State Data Breach Notification Letter
DISTRICT OF COLUMBIA
DATA BREACH NOTIFICATION LETTER TEMPLATE
(Prepared for compliance with the District of Columbia Security Breach Protection Act, D.C. Code § 28-3851 et seq.)
TABLE OF CONTENTS
- Attorney General Notice
- Exhibit A – Consumer Notice (Resident Letter)
- Exhibit B – Identity Theft & Credit Monitoring Service Instructions (include only if required)
1. ATTORNEY GENERAL NOTICE
(Use this section only if the breach affects 50 or more District residents. Provide written notice to the D.C. Attorney General in the most expedient manner possible, without unreasonable delay, and no later than the resident notice. See D.C. Code § 28-3852(b-1).)
[COMPANY LETTERHEAD]
[PHYSICAL ADDRESS] | [PHONE] | [EMAIL]DATE: [MM/DD/YYYY]
VIA: [Certified Mail / Overnight Courier / OAG Portal]
Office of the Attorney General for the District of Columbia
Consumer Protection Section
400 Sixth Street NW
Washington, DC 20001RE: Notice of Security Breach – [COMPANY LEGAL NAME]
(pursuant to D.C. Code § 28-3851 et seq.)
A. Identity of the Covered Entity
- Legal Name: [COMPANY LEGAL NAME]
- Trade/DBA Names (if any): [DBA]
- Principal Address: [ADDRESS]
- Point of Contact Regarding Breach:
• Name/Title: [NAME, TITLE]
• Telephone: [###-###-####]
• Email: [EMAIL]
B. Incident Overview
- Date(s) of Breach: [MM/DD/YYYY–MM/DD/YYYY]
- Date Discovered: [MM/DD/YYYY]
- Systems Affected: [High-level description]
- Description of the Breach: [Concise factual narrative; avoid privileged conclusions]
C. Personal Information Involved
| Category | Exposed? (Y/N) |
|---|---|
| Social Security / Tax ID Numbers | [___] |
| Driver’s License / DC ID Numbers | [___] |
| Credit/Debit Card Numbers + Security Codes | [___] |
| Medical / Health Information | [___] |
| Biometric Data | [___] |
| Username + Password / Access Credentials | [___] |
| Other (specify) | [___] |
Total number of District residents affected (reasonably known): [###]
D. Containment & Remediation Actions
- Date access terminated or vulnerability fixed: [DATE]
- Steps taken to secure systems: [BULLETED LIST]
- Third-party forensic firm engaged: [NAME] (engagement date [DATE])
- Law-enforcement contact (if any): [AGENCY, CONTACT, DATE]
• Is delayed notice requested by law enforcement? [Yes/No] (Attach written request if “Yes”)
E. Consumer Notification Plan
- Planned Notice Date to Residents: [DATE] (most expedient time possible and without unreasonable delay, subject to the investigation/restoration and law-enforcement provisions of § 28-3852(a), (d))
- Method(s): [First-class mail / Email with active consent / Substitute notice*]
- If substitute notice: identify the statutory basis (cost exceeds $50,000; more than 100,000 recipients; or insufficient contact information) and use all required components: email where available, conspicuous website posting if a website is maintained, and notice to major local and, if applicable, national media. See § 28-3851(2)(C).
- Sample Consumer Notice: Attached as Exhibit A
- Optional identity-theft protection/credit-monitoring services, if offered or required by another applicable law, contract, or order: [Provider Name], [TERM] (details in Exhibit B). D.C. Code § 28-3852 does not prescribe an 18- or 24-month monitoring term.
F. Contact for Follow-Up
For additional information, please contact the undersigned.
Respectfully submitted,
______________________________
[AUTHORIZED SIGNATORY NAME]
[Title]
[COMPANY LEGAL NAME]
[PHONE] | [EMAIL]
EXHIBIT A
SAMPLE CONSUMER NOTICE – DISTRICT OF COLUMBIA RESIDENT
NOTICE OF DATA SECURITY INCIDENT
[COMPANY LOGO]
Dear [NAME] (or “Dear Parent/Legal Guardian” for minors):
1. What Happened?
On [DATE], we discovered unauthorized access to certain [COMPANY] systems. Our investigation, concluded on [DATE], determined that from [START DATE] to [END DATE] an unauthorized actor may have obtained certain files containing your personal information.
