Category Archives: Contract Requirements

Colorado

Who Is Covered?

A covered entity that maintains, owns, or licenses computerized data that includes personal information about a resident of Colorado. Colo. Rev. Stat. § 6-1-716(2).

“Covered entity” means a person that maintains, owns, or licenses personal information in the course of the person’s business, vocation, or occupation. “Covered entity” does not include a person acting as a third-party service provider. Colo. Rev. Stat. § 6-1-716(1)(b).

What Information Is Protected?

“Personal information” means:

A. A Colorado resident’s first name or first initial and last name in combination with any one or more of the following data elements that relate to the resident, when the data elements are not encrypted, redacted, or secured by any other method rendering the name or the element unreadable or unusable:

  1. Social security number;
  2. Student, military, or passport identification number;
  3. Driver’s license number or identification card number;
  4. Medical information;
  5. Health insurance identification number; or
  6. Biometric data;

B. A Colorado resident’s username or e-mail address, in combination with a password or security questions and answers, that would permit access to an online account; or

C. A Colorado resident’s account number or credit or debit card number in combination with any required security code, access code, or password that would permit access to that account. Colo. Rev. Stat. § 6-1-716(1)(g).

What Is A “Breach”?

“Security breach” means the unauthorized acquisition of unencrypted computerized data that compromises the security, confidentiality, or integrity of personal information maintained by a covered entity. Good faith acquisition of personal information by an employee or agent of a covered entity for the covered entity’s business purposes is not a security breach if the personal information is not used for a purpose unrelated to the lawful operation of the business or is not subject to further unauthorized disclosure. Colo. Rev. Stat. § 6-1-716(1)(h).

What Triggers Notification?

A determination, following investigation, that there is a likelihood that personal information has been or will be misused. 

Likelihood of Harm Analysis: Notification is not required if the investigation determines that the misuse of information about a Colorado resident has not occurred and is not reasonably likely to occur. Colo. Rev. Stat. § 6-1-716(2)(a).

How Is Notice Provided To Individuals?

Timing: Notice must be made in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system. Colo. Rev. Stat. § 6-1-716(2).

Delivery: Notice may be by:

  1. Written notice to the postal address listed in the records of the covered entity;
  2. Telephonic notice;
  3. Electronic notice, if a primary means of communication by the covered entity with a Colorado resident is by electronic means or the notice provided is consistent with the provisions regarding electronic records and signatures set forth in the federal “Electronic Signatures in Global and National Commerce Act”, 15 U.S.C. sec. 7001 et seq.; or
  4. Substitute notice, if the covered entity required to provide notice demonstrates that the cost of providing notice will exceed $250,000, the affected class of persons to be notified exceeds 250,000 Colorado residents, or the covered entity does not have sufficient contact information to provide notice. Substitute notice consists of all of the following: a) E-mail notice if the covered entity has e-mail addresses for the members of the affected class of Colorado residents; b) Conspicuous posting of the notice on the website page of the covered entity if the covered entity maintains one; and c) Notification to major statewide media. Colo. Rev. Stat. § 6-1-716(1)(f).

Content: In the case of a breach of personal information, notice must include the following information:

  1. The date, estimated date, or estimated date range of the security breach;
  2. A description of the personal information that was acquired or reasonably believed to have been acquired as part of the security breach;
  3. Information that the resident can use to contact the covered entity to inquire about the security breach;
  4. The toll-free numbers, addresses, and websites for consumer reporting agencies;
  5. The toll-free number, address, and website for the Federal Trade Commission; and
  6. A statement that the resident can obtain information from the Federal Trade Commission and the credit reporting agencies about fraud alerts and security freezes. Colo. Rev. Stat. § 6-1-716(2)(a.2).

Is Notice To The Government Required?

Yes. A covered entity that must notify Colorado residents of a data breach must provide notice of any security breach to the Colorado attorney general in the most expedient time possible and without unreasonable delay, but not later than 30 days after the date of determination that a security breach occurred, if the security breach is reasonably believed to have affected 500 Colorado residents or more, unless the investigation determines that the misuse of information about a Colorado resident has not occurred and is not likely to occur. Colo. Rev. Stat. § 6-1-716(2)(f).

