Category Archives: Breach Notification

Colorado

Who Is Covered?

A covered entity that maintains, owns, or licenses computerized data that includes personal information about a resident of Colorado. Colo. Rev. Stat. § 6-1-716(2).

“Covered entity” means a person that maintains, owns, or licenses personal information in the course of the person’s business, vocation, or occupation. “Covered entity” does not include a person acting as a third-party service provider. Colo. Rev. Stat. § 6-1-716(1)(b).

What Information Is Protected?

“Personal information” means:

A. A Colorado resident’s first name or first initial and last name in combination with any one or more of the following data elements that relate to the resident, when the data elements are not encrypted, redacted, or secured by any other method rendering the name or the element unreadable or unusable:

  1. Social security number;
  2. Student, military, or passport identification number;
  3. Driver’s license number or identification card number;
  4. Medical information;
  5. Health insurance identification number; or
  6. Biometric data;

B. A Colorado resident’s username or e-mail address, in combination with a password or security questions and answers, that would permit access to an online account; or

C. A Colorado resident’s account number or credit or debit card number in combination with any required security code, access code, or password that would permit access to that account. Colo. Rev. Stat. § 6-1-716(1)(g).

What Is A “Breach”?

“Security breach” means the unauthorized acquisition of unencrypted computerized data that compromises the security, confidentiality, or integrity of personal information maintained by a covered entity. Good faith acquisition of personal information by an employee or agent of a covered entity for the covered entity’s business purposes is not a security breach if the personal information is not used for a purpose unrelated to the lawful operation of the business or is not subject to further unauthorized disclosure. Colo. Rev. Stat. § 6-1-716(1)(h).

What Triggers Notification?

A determination, following investigation, that there is a likelihood that personal information has been or will be misused. 

Likelihood of Harm Analysis: Notification is not required if the investigation determines that the misuse of information about a Colorado resident has not occurred and is not reasonably likely to occur. Colo. Rev. Stat. § 6-1-716(2)(a).

How Is Notice Provided To Individuals?

Timing: Notice must be made in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system. Colo. Rev. Stat. § 6-1-716(2).

Delivery: Notice may be by:

  1. Written notice to the postal address listed in the records of the covered entity;
  2. Telephonic notice;
  3. Electronic notice, if a primary means of communication by the covered entity with a Colorado resident is by electronic means or the notice provided is consistent with the provisions regarding electronic records and signatures set forth in the federal “Electronic Signatures in Global and National Commerce Act”, 15 U.S.C. sec. 7001 et seq.; or
  4. Substitute notice, if the covered entity required to provide notice demonstrates that the cost of providing notice will exceed $250,000, the affected class of persons to be notified exceeds 250,000 Colorado residents, or the covered entity does not have sufficient contact information to provide notice. Substitute notice consists of all of the following: a) E-mail notice if the covered entity has e-mail addresses for the members of the affected class of Colorado residents; b) Conspicuous posting of the notice on the website page of the covered entity if the covered entity maintains one; and c) Notification to major statewide media. Colo. Rev. Stat. § 6-1-716(1)(f).

Content: In the case of a breach of personal information, notice must include the following information:

  1. The date, estimated date, or estimated date range of the security breach;
  2. A description of the personal information that was acquired or reasonably believed to have been acquired as part of the security breach;
  3. Information that the resident can use to contact the covered entity to inquire about the security breach;
  4. The toll-free numbers, addresses, and websites for consumer reporting agencies;
  5. The toll-free number, address, and website for the Federal Trade Commission; and
  6. A statement that the resident can obtain information from the Federal Trade Commission and the credit reporting agencies about fraud alerts and security freezes. Colo. Rev. Stat. § 6-1-716(2)(a.2).

Is Notice To The Government Required?

Yes. A covered entity that must notify Colorado residents of a data breach must provide notice of any security breach to the Colorado attorney general in the most expedient time possible and without unreasonable delay, but not later than 30 days after the date of determination that a security breach occurred, if the security breach is reasonably believed to have affected 500 Colorado residents or more, unless the investigation determines that the misuse of information about a Colorado resident has not occurred and is not likely to occur. Colo. Rev. Stat. § 6-1-716(2)(f).

Is Notice To Credit Reporting Agencies Required?

Yes. If a covered entity is required to notify more than 1,000 Colorado residents of a security breach pursuant to this section, the covered entity shall also notify, in the most expedient time possible and without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the anticipated date of the notification to the residents and the approximate number of residents who are to be notified. Colo. Rev. Stat. § 6-1-716(2)(d).

Are There Security Measure Standards?

Yes. To protect personal identifying information from unauthorized access, use, modification, disclosure, or destruction, a covered entity that maintains, owns, or licenses personal identifying information of an individual residing in the state shall implement and maintain reasonable security procedures and practices that are appropriate to the nature of the personal identifying information and the nature and size of the business and its operations. Colo. Rev. Stat. § 6-1-713.5(1).

Additionally, unless a covered entity agrees to provide its own security protection for the information it discloses to a third-party service provider, the covered entity shall require that the third-party service provider implement and maintain reasonable security procedures and practices that are:

  1. Appropriate to the nature of the personal identifying information disclosed to the third-party service provider; and
  2. Reasonably designed to help protect the personal identifying information from unauthorized access, use, modification, disclosure, or destruction. Colo. Rev. Stat. § 6-1-713.5(2)

What Are The Possible Consequences Of A Violation?

The attorney general may bring an action in law or equity to address violations of this section, § 6-1-713 [protection of personal identifying information] or § 6-1-715 [confidentiality of social security numbers] and for other relief that may be appropriate to ensure compliance with this section or to recover direct economic damages resulting from a violation, or both. Colo. Rev. Stat. § 6-1-716(4).

Are There Any Exemptions/Exceptions?

Not per se, but a covered entity that maintains its own notification procedures as part of an information security policy for the treatment of personal information and whose procedures are otherwise consistent with the timing requirements of this section is in compliance with the notice requirements of this section if the covered entity notifies affected Colorado residents in accordance with its policies in the event of a security breach; except that notice to the attorney general is still required. Colo. Rev. Stat. § 6-1-716(3)(a).

Additionally, a covered entity that is regulated by state or federal law and that maintains procedures for a security breach pursuant to the laws, rules, regulations, guidances, or guidelines established by its state or federal regulator is in compliance with this section; except that notice to the attorney general is still required. Colo. Rev. Stat. § 6-1-716(3)(b).

Confidentiality Of Social Security Numbers

Note: Additional restrictions apply to the use of social security numbers. See Colo. Rev. Stat. § 6-1-715.

Wyoming

Who Is Covered?

An individual or commercial entity that conducts business in Wyoming and that owns or licenses computerized data that includes personal identifying information about a resident of Wyoming. Wyo. Stat. Ann. § 40-12-502(a).

What Information Is Protected?

“Personal identifying information” means the first name or first initial and last name of a person in combination with one or more of the following data elements when the data elements are not redacted:

  1. Social security number;
  2. Driver’s license number;
  3. Account number, credit card number or debit card number in combination with any security code, access code or password that would allow access to a financial account of the person;
  4. Tribal identification card;
  5. Federal or state government issued identification card;
  6. Shared secrets or security tokens that are known to be used for data based authentication;
  7. A username or email address, in combination with a password or security question and answer that would permit access to an online account;
  8. A birth or marriage certificate;
  9. Medical information, meaning a person’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional;
  10. Health insurance information, meaning a person’s health insurance policy number or subscriber identification number or any unique identifier used by a health insurer to identify the person or information related to a person’s application and claims history;
  11. Unique biometric data, meaning data generated from measurements or analysis of human body characteristics for authentication purposes;
  12. An individual taxpayer identification number. Wyo. Stat. Ann. §§ 40-12-501(a)(vii); 6-3-901(b)(iii)-(xiv).

What Is A “Breach”?

“Breach of the security of the data system” means unauthorized acquisition of computerized data that materially compromises the security, confidentiality or integrity of personal identifying information maintained by a person or business and causes or is reasonably believed to cause loss or injury to a resident of this state. Good faith acquisition of personal identifying information by an employee or agent of a person or business for the purposes of the person or business is not a breach of the security of the data system, provided that the personal identifying information is not used or subject to further unauthorized disclosure. Wyo. Stat. Ann. § 40-12-501(a)(i).

