Data Breach Notification Laws: How to Manufacture a Confident Response

November 15, 2021
Keyboard with the words

Credit: iStock/GOCMEN

With the number of reported data breaches steadily increasing every year, they are in the news so frequently that it’s hard to keep them all straight. In 2017, Equifax suffered a massive breach, and almost 150 million customer records (representing nearly half the U.S. population) were stolen. In 2018, Marriott International experienced a breach where hundreds of millions of customer records – including personal information, credit card numbers and even passport numbers – were compromised.

Data breaches affect all types of organizations – large and small, popular and little known. While the big company breaches make the news, you rarely hear about smaller companies that are often vulnerable and can find themselves in the crosshairs of cybercriminals. Most involve some type of hacking, such as a phishing attacks or malware, where an attacker successfully gains access to protected or private information.

Data Breach Notification Laws – It’s Complicated


If your manufacturing company experiences a breach, what will you do? Should you notify law enforcement right away? Notify customers? Is there anyone else to inform? How long do you have?

The answers are complicated. While no comprehensive federal laws exist, each state and territory has its own data breach notification law. These laws require anyone that suffers, or even suspects, a breach to notify customers of anything involving personally identifiable information. The laws also require notifying law enforcement and taking specific steps to remedy the situation. But state laws vary considerably when it comes to the types of information covered, timing of notifications and reporting standards. Who must comply and what even constitutes personal data varies state to state. Adding to the complexity, requirements are also changing, with some states recently updating their laws.

How Much Time Do I Have to Report a Data Breach?


Most data notification laws require that businesses notify customers without unreasonable delay. The length of time varies by state and industry sector. When dealing with a data breach, manufacturers have competing responsibilities – to their company, to others in the industry, to customers and to law enforcement. There are even circumstances where law enforcement is investigating a breach and it must be temporarily concealed.

Prepare for Data Breaches Before They Happen


Treat data breach notification plans as you would any other disaster plan – don’t wait! Since there is no single, standard response to a data breach, U.S. manufacturers must understand the specific state and federal laws that apply to them. Manufacturers must consider the laws in all states where they conduct business.

Luckily, there are several excellent resources manufacturers can turn to for some clarity. Several organizations summarize state data breach laws, including National Conference of State LegislaturesIT Governance and Perkins Coie.

To ensure that your manufacturing company complies with data protection laws, you should stay aware of current regulations for your state and industry. A data breach will always be a stressful event. Awareness of your obligations and a plan in place can ease some of the stress – and help you avoid heavy fines. Here are some tips:

  • Identify the state and industry laws that cover your company
  • Document the data breach notification requirements that affect your company, along with the process(es) to meet those requirements in a worst-case scenario
  • Create a policy around the breach notification requirements that affect your company
  • If there are overlapping regulations, use the most stringent one for your company’s policy
  • Create draft notification letters and emails ahead of time
  • Create a clear communication strategy for data breaches and get it through your company’s legal and public relations departments ahead of time, if necessary

The MEP National Network is Ready to Help You


(Contact CONNSTEP) for help understanding your state’s data breach notification laws and other cybersecurity questions.

 

This article originally appeared on NIST’s Manufacturing Innovation blog and is reprinted with permission.

