
On September 9, 2026, Greenberg Traurig, LLP filed a breach notification with the California Attorney General — entry sb24-629493, breach date August 26, 2026. The sample notice attached to that filing is a letter dated September 8, headed "NOTICE OF DATA BREACH," addressed to an individual, signed "Greenberg Traurig, LLP," and offering three years of credit monitoring. Its state appendix records that "There were 33 Rhode Island residents notified in this incident."
The firm's own account, from the letter: "On August 26, 2026, an unauthorized individual obtained a limited number of files maintained by GT in connection with its legal work."
The same letter explains why the firm held the data at all: "We had this information in our systems because it was collected and processed in the ordinary course of providing legal services." That sentence is the whole problem. A law firm's document store holds personal information about people who are not its clients — a client's employees whose personnel files went over for an employment matter, custodians in a discovery set, names in deal documents. When it is breached, the firm owes notice to those individuals and to the states they live in. Thirty-three Rhode Islanders is what that duty looks like.
What the filing does not do is start anybody else's clock. No public document tells a client organization whether its matters were in the affected set. That determination lives inside the firm, and until it is communicated the client cannot form a belief about its own data. It is the same gap as a vendor disclosing through the wrong venue: the disclosure happened, correctly, to a regulator, and told you nothing you can act on.

The firm calls its Miami office at 333 SE 2nd Avenue "the founding office of Greenberg Traurig and the only global law firm founded in Miami." A meaningful share of the matters in that store belong to Florida companies, and Florida is where their clocks are written.
The term that decides how long you wait
Florida supplies a default that most people negotiating an engagement letter have never read. Fla. Stat. 501.171(6)(a):
In the event of a breach of security of a system maintained by a third-party agent, such third-party agent shall notify the covered entity of the breach of security as expeditiously as practicable, but no later than 10 days following the determination of the breach of security or reason to believe the breach occurred. ... A third-party agent shall provide a covered entity with all information that the covered entity needs to comply with its notice requirements.
Ten days, and an affirmative duty to hand over what you need. The catch is the definition. A "third-party agent" is "an entity that has been contracted to maintain, store, or process personal information on behalf of a covered entity" (§501.171(1)(h)). Whether outside counsel meets that is arguable both ways — the firm you hired to defend a wrongful-termination claim, holding personnel files you shipped it, looks like one; the firm that reviewed your lease does not. You do not want that argument happening for the first time while a 30-day clock runs.
So settle it in the engagement letter, and be specific about four things: the deadline in hours rather than "without undue delay"; a named recipient at your organization rather than "the client"; reason to believe as the trigger rather than confirmed breach; and an obligation to identify affected matters, not merely to announce an incident. The last one is the clause firms leave out and the only one that actually starts your clock.
The cost is worth stating plainly: you are asking a firm with more negotiating leverage than you to depart from its standard engagement terms, and a small client on an hourly matter may simply not get it. If you cannot get the term, keep your own copy of the answer instead: log what leaves for each firm — which matter, which files, whose personal information — at the point of transfer. Then a notice that arrives with no matter list still lets you compute exposure in a day. That is the same data inventory problem that turned a four-day detection into a 380-day notification elsewhere.
And the clock may not wait for the call. Fla. Stat. 501.171(4)(a) gives you 30 days from "the determination of a breach or reason to believe a breach occurred." Reason to believe is a low bar: if you read that your firm was breached and you know you sent it four hundred personnel files, your clock may already be running while you wait for the phone. That trigger point is a definition to settle in advance, not during.
What to check this week
- Pull the engagement letters for the two or three firms holding your most sensitive matters and find the security-incident notification clause. Record the deadline, the recipient, and the trigger. No clause is itself the finding.
- Ask each firm in writing: which of our matters are in your document management system today, and can you tell us within five business days whether a named matter was in an affected set?
- Check whether your engagement terms characterize the firm as a third-party agent or processor for the personal information you transfer. Silence leaves you with an argument rather than a deadline.
- Confirm who receives that call, and whether that person can open a notification assessment without convening a committee.
North InfoSec runs AI-assisted penetration testing and security assessments, including third-party and supply-chain exposure reviews of the systems you rely on but do not own. northinfosec.com