

Tennessee’s Data Breach Notification Clock Starts When You Knew.

If your business holds personal information about Tennessee residents and that information is exposed, state law gives you a deadline to tell the people affected. It is 45 days. The part that catches businesses off guard is when the clock starts: not when you finish investigating, and not when you are certain, but when you […]

If your business holds personal information about Tennessee residents and that information is exposed, state law gives you a deadline to tell the people affected. It is 45 days. The part that catches businesses off guard is when the clock starts: not when you finish investigating, and not when you are certain, but when you discover the breach. “We were still looking into it” is not a reason the timeline pauses.

This is one of those compliance obligations that sits quietly until the worst week of your year, when you least want to be reading a statute. A short walk through what the law asks now saves a scramble later. It also pairs with the documentation discipline we cover for regulated clients in compliance and regulatory support.

A quick note: this is general information, not legal advice. Breach response has real legal consequences, and you should confirm specifics with your attorney.

What the Law Actually Requires

Tennessee’s breach notification rule lives in the state code at Tenn. Code 47-18-2107. In plain terms, a business that owns or licenses computerized personal information about a Tennessee resident must notify that resident when unencrypted personal information is acquired by an unauthorized person in a way that compromises its security. Notification must occur immediately and no later than 45 days after discovery of the breach.

“Personal information” here means a resident’s name combined with a sensitive data element, such as a Social Security number, a driver’s license number, or a financial account or card number. The definition is specific, which is exactly why a breach response starts with figuring out what data was actually exposed before you decide what you owe.

The Clock Starts at Discovery, Not at Cleanup

The single most important thing to understand is the trigger. The 45-day window opens when you discover the breach, or when you are notified of it, not when your investigation wraps up. Businesses lose weeks assuming they have until they fully understand what happened. They do not. The investigation and the notification timeline run at the same time.

There is one built-in pause. If a law enforcement agency determines that notifying people would impede a criminal investigation, the notice can be delayed, but only for as long as that determination holds, and then the 45-day requirement resumes. Outside of that, the clock keeps ticking while you work.

Who You Have to Tell

The first duty is to the affected Tennessee residents, in writing or by the methods the statute allows. If the breach affects a large number of people, you may also have to notify the major consumer credit reporting agencies so they can watch for downstream fraud. Businesses that only hold data on behalf of someone else have a duty too, because they must alert the data’s owner so that owner can make the required notifications. If your practice is also covered by HIPAA, a health data breach can trigger both the state rule and federal requirements at once, which is why we treat HIPAA compliance documentation and state breach readiness as one workflow.

Why “We Were Not Sure Yet” Is Not a Defense

Regulators and plaintiffs’ attorneys look at two things after a breach: whether you notified in time, and whether you can show what you did. A business that waited past 45 days because it “wanted to be certain” has a weak position, because the law does not require certainty to start the clock. Worse, a company that cannot produce basic records looks unprepared regardless of intent, unable to say what data it held, who had access, and when it first noticed the problem. The businesses that come through a breach in good shape are the ones that could answer those questions on day one.

What to Have Ready Before You Need It

You do not build a breach response during the breach. The pieces that make the 45 days manageable are boring and cheap to assemble in advance: a current inventory of what personal data you hold and where it lives, an access review so you know who could reach it, an incident response plan that names who declares a breach and who contacts counsel and insurance, and monitoring that tells you a breach happened early rather than late.’

A security assessment produces most of that baseline, and for defense-adjacent and regulated businesses it feeds directly into the broader controls we build in CMMC compliance for Tennessee contractors.

Tennessee law gives you 45 days to notify affected residents after a breach of unencrypted personal information, and the clock starts at discovery, not at the end of your investigation. Tell the affected residents, sometimes the credit bureaus, and, if you hold data for someone else, the owner. Only a law enforcement request can pause the timeline. Prepare the inventory, access review, and response plan now, because you cannot build them during the breach.

Would Your Business Meet the 45-Day Deadline?

If a breach were discovered tomorrow, could you say what data was exposed, who was affected, and when you first knew? We will assess your data inventory, access controls, and incident response plan so the answer is yes before you ever need it.

You can also find us on Google to read what other Nashville businesses say about working with us. 

Check Your Breach Readiness →

Frequently Asked Questions About the Tennessee Data Breach Notification Law

How long does a business have to report a data breach in Tennessee?

Tennessee’s data breach notification law requires notice to affected residents immediately and no later than 45 days from the discovery of the breach. The only standard exception is a documented law enforcement request to delay because notice would impede a criminal investigation, after which the 45-day requirement resumes.

When does the notification clock start under Tennessee law?

It starts when you discover the breach or are notified of it, not when your investigation is complete. This is where many businesses get caught, because they assume the deadline waits for certainty. It does not. Your investigation and your 45-day notification window run at the same time.

Who has to be notified after a breach in Tennessee?

The affected Tennessee residents come first. If a breach affects a large number of people, you may also need to notify the major consumer credit reporting agencies. Businesses that hold data on behalf of another company must notify that owner so it can issue the required notices. Health data may also trigger HIPAA obligations on top of the state rule.