What Triggers Notification?

A determination that the misuse of personal identifying information about a Wyoming resident has occurred or is reasonably likely to occur, following a reasonable and prompt investigation to determine the likelihood that personal identifying information has been or will be misused. Wyo. Stat. Ann. § 40-12-502(a).

How Is Notice Provided To Individuals?

Timing: Notice must be given as soon as possible to the affected Wyoming resident. Notice must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system. Wyo. Stat. Ann. § 40-12-502(a).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic mail notice;
  3. Substitute notice, if the person demonstrates: a) That the cost of providing notice would exceed $10,000 for Wyoming-based persons or businesses, and $250,000 for all other businesses operating but not based in Wyoming; b) That the affected class of subject persons to be notified exceeds 10,000 for Wyoming-based persons or businesses and 500,000 for all other businesses operating but not based in Wyoming; or c) The person does not have sufficient contact information.

Substitute notice must include all of the following:

  1. Conspicuous posting of the notice on the Internet, the World Wide Web or a similar proprietary or common carrier electronic system site of the person collecting the data, if the person maintains a public Internet, the World Wide Web or a similar proprietary or common carrier electronic system site; and
  2. Notification to major statewide media. The notice to media shall include a toll-free phone number where an individual can learn whether or not that individual’s personal data is included in the security breach. Wyo. Stat. Ann. § 40-12-502(d).

Content: Notice must be clear and conspicuous and shall include, at a minimum:

  1. A toll-free number: a) That the individual may use to contact the person collecting the data, or his agent; and b) From which the individual may learn the toll-free contact telephone numbers and addresses for the major credit reporting agencies.
  2. The types of personal identifying information that were or are reasonably believed to have been the subject of the breach;
  3. A general description of the breach incident;
  4. The approximate date of the breach of security, if that information is reasonably possible to determine at the time notice is provided;
  5. In general terms, the actions taken by the individual or commercial entity to protect the system containing the personal identifying information from further breaches;
  6. Advice that directs the person to remain vigilant by reviewing account statements and monitoring credit reports;
  7. Whether notification was delayed as a result of a law enforcement investigation, if that information is reasonably possible to determine at the time the notice is provided. W.S. 6-3-901(b)(iii) through (xiv).

Is Notice To The Government Required?

No.

Is Notice To Credit Reporting Agencies Required?

No.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

The attorney general may bring an action in law or equity to address any violation of this section and for other relief that may be appropriate to ensure proper compliance with this section, to recover damages, or both. Wyo. Stat. Ann. § 40-12-502(f).

Are There Any Exemptions/Exceptions?

Any financial institution as defined in 15 U.S.C. 6809 or federal credit union as defined by 12 U.S.C. 1752 that maintains notification procedures subject to the requirements of 15 U.S.C. 6801(b)(3) and 12 C.F.R. Part 364 Appendix B or Part 748 Appendix B, is deemed to be in compliance with this section if the financial institution notifies affected Wyoming customers in compliance with the requirements of 15 U.S.C. 6801 through 6809 and 12 C.F.R. Part 364 Appendix B or Part 748 Appendix B. Wyo. Stat. Ann. § 40-12-502(c).

Wisconsin

Who Is Covered?

“Entity” means a person, other than an individual, that does any of the following:

  1. Conducts business in this state and maintains personal information in the ordinary course of business.
  2. Licenses personal information in this state.
  3. Maintains for a resident of this state a depository account as defined in s. 815.18 (2) (e).
  4. Lends money to a resident of this state. Wis. Stat. Ann. § 134.98(1)(a).

What Information Is Protected?

“Personal information” means an individual’s last name and the individual’s first name or first initial, in combination with and linked to any of the following elements, if the element is not publicly available information and is not encrypted, redacted, or altered in a manner that renders the element unreadable:

  1. The individual’s social security number.
  2. The individual’s driver’s license number or state identification number.
  3. The number of the individual’s financial account number, including a credit or debit card account number, or any security code, access code, or password that would permit access to the individual’s financial account.
  4. The individual’s deoxyribonucleic acid profile, as defined in s. 939.74 (2d) (a).
  5. The individual’s unique biometric data, including fingerprint, voice print, retina or iris image, or any other unique physical representation. Wis. Stat. Ann. § 134.98(1)(b).

What Is A “Breach”?

Knowledge that personal information of a resident of Wisconsin has been acquired by a person not authorized to acquire the personal information by:

  1. An entity whose principal place of business is located in this state or an entity that maintains or licenses personal information in this state; or
  2. An entity whose principal place of business is not located in this state. Wis. Stat. Ann. § 134.98(2)(a), (b).

What Triggers Notification?

Knowledge that personal information in the entity’s possession has been acquired by a person not authorized to acquire the personal information. Wis. Stat. Ann. § 134.98(2)(a), (b).

However, an entity is not required to provide notice of the acquisition of personal information if any of the following applies:

  1. The acquisition of personal information does not create a material risk of identity theft or fraud to the subject of the personal information. 
  2. The personal information was acquired in good faith by an employee or agent of the entity, if the personal information is used for a lawful purpose of the entity. Wis. Stat. Ann. § 134.98(2)(cm).

How Is Notice Provided To Individuals?

Timing: Subject to the needs of law enforcement, an entity shall provide the notice within a reasonable time, not to exceed 45 days after the entity learns of the acquisition of personal information. A determination as to reasonableness under this paragraph shall include consideration of the number of notices that an entity must provide and the methods of communication available to the entity. Wis. Stat. Ann. § 134.98(3)(a).

Delivery: An entity must provide notice by mail or by a method the entity has previously employed to communicate with the subject of the personal information. If an entity cannot with reasonable diligence determine the mailing address of the subject of the personal information, and if the entity has not previously communicated with the subject of the personal information, the entity shall provide notice by a method reasonably calculated to provide actual notice to the subject of the personal information. Wis. Stat. Ann. § 134.98(3)(b).

Content: The notice shall indicate that the entity knows of the unauthorized acquisition of personal information pertaining to the subject of the personal information. Wis. Stat. Ann. § 134.98(2)(b).

Is Notice To The Government Required?

No.

Is Notice To Credit Reporting Agencies Required?

Yes. If, as the result of a single incident, an entity is required to notify 1,000 or more individuals that personal information pertaining to the individuals has been acquired, the entity shall without unreasonable delay notify all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notices sent to the individuals. Wis. Stat. Ann. § 134.98(2)(br).

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

Failure to comply with this section is not negligence or a breach of any duty, but may be evidence of negligence or a breach of a legal duty. Wis. Stat. Ann. § 134.98(4).

Are There Any Exemptions/Exceptions?

This section does not apply to any of the following: a) An entity that is subject to, and in compliance with, the privacy and security requirements of 15 USC 6801 to 6827, or a person that has a contractual obligation to such an entity, if the entity or person has in effect a policy concerning breaches of information security. b) An entity that is described in 45 CFR 164.104 (a), if the entity complies with the requirements of 45 CFR part 164. Wis. Stat. Ann. § 134.98(3m).

West Virginia

Who Is Covered?

An individual or entity that owns or licenses computerized data that includes personal information. W. Va. Code § 46A-2A-102(a).

What Information Is Protected?

“Personal information” means the first name or first initial and last name linked to any one or more of the following data elements that relate to a resident of this state, when the data elements are neither encrypted nor redacted:

  1. Social security number;
  2. Driver’s license number or state identification card number issued in lieu of a driver’s license; or
  3. Financial account number, or credit card, or debit card number in combination with any required security code, access code or password that would permit access to a resident’s financial accounts. W. Va. Code § 46A-2A-101(6).

What Is A “Breach”?

“Breach of the security of a system” means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information maintained by an individual or entity as part of a database of personal information regarding multiple individuals and that causes the individual or entity to reasonably believe that the breach of security has caused or will cause identity theft or other fraud to any resident of this state. Good faith acquisition of personal information by an employee or agent of an individual or entity for the purposes of the individual or the entity is not a breach of the security of the system, provided that the personal information is not used for a purpose other than a lawful purpose of the individual or entity or subject to further unauthorized disclosure. W. Va. Code § 46A-2A-101(1).

What Triggers Notification?