Is Notice To Credit Reporting Agencies Required?

Yes. If a covered entity is required to notify more than 1,000 Colorado residents of a security breach pursuant to this section, the covered entity shall also notify, in the most expedient time possible and without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the anticipated date of the notification to the residents and the approximate number of residents who are to be notified. Colo. Rev. Stat. § 6-1-716(2)(d).

Are There Security Measure Standards?

Yes. To protect personal identifying information from unauthorized access, use, modification, disclosure, or destruction, a covered entity that maintains, owns, or licenses personal identifying information of an individual residing in the state shall implement and maintain reasonable security procedures and practices that are appropriate to the nature of the personal identifying information and the nature and size of the business and its operations. Colo. Rev. Stat. § 6-1-713.5(1).

Additionally, unless a covered entity agrees to provide its own security protection for the information it discloses to a third-party service provider, the covered entity shall require that the third-party service provider implement and maintain reasonable security procedures and practices that are:

  1. Appropriate to the nature of the personal identifying information disclosed to the third-party service provider; and
  2. Reasonably designed to help protect the personal identifying information from unauthorized access, use, modification, disclosure, or destruction. Colo. Rev. Stat. § 6-1-713.5(2)

What Are The Possible Consequences Of A Violation?

The attorney general may bring an action in law or equity to address violations of this section, § 6-1-713 [protection of personal identifying information] or § 6-1-715 [confidentiality of social security numbers] and for other relief that may be appropriate to ensure compliance with this section or to recover direct economic damages resulting from a violation, or both. Colo. Rev. Stat. § 6-1-716(4).

Are There Any Exemptions/Exceptions?

Not per se, but a covered entity that maintains its own notification procedures as part of an information security policy for the treatment of personal information and whose procedures are otherwise consistent with the timing requirements of this section is in compliance with the notice requirements of this section if the covered entity notifies affected Colorado residents in accordance with its policies in the event of a security breach; except that notice to the attorney general is still required. Colo. Rev. Stat. § 6-1-716(3)(a).

Additionally, a covered entity that is regulated by state or federal law and that maintains procedures for a security breach pursuant to the laws, rules, regulations, guidances, or guidelines established by its state or federal regulator is in compliance with this section; except that notice to the attorney general is still required. Colo. Rev. Stat. § 6-1-716(3)(b).

Confidentiality Of Social Security Numbers

Note: Additional restrictions apply to the use of social security numbers. See Colo. Rev. Stat. § 6-1-715.

Rhode Island

Who Is Covered?

Any municipal agency, state agency, or person that stores, owns, collects, processes, maintains, acquires, uses, or licenses data that includes personal information. R.I. Gen. Laws Section 11-49.3-4(a)(1).

What Information Is Protected?

“Personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements, when the name and the data elements are not encrypted or are in hard copy, paper format:

  1. Social security number;
  2. Driver’s license number, Rhode Island identification card number, or tribal identification number;
  3. Account number, credit, or debit card number, in combination with any required security code, access code, password, or personal identification number, that would permit access to an individual’s financial account;
  4. Medical or health insurance information; or
  5. Email address with any required security code, access code, or password that would permit access to an individual’s personal, medical, insurance, or financial account. R.I. Gen. Laws Section 11-49.3-3(a)(8).

“Health insurance information” means an individual’s health insurance policy number, subscriber identification number, or any unique identifier used by a health insurer to identify the individual. R.I. Gen. Laws Section 11-49.3-3(a)(3).

“Medical information” means any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional or provider. R.I. Gen. Laws Section 11-49.3-3(a)(4).

What Is A “Breach”?

“Breach of the security of the system” means unauthorized access or acquisition of unencrypted, computerized data information that compromises the security, confidentiality, or integrity of personal information maintained by the municipal agency, state agency, or person. Good-faith acquisition of personal information by an employee or agent of the agency for the purposes of the agency is not a breach of the security of the system; provided, that the personal information is not used or subject to further unauthorized disclosure. R.I. Gen. Laws Section 11-49.3-3(a)(1).

What Triggers Notification?

The disclosure of personal information, or any breach of the security of the system, that poses a significant risk of identity theft to any resident of Rhode Island whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person or entity. R.I. Gen. Laws Section 11-49.3-4(a)(1).

