A data breach is unauthorized access to or acquisition of information an organization is responsible for protecting. For employers the category that matters most is workforce data — identifiers, banking details, medical information, dependents — and the obligations that follow are the same whether the exposure happened in the employer's own systems or at a vendor holding the data on their behalf.
The word carries a specific legal weight. A security incident becomes a breach when it meets the definition in the applicable statute, and that determination drives everything that follows.
Not every security problem is a breach. A blocked phishing attempt, malware caught before execution, or a failed login attempt are incidents. A breach generally requires unauthorized access to or acquisition of specified categories of personal information.
The distinction matters because breaches carry notification duties on statutory clocks, and incidents do not. It also matters because the determination is a legal judgment rather than a technical one, and employers are better served making it with counsel than assuming either way.
Encryption is usually the pivot. Most statutes are triggered by exposure of unencrypted personal information, so properly encrypted data that is stolen frequently does not trigger notification at all.
The dramatic version is rare. The common ones are mundane:
Two of those — misdirected email and lost devices — involve no attacker at all, which is worth remembering when designing controls.
What an organization does early determines how the rest goes.
Contain first: revoke sessions, reset credentials, isolate affected systems. Then preserve evidence rather than wiping and rebuilding, because the forensic question of what was accessed depends on logs that a hasty cleanup can destroy.
Engage counsel early. Beyond the multi-state notification analysis, the assessment work benefits from privilege considerations that are difficult to establish retroactively.
Then determine scope: what data, whose data, whether it was encrypted, and which jurisdictions are implicated. This is where preparation shows — an employer with a current data inventory answers in hours, one without spends days establishing basic facts while the notification clock runs.
Obligations follow the affected individual's residence, not the employer's location. An employer with staff in twelve states faces twelve sets of requirements differing in covered data, timing, notice content, and whether regulators or credit bureaus must be told.
California imposes its own content and formatting requirements and submission to the attorney general above a threshold. Employers with California employees should treat those as a baseline.
The clock generally starts at discovery, not resolution — which is why the scope determination is urgent rather than something to work through after the technical response finishes.
Employees did not choose to hand over their Social Security number; employment required it. They cannot take their business elsewhere. And they remain in the building afterward.
That changes the communication requirement. A notice written purely to satisfy a statute preserves far less trust than one that is clear about what happened, what data was involved, what the employer is doing, and what the employee should do. Employers that under-invest here frequently find the internal damage outlasts the legal exposure.
Credit monitoring is customary where identifiers were exposed, and a channel for employee questions should exist before notices go out rather than being improvised afterward.
Employer's Guardian helps employers prepare for these obligations alongside their broader state requirements through California HR compliance.
This article provides general educational information, not legal advice. Breach obligations are jurisdiction-specific and time-sensitive. Engage qualified counsel immediately if you suspect a breach.