The discovery or notification of the breach of the security of the system involving any resident of this state whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person and that causes, or the individual or entity reasonably believes has caused or will cause, identity theft or other fraud to any resident of this state. W. Va. Code § 46A-2A-102(a).

An individual or entity must give notice of the breach of the security of the system if encrypted information is accessed and acquired in an unencrypted form or if the security breach involves a person with access to the encryption key and the individual or entity reasonably believes that such breach has caused or will cause identity theft or other fraud to any resident of this state. W. Va. Code § 46A-2A-102(b).

How Is Notice Provided To Individuals?

Timing: The notice must be made without reasonable delay, subject to the needs of law enforcement. W. Va. Code § 46A-2A-102(a).

Delivery: Notice may be by:

  1. Written notice to the postal address in the records of the individual or entity;
  2. Telephonic notice;
  3. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures, set forth in Section 7001, United States Code Title 15, Electronic Signatures in Global and National Commerce Act;
  4. Substitute notice, if the individual or the entity required to provide notice demonstrates that the cost of providing notice will exceed $50,000 or that the affected class of residents to be notified exceeds 100,000 persons or that the individual or the entity does not have sufficient contact information or to provide notice as described [above]. Substitute notice consists of any two of the following: (i) E-mail notice if the individual or the entity has e-mail addresses for the members of the affected class of residents; (ii) Conspicuous posting of the notice on the website of the individual or the entity if the individual or the entity maintains a website; or (iii) Notice to major statewide media. W. Va. Code § 46A-2A-101(7).

Content: The notice must include:

  1. To the extent possible, a description of the categories of information that were reasonably believed to have been accessed or acquired by an unauthorized person, including social security numbers, driver’s licenses or state identification numbers and financial data;
  2. A telephone number or website address that the individual may use to contact the entity or the agent of the entity and from whom the individual may learn: a) What types of information the entity maintained about that individual or about individuals in general; and b) Whether or not the entity maintained information about that individual.
  3. The toll-free contact telephone numbers and addresses for the major credit reporting agencies and information on how to place a fraud alert or security freeze. W. Va. Code § 46A-2A-102(d).

Is Notice To The Government Required?

No.

Is Notice To Credit Reporting Agencies Required?

Yes. If an entity is required to notify more than one thousand persons of a breach of security pursuant to this article, the entity shall also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on a nationwide basis of the timing, distribution and content of the notices. Nothing in this subsection shall be construed to require the entity to provide to the consumer reporting agency the names or other personal identifying information of breach notice recipients. This subsection shall not apply to an entity who is subject to Title V of the Gramm Leach Bliley Act. W. Va. Code § 46A-2A-102(f).

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

Failure to comply with the notice provisions constitutes an unfair or deceptive act or practice and may be enforced by the Attorney General pursuant to the enforcement provisions of this chapter. W. Va. Code § 46A-2A-104(a).

No civil penalty may be assessed in an action unless the court finds that the defendant has engaged in a course of repeated and willful violations of this article. No civil penalty shall exceed $150,000 per breach of security of the system or series of breaches of a similar nature that are discovered in a single investigation. W. Va. Code § 46A-2A-104(b).

A violation by a licensed financial institution is enforceable exclusively by the financial institution’s primary functional regulator. W. Va. Code § 46A-2A-104(c).

Are There Any Exemptions/Exceptions?

An entity that maintains its own notification procedures as part of an information privacy or security policy for the treatment of personal information and that are consistent with the timing requirements of this article shall be deemed to be in compliance with the notification requirements of this article if it notifies residents of this state in accordance with its procedures in the event of a breach of security of the system. W. Va. Code § 46A-2A-103(a).

Additionally, a financial institution that responds in accordance with the notification guidelines prescribed by the Federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice is deemed to be in compliance with this article. W. Va. Code § 46A-2A-103(b).

Also, an entity that complies with the notification requirements or procedures pursuant to the rules, regulations, procedures or guidelines established by the entity’s primary or functional regulator shall be in compliance with this article. W. Va. Code § 46A-2A-103(c).

Washington

Who Is Covered?

Any person or business that conducts business in Washington and that owns or licenses data that includes personal information. Wash. Rev. Code Ann. § 19.255.010(1).

What Information Is Protected?

“Personal information” is:

A. An individual’s first name or first initial and last name in combination with any one or more of the following data elements:

  1. Social security number;
  2. Driver’s license number or Washington identification card number;
  3. Account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account, or any other numbers or information that can be used to access a person’s financial account;
  4. Full date of birth;
  5. Private key that is unique to an individual and that is used to authenticate or sign an electronic record;
  6. Student, military, or passport identification number;
  7. Health insurance policy number or health insurance identification number;
  8. Any information about a consumer’s medical history or mental or physical condition or about a health care professional’s medical diagnosis or treatment of the consumer; or
  9. Biometric data generated by automatic measurements of an individual’s biological characteristics such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that is used to identify a specific individual;

B. Username or email address in combination with a password or security questions and answers that would permit access to an online account; and

C. Any of the data elements or any combination of the data elements described in subsection A, above, without the consumer’s first name or first initial and last name if:

  1. Encryption, redaction, or other methods have not rendered the data element or combination of data elements unusable; and
  2. The data element or combination of data elements would enable a person to commit identity theft against a consumer. Rev. Code Wash. (ARCW) § 19.255.005(2)(a).

What Is A “Breach”?

“Breach of the security of the system” means unauthorized acquisition of data that compromises the security, confidentiality, or integrity of personal information maintained by the person or business. Good faith acquisition of personal information by an employee or agent of the person or business for the purposes of the person or business is not a breach of the security of the system when the personal information is not used or subject to further unauthorized disclosure. Wash. Rev. Code Ann. § 19.255.005(1).

What Triggers Notification?

Any breach of the security of the system involving a resident’s personal information that was, or is reasonably believed to have been, acquired by an unauthorized person and the personal information was not secured. Wash. Rev. Code Ann. § 19.255.010(1).

Likelihood of Harm Analysis: Notice is not required if the breach of the security of the system is not reasonably likely to subject consumers to a risk of harm. The breach of secured personal information must be disclosed if the information acquired and accessed is not secured during a security breach or if the confidential process, encryption key, or other means to decipher the secured information was acquired by an unauthorized person. Wash. Rev. Code Ann. § 19.255.010(1).

How Is Notice Provided To Individuals?

Timing: Notification to affected consumers must be made in the most expedient time possible, without unreasonable delay, and no more than 30 calendar days after the breach was discovered, unless the delay is at the request of law enforcement or the delay is due to any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Wash. Rev. Code Ann. § 19.255.010(8).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. Sec. 7001;
  3. Substitute notice, if the person or business demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars, or that the affected class of subject persons to be notified exceeds five hundred thousand, or the person or business does not have sufficient contact information. Substitute notice shall consist of all of the following: (i) Email notice when the person or business has an email address for the subject persons; (ii) Conspicuous posting of the notice on the website page of the person or business, if the person or business maintains one; and (iii) Notification to major statewide media. Wash. Rev. Code Ann. § 19.255.010(4)(a)-(c).

If the breach of the security of the system involves personal information including a user name or password, notice may be provided electronically or by email. The notice must inform the person whose personal information has been breached to promptly change his or her password and security question or answer, as applicable, or to take other appropriate steps to protect the online account with the person or business and all other online accounts for which the person whose personal information has been breached uses the same user name or email address and password or security question or answer. Wash. Rev. Code Ann. § 19.255.010(4)(d)(i).

However, when the breach of the security of the system involves login credentials of an email account furnished by the person or business, the person or business may not provide the notification to that email address, but must provide notice using another method described [above]. The notice must inform the person whose personal information has been breached to promptly change his or her password and security question or answer, as applicable, or to take other appropriate steps to protect the online account with the person or business and all other online accounts for which the person whose personal information has been breached uses the same user name or email address and password or security question or answer. Wash. Rev. Code Ann. § 19.255.010(4)(d)(ii).

Content: The notice must be written in plain language and include the following information:

  1. The name and contact information of the reporting person or business subject to this section;
  2. A list of the types of personal information that were or are reasonably believed to have been the subject of a breach;
  3. A time frame of exposure, if known, including the date of the breach and the date of the discovery of the breach; and
  4. The toll-free telephone numbers and addresses of the major credit reporting agencies if the breach exposed personal information. Wash. Rev. Code Ann. § 19.255.010(6).