How Is Notice Provided To Individuals?

Timing: The notification must be made in the most expedient time possible, but no later than 45 calendar days after confirmation of the breach and the ability to ascertain the information required to be included in the notification. R.I. Gen. Laws § 11-49.3-4(a)(2).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001; or
  3. Substitute notice, if the municipal agency, state agency, or person demonstrates that the cost of providing notice would exceed $25,000, or that the affected class of subject persons to be notified exceeds 50,000, or the municipal agency, state agency, or person does not have sufficient contact information. Substitute notice shall consist of all of the following: (A) Email notice when the municipal agency, state agency, or person has an email address for the subject persons; (B) Conspicuous posting of the notice on the municipal agency’s, state agency’s or person’s website page, if the municipal agency, state agency, or person maintains one; and (C) Notification to major statewide media. R.I. Gen. Laws Section 11-49.3-3(c).

Content: The notice must include:

  1. A general and brief description of the incident, including how the security breach occurred and the number of affected individuals;
  2. The type of information that was subject to the breach;
  3. Date of breach, estimated date of breach, or the date range within which the breach occurred;
  4. Date that the breach was discovered;
  5. A clear and concise description of any remediation services offered to affected individuals including toll free numbers and websites to contact: (i) The credit reporting agencies; (ii) Remediation service providers; (iii) The attorney general; and
  6. A clear and concise description of the consumer’s ability to file or obtain a police report; how a consumer requests a security freeze and the necessary information to be provided when requesting the security freeze; and that fees may be required to be paid to the consumer reporting agencies. R.I. Gen. Laws § 11-49.3-4(d).

Is Notice To The Government Required?

Yes. In the event that more than 500 Rhode Island residents are to be notified, the municipal agency, state agency, or person shall notify the attorney general and the major credit reporting agencies as to the timing, content, and distribution of the notices and the approximate number of affected individuals. Notification to the attorney general and the major credit reporting agencies shall be made without delaying notice to affected Rhode Island residents. R.I. Gen. Laws Section 11-49.3-4(a)(2).

Is Notice To Credit Reporting Agencies Required?

Yes. See above.

Are There Security Measure Standards?

Yes. A municipal agency, state agency, or person who or that stores, collects, processes, maintains, acquires, uses, owns, or licenses personal information about a Rhode Island resident shall implement and maintain a risk-based information security program that contains reasonable security procedures and practices appropriate to the size and scope of the organization; the nature of the information; and the purpose for which the information was collected in order to protect the personal information from unauthorized access, use, modification, destruction, or disclosure and to preserve the confidentiality, integrity, and availability of such information. A municipal agency, state agency, or person shall not retain personal information for a period longer than is reasonably required to provide the services requested; to meet the purpose for which it was collected; or in accordance with a written retention policy or as may be required by law. A municipal agency, state agency, or person shall destroy all personal information, regardless of the medium that such information is in, in a secure manner, including, but not limited to, shredding, pulverization, incineration, or erasure. R.I. Gen. Laws Section 11-49.3-2(a).

Additionally, a municipal agency, state agency, or person who or that discloses personal information about a Rhode Island resident to a nonaffiliated third party shall require by written contract that the third party implement and maintain reasonable security procedures and practices appropriate to the size and scope of the organization; the nature of the information; and the purpose for which the information was collected in order to protect the personal information from unauthorized access, use, modification, destruction, or disclosure. The provisions of this section shall apply to contracts entered into after the effective date of this act. R.I. Gen. Laws Section 11-49.3-2(b).

What Are The Possible Consequences Of A Violation?

Each reckless violation of this chapter is a civil violation for which a penalty of not more than $100 per record may be adjudged against a defendant. Each knowing and willful violation of this chapter is a civil violation for which a penalty of not more than $200 per record may be adjudged against a defendant. Additionally, whenever the attorney general has reason to believe that a violation has occurred and that proceedings would be in the public interest, the attorney general may bring an action in the name of the state against the business or person in violation. R.I. Gen. Laws Section 11-49.3-5.

Are There Any Exemptions/Exceptions?

