Other Developments
Statutory basis confirmed. The Security Breach Protection Amendment Act (D.C. Law 23-98) took effect on 17 June 2020 and amended DC Code § 28-3852, the primary statutory anchor for the District's breach-notification regime. This is a standing instrument rather than a new development this cycle, but it is the confirmed statutory basis underpinning the enforcement mechanics described above. Notification threshold reported with lower confidence. The fifty-or-more-residents notice threshold to the Attorney General is drawn from a secondary summary source this cycle; the primary DC Code text for this specific numerical threshold was not independently re-verified, so this figure is reported in qualified rather than assertive terms.
Cross-Monitor Connections
The enforcement mechanics described here connect to the financial-integrity monitor's standing interest in DC's designated regulatory authorities for consumer-facing obligations, though no financial-integrity finding this cycle addresses breach notification directly. No world-payments or advennt cross-reference arises from this cycle's data-protection findings.
Outlook
The DC breach-notification regime is expected to remain the operative consumer-data-protection mechanism in the District absent a new comprehensive privacy bill; whether such a bill is pending in the DC Council was not independently verified this cycle and remains an open question for a future cycle to resolve. The reported fifty-resident notification threshold would benefit from primary-source verification in a subsequent cycle to move it from a qualified to an assertive framing.
1 earlier update not shown here.
Standing brief · as of 26 August 2026
Written before the update above. Where they differ, the update is the more recent position.
Lead Signal
The District of Columbia's data-protection posture is understood to face its most consequential near-term threat from federal legislation rather than local rulemaking. The SECURE Data Act (H.R. 8413) is understood to have been introduced on April 22, 2026, carrying a broad preemption clause that would reach District sectoral and comprehensive privacy laws; the bill remains in committee and is opposed by a coalition of eighteen state attorneys general.
Other Developments
The Security Breach Protection Amendment Act of 2020 (D.C. Code §28-3851 et seq.) remains the primary in-force data-protection instrument in the District, having entered into effect on April 10, 2020. The District has not enacted a comprehensive omnibus consumer-privacy statute. D.C. Bill B26-0670, the District of Columbia Government Data Privacy and Protection Act of 2026, is understood to have been introduced on April 27, 2026 and referred to the Committee on Public Works and Operations on May 5, 2026, with committee testimony recorded June 29, 2026, and to remain pending and unenacted as of the retrieval date. It is understood to supersede the earlier B24-0451, modeled on the ULC Uniform Personal Data Protection Act, which stalled in committee and is no longer the most current pending comprehensive-adjacent proposal.
Entities suffering a breach affecting 50 or more District residents must provide written notice to the Office of the Attorney General, and the Act created security requirements for entities handling District residents' personal information. The statute's protected-information categories were broadened to include biometric identifiers and, separately, genetic print, though only for breach-notification purposes. The statute's notice trigger is understood to run on the residency of affected individuals rather than a controller's place of establishment, giving it extraterritorial reach over any entity holding District residents' data.
The FTC's Health Breach Notification Rule expressly names the District within its definition of "State," extending its notification duties to non-HIPAA-covered vendors of personal health records operating in the District. The Rule also triggers a media-notice obligation where a breach of unsecured PHR-identifiable health data affects 500 or more District residents.
D.C. Council Bill 25-0114, the Stop Discrimination by Algorithms Act of 2023, would have required notice to individuals whose data is used in algorithmic eligibility determinations. It would also have required covered entities to submit audit reports to the Office of the Attorney General. The bill is understood to have died at the end of the 25th DC Council session (2023-2024) without passage, with no reintroduction confirmed in the 26th Council as of October 2025.
The Office of the Attorney General functions as the District's primary consumer-protection and data-breach enforcement authority, coordinating with the FTC. It also holds parens patriae and general consumer-protection enforcement authority, coordinating with the FTC and other state attorneys general on privacy and data-breach matters. The District is understood to have participated in significant multistate privacy enforcement actions, including the AshleyMadison data-breach settlement and joint FTC-state sweeps such as Operation Stop Scam Calls.
Cross-Monitor Connections
The lapsed Bill 25-0114 and the pending B26-0670 both touch algorithmic eligibility determinations and audit requirements with framing adjacent to AI-specific regulation; AI-Act-adjacent analysis of those provisions is routed to the artificial-intelligence monitor, while this monitor retains the profiling and automated-decision-making transparency angle proper to data protection.
Outlook
The SECURE Data Act's preemption clause is understood to be the development most likely to reshape the District's data-protection landscape over the coming cycles, given its potential to reach both the existing breach statute and any future comprehensive District privacy law. Whether B26-0670 advances beyond committee in the current 26th Council session remains unresolved and will require monitoring of committee markup schedules in subsequent cycles. Additional District-level developments flagged internally for verification, including sectoral health-data legislation and a possible student-data statute, remain outside this cycle's confirmed factual record and will be revisited once independently verified.