Privacy Law Library

State Agency Protection of Personal Information and Breach Notification

MT State Agency Breach Law

Government records · Breach notification · Data security

Montana state agencies must protect personal information and notify affected people of data breaches without unreasonable delay. Contractors that hold agency data must notify the agency immediately, notify affected individuals, keep a security policy, and file notice copies with the state CISO and the Attorney General.

Where
Montana
Citation
Mont. Code Ann. 2-6-1501 to 2-6-1504
Status
In force
In force since
2015-10-01
Last amended
2025-10-01
Enforced by
Montana Department of Administration (chief information security officer); Attorney General receives notice copies
People can sue
No
Penalties
No specific penalty stated; an agency that notifies after a contractor fails to may recover its reasonable notice costs from the contractor (2-6-1503(2)(b)).
Applies to
  • Montana state agencies in the legislative and executive branches (2-6-1501(8))
  • Private third parties that receive personal information from a state agency and maintain it in a computerized system to perform a state agency function (2-6-1503(2), (4))

Security duties

  • Agencies and third-party recipients must maintain an information security policy and breach notification procedures.Mont. Code Ann. 2-6-1503(4)

Breach duties

  • Third parties holding agency data must notify the agency immediately after discovering a breach and make reasonable efforts to notify affected individuals in the same manner as agencies.Mont. Code Ann. 2-6-1503(2)(a) · Only if: Third party maintains personal information received from a state agency
  • Agencies must notify affected persons without unreasonable delay (law enforcement delay permitted).Mont. Code Ann. 2-6-1503(1), (3)
  • Simultaneously send an electronic copy of each individual notice, with date and method of distribution, to the state chief information security officer and the AG's consumer protection office.Mont. Code Ann. 2-6-1503(5)
  • Agencies must immediately report any security incident to the state chief information security officer.Mont. Code Ann. 2-6-1504

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Effective dates inferred from history notes (En. Ch. 348, L. 2015; amd. Ch. 227, L. 2023 and Ch. 395, L. 2025) and the default October 1 rule. Content of the 2025 definitional amendment (Ch. 395) not reviewed.

Research reference, not legal advice.