  1. Any municipal agency, state agency, or person shall be deemed to be in compliance with the security breach notification requirements of § 11-49.3-4 if: a) The municipal agency, state agency, or person maintains its own security breach procedures as part of an information security policy for the treatment of personal information and otherwise complies with the timing requirements of § 11-49.3-4, and notifies subject persons in accordance with such municipal agency’s, state agency’s, or person’s notification policies in the event of a breach of security; or b) The person maintains a security breach procedure pursuant to the rules, regulations, procedures, or guidelines established by the primary or functional regulator, as defined in 15 U.S.C. § 6809(2), and notifies subject persons in accordance with the policies or the rules, regulations, procedures, or guidelines established by the primary or functional regulator in the event of a breach of security of the system.
  2. A financial institution, trust company, credit union, or its affiliates that is subject to and examined for, and found in compliance with, the Federal Interagency Guidelines on Response Programs for Unauthorized Access to Customer Information and Customer Notice shall be deemed in compliance with this chapter.
  3. A provider of health care, health care service plan, health insurer, or a covered entity governed by the medical privacy and security rules issued by the Federal Department of Health and Human Services, Parts 160 and 164 of Title 45 of the Code of Federal Regulations, established pursuant to the Health Insurance Portability and Accountability Act of 1996 shall be deemed in compliance with this chapter. R.I. Gen. Laws Section 11-49.3-6.

Nevada

Who Is Covered?

Any data collector that owns or licenses computerized data which includes personal information. Nev. Rev. Stat. Ann. § 603A.220(1).

“Data collector” means any governmental agency, institution of higher education, corporation, financial institution or retail operator or any other type of business entity or association that, for any purpose, whether by automated collection or otherwise, handles, collects, disseminates or otherwise deals with nonpublic personal information. Nev. Rev. Stat. Ann. § 603A.030.

What Information Is Protected?

“Personal information” means a natural person’s first name or first initial and last name in combination with any one or more of the following data elements, when the name and data elements are not encrypted:

  1. Social security number.
  2. Driver’s license number, driver authorization card number or identification card number.
  3. Account number, credit card number or debit card number, in combination with any required security code, access code or password that would permit access to the person’s financial account.
  4. A medical identification number or a health insurance identification number.
  5. A user name, unique identifier or electronic mail address in combination with a password, access code or security question and answer that would permit access to an online account. Nev. Rev. Stat. Ann. § 603A.040(1).

What Is A “Breach”?

“Breach of the security of the system data” means unauthorized acquisition of computerized data that materially compromises the security, confidentiality or integrity of personal information maintained by the data collector. The term does not include the good faith acquisition of personal information by an employee or agent of the data collector for a legitimate purpose of the data collector, so long as the personal information is not used for a purpose unrelated to the data collector or subject to further unauthorized disclosure. Nev. Rev. Stat. Ann. § 603A.020.

What Triggers Notification?

The discovery or notification of the breach of data relating to any resident of Nevada whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Nev. Rev. Stat. Ann. § 603A.220(1).

How Is Notice Provided To Individuals?

Timing: The disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the system data. Nev. Rev. Stat. Ann. § 603A.220(1).

Delivery: Notice may be by:

  1. Written notification.
  2. Electronic notification, if the notification provided is consistent with the provisions of the E-Sign Act.
  3. Substitute notification, if the data collector demonstrates that the cost of providing notification would exceed $250,000, the affected class of subject persons to be notified exceeds 500,000 or the data collector does not have sufficient contact information. Nev. Rev. Stat. Ann. § 603A.220(4).

Content: None specified.

Is Notice To The Government Required?

No.

Is Notice To Credit Reporting Agencies Required?

Yes. If a data collector determines that notification is required to be given pursuant to the provisions of this section to more than 1,000 persons at any one time, the data collector shall also notify, without unreasonable delay, any consumer reporting agency that compiles and maintains files on consumers on a nationwide basis, of the time the notification is distributed and the content of the notification. Nev. Rev. Stat. Ann. § 603A.220(6)

Are There Security Measure Standards?

Yes. A data collector that maintains records which contain personal information of a resident of this state shall implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification or disclosure. Nev. Rev. Stat. Ann. § 603A.210(1).