Is Notice To The Government Required?

Yes. Any person or business that is required to issue a notification pursuant to this section to more than 500 Washington residents as a result of a single breach shall notify the attorney general of the breach no more than 30 days after the breach was discovered. The notice must include:

  1. The number of Washington consumers affected by the breach, or an estimate if the exact number is not known;
  2. A list of the types of personal information that were or are reasonably believed to have been the subject of a breach;
  3. A time frame of exposure, if known, including the date of the breach and the date of the discovery of the breach;
  4. A summary of steps taken to contain the breach; and
  5. A single sample copy of the security breach notification, excluding any personally identifiable information. Wash. Rev. Code Ann. § 19.255.010(7).

Is Notice To Credit Reporting Agencies Required?

No.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

The attorney general may bring an action in the name of the state, or as parens patriae on behalf of persons residing in the state, to enforce this chapter. For actions brought by the attorney general to enforce this chapter, the legislature finds that the practices covered by this chapter are matters vitally affecting the public interest for the purpose of applying the consumer protection act, chapter 19.86 RCW. For actions brought by the attorney general to enforce this chapter, a violation of this chapter is not reasonable in relation to the development and preservation of business and is an unfair or deceptive act in trade or commerce and an unfair method of competition for purposes of applying the consumer protection act, chapter 19.86 RCW. Wash. Rev. Code Ann. § 19.255.040(2).

Additionally, any consumer injured by a violation of this chapter may institute a civil action to recover damages. Wash. Rev. Code Ann. § 19.255.040(3).

Are There Any Exemptions/Exceptions?

A covered entity under the federal Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. Sec. 1320d et seq., is deemed to have complied with the requirements of this chapter with respect to protected health information if it has complied with section 13402 of the federal Health Information Technology for Economic and Clinical Health Act, P.L. 111-5 as it existed on July 24, 2015. Covered entities shall notify the attorney general pursuant to RCW 19.255.010(7) in compliance with the timeliness of notification requirements of section 13402 of the federal Health Information Technology for Economic and Clinical Health Act, P.L. 111-5 as it existed on July 24, 2015, notwithstanding the timeline in RCW 19.255.010(7). Wash. Rev. Code Ann. § 19.255.030(1).

Additionally, a financial institution under the authority of the Office of the Comptroller of the Currency, the Federal Deposit Insurance Corporation, the National Credit Union Administration, or the Federal Reserve System is deemed to have complied with the requirements of this chapter with respect to “sensitive customer information” as defined in the Interagency Guidelines Establishing Information Security Standards, 12 C.F.R. Part 30, Appendix B, 12 C.F.R. Part 208, Appendix D-2, 12 C.F.R. Part 225, Appendix F, and 12 C.F.R. Part 364, Appendix B, and 12 C.F.R. Part 748, Appendices A and B, as they existed on July 24, 2015, if the financial institution provides notice to affected consumers pursuant to the interagency guidelines and the notice complies with the customer notice provisions of the Interagency Guidelines Establishing Information Security Standards and the Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice under 12 C.F.R. Part 364 as it existed on July 24, 2015. The entity shall notify the attorney general pursuant to RCW 19.255.010 in addition to providing notice to its primary federal regulator. Wash. Rev. Code Ann. § 19.255.030(2).

Payment Processors

Note: Additional requirements apply to a person or entity “that directly processes or transmits account information for or on behalf of another person as part of a payment processing service.” See Wash. Rev. Code Ann. § 19.255.020.

Virginia

Who Is Covered?

An individual or entity that owns or licenses computerized data that includes personal information. Va. Code Ann. § 18.2-186.6(B).

What Information Is Protected?

“Personal information” means the first name or first initial and last name in combination with and linked to any one or more of the following data elements that relate to a resident of the Commonwealth, when the data elements are neither encrypted nor redacted:

  1. Social security number.
  2. Driver’s license number or state identification card number issued in lieu of a driver’s license number;
  3. Financial account number, or credit card or debit card number, in combination with any required security code, access code, or password that would permit access to a resident’s financial accounts;
  4. Passport number; or
  5. Military identification number. Va. Code Ann. § 18.2-186.6(A).

What Is A “Breach”?

“Breach of the security of the system” means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information maintained by an individual or entity as part of a database of personal information regarding multiple individuals and that causes, or the individual or entity reasonably believes has caused, or will cause, identity theft or other fraud to any resident of the Commonwealth. Good faith acquisition of personal information by an employee or agent of an individual or entity for the purposes of the individual or entity is not a breach of the security of the system, provided that the personal information is not used for a purpose other than a lawful purpose of the individual or entity or subject to further unauthorized disclosure. Va. Code Ann. § 18.2-186.6(A).

What Triggers Notification?

If unencrypted or unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person and causes, or the individual or entity reasonably believes has caused or will cause, identity theft or another fraud to any resident. Va. Code Ann. § 18.2-186.6(B).

How Is Notice Provided To Individuals?

Timing: Notification must be made without unreasonable delay. Notice may be reasonably delayed to allow the individual or entity to determine the scope of the breach of the security of the system and restore the reasonable integrity of the system. Notice required by this section may be delayed if, after the individual or entity notifies a law-enforcement agency, the law-enforcement agency determines and advises the individual or entity that the notice will impede a criminal or civil investigation, or homeland or national security. Notice shall be made without unreasonable delay after the law-enforcement agency determines that the notification will no longer impede the investigation or jeopardize national or homeland security. Va. Code Ann. § 18.2-186.6(B).

Delivery: Notice may be by:

  1. Written notice to the last known postal address in the records of the individual or entity;
  2. Telephone notice;
  3. Electronic notice; or
  4. Substitute notice, if the individual or the entity required to provide notice demonstrates that the cost of providing notice will exceed $50,000, the affected class of Virginia residents to be notified exceeds 100,000 residents, or the individual or the entity does not have sufficient contact information or consent to provide notice as described in subdivisions 1, 2, or 3 of this definition. Substitute notice consists of all of the following: a) E-mail notice if the individual or the entity has e-mail addresses for the members of the affected class of residents; b) Conspicuous posting of the notice on the website of the individual or the entity if the individual or the entity maintains a website; and  c) Notice to major statewide media. Va. Code Ann. § 18.2-186.6(A).

Content: The notice must contain a description of:

  1. The incident in general terms; 
  2. The type of personal information that was subject to the unauthorized access and acquisition;
  3. The general acts of the individual or entity to protect the personal information from further unauthorized access;
  4. A telephone number that the person may call for further information and assistance, if one exists; and
  5. Advice that directs the person to remain vigilant by reviewing account statements and monitoring free credit reports. Va. Code Ann. § 18.2-186.6(A).

Is Notice To The Government Required?

Yes. In the event an individual or entity provides notice to more than 1,000 persons at one time pursuant to this section, the individual or entity shall notify, without unreasonable delay, the Office of the Attorney General and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notice.

Is Notice To Credit Reporting Agencies Required?

Yes. See above.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

The Attorney General may bring an action to address violations of this section. The Office of the Attorney General may impose a civil penalty not to exceed $150,000 per breach of the security of the system or a series of breaches of a similar nature that are discovered in a single investigation. Nothing in this section shall limit an individual from recovering direct economic damages from a violation of this section. A violation of this section by a state-chartered or licensed financial institution shall be enforceable exclusively by the financial institution’s primary state regulator. Va. Code Ann. § 18.2-186.6(I), (J).

Are There Any Exemptions/Exceptions?

An entity that maintains its own notification procedures as part of an information privacy or security policy for the treatment of personal information that are consistent with the timing requirements of this section shall be deemed to be in compliance with the notification requirements of this section if it notifies residents of the Commonwealth in accordance with its procedures in the event of a breach of the security of the system. Va. Code Ann. § 18.2-186.6(F).

Additionally, an entity that is subject to Title V of the Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.) and maintains procedures for notification of a breach of the security of the system in accordance with the provision of that Act and any rules, regulations, or guidelines promulgated thereto shall be deemed to be in compliance with this section. Va. Code Ann. § 18.2-186.6(G).

