, Reporting a Data Breach; California Legislature, SB 446, Data breaches: customer notification; Federal Trade Commission, Data Breach Response: A Guide for Business; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.