2. What Information Was Involved?
Based on our review, the following information related to you may have been involved: [LIST CATEGORIES – e.g., full name and Social Security number]. We have no evidence of misuse of your information at this time.
3. What We Are Doing
• Immediately contained the incident and engaged leading cybersecurity experts.
• Notified law enforcement.
• Enhanced network monitoring, access controls, and employee security training.
• Identity-Theft & Credit-Monitoring Services (include only if actually offered): We are offering you [TERM] of complimentary identity-theft protection and credit-monitoring services through [SERVICE PROVIDER]. The services include: [VERIFY AND DESCRIBE ACTUAL FEATURES]. See Exhibit B for enrollment instructions.
4. What You Can Do
We encourage you to:
- Enroll in the complimentary services no later than [ENROLLMENT DEADLINE].
- Review your account statements and credit reports.
- Consider placing a fraud alert or security freeze.
- Remain vigilant and report any suspected identity theft.
We have included contact information for the three nationwide consumer reporting agencies, the Federal Trade Commission (“FTC”), and the District of Columbia Office of the Attorney General.
| Agency | Phone | Website |
|---|---|---|
| Equifax | 1-800-685-1111 | www.equifax.com |
| Experian | 1-888-397-3742 | www.experian.com |
| TransUnion | 1-800-916-8800 | www.transunion.com |
| FTC | 1-877-438-4338 | www.IdentityTheft.gov |
| DC OAG | 1-202-442-9828 | oag.dc.gov |
5. For More Information
If you have questions, please contact our dedicated assistance line at [###-###-####] (Monday–Friday, [HOURS EST]), email [EMAIL], or write to [ADDRESS].
We regret any concern or inconvenience this incident may cause and remain committed to safeguarding your information.
Sincerely,
______________________________
[AUTHORIZED SIGNATORY NAME]
[Title]
[COMPANY LEGAL NAME]
EXHIBIT B
CREDIT-MONITORING & IDENTITY-THEFT PROTECTION INSTRUCTIONS
KEY COMPLIANCE CHECKLIST (Do Not Send)
☐ If 50 or more District residents are affected, written notice to D.C. OAG sent without unreasonable delay and no later than resident notice
☐ Resident notices sent in the most expedient time possible and without unreasonable delay, subject to § 28-3852(a), (d)
☐ Any credit-monitoring offer accurately states the actual provider, term, features, and enrollment deadline; no fixed D.C. statutory term is assumed
☐ Content includes incident description, info categories, remediation steps, consumer steps, contact info, and FTC/OAG resources
☐ Substitute notice used only if § 28-3851(2)(C) is satisfied, with all required notice components
☐ Law-enforcement delay documented (if applicable)
☐ If more than 1,000 persons must be notified, nationwide consumer reporting agencies notified without unreasonable delay under § 28-3852(c), unless the statutory GLBA exception applies
OFFICIAL SOURCES
- D.C. Code § 28-3851 — definitions and notice methods
- D.C. Code § 28-3852 — notification of security breach
- D.C. Code § 28-3853 — enforcement
© 20[YY] [COMPANY LEGAL NAME]. All rights reserved.
About This Template
Formal legal letters create a written record, trigger response deadlines, and often preserve rights under a statute or contract. Cease-and-desist letters, notice letters, and formal responses all have their own expected format, and the language used can mean the difference between a quick resolution and a courtroom fight. Well-drafted correspondence also documents that you tried to resolve things reasonably, which matters if the dispute escalates later.
Important Notice
This template is provided for informational purposes. It is not legal advice. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Last updated: July 2026
Get your State Data Breach Notification Letter, done and ready to use
Fill it in for your situation, adjust it for your state, and download the finished Word and PDF. Let the AI do it in about 5 minutes, or finish it yourself in the editor. $99 one time, or go Pro for access to every document and every Ezel app.