Contract Requirements: Additionally, a contract for the disclosure of the personal information of a resident of this state which is maintained by a data collector must include a provision requiring the person to whom the information is disclosed to implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification or disclosure. Nev. Rev. Stat. Ann. § 603A.210(3).

Payment Cards: If a data collector doing business in this state accepts a payment card in connection with a sale of goods or services, the data collector shall comply with the current version of the Payment Card Industry (PCI) Data Security Standard, as adopted by the PCI Security Standards Council or its successor organization, with respect to those transactions, not later than the date for compliance set forth in the Payment Card Industry (PCI) Data Security Standard or by the PCI Security Standards Council or its successor organization. Nev. Rev. Stat. Ann. § 603A.215(1).

Destruction of Records: A business that maintains records which contain personal information concerning the customers of the business shall take reasonable measures to ensure the destruction of those records when the business decides that it will no longer maintain the records. “Reasonable measures to ensure the destruction” means any method that modifies the records containing the personal information in such a way as to render the personal information contained in the records unreadable or undecipherable, including, without limitation: (1) Shredding of the record containing the personal information; or (2) Erasing of the personal information from the records. Nev. Rev. Stat. Ann. § 603A.200.

What Are The Possible Consequences Of A Violation?

If the Attorney General or a district attorney of any county has reason to believe that any person is violating, proposes to violate or has violated the provisions of Nev. Rev. Stat. Ann. § 603A.010 to 603A.290, inclusive, the Attorney General or district attorney may bring an action against that person to obtain a temporary or permanent injunction against the violation. Nev. Rev. Stat. Ann. § 603A.290.

Are There Any Exemptions/Exceptions?

A data collector will be deemed in compliance with the notification requirements if it:

  1. Maintains its own notification policies and procedures as part of an information security policy for the treatment of personal information that is otherwise consistent with the timing requirements of this section shall be deemed to be in compliance with the notification requirements of this section if the data collector notifies subject persons in accordance with its policies and procedures in the event of a breach of the security of the system data.
  2. Is subject to and complies with the privacy and security provisions of the Gramm-Leach-Bliley Act, 15 U.S.C. §§ 6801, et seq., shall be deemed to be in compliance with the notification requirements of this section. Nev. Rev. Stat. Ann. § 603A.220(5).

Nebraska

Who Is Covered?

An individual or a commercial entity that conducts business in Nebraska and that owns or licenses computerized data that includes personal information about a resident of Nebraska. Neb. Rev. Stat. Ann § 87-803(1).

What Information Is Protected?

Personal information means either of the following:

A. A user name or email address, in combination with a password or security question and answer, that would permit access to an online account; or

B. A Nebraska resident’s first name or first initial and last name in combination with any one or more of the following data elements that relate to the resident if either the name or the data elements are not encrypted, redacted, or otherwise altered by any method or technology in such a manner that the name or data elements are unreadable:

  1. Social security number;
  2. Motor vehicle operator’s license number or state identification card number;
  3. Account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to a resident’s financial account;
  4. Unique electronic identification number or routing code, in combination with any required security code, access code, or password; or
  5. Unique biometric data, such as a fingerprint, voice print, or retina or iris image, or other unique physical representation. Neb. Rev. Stat. Ann § 87-802(5).

What Is A “Breach”?

Breach of the security of the system means the unauthorized acquisition of unencrypted computerized data that compromises the security, confidentiality, or integrity of personal information maintained by an individual or a commercial entity. Good faith acquisition of personal information by an employee or agent of an individual or a commercial entity for the purposes of the individual or the commercial entity is not a breach of the security of the system if the personal information is not used or subject to further unauthorized disclosure. Acquisition of personal information pursuant to a search warrant, subpoena, or other court order or pursuant to a subpoena or order of a state agency is not a breach of the security of the system. Neb. Rev. Stat. Ann § 87-802(1).

What Triggers Notification?

After becoming aware of a breach of the security of the system, determining there is a likelihood that personal information has been or will be used for an unauthorized purpose and that the use of information about a Nebraska resident for an unauthorized purpose has occurred or is reasonably likely to occur. Neb. Rev. Stat. Ann § 87-803(1).

How Is Notice Provided To Individuals?

Timing: Notice shall be made as soon as possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system. Neb. Rev. Stat. Ann § 87-803(1).