Finally, an entity that complies with the notification requirements or procedures pursuant to the rules, regulations, procedures, or guidelines established by the entity’s primary or functional state or federal regulator shall be in compliance with this section. Va. Code Ann. § 18.2-186.6(H).

Breach of Medication Information

NOTE: Similar notification requirements apply to a breach of medical information. See Va. Code Ann. § 32.1-127.1:05.

Vermont

Who Is Covered?

“Data collector” means a person who, for any purpose, whether by automated collection or otherwise, handles, collects, disseminates, or otherwise deals with personally identifiable information, and includes the state, state agencies, political subdivisions of the state, public and private universities, privately and publicly held corporations, limited liability companies, financial institutions, and retail operators. Vt. Stat. Ann. tit. 9, § 2430(6).

What Information Is Protected?

“Personally identifiable information” means a consumer’s first name or first initial and last name in combination with one or more of the following digital data elements, when the data elements are not encrypted, redacted, or protected by another method that renders them unreadable or unusable by unauthorized persons:

  1. A Social Security number;
  2. A driver license or nondriver state identification card number, individual taxpayer identification number, passport number, military identification card number, or other identification number that originates from a government identification document that is commonly used to verify identity for a commercial transaction;
  3. A financial account number or credit or debit card number, if the number could be used without additional identifying information, access codes, or passwords;
  4. A password, personal identification number, or other access code for a financial account;
  5. Unique biometric data generated from measurements or technical analysis of human body characteristics used by the owner or licensee of the data to identify or authenticate the consumer, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data;
  6. Genetic information; and
  7. (a) health records or records of a wellness program or similar program of health promotion or disease prevention; (b) a health care professional’s medical diagnosis or treatment of the consumer; or (c) a health insurance policy number. Vt. Stat. Ann. tit. 9, § 2430(10).

“Login credentials” means a consumer’s user name or email address, in combination with a password or an answer to a security question, that together permit access to an online account. Vt. Stat. Ann. tit. 9, § 2430(9).

What Is A “Breach”?

“Security breach” means unauthorized acquisition of electronic data or a reasonable belief of an unauthorized acquisition of electronic data that compromises the security, confidentiality, or integrity of a consumer’s personally identifiable information or login credentials maintained by a data collector. Vt. Stat. Ann. tit. 9, § 2430(13).

In determining whether personally identifiable information or login credentials have been acquired or is reasonably believed to have been acquired by a person without valid authorization, a data collector may consider the following factors, among others:

  1. Indications that the information is in the physical possession and control of a person without valid authorization, such as a lost or stolen computer or other device containing information;
  2. Indications that the information has been downloaded or copied;
  3. Indications that the information was used by an unauthorized person, such as fraudulent accounts opened or instances of identity theft reported; or
  4. That the information has been made public. Vt. Stat. Ann. tit. 9, § 2430(13)(C).

Likelihood of Harm Analysis: Notice of a security breach is not required if the data collector establishes that misuse of personally identifiable information or login credentials is not reasonably possible and the data collector provides notice of the determination that the misuse of the personally identifiable information or login credentials is not reasonably possible pursuant to the requirements of this subsection. If the data collector establishes that misuse of the personally identifiable information or login credentials is not reasonably possible, the data collector shall provide notice of its determination that misuse of the personally identifiable information or login credentials is not reasonably possible and a detailed explanation for said determination to the Vermont Attorney General or to the Department of Financial Regulation in the event that the data collector is a person or entity licensed or registered with the Department under Title 8 or this title. Vt. Stat. Ann. tit. 9, § 2435(d)(1).

What Triggers Notification?

Discovery or notification to the data collector of the breach. Vt. Stat. Ann. tit. 9, § 2435(b)(1).

How Is Notice Provided To Individuals?

Timing: Notice of the security breach shall be made in the most expedient time possible and without unreasonable delay, but not later than 45 days after the discovery or notification, consistent with the legitimate needs of the law enforcement agency or with any measures necessary to determine the scope of the security breach and restore the reasonable integrity, security, and confidentiality of the data system. Vt. Stat. Ann. tit. 9, § 2435(b)(1).

Delivery: Delivery may be by direct notice or substitute notice. If by direct notice, it may be by:

  1. Written notice mailed to the consumer’s residence;
  2. Electronic notice, for those consumers for whom the data collector has a valid email address if: a) the data collector’s primary method of communication with the consumer is by electronic means, the electronic notice does not request or contain a hypertext link to a request that the consumer provide personal information, and the electronic notice conspicuously warns consumers not to provide personal information in response to electronic communications regarding security breaches; or b) the notice is consistent with the provisions regarding electronic records and signatures for notices in 15 U.S.C. § 7001; or
  3. Telephonic notice, provided that telephonic contact is made directly with each affected consumer and not through a prerecorded message.

Substitute notice may be made by conspicuously posting the notice on the data collector’s website if the data collector maintains one and notifying major statewide and regional media if:

  1. The data collector demonstrates that the lowest cost of providing notice to affected consumers pursuant to subdivision (6)(A) of this subsection among written, email, or telephonic notice would exceed $10,000; or
  2. The data collector does not have sufficient contact information. Vt. Stat. Ann. tit. 9, § 2435(b)(6).

Content: The notice sent to consumers must be clear and conspicuous and include each of the following, if known:

  1. The incident in general terms;
  2. The type of personally identifiable information that was subject to the security breach;
  3. The general acts of the data collector to protect the personally identifiable information from further security breach;
  4. A telephone number, toll-free if available, that the consumer may call for further information and assistance;
  5. Advice that directs the consumer to remain vigilant by reviewing account statements and monitoring free credit reports; and
  6. The approximate date of the security breach. Vt. Stat. Ann. tit. 9, § 2435(b)(5).

If a security breach is limited to an unauthorized acquisition of login credentials for an online account other than an email account the data collector shall provide notice of the security breach to the consumer electronically or through one or more of the methods specified above and shall advise the consumer to take steps necessary to protect the online account, including to change his or her login credentials for the account and for any other account for which the consumer uses the same login credentials. Vt. Stat. Ann. tit. 9, § 2435(d)(3).

If a security breach is limited to an unauthorized acquisition of login credentials for an email account: (A) the data collector shall not provide notice of the security breach through the email account; and (B) the data collector shall provide notice of the security breach through one or more of the methods specified above or by clear and conspicuous notice delivered to the consumer online when the consumer is connected to the online account from an Internet protocol address or online location from which the data collector knows the consumer customarily accesses the account. Vt. Stat. Ann. tit. 9, § 2435(d)(4).

Is Notice To The Government Required?

Yes. A data collector or other entity regulated by the Department of Financial Regulation under Title 8 or this title shall provide notice of a breach to the Department. All other data collectors or other entities subject to this subchapter shall provide notice of a breach to the Attorney General. The data collector shall notify the Attorney General or the Department, as applicable, of the date of the security breach and the date of discovery of the breach and shall provide a preliminary description of the breach within 14 business days, consistent with the legitimate needs of the law enforcement agency, of the data collector’s discovery of the security breach or when the data collector provides notice to consumers pursuant to this section, whichever is sooner. Vt. Stat. Ann. tit. 9, § 2435(b)(3).

When the data collector provides notice of the breach pursuant to subdivision (1) of this subsection (b), the data collector shall notify the Attorney General or the Department, as applicable, of the number of Vermont consumers affected, if known to the data collector, and shall provide a copy of the notice provided to consumers. The data collector may send to the Attorney General or the Department, as applicable, a second copy of the consumer notice, from which is redacted the type of personally identifiable information or login credentials that was subject to the breach, and which the Attorney General or the Department shall use for any public disclosure of the breach. Vt. Stat. Ann. tit. 9, § 2435(b)(3)(C).

Is Notice To Credit Reporting Agencies Required?

Yes. In the event a data collector provides notice to more than 1,000 consumers at one time pursuant to this section, the data collector shall notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notice. This subsection shall not apply to a person who is licensed or registered under Title 8 by the Department of Financial Regulation. Vt. Stat. Ann. tit. 9, § 2435(c).

Are There Security Measure Standards?

The Social Security Number Protection Act, Vt. Stat. Ann. tit. 9, § 2440, restricts the use of individuals’ social security numbers, and the Document Safe Destruction Act, Vt. Stat. Ann. tit. 9, § 2445, requires that businesses take all reasonable steps to destroy or arrange for the destruction of a customer’s records within its custody or control containing personal information that are no longer to be retained by the business.

