Situation

You live in Arizona, heard about a company's security incident through the news, and want to know how long you might have to wait for an official letter — or whether one is even required.

The 45-day clock, and when it starts

Arizona requires notice to affected individuals within 45 days after a company determines a breach occurred — not 45 days from when the intrusion happened, but from when the determination was made. Investigations can take weeks before a company is confident enough to call something a confirmed breach, so the gap between the incident and your letter can be longer than 45 days even when the company is fully compliant.

If law enforcement asks the company to delay notice because it would compromise an active investigation, the 45-day clock restarts once law enforcement says notice would no longer interfere — which can push a letter out much further than the base deadline suggests.

The unusual exemption: ‘substantial economic loss’

Arizona's law does not require notice if the company determines the breach has not resulted in and is not reasonably likely to result in substantial economic loss to affected individuals. Most states use a broader “risk of harm” or “material risk” standard; Arizona's is narrower and specifically tied to economic loss.

That means an incident a company judges to carry only a low financial-loss risk — for example, exposure limited to a username without a password, or data the company believes was not actually viewed — can legally end without any letter to you at all, even if you would still consider your privacy affected.

When the state and credit bureaus get told

If a breach affects more than 1,000 Arizona residents, the company must also notify the three largest nationwide consumer reporting agencies and the Arizona Attorney General's Office. A letter that mentions bureau notification is telling you the incident crossed that 1,000-resident threshold.

What counts as protected information in Arizona

Arizona's definition is broader than many older state laws. Alongside your name paired with a Social Security number, driver license or state ID number, or financial account or card number with an access code, it also covers a taxpayer identification number, medical or mental health treatment information, health insurance identification, and biometric data such as a fingerprint, retina, or iris scan, or DNA profile. It also covers a username or email address paired with a password or security question and answer that would let someone into an online account.

If your Arizona breach letter mentions medical information or biometric data, that reflects this broader list — not every state's breach law would have required disclosure for the same underlying exposure.

Respond before the 45 days are up, not after

The 45-day figure is a legal deadline for the company, not a suggested waiting period for you. Once you know your data was involved — by letter, or through your own suspicion after a public disclosure — secure the affected account's password, review recent statements, and freeze your credit at all three nationwide bureaus if a Social Security number, driver license number, or financial account number is involved.

If you never got a letter but think you should have

Contact the company through a verified channel and ask two direct questions: was your information part of the breach, and did the company determine there was no substantial risk of economic loss. You are entitled to ask, even though the law does not require the company to send you its internal risk analysis.

You can still freeze your credit and pull your own reports regardless of the answer — Arizona's economic-loss exemption affects the company's notice obligation, not your right to protect your own file.

A retailer decides notice isn't required

A subscription service you use in Arizona posts a public notice that it found unauthorized access to a server holding email addresses and account usernames, with no passwords or payment data involved. You never receive a personal letter.

Under Arizona's economic-loss standard, that combination — email and username only, no password or financial number — is the kind of exposure a company can reasonably argue does not create substantial economic loss, so no individual notice may be legally required. You can still change that account's password as a precaution and watch for a rise in phishing email that references the service by name, since that is the practical risk from this kind of exposure even without a financial loss angle.

How Arizona compares to states without an economic-loss carve-out

Most states use a broader “risk of harm” or “material risk of fraud” test for deciding whether a letter is required, which can cover privacy or identity-related harm beyond a strictly financial one. Arizona's focus on “substantial economic loss” specifically is narrower, and it's worth knowing that if you're used to a different state's broader standard from a past breach and are now comparing it to an Arizona notice — the two states can reach different conclusions about the exact same type of exposure.

This matters most for exposures that are more about privacy than money — an email address paired with browsing history, for example — where a company could reasonably argue Arizona's economic-loss bar isn't met, while a state with a broader harm standard might still require notice for the same incident.

Frequently asked questions about Arizona breach notices

  • Who enforces Arizona's breach law? The Arizona Attorney General's Office can bring an enforcement action against a company for violating the notification law, and civil penalties can apply for knowing and willful violations.
  • Does Arizona require the company to offer credit monitoring? No — Arizona's statute sets notification requirements, not a mandated remedy; any monitoring offer is a business decision, not a legal requirement tied to this specific law.
  • What if I'm not sure whether I'm one of the affected 1,000+ residents? You can still ask the company directly whether Arizona's bureau and Attorney General notification threshold was triggered for the incident — that's a factual question about the breach's scope, separate from whether you personally received a letter.
  • Does the 45-day deadline reset if the breach turns out to be bigger than first thought? The deadline runs from the determination date for the incident as understood at the time; a materially expanded understanding of scope can affect when a company reasonably “determines” further breach details, which is part of why determination dates in these cases aren't always as clean as they sound.

Keep the determination date, if the company gives you one

If a letter does arrive, note the date it says the company determined a breach occurred — that is the date the 45-day clock ran from, not the date of the intrusion itself, and it is the number worth keeping if you ever need to raise a timing concern with the Arizona Attorney General's Office.

Primary sources used

Check the official source before you submit sensitive information.