Law / United States / Idaho

Identity Theft Act, breach of security disclosure duty

Idaho Code § 28-51-105

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

Commencement not set.

A breach notification rule binding public and private bodies.

As of 28 August 2026.

What it requires

  • Give notice to each affected Idaho resident as soon as possible, and in the most expedient time possible without unreasonable delay, after discovering a breach of system security involving personal information.
  • If you are a government agency, also notify the Idaho Attorney General within 24 hours of discovering the breach; this duty does not extend to a private commercial entity.
  • Do not treat a breach exposing only biometric, genetic, or health data as triggering this notice duty. Idaho's breach definition of personal information does not include those categories.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

An agency, individual, or commercial entity that owns or licenses computerized data including personal information must give notice as soon as possible, and in the most expedient time possible without unreasonable delay, to each affected Idaho resident following a breach of system security. A government agency must additionally notify the Idaho Attorney General within 24 hours of discovery; this duty does not extend to a private commercial entity.

Any governmental employee who intentionally discloses personal information not subject to disclosure otherwise allowed by law is guilty of a misdemeanor, punishable by up to a $2,000 fine, up to one year in county jail, or both.

Personal information is a resident's name combined with a Social Security number, a driver's license or Idaho identification card number, or a financial account or card number with an access code, and does not include publicly available information lawfully made available to the general public from government records or widely distributed media; it carries no biometric, genetic, or health element, so a breach exposing only biometric data does not trigger this duty.

The statute, added in 2006 and amended in 2014, sets no fixed numeric notice deadline and no consumer reporting agency threshold.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

official Idaho statute text, Idaho Code Title 28, Chapter 51, Idaho Legislature

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app