Law status
No verified general comprehensive law
No comprehensive consumer privacy law verified (SB 1037 (2025) was a pending bill)
- Official name / citation
- n.a.
- Status / effective date
- Bill only
- Principal enforcer
- Hawaii Attorney General; Office of Consumer Protection (DCCA)
Direct attached-library attribution
0 cases · $0
These totals are assigned solely by the attachment’s state heading. Shared multistate totals are not allocated in full to every state.
The attached library does not enumerate participant-level allocations for every multistate matter; shared settlement totals are presented once at the national level and are not duplicated into state totals.
Official law sources
Other generally applicable PII law
Hawaii Revised Statutes § 487N-2 (security breach of personal information) - https://cca.hawaii.gov/ocp/notices/security-breach/
Public enforcement context
Tier 1
Blackbaud, Inc.
$49.5 million to the states; Hawaii share stated as $420,086 · October 18, 2023
Hawaii joined the 50-jurisdiction Blackbaud settlement over the 2020 ransomware breach.
Legal basis: State consumer protection laws, breach-notification laws and HIPAA
Mapped control outcomes
1 personal data inventory/data map; 2 sensitive-data discovery; 3 downstream copy tracking; 8 breach blast-radius analysis; 9 retention/minimization; 10 regulator audit evidence
Kestryl can evidence where regulated personal data actually resides across structured stores and unstructured attachments/images, produce audit rows and evidence packs showing when each location was discovered and reviewed, and apply structured-data remediation modes (mask, vault, strip) to reduce exposure. It does not alter source attachments or documents, and its output is technical evidence supporting controls, not proof of legal compliance.
Educational information, not legal advice. The supplied snapshot is dated August 25, 2026; confirm current law, applicability, exceptions, official status, and reporting decisions with qualified counsel and the relevant authority.