Recent Posts

April 29, 2026
Phoenix Manufacturing, Inc., founded in 1989, is a privately held family-operated small business in Enfield, Connecticut, specializing in precision machining for the aerospace industry. What began as a two-person operation in a 2,000-square-foot building has grown into a company with over 100 employees operating out of a 114,000-square-foot, state-of-the-art manufacturing facility. As a contract manufacturer, Phoenix specializes in complex, tight-tolerance components, supported by more than 40 CNC machines and a multi-axis mill/turn line. The company provides end-to-end manufacturing solutions—from engineering consultation through full-scale production—serving commercial aviation, spaceflight, and defense markets for both domestic and global customers, including leading aerospace and defense OEMs. A defining element of Phoenix’s growth has been its strategic investment in advanced manufacturing technology, particularly palletized machining centers. Since 2017, the company has added 11 machining centers integrated with palletized systems, enabling unattended, automated production and significantly expanding machining capacity. This automation journey has positioned Phoenix to better meet increasing customer demand while maximizing machine utilization. Phoenix’s commitment to quality is central to its operations and customer relationships. Managing more than 600 active part numbers, the company strives for 0 parts per million (PPM) defects and 99% on-time delivery (OTD) for major OEM customers. Its quality management system is certified to ISO 9001 and AS9100 Rev D standards, and Phoenix also holds NADCAP certifications in Nonconventional Machining and Nondestructive Testing, reflecting a rigorous, inspection-driven approach to delivering consistent, high-quality results.  Guided by a mission to deliver high-quality, cost-effective products through advanced technology and an uncompromising commitment to quality, Phoenix continues to invest in innovation, automation, and the next generation of manufacturing leadership.
April 28, 2026
Founded in 1959, Projects Inc. is a Glastonbury, Connecticut-based manufacturer specializing in precision-machined components for aerospace, industrial, and commercial applications. With 102 employees, the company operates out of 66,000 square feet of manufacturing and office space and supports customers across a range of industries, including aerospace and power generation. Projects Inc. has deep roots in the aerospace industry, where it has provided high-quality machining services for decades. Since 1996, the company has supplied FAA Parts Manufacturer Approval (PMA) components to the aviation sector. Projects Inc. received FAA Repair Station Certification in 1984. As a maintenance, repair, and overhaul (MRO) provider, Projects supports customers with repair solutions that help keep critical aerospace equipment operating safely and efficiently. Its customer base includes major aerospace companies such as Sikorsky, Pratt & Whitney, and GE Aerospace, along with airlines including United, Delta, American, and Lufthansa. Projects Inc. is Federal Aviation Administration (FAA), European Union Aviation Safety Agency (EASA), and UK Civil Aviation Authority (CAA) – approved. The company is also AS9100D and ISO 9001: 2015-certified, reflecting its commitment to quality, consistency, and industry standards. With capabilities that include prototyping, CNC machining, EDM, laser cutting, and grinding, Projects Inc. offers a broad range of precision manufacturing services supported by advanced in-house equipment and technical expertise. Today, Projects Inc. is recognized as an experienced supplier of high-quality components, with a long-standing focus on quality, reliability, and customer service.
Penn Globe logo over a room with people, possibly a conference.
February 11, 2026
Learn how Penn Globe partnered with CONNSTEP to invest in employee training, strengthen skills, and support business growth and competitiveness.
Logo of Specialty Cable Corporation (SCC) in a warehouse setting.
February 10, 2026
See how Specialty Cable Manufacturers partnered with CONNSTEP to strengthen quality systems and successfully achieve AS9100 recertification.
People in a factory setting, with the Forum Contract Manufacturing logo in the foreground.
February 9, 2026
Learn how Forum Plastics partnered with CONNSTEP to invest in supervisory training, strengthen leadership skills, and support long-term growth.
Logo of the letter
February 8, 2026
See how a Connecticut printing company partnered with CONNSTEP to improve efficiency, reduce waste, and advance environmental sustainability.
Beekley Medical logo with text
February 7, 2026
Learn how a medical products manufacturer partnered with CONNSTEP to strengthen quality systems and achieve successful recertification.
Pursuit Aerospace logo over a blurred medical equipment background. The logo is white text on a black rectangular box.
February 6, 2026
See how an aerospace manufacturer partnered with CONNSTEP to conduct an internal quality audit and get back on track to compliance.
Woman in lab setting, logo overlay of Syn-Mar Products Inc., blue and white color scheme.
February 5, 2026
Learn how a home bathroom remodeling manufacturer partnered with CONNSTEP to use lean training to streamline operations and improve efficiency.
Logo for Wild CNC Machining Services on a blue background.
February 4, 2026
See how a manufacturer partnered with CONNSTEP to update HR policies, strengthen people practices, and support future business growth.
Show More