Delivery: Notice may be by:

  1. Written notice;
  2. Telephonic notice;
  3. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. 7001; or
  4. Substitute notice, if the individual or commercial entity required to provide notice demonstrates that the cost of providing notice will exceed seventy-five thousand dollars, that the affected class of Nebraska residents to be notified exceeds one hundred thousand residents, or that the individual or commercial entity does not have sufficient contact information to provide notice. Neb. Rev. Stat. Ann § 87-802(4).

Content: None specified.

Is Notice To The Government Required?

Yes. If notice of a breach of security of the system is required, the individual or commercial entity shall also, not later than the time when notice is provided to the Nebraska resident, provide notice of the breach of security of the system to the Attorney General. Neb. Rev. Stat. Ann § 87-803(2).

Is Notice To Credit Reporting Agencies Required?

No.

Are There Security Measure Standards?

Yes. To protect personal information from unauthorized access, acquisition, destruction, use, modification, or disclosure, an individual or a commercial entity that conducts business in Nebraska and owns, licenses, or maintains computerized data that includes personal information about a resident of Nebraska shall implement and maintain reasonable security procedures and practices that are appropriate to the nature and sensitivity of the personal information owned, licensed, or maintained and the nature and size of, and the resources available to, the business and its operations, including safeguards that protect the personal information when the individual or commercial entity disposes of the personal information. Neb. Rev. Stat. Ann § 87-808(1).

Additionally, an individual or commercial entity that discloses computerized data that includes personal information about a Nebraska resident to a nonaffiliated, third-party service provider shall require by contract that the service provider implement and maintain reasonable security procedures and practices that:

  1. Are appropriate to the nature of the personal information disclosed to the service provider; and
  2. Are reasonably designed to help protect the personal information from unauthorized access, acquisition, destruction, use, modification, or disclosure. Neb. Rev. Stat. Ann § 87-808(2).

An individual or commercial entity is in compliance with these security procedures and practices if it:

  1. Complies with a state or federal law that provides greater protection to personal information than the protections that this section provides; or
  2. Complies with the regulations promulgated under Title V of the Gramm-Leach-Bliley Act or the Health Insurance Portability and Accountability Act if the individual or commercial entity is subject to either or both of such acts or sections. Neb. Rev. Stat. Ann § 87-808(3).

What Are The Possible Consequences Of A Violation?

For purposes of the data breach notification requirements, the Attorney General may issue subpoenas and seek and recover direct economic damages for each affected Nebraska resident. Neb. Rev. Stat. Ann § 87-808(1).

A violation of section 87-808 [security standards] shall be considered an unfair or deceptive act or practice under Neb. Rev. Stat. Ann § 59-1602, and the attorney general may seek an injunction and civil penalties. A violation of section 87-808 does not give rise to a private cause of action. Neb. Rev. Stat. Ann § 87-808(2).

Are There Any Exemptions/Exceptions

An individual or a commercial entity that maintains its own notice procedures which are part of an information security policy for the treatment of personal information and which are otherwise consistent with the timing requirements of section 87-803, is deemed to be in compliance with the notice requirements of section 87-803 if the individual or the commercial entity notifies affected Nebraska residents and the Attorney General in accordance with its notice procedures in the event of a breach of the security of the system. Neb. Rev. Stat. Ann § 87-804(2). 

Also, an individual or a commercial entity that is regulated by state or federal law and that maintains procedures for a breach of the security of the system pursuant to the laws, rules, regulations, guidances, or guidelines established by its primary or functional state or federal regulator is deemed to be in compliance with section 87-803 if the individual or commercial entity notifies affected Nebraska residents and the Attorney General in accordance with the maintained procedures in the event of a breach of the security of the system. Neb. Rev. Stat. Ann § 87-804(1).

Maryland

Who Is Covered?

A business that owns, licenses, or maintains computerized data that includes personal information of an individual residing in Maryland. Md. Code Ann., Com. Law § 14-3504(b).

 

What Information Is Protected?

