Law / United States / District of Columbia

District of Columbia

United States law applies in District of Columbia District of Columbia is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of District of Columbia, described on this page below, applies here too.

2 of 7 named instruments researched to a stage, across two of the six areas of law we track: 2 in force. As of 18 September 2026.

  1. AI law none researched
  2. Privacy law 1
  3. Scraping law none researched
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law1 instrument, 1 in force

Research summary (132 words)

The District of Columbia has no comprehensive consumer data-protection act of the kind most states have enacted; the federal sectoral posture recorded in the national document applies unmodified.

The District's own contribution is a Consumer Security Breach Notification law that requires prompt notice to affected residents and, above a 50-resident threshold, to the Attorney General, and whose definition of covered personal information expressly reaches biometric identifiers including a voice print.

The Consumer Protection Procedures Act, the basis of the Attorney General's Meta and TikTok suits, carries no independent data-handling duty of its own; it supplies the enforcement mechanism and private right of action for a breach-notice violation, and expressly caps a consumer's private recovery for that one violation type to actual damages rather than the treble-damages-or-statutory-minimum floor it gives every other violation.

Breach notification

Consumer Security Breach Notification

D.C. Code §§ 28-3851 to 28-3853 (Title 28, Chapter 38, Subchapter II)official text, D.C. Law Library (code.dccouncil.gov)

In force since 1 July 2007. Binds private bodies.

What this law does

Any person or entity conducting business in the District that owns or licenses computerized data containing personal information must notify affected District residents in the most expedient time possible after discovering a breach of the security of the system, and must also notify the Office of the Attorney General in writing if the breach affects 50 or more residents.

Personal information covered by the notification duty includes biometric data such as a fingerprint, voice print, genetic print, or retina or iris image used to authenticate identity. A violation of this notification duty is an unfair or deceptive trade practice under the Consumer Protection Procedures Act.

For this specific violation, though, a consumer's private recovery is limited to actual damages rather than the treble-damages-or-$1,500-per-violation floor available for other violations of that Act. The definition of personal information excludes information that is publicly available from government records. The statute was enacted in 2007 and amended in 2020 by the Security Breach Protection Amendment Act.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (352 words)

The District of Columbia's product-security and cyber-resilience posture rests on one enacted, standalone safeguards duty, D.C. Code § [28-3852.01] (Title 28, Chapter 38, Subchapter II, added by the Security Breach Protection Amendment Act of 2020, D.C. Law 23-98, effective June 17, 2020).

It requires any person or entity that owns, licenses, maintains, handles, or otherwise possesses the personal information of an individual residing in the District to implement and maintain reasonable security safeguards, including procedures and practices appropriate to the nature of that information and to the entity's own nature and size; to require by written agreement that a nonaffiliated third-party service provider implement and maintain its own reasonable security procedures and practices over any personal information disclosed to it; and to take reasonable steps against unauthorized access when destroying records that contain personal information.

A person or entity already subject to and in compliance with the security-procedure requirements of the Gramm-Leach-Bliley Act, Health Insurance Portability and Accountability Act (HIPAA), or the HITECH Act is deemed to comply, and the definition of person or entity expressly excludes the District government and its own agencies and instrumentalities, so the duty binds only the private sector.

No enacted District statute sets security requirements a connected device or software product must meet before or after it reaches the market, imposes a private-sector duty to report an exploited vulnerability or a security incident to an authority, or establishes a sector-specific cyber-resilience regime naming a private digital service.

A violation of the safeguards duty is, like a violation of the notification duty in the same subchapter, an unfair or deceptive trade practice under the Consumer Protection Procedures Act: the Attorney General may recover a civil penalty of up to $5,000 for a first violation and up to $10,000 for each subsequent violation under D.C. Code § 28-3909(b), and a consumer may bring a private action under D.C. Code § 28-3905(k), though recovery for this violation is limited to actual damages rather than the treble-damages-or-$1,500-per-violation floor available for most other violations of that Act.

The District's breach-notification duty, D.C. Code §§ 28-3851 to 28-3853, is already this jurisdiction's privacy row rather than repeated here.

Security baseline statutes

Security requirements for personal information (Security Breach Protection Amendment Act of 2020)

D.C. Code § [28-3852.01] (Title 28, Chapter 38, Subchapter II, "Security requirements," added by the Security Breach Protection Amendment Act of 2020, D.C. Law 23-98, § 2(a)(5), 67 DCR 3923)official statute text, D.C. Law Library (code.dccouncil.gov)

In force since 17 June 2020. Binds private bodies.

What this law does

Any person or entity that owns, licenses, maintains, handles, or otherwise possesses personal information of an individual residing in the District of Columbia must implement and maintain reasonable security safeguards, including procedures and practices appropriate to the nature of the personal information and the nature and size of the entity or operation.

The same person or entity must require by written agreement that a nonaffiliated third-party service provider implement and maintain reasonable security procedures and practices over any personal information disclosed to it. When destroying records that contain personal information, the same person or entity must take reasonable steps to protect against unauthorized access to or use of that personal information.

A person or entity already subject to and in compliance with the security-procedure requirements of Title V of the Gramm-Leach-Bliley Act, the Health Insurance Portability and Accountability Act, or the Health Information Technology for Economic and Clinical Health Act is deemed to be in compliance with this section. A violation of this section is, like a violation of the notification duty in the same subchapter, an unfair or deceptive trade practice under the Consumer Protection Procedures Act.

The Attorney General may enforce it for a civil penalty of up to $5,000 for a first violation and up to $10,000 for each subsequent violation. A consumer may also bring a private action for the same violation, but limited to actual damages.

What it requires

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.