What Are The Possible Consequences Of A Violation?

With respect to all data collectors and other entities subject to this subchapter, other than a person or entity licensed or registered with the Department of Financial Regulation under Title 8 or this title, the Attorney General and State’s Attorney shall have sole and full authority to investigate potential violations of this subchapter and to enforce, prosecute, obtain, and impose remedies for a violation of this subchapter or any rules or regulations made pursuant to this chapter as the Attorney General and State’s Attorney have under chapter 63 of this title. Vt. Stat. Ann. tit. 9, § 2435(h)(1).

With respect to a data collector that is a person or entity licensed or registered with the Department of Financial Regulation under Title 8 or this title, the Department of Financial Regulation shall have the full authority to investigate potential violations of this subchapter and to prosecute, obtain, and impose remedies for a violation of this subchapter or any rules or regulations adopted pursuant to this subchapter, as the Department has under Title 8 or this title or any other applicable law or regulation. Vt. Stat. Ann. tit. 9, § 2435(h)(2).

Are There Any Exemptions/Exceptions?

A data collector that is subject to the privacy, security, and breach notification rules adopted pursuant to the federal Health Insurance Portability and Accountability Act is deemed to be in compliance with this subchapter if: a) the data collector experiences a security breach that is limited to personally identifiable information specified in 2430(10)(A)(vii); and b) the data collector provides notice to affected consumers pursuant to the requirements of the breach notification rule in 45 C.F.R. Part 164, Subpart D. Vt. Stat. Ann. tit. 9, § 2435(e).

Additionally, a financial institution that is subject to the following guidances, and any revisions, additions, or substitutions relating to an interagency guidance shall be exempt from this section: 

  1. The Federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information and Customer Notice, issued on March 7, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision. 
  2. Final Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice, issued on April 14, 2005, by the National Credit Union Administration. 
  3. A financial institution regulated by the Department of Financial Regulation that is subject to subdivision (1) or (2) of this subsection (g) shall notify the Department as soon as possible after it becomes aware of an incident involving unauthorized access to or use of personally identifiable information. Vt. Stat. Ann. tit. 9, § 2435(g).

Texas

Who Is Covered?

A person who conducts business in Texas and owns or licenses computerized data that includes sensitive personal information. Tex. Bus. & Com. Code § 521.053(b).

 

What Information Is Protected?

“Personal identifying information” means information that alone or in conjunction with other information identifies an individual, including an individual’s:

 

  1. Name, social security number, date of birth, or government-issued identification number;
  2. Mother’s maiden name;
  3. Unique biometric data, including the individual’s fingerprint, voice print, and retina or iris image;
  4. Unique electronic identification number, address, or routing code; and
  5. Telecommunication access device as defined by Section 32.51, Penal Code. Tex. Bus. & Com. Code § 521.002(a)(1).

“Sensitive personal information” means:

 

  1. An individual’s first name or first initial and last name in combination with any one or more of the following items, if the name and the items are not encrypted: (i) social security number; (ii) driver’s license number or government-issued identification number; or (iii) account number or credit or debit card number in combination with any required security code, access code, or password that would permit access to an individual’s financial account; or
  2. Information that identifies an individual and relates to: (i) the physical or mental health or condition of the individual; (ii) the provision of health care to the individual; or (iii) payment for the provision of health care to the individual. Tex. Bus. & Com. Code § 521.002(a)(2).

 

What Is A “Breach”?

“Breach of system security” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of sensitive personal information maintained by a person, including data that is encrypted if the person accessing the data has the key required to decrypt the data. Good faith acquisition of sensitive personal information by an employee or agent of the person for the purposes of the person is not a breach of system security unless the person uses or discloses the sensitive personal information in an unauthorized manner. Tex. Bus. & Com. Code § 521.053(a).

 

What Triggers Notification?

Discovering or receiving notification of the breach where any individual’s sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Tex. Bus. & Com. Code § 521.053(b).

 

How Is Notice Provided To Individuals?

Non-Residents: If the individual whose sensitive personal information was or is reasonably believed to have been acquired by an unauthorized person is a resident of a state that requires a person [under Texas law] to provide notice of a breach of system security, the notice of the breach of system security may be provided under that state’s law or under Texas law. Tex. Bus. & Com. Code § 521.053(b-1).

Timing: The disclosure shall be made without unreasonable delay and in each case not later than the 60th day after the date on which the person determines that the breach occurred, except as necessary for the needs of law enforcement or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Tex. Bus. & Com. Code § 521.053(b), (d).

Delivery: Notice may be provided by:

 

  1. Written notice at the last known address of the individual;
  2. Electronic notice, if the notice is provided in accordance with 15 U.S.C. Section 7001; or
  3. Substitute notice if it is demonstrated that the cost of providing notice would exceed $250,000, the number of affected persons exceeds 500,000, or the person does not have sufficient contact information, in which case the notice may be given by: a) electronic mail, if the person has electronic mail addresses for the affected persons; b) conspicuous posting of the notice on the person’s website; or c) notice published in or broadcast on major statewide media. Tex. Bus. & Com. Code § 521.053(e), (f).

Content: None specified.

 

Is Notice To The Government Required?

Yes. A person who is required to disclose or provide notification of a breach of system security under this section shall notify the attorney general of that breach as soon as practicable and not later than the 30th day after the date on which the person determines that the breach occurred if the breach involves at least 250 residents of this state. The notification under this subsection must be submitted electronically using a form accessed through the attorney general’s Internet website and must include:

 

  1. A detailed description of the nature and circumstances of the breach or the use of sensitive personal information acquired as a result of the breach;
  2. The number of residents of this state affected by the breach at the time of notification;
  3. the number of affected residents that have been sent a disclosure of the breach by mail or other direct method of communication at the time of notification;
  4. The measures taken by the person regarding the breach;
  5. Any measures the person intends to take regarding the breach after the notification under this subsection; and
  6. Information regarding whether law enforcement is engaged in investigating the breach. Tex. Bus. & Com. Code § 521.053(i).

 

Is Notice To Credit Reporting Agencies Required?

Yes. If a person is required by this section to notify at one time more than 10,000 persons of a breach of system security, the person shall also notify each consumer reporting agency of the timing, distribution, and content of the notices. The person shall provide the notice required by this subsection without unreasonable delay. Tex. Bus. & Com. Code § 521.053(h).

 

Are There Security Measure Standards?

Yes. A business shall implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect from unlawful use or disclosure any sensitive personal information collected or maintained by the business in the regular course of business. Tex. Bus. & Com. Code § 521.052(a).

Additionally, a business shall destroy or arrange for the destruction of customer records containing sensitive personal information within the business’s custody or control that are not to be retained by the business by:(1) shredding; (2) erasing; or (3) otherwise modifying the sensitive personal information in the records to make the information unreadable or indecipherable through any means. Tex. Bus. & Com. Code § 521.052(b).

 

What Are The Possible Consequences Of A Violation?

A person who violates this chapter is liable to this state for a civil penalty of at least $2,000 but not more than $50,000 for each violation. The attorney general may bring an action to recover the civil penalty imposed under this subsection. Tex. Bus. & Com. Code § 521.151(a).

In addition to penalties assessed under Subsection (a), a person who fails to take reasonable action to comply with Section 521.053(b) is liable to this state for a civil penalty of not more than $100 for each individual to whom notification is due under that subsection for each consecutive day that the person fails to take reasonable action to comply with that subsection. Civil penalties under this section may not exceed $250,000 for all individuals to whom notification is due after a single breach. The attorney general may bring an action to recover the civil penalties imposed under this subsection. Tex. Bus. & Com. Code § 521.151(a-1).

 

Are There Any Exemptions/Exceptions?

A person who maintains the person’s own notification procedures as part of an information security policy for the treatment of sensitive personal information that complies with the timing requirements for notice under this section complies with this section if the person notifies affected persons in accordance with that policy. Tex. Bus. & Com. Code § 521.053(g).

Tennessee

Who Is Covered?

“Information holder” means any person or business that conducts business in Tennessee, or any agency of this state or any of its political subdivisions, that owns or licenses computerized personal information of residents of this state. Tenn. Code Ann. § 47-18-2107(a)(3).

