Alabama

Who Is Covered?

A “covered entity” is a person, sole proprietorship, partnership, government entity, corporation, nonprofit, trust, estate, cooperative association, or other business entity that acquires or uses sensitive personally identifying information. Ala. Code § 8-38-2(2).

What Information Is Protected?

“Sensitive Personally Identifying Information” is an Alabama resident’s first name or first initial and last name in combination with one or more of the following with respect to the same Alabama resident:

  1. A non-truncated social security number or tax identification number.
  2. A non-truncated driver’s license number, state-issued identification card number, passport number, military identification number, or other unique identification number issued on a government document used to verify the identity of a specific individual.
  3. A financial account number, including a bank account number, credit card number, or debit card number, in combination with any security code, access code, password, expiration date, or PIN, that is necessary to access the financial account or to conduct a transaction that will credit or debit the financial account.
  4. Any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional.
  5. An individual’s health insurance policy number or subscriber identification number and any unique identifier used by a health insurer to identify the individual.
  6. A user name or email address, in combination with a password or security question and answer that would permit access to an online account affiliated with the covered entity that is reasonably likely to contain or is used to obtain sensitive personally identifying information. Ala. Code § 8-38-2(6)(a).

What Is A “Breach”?

A “breach of security” or “breach” is the unauthorized acquisition of data in electronic form containing sensitive personally identifying information. Acquisition occurring over a period of time committed by the same entity constitutes one breach. Ala. Code § 8-38-2(1).

What Triggers Notification?

Notification is required when a covered entity determines that, as a result of a breach of security, sensitive personally identifying information has been acquired or is reasonably believed to have been acquired by an unauthorized person, and is reasonably likely to cause substantial harm to the individuals to whom the information relates, it shall give notice of the breach to each individual. Ala. Code § 8-38-5(a).

How Is Notice Provided To Individuals?

Timing: Notice to individuals shall be made as expeditiously as possible and without unreasonable delay. Ala. Code § 8-38-5(b).

Delivery: Notice must be given in writing, sent to the mailing address of the individual in the records of the covered entity, or by email notice sent to the email address of the individual in the records of the covered entity. Ala. Code § 8-38-5(d).

Substitute notice is allowed if direct notice is not feasible due to any of the following:

  1. Excessive cost. The term includes either of the following: a) Excessive cost to the covered entity relative to the resources of the covered entity. b) The cost to the covered entity exceeds $500,000.
  2. Lack of sufficient contact information for the individual required to be notified.
  3. The affected individuals exceed 100,000 persons.

Substitute notice must be by both:

  1. A conspicuous notice on the Internet website of the covered entity, if the covered entity maintains a website, for a period of 30 days; and
  2. Notice in print and in broadcast media, including major media in urban and rural areas where the affected individuals reside. Ala. Code § 8-38-6(e).

Content: The notice must include, at a minimum, all of the following:

  1. The date, estimated date, or estimated date range of the breach.
  2. A description of the sensitive personally identifying information that was acquired by an unauthorized person as part of the breach.
  3. A general description of the actions taken by a covered entity to restore the security and confidentiality of the personal information involved in the breach.
  4. A general description of steps an affected individual can take to protect himself or herself from identity theft.
  5. Information that the individual can use to contact the covered entity to inquire about the breach. Ala. Code § 8-38-5(d).

Is Notice To The Government Required?

Yes. If the number of individuals a covered entity is required to notify exceeds 1,000, the entity must provide written notice of the breach to the Attorney General as expeditiously as possible and without unreasonable delay. Ala. Code § 8-38-6(a).

The written notice must include:

  1. A synopsis of the events surrounding the breach at the time that notice is provided.
  2. The approximate number of individuals in the state who were affected by the breach.
  3. Any services related to the breach being offered or scheduled to be offered, without charge, by the covered entity to individuals, and instructions on how to use the services.
  4. The name, address, telephone number, and email address of the employee or agent of the covered entity from whom additional information may be obtained about the breach. Ala. Code § 8-38-6(b).

Is Notice To Credit Reporting Agencies Required?

Yes. If a covered entity discovers circumstances requiring notice of more than 1,000 individuals at a single time, the entity shall also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notices. Ala. Code § 8-38-7.

Are There Security Measure Standards?

Yes. “Reasonable security measures” means security measures practicable for the covered entity to implement and maintain, including consideration of all of the following:

  1. Designation of an employee or employees to coordinate the covered entity’s security measures to protect against a breach of security. An owner or manager may designate himself or herself.
  2. Identification of internal and external risks of a breach of security.
  3. Adoption of appropriate information safeguards to address identified risks of a breach of security and assess the effectiveness of such safeguards.
  4. Retention of service providers, if any, that are contractually required to maintain appropriate safeguards for sensitive personally identifying information.
  5. Evaluation and adjustment of security measures to account for changes in circumstances affecting the security of sensitive personally identifying information.
  6. Keeping the management of the covered entity, including its board of directors, if any, appropriately informed of the overall status of its security measures. Ala. Code § 8-38-3(b).

Additionally, an assessment of a covered entity’s security must be based upon the entity’s reasonable security measures as a whole and shall place an emphasis on data security failures that are multiple or systemic, including consideration of all of the following:

  1. The size of the covered entity.
  2. The amount of sensitive personally identifying information and the type of activities for which the sensitive personally identifying information is accessed, acquired, maintained, stored, utilized, or communicated by, or on behalf of, the covered entity.
  3. The covered entity’s cost to implement and maintain the reasonable security measures to protect against a breach of security relative to its resources. Ala. Code § 8-38-3(c).

Furthermore, a covered entity or third-party agent shall take reasonable measures to dispose, or arrange for the disposal, of records containing sensitive personally identifying information within its custody or control when the records are no longer to be retained pursuant to applicable law, regulations, or business needs. Disposal shall include shredding, erasing, or otherwise modifying the personal information in the records to make it unreadable or undecipherable through any reasonable means consistent with industry standards. Ala. Code § 8-38-10.

What Are The Possible Consequences Of A Violation?

A violation of the notification provisions is an unlawful trade practice under the Alabama Deceptive Trade Practices Act, with penalties not to exceed $500,000 per breach. Additionally, civil penalties of not more than $5,000 per day may be assessed for each consecutive day that the covered entity fails to take reasonable action to comply with the notice provisions. Ala. Code § 8-38-9.

Are There Any Exemptions?

Yes. A) An entity subject to or regulated by federal laws, rules, regulations, procedures, or guidance on data breach notification established or enforced by the federal government; or B) is subject to or regulated by state laws, rules, regulations, procedures, or guidance on data breach notification that are established or enforced by state government, and are at least as thorough as the notice requirements provided in Alabama’s breach notification law, is exempt from this chapter as long as the entity does all of the following:

  1. Maintains procedures pursuant to those laws, rules, regulations, procedures, or guidance.
  2. Provides notice to affected individuals pursuant to those laws, rules, regulations, procedures, or guidance.
  3. Timely provides a copy of the notice to the Attorney General when the number of individuals the entity notified exceeds 1,000.