‘Close Enough’ Data Breach Notifications Create Exposure
Posted in Data Breaches
One ruling is not a trend. And there can be unique factors at play in regulatory investigations related to large incidents. But a summary judgment ruling in favor of a state in a lawsuit against a telecom shows how not achieving technical compliance with state data breach notification laws in a large incident is a billion-dollar area of risk.
T-Mobile disclosed a security incident in August 2021 that involved 76 million records (approximately 47 million had SSNs). The notification requirement of Washington’s data breach notice law is similar to most states – if there is a notice obligation, the notice has to be provided by sending a letter by regular mail, an email if there is E-Sign consent, or substitute notice (and substitute notice requires a press release, a posting on the company’s website and an email if the company has an email address for the individuals to be notified). Washington’s notification law, like many other states, also has content requirements (e.g., the notice has to include the name of and contact information for the company, the data elements involved and the date of the breach). Washington’s law also provides that if a company has an internal notice procedure and issues notice that meets Washington’s notification time requirement, the company complies with Washington law by following its policy. T-Mobile sent a text message as its method of notice to 361,030 Washington residents.
The Washington Attorney General filed a lawsuit against T-Mobile in January 2025 alleging that T-Mobile committed violations of Washington’s consumer protection law by not providing notice in compliance with the requirements of Washington’s data breach notice law. A Washington state court issued a decision in July 2026 granting summary judgment in favor of Washington. The court determined that T-Mobile’s text message resulted in two separate violations of Washington’s law for each of the 361,030 residents: (1) the method of notice did not meet the substitute notice requirements and (2) the words in the text message did not meet the content requirements. Washington law permits the recovery of a civil penalty of not more than $7,500 for each violation. Using a penalty of just $100 per violation for the 722,060 violations, T-Mobile would face a civil penalty of $72 million (an amount per violation at the top end would impose billions in civil penalties).
T-Mobile filed a motion in August 2026 seeking reconsideration of the summary judgment ruling. The motion argued that the court should not have granted summary judgment without (1) evaluating whether T-Mobile substantially complied with Washington’s notice law because the text message contained a link to a post on T-Mobile’s website that contained all required content and (2) addressing whether T-Mobile complied with Washington law by following T-Mobile’s notice procedure. T-Mobile also attacked the double-counting of violations, asserting that the order imposes more liability on T-Mobile for how it provided notice than if T-Mobile had not provided any notice. Presumably, if T-Mobile had not provided any notice, Washington could argue that there were at least four separate violations: (1) not providing timely notice, (2) not providing notice by the required method, (3) not providing the required content in the notice and (4) not notifying the Washington Attorney General.
Companies addressing significant security incidents face a lot of challenges and risks. Individuals who are notified can bring lawsuits. Regulators can investigate to determine if the company had a reasonable security program. Providing notice in a manner that leaves the door open for a regulator to allege that there were areas of noncompliance with notice requirements (e.g., timing, method, content) adds an extra layer of risk and often sends an invitation for further inquiry where it otherwise would not exist (especially at a time when state attorneys general collaboration is high).