What Information Is Protected?

“Personal information” means an individual’s first name or first initial and last name, in combination with any one (1) or more of the following data elements:

  1. Social security number;
  2. Driver license number; or
  3. Account, credit card, or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account. Tenn. Code Ann. § 47-18-2107(a)(4).

What Is A Breach?

“Breach of system security” means the acquisition of the following information by an unauthorized person that materially compromises the security, confidentiality, or integrity of personal information maintained by the information holder:

  1. Unencrypted computerized data; or
  2. Encrypted computerized data and the encryption key. Tenn. Code Ann. § 47-18-2107(a)(1).

What Triggers Notification?

Discovery or notification of a breach of system security by an information holder where the personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Tenn. Code Ann. § 47-18-2107(b).

How Is Notice Provided To Individuals?

Timing: The disclosure must be made no later than forty-five (45) days from the discovery or notification of the breach of system security, unless a longer period of time is required due to the legitimate needs of law enforcement. Tenn. Code Ann. § 47-18-2107(b).

Delivery: Notification may be by:

  1. Written notice;
  2. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001 or if the information holder’s primary method of communication with the resident of this state has been by electronic means; or
  3. Substitute notice, if the information holder demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars ($250,000), that the affected class of subject persons to be notified exceeds five hundred thousand (500,000) persons, or the information holder does not have sufficient contact information and the notice consists of all of the following: (A) Email notice, when the information holder has an email address for the subject persons; (B) Conspicuous posting of the notice on the information holder’s website, if the information holder maintains a website page; and (C) Notification to major statewide media. Tenn. Code Ann. § 47-18-2107(e).

Content: None specified.

Is Notice To The Government Required?

No.

Is Notice To Credit Reporting Agencies Required?

Yes. If an information holder discovers circumstances requiring notification pursuant to this section of more than 1,000 persons at one time, the information holder must also notify, without unreasonable delay, all consumer reporting agencies and credit bureaus that compile and maintain files on consumers on a nationwide basis, of the timing, distribution, and content of the notices. Tenn. Code Ann. § 47-18-2107(g).

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

Any customer of an information holder who is a person or business entity, but who is not an agency of this state or any political subdivision of this state, and who is injured by a violation of this section, may institute a civil action to recover damages and to enjoin the information holder from further action in violation of this section. The rights and remedies available under this section are cumulative to each other and to any other rights and remedies available under law. Tenn. Code Ann. § 47-18-2107(h).

Additionally, in addition to injunctive relief and attorney fees, the attorney general may seek a civil penalty of whichever of the following is greater: a) $10,000; b) $5,000 per day for each day that a person’s identity has been assumed; or c) 10 times the amount obtained or attempted to be obtained by the person using the identity theft.  Tenn. Code Ann. § 47-18-2105.

Are There Any Exemptions/Exceptions?

If an information holder maintains its own notification procedures as part of an information security policy for the treatment of personal information and if the policy is otherwise consistent with the timing requirements of this section, the information holder is in compliance with the notification requirements of this section, as long as the information holder notifies subject persons in accordance with its policies in the event of a breach of system security. Tenn. Code Ann. § 47-18-2107(f).

Additionally, the requirements do not apply to any information holder subject to:

  1. Title V of the Gramm-Leach-Bliley Act; or 
  2. The Health Insurance Portability and Accountability Act. Tenn. Code Ann. § 47-18-2107(i).

South Dakota

Who Is Covered?

“Information holder,” any person or business that conducts business in this state, and that owns or licenses computerized personal or protected information of residents of this state; S.D. Codified Laws § 22-40-19(3).

What Information Is Protected?

“Personal information” is a person’s first name or first initial and last name, in combination with any one or more of the following data elements:

  1. Social security number;
  2. Driver license number or other unique identification number created or collected by a government body;
  3. Account, credit card, or debit card number, in combination with any required security code, access code, password, routing number, PIN, or any additional information that would permit access to a person’s financial account;
  4. Health information as defined in 45 CFR 160.103; or
  5. An identification number assigned to a person by the person’s employer in combination with any required security code, access code, password, or biometric data generated from measurements or analysis of human body characteristics for authentication purposes. S.D. Codified Laws § 22-40-19(4).

“Protected information” includes:

  1. A user name or email address, in combination with a password, security question answer, or other information that permits access to an online account; and
  2. Account number or credit or debit card number, in combination with any required security code, access code, or password that permits access to a person’s financial account. S.D. Codified Laws § 22-40-19(5).

What Is A “Breach”?

“Breach of system security,” the unauthorized acquisition of unencrypted computerized data or encrypted computerized data and the encryption key by any person that materially compromises the security, confidentiality, or integrity of personal or protected information maintained by the information holder. The term does not include the good faith acquisition of personal or protected information by an employee or agent of the information holder for the purposes of the information holder if the personal or protected information is not used or subject to further unauthorized disclosure S.D. Codified Laws § 22-40-19(1).

What Triggers Notification?

Discovery by or notification to an information holder of a breach of system security where personal or protected information was, or is reasonably believed to have been, acquired by an unauthorized person. S.D. Codified Laws § 22-40-20.

An information holder is not required to make a disclosure under this section if, following an appropriate investigation and notice to the attorney general, the information holder reasonably determines that the breach will not likely result in harm to the affected person. The information holder shall document the determination under this section in writing and maintain the documentation for not less than three years. S.D. Codified Laws § 22-40-20.

How Is Notice Provided To Individuals?

Timing: The disclosure must be made not later than sixty days from the discovery or notification of the breach of system security, unless a longer period of time is required due to the legitimate needs of law enforcement. S.D. Codified Laws § 22-40-20.

Delivery: The disclosure may be provided by:

  1. Written notice;
  2. Electronic notice, if the electronic notice is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. Section 7001 in effect as of January 1, 2018, or if the information holder’s primary method of communication with the resident of this state has been by electronic means; or
  3. Substitute notice, if the information holder demonstrates that the cost of providing notice would exceed 250,000, that the affected class of persons to be notified exceeds five hundred thousand persons, or that the information holder does not have sufficient contact information and the notice consists of each of the following: (a) Email notice, if the information holder has an email address for the subject persons; (b) Conspicuous posting of the notice on the information holder’s website, if the information holder maintains a website page; and (c) Notification to statewide media. S.D. Codified Laws § 22-40-22.

Content: None specified.

Is Notice To The Government Required?

Yes. Any information holder that experiences a breach of system security under this section shall disclose to the attorney general by mail or electronic mail any breach of system security that exceeds 250 residents of this state. S.D. Codified Laws § 22-40-20.

Is Notice To Credit Reporting Agencies Required?

Yes. If an information holder discovers circumstances that require notification, the information holder shall also notify, without unreasonable delay, all consumer reporting agencies and any other credit bureau or agency that compiles and maintains files on consumers on a nationwide basis, of the timing, distribution, and content of the notice. S.D. Codified Laws § 22-40-24.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

The attorney general may prosecute each failure to disclose under the provisions of this Act as a deceptive act or practice under Section 37-24-6. In addition to any remedy provided under chapter 37-24, the attorney general may bring an action to recover on behalf of the state a civil penalty of not more than $10,000 per day per violation. The attorney general may recover attorney’s fees and any costs associated with any action brought under this section. S.D. Codified Laws § 22-40-25.

Are There Any Exemptions/Exceptions?

Notwithstanding any other provisions in this Act, any information holder that is regulated by federal law or regulation, including the Health Insurance Portability and Accountability Act or the Gramm Leach Bliley Act and that maintains procedures for a breach of system security pursuant to the laws, rules, regulations, guidance, or guidelines established by its primary or functional federal regulator is deemed to be in compliance with this chapter if the information holder notifies affected South Dakota residents in accordance with the provisions of the applicable federal law or regulation. S.D. Codified Laws § 22-40-26.

Utah

Who Is Covered?

A person who owns or licenses computerized data that includes personal information concerning a Utah resident. Utah Code Ann. § 13-44-202(1)(a).

 

What Information Is Protected?

