USPrivacyAtlasState Privacy & Data Security Law Matcher

State Guide

Washington Privacy & Data Security Laws

Every statute below can apply to a business handling Washington residents' data, depending on your revenue, the number of Washington consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Data Security & Breach Notification · 1

Varies by state
Washington data breach notification law
WA Breach Notification

Requires notifying affected residents (and often the state AG/regulator) after a breach of unencrypted personal information such as SSNs, driver's license/state ID numbers, or financial account numbers. Applies regardless of company size whenever you hold covered personal information about a resident of this state.

Wash. Rev. Code § 19.255.010 et seq.Read statute →

Biometric Privacy · 1

Jul 23, 2017
Washington Biometric Privacy Act
WA Biometric Act

Requires notice and consent before enrolling biometric identifiers in a database for a commercial purpose. AG-enforced.

Wash. Rev. Code § 19.375

Consumer Health Data · 1

Mar 31, 2024 (small business provisions Jun 30, 2024)
Washington My Health My Data Act
MHMDA

Broadly defines "consumer health data" (far beyond HIPAA) and requires opt-in consent for collection/sharing and a strict prohibition on sale without authorization. Enforceable via Washington's Consumer Protection Act, which includes a private right of action.

Wash. Rev. Code § 19.373Read statute →