What Happened
T-Mobile has been found liable for over 722,000 violations of Washington State's data breach notification law, as ruled by a King County Superior Court. The Washington State Attorney General's office is opposing T-Mobile's request to reconsider this decision, highlighting the state's commitment to enforcing these laws.
The sheer number of violations underscores a critical issue: the focus isn't on whether T-Mobile experienced a breach, but on how they handled the notification process afterward.
Timeline
Here's what we know:
- A data breach affected Washington State residents.
- T-Mobile's notification process didn't meet state law requirements.
- The court ruled T-Mobile liable for over 722,000 violations.
- T-Mobile requested reconsideration.
- The Attorney General opposed this request (September 2026).
What's not clear, but crucial for your planning, is the time between breach discovery and the first notification attempt, and whether T-Mobile had documented procedures in place beforehand.
Which Controls Failed or Were Missing
While we don't have access to all court findings, the violation count suggests several control failures. Washington's data breach notification law counts each affected individual who doesn't receive proper notice as a separate violation.
Here's what might have gone wrong:
Notification delay or failure. T-Mobile may have missed deadlines, sent notifications too late, or failed to notify some individuals entirely.
Inadequate breach detection. Without quickly understanding a breach's scope, timely notification is impossible. This often results from logging gaps, incomplete forensic responses, or delayed escalation from IT to legal.
Deficient notification content. State laws specify what breach notices must include. Missing elements in your template can turn each notice into a violation.
No documented notification procedure. Some organizations plan to figure out breach notification as they go. This approach fails when coordinating legal review, call center setup, credit monitoring offers, and regulatory filings under tight deadlines.
What the Relevant Standard Requires
Washington's data breach notification law (RCW 19.255.010) mandates that any entity experiencing a breach affecting Washington residents must notify them "in the most expedient time possible and without unreasonable delay."
Key requirements include:
Timing. Notify affected individuals without unreasonable delay. Courts assess "unreasonable" based on what you knew, when you knew it, and your actions.
Content. Notices must describe the breach, compromised information, your response, and steps individuals can take to protect themselves.
Method. Written notice is standard. Electronic notice is acceptable if it's your primary communication method. Substitute notice (like website postings or media notifications) is allowed only when direct notice isn't feasible.
Attorney General notification. If a breach affects more than 500 Washington residents, notify the Attorney General's office.
All 50 states have breach notification laws, but specifics vary. Some states allow more time, require different content, or have stricter standards for what constitutes a breach.
Lessons and Action Items for Your Team
Document Your Notification Procedure Now
Don't wait for a breach to decide who approves, drafts, and sends notifications. Your procedure should include:
- Roles and decision points (who determines breach scope, who reviews legal language, who authorizes sending)
- Notification templates for different breach types
- Vendor contacts (forensic firms, call center providers, credit monitoring services)
- Regulatory notification requirements by jurisdiction
Test this procedure annually. Run a tabletop exercise simulating a breach affecting 10,000 people across five states to ensure your team knows what to do.
Map Your State Law Obligations
If you have customers or employees in multiple states, you're subject to various notification laws. Create a matrix for each state where you have covered individuals:
- Notification deadline
- Required notice content
- Substitute notice thresholds and methods
- State regulator notification requirements
- Private right of action (can individuals sue you directly?)
The state with the strictest deadline controls your response timeline if you have a multi-state breach.
Build Breach Detection into Your Security Program
You can't notify people promptly if you don't know a breach happened. Design your security monitoring to detect unauthorized access to personal information specifically.
Log access to databases containing customer data, monitor for bulk data exports, and review those logs regularly. Ensure your incident response team can scope a breach: how many records, what data elements, which jurisdictions.
Treat Notification as a Compliance Obligation, Not a PR Decision
Don't let reputation concerns delay notification. Your communications team will want time to craft messaging, and executives will want to understand the full scope before going public. Your insurance carrier will want to review everything.
These are legitimate concerns, but they can't override your legal deadline. Ensure legal review and executive approval happen quickly so notification goes out within your statutory window.
Keep Records of Your Notification Efforts
If you're ever in T-Mobile's position, you'll need to prove you sent notices, when you sent them, and to whom. Keep:
- Copies of the notices you sent
- Mailing lists or email distribution records
- Bounce-back reports
- Call center logs if you offered a hotline
- Any substitute notice (website postings, media advisories)
These records prove compliance. Without them, you're arguing your good intentions against a state regulator's spreadsheet of affected individuals.
Understand That Each Affected Person Is a Separate Violation
This is the lesson from 722,000 violations. State breach notification laws typically create per-person penalties. If your state allows $1,000 per violation and you failed to notify 10,000 people, that's $10 million in exposure before any settlement negotiation.
This math changes how you prioritize breach response. It's not just about preventing the breach; it's about what you do in the 72 hours after you discover it.