“Personal information” means:

A. An individual’s first name or first initial and last name in combination with any one or more of the following data elements, when the data elements are not encrypted, redacted, or otherwise protected by another method that renders the information unreadable or unusable:

  1. A social security number, an individual taxpayer identification number, a passport number, or other identification number issued by the federal government;
  2. A driver’s license number or state identification card number;
  3. An account number, a credit card number, or a debit card number, in combination with any required security code, access code, or password, that permits access to an individual’s financial account;
  4. Health information, including information about an individual’s mental health;
  5. A health insurance policy or certificate number or health insurance subscriber identification number, in combination with a unique identifier used by an insurer or an employer that is self-insured, that permits access to an individual’s health information; 
  6. Biometric data of an individual generated by automatic measurements of an individual’s biological characteristics such as a fingerprint, voice print, genetic print, retina or iris image, or other unique biological characteristic, that can be used to uniquely authenticate the individual’s identity when the individual accesses a system or account; or
  7. For purposes of the notifications required under § 14-3504(b)(2), (c), (d), (e), (f), and (g) of this subtitle, genetic information with respect to an individual;Md. Code Ann., Com. Law § 14-3501(e).

B. A user name or e-mail address in combination with a password or security question and answer that permits access to an individual’s e-mail account; or

C. For the purposes of the requirements of this title other than the notifications required under § 14-3504(b)(2), (c), (d), (e), (f), and (g) of this subtitle, genetic information with respect to an individual when the genetic information is not encrypted, redacted, or otherwise protected by another method that renders the information unreadable or unusable, including:

  1. Data, regardless of its format, that results from the analysis of a biological sample of the individual or from another source that enables equivalent information to be obtained and that concerns genetic material;
  2. Deoxyribonucleic acids;
  3. Ribonucleic acids;
  4. Genes;
  5. Chromosomes;
  6. Alleles;
  7. Genomes;
  8. Alterations or modifications to deoxyribonucleic acids or ribonucleic acids;
  9. Single nucleotide polymorphisms;
  10. Uninterrupted data that results from the analysis of a biological sample from the individual or other sources; and
  11. Information extrapolated, derived, or inferred from item 1, 2, 3, 4, 5, 6, 7, 8, 9, or 10 of this item. Md. Code Ann., Com. Law § 14-3501

 

What Is A “Breach”?

“Breach of the security of a system” means the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of the personal information maintained by a business. Md. Code Ann., Com. Law § 14-3504(a).

 

What Triggers Notification?

A determination following an investigation that the breach of the security of the system creates a likelihood that personal information has been or will be misused. Md. Code Ann., Com. Law § 14-3504(b).

 

Likelihood of Harm Analysis

Notification to the individual in not necessary if the business reasonably determines that the breach of the security of the system does not create a likelihood that personal information has been or will be misused. Md. Code Ann., Com. Law § 14-3504(c)(2).

 

How Is Notice Provided To Individuals?

Timing: Notice must be given as soon as reasonably practicable, but not later than 45 days after the business discovers or is notified of the breach of the security system. Md. Code Ann., Com. Law § 14-3504(b)(3).

 

Delivery: Notice may be made by:

  1. Written notice sent to the most recent address of the individual in the records of the business;
  2. Electronic mail to the most recent electronic mail address of the individual in the records of the business, if: (i)  The individual has expressly consented to receive electronic notice; or (ii)  The business conducts its business primarily through Internet account transactions or the Internet;
  3. Telephonic notice, to the most recent telephone number of the individual in the records of the business; or
  4. Substitute notice if the business does not have sufficient contact information to give notice in accordance with item (1), (2), or (3) of this subsection. Substitute notice shall consist of: shall consist of: (a) Electronically mailing the notice to an individual entitled to notification under subsection (b) of this section, if the business has an electronic mail address for the individual to be notified; (b) Conspicuous posting of the notice on the website of the business, if the business maintains a website; and (c) Notification to major print or broadcast media in geographic areas where the individuals affected by the breach likely reside.

 

Content: Except for a breach involving only an email account, notification must include:

  1. To the extent possible, a description of the categories of information that were, or are reasonably believed to have been, acquired by an unauthorized person, including which of the elements of personal information were, or are reasonably believed to have been, acquired;
  2. Contact information for the business making the notification, including the business’s address, telephone number, and toll-free telephone number if one is maintained;
  3. The toll-free telephone numbers and addresses for