The Small-Agency Exemption in Your State's Data Security Law Covers Less Than You Think

A countdown clock beside a stack of insurance files, representing the 72-hour breach notification deadline

If your agency has fewer than 10 employees, you've probably heard you're exempt from the new data security rules your state adopted. That's true for one piece of the law. It is not true for the piece that actually gets an agency in trouble: the clock that starts the moment you discover a breach.

As of last year, 27 states plus Puerto Rico had adopted some version of the NAIC Insurance Data Security Model Law, nearly triple the number that had it on the books in 2020. It applies to "licensees," a term the model law defines broadly enough to include individual agents and small agency and brokerage businesses, not just carriers. South Carolina was the first to adopt it back in 2018; states have kept adding on since. North Carolina has not adopted it as of this writing, but agencies that write business across state lines, or that are watching where this trend is headed, are the ones asking about it now.

What the exemption actually covers

The model law's small-licensee exemption applies to agencies with fewer than 10 employees, contractors included. It excuses those agencies from the full written Information Security Program requirement: the board-approved plan, the annual risk assessment, the designated security officer, the whole documented program a larger agency has to maintain and update every year.

What it does not touch is breach notification. Every licensee, exempt or not, still has to investigate a suspected cybersecurity event and notify the state insurance commissioner, and in most adopting states that notice is due no later than 72 hours after you determine an event occurred. A few states run it differently (Ohio and Delaware use 3 business days, Michigan gives 10 days), but the shape is the same everywhere: a short, fixed clock that starts the moment you know, not the moment you've had time to figure out what to do about it.

Why the gap catches small agencies specifically

A two-person agency that read "exempt" and stopped reading is the agency most likely to miss the 72-hour window, because nobody wrote down who calls the commissioner, in what order, or what the notice has to say. The notification itself isn't complicated: the date of the event, how the information was exposed, whether law enforcement was contacted, and an estimate of how many people were affected. But all four of those are hard to produce inside three days if the first time anyone thought about the process is the day of the incident.

The agencies that handle this well tend to have three things written down before anything happens, not after: who gets the first call when something looks wrong, what counts as a reportable event versus a false alarm, and which vendor or partner touches client data on the agency's behalf (the model law makes you responsible for their security too, not just your own systems).

Where this fits into ordinary agency work

None of this is a reason to build a compliance department. It's a reason to have the three items above written down somewhere findable, and to know which states you're licensed in have adopted the law so you're not looking it up for the first time during an actual event. We build agents for insurance agencies that read the renewal and endorsement paperwork that piles up around this kind of deadline and flag what needs a person's attention, the same way our agents work through any document-heavy queue (see how it works). The agent never files a notification or talks to a regulator. It surfaces the deadline and the facts; a person on your team makes the call and sends it.

Sources: Compass MSP, "The Insurance-Specific Cybersecurity Law Your State Passed Without Telling You"; Tech Savvy Insurance, "The NAIC Data Security Law: What It Requires in 2026".

Book a 30-min call →