“Personal information” means a person’s first name or first initial and last name, combined with any one or more of the following data elements relating to that person when either the name or date element is unencrypted or not protected by another method that renders the data unreadable or unusable:

 

  1. Social Security number;
  2. (A) financial account number, or credit or debit card number; and (b) any required security code, access code, or password that would permit access to the person’s account; or
  3. Driver license number or state identification card number. Utah Code Ann. § 13-44-102(4).

 

What Is A “Breach”?

“Breach of system security” means an unauthorized acquisition of computerized data maintained by a person that compromises the security, confidentiality, or integrity of personal information. Utah Code Ann. § 13-44-102(1)(a).

 

What Triggers Notification?

When a person becomes aware of a breach of system security, the person must conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be misused for identity theft or fraud purposes. Notification must be provided if the investigation reveals that the misuse of personal information for identity theft or fraud purposes has occurred, or is reasonably likely to occur, the person shall provide notification to each affected Utah resident. Utah Code Ann. § 13-44-202(1).

 

How Is Notice Provided To Individuals?

Timing: Notification must be made in the most expedient time possible without unreasonable delay considering the legitimate investigative needs of law enforcement, after determining the scope of the breach of system security and after restoring the reasonable integrity of the system. Utah Code Ann. § 13-44-202(2).

Delivery: Notification may be provided:

 

  1. In writing by first-class mail to the most recent address the person has for the resident;
  2. Electronically, if the person’s primary method of communication with the resident is by electronic means, or if provided in accordance with the consumer disclosure provisions of 15 U.S.C. Section 7001;
  3. By telephone, including through the use of automatic dialing technology not prohibited by other law; or
  4. For residents of the state for whom notification in a manner described above is not feasible, by publishing notice of the breach of system security: (A) in a newspaper of general circulation; and (B) as required in Section 45-1-101 [legal notice publication requirements]. Utah Code Ann. § 13-44-202.

Content: None specified.

 

Is Notice To The Government Required?

Yes. If the investigation reveals that the misuse of personal information relating to 500 or more Utah residents, for identity theft or fraud purposes, has occurred or is reasonably likely to occur, the person shall, in addition to the notification required in Subsection (1)(b), provide notification to: 

  1. the office of the Attorney General; and
  2. the Utah Cyber Center. Utah Code Ann. § 13-44-202(1)(c).

 

Is Notice To Credit Reporting Agencies Required?

Yes, if the investigation reveals that the misuse of personal information relating to 1,000 or more Utah residents, for identity theft or fraud purposes, has occurred or is reasonably likely to occur.
Utah Code Ann. § 13-44-202(1)(d).

 

Are There Security Measure Standards?

Yes. Any person who conducts business in the state and maintains personal information shall implement and maintain reasonable procedures to:

 

  1. Prevent unlawful use or disclosure of personal information collected or maintained in the regular course of business; and
  2. Destroy, or arrange for the destruction of, records containing personal information that are not to be retained by the person. 

The destruction of records shall be by: (a) shredding; (b) erasing; or (c) otherwise modifying the personal information to make the information indecipherable. Utah Code Ann. § 13-44-201.

 

What Are The Possible Consequences Of A Violation?

In addition to injunctive relief and attorney fees and costs, the attorney general may seek a civil penalty of:

 

  1. No greater than $2,500 for a violation or series of violations concerning a specific consumer; and
  2. No greater than $100,000 in the aggregate for related violations concerning more than one consumer, unless: a) the violations concern: (i) 10,000 or more consumers who are residents of the state; and (ii) 10,000 or more consumers who are residents of other states; or b) the person agrees to settle for a greater amount. Utah Code Ann. § 13-44-301(3), (4).

 

Are There Any Exemptions/Exceptions?

If a person maintains the person’s own notification procedures as part of an information security policy for the treatment of personal information the person is considered to be in compliance with this chapter’s notification requirements if the procedures are otherwise consistent with this chapter’s timing requirements and the person notifies each affected Utah resident in accordance with the person’s information security policy in the event of a breach. Utah Code Ann. § 13-44-202(5)(b).

Also, a person who is regulated by state or federal law and maintains procedures for a breach of system security under applicable law established by the primary state or federal regulator is considered to be in compliance with this part if the person notifies each affected Utah resident in accordance with the other applicable law in the event of a breach. Utah Code Ann. § 13-44-202(5)(c).

South Carolina

Who Is Covered?

A person conducting business in South Carolina and owning or licensing computerized data or other data that includes personal identifying information. S.C. Code Ann. § 39-1-90(A).

What Information Is Protected?

“Personal identifying information” means the first name or first initial and last name in combination with and linked to any one or more of the following data elements that relate to a resident of this State, when the data elements are neither encrypted nor redacted:

  1. Social security number;
  2. Driver’s license number or state identification card number issued instead of a driver’s license;
  3. Financial account number, or credit card or debit card number in combination with any required security code, access code, or password that would permit access to a resident’s financial account; or
  4. Other numbers or information which may be used to access a person’s financial accounts or numbers or information issued by a governmental or regulatory entity that uniquely will identify an individual. S.C. Code Ann. § 39-1-90(D)(3).

What Is A “Breach”?

“Breach of the security of the system” means unauthorized access to and acquisition of computerized data that was not rendered unusable through encryption, redaction, or other methods that compromises the security, confidentiality, or integrity of personal identifying information maintained by the person, when illegal use of the information has occurred or is reasonably likely to occur or use of the information creates a material risk of harm to a resident. Good faith acquisition of personal identifying information by an employee or agent of the person for the purposes of its business is not a breach of the security of the system if the personal identifying information is not used or subject to further unauthorized disclosure. S.C. Code Ann. § 39-1-90(D)(1).

What Triggers Notification?

The discovery or notification of the breach in the security of the data to a resident whose personal identifying information that was not rendered unusable through encryption, redaction, or other methods was, or is reasonably believed to have been, acquired by an unauthorized person when the illegal use of the information has occurred or is reasonably likely to occur or use of the information creates a material risk of harm to the resident. S.C. Code Ann. § 39-1-90(A).

How Is Notice Provided To Individuals?

Timing: The disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement or with measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. S.C. Code Ann. § 39-1-90(A).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic notice, if the person’s primary method of communication with the individual is by electronic means or is consistent with the provisions regarding electronic records and signatures in Section 7001 of Title 15 USC and Chapter 6, Title 11 of the 1976 Code;
  3. Telephonic notice; or
  4. Substitute notice, if the person demonstrates that the cost of providing notice exceeds two hundred fifty thousand dollars or that the affected class of subject persons to be notified exceeds five hundred thousand or the person has insufficient contact information. Substitute notice consists of: (a) e-mail notice when the person has an e-mail address for the subject persons; (b) conspicuous posting of the notice on the web site page of the person, if the person maintains one; or (c) notification to major statewide media. S.C. Code Ann. § 39-1-90(E).

Content: Not specified.

Is Notice To The Government Required?

Yes. If a business provides notice to more than 1,000 persons at one time pursuant to this section, the business shall notify, without unreasonable delay, the Consumer Protection Division of the Department of Consumer Affairs and all consumer reporting agencies that compile and maintain files on a nationwide basis of the timing, distribution, and content of the notice. S.C. Code Ann. § 39-1-90(K).

Is Notice To Credit Reporting Agencies Required?

Yes. See above.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

A resident of South Carolina who is injured by a violation of this section, in addition to and cumulative of all other rights and remedies available at law, may: (1) institute a civil action to recover damages in case of a willful and knowing violation; (2) institute a civil action that must be limited to actual damages resulting from a violation in case of a negligent violation of this section; (3) seek an injunction to enforce compliance; and (4) recover attorney’s fees and court costs, if successful. S.C. Code Ann. § 39-1-90(G).

Additionally, a person who knowingly and wilfully violates this section is subject to an administrative fine in the amount of one thousand dollars for each resident whose information was accessible by reason of the breach, the amount to be decided by the Department of Consumer Affairs. S.C. Code Ann. § 39-1-90(H).

Are There Any Exemptions/Exceptions?

This section does not apply to a bank or financial institution that is subject to and in compliance with the privacy and security provision of the Gramm-Leach-Bliley Act. S.C. Code Ann. § 39-1-90(I).

Also, a financial institution that is subject to and in compliance with the federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information and Customer Notice, issued March 7, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision, as amended, is considered to be in compliance with this section. S.C. Code Ann. § 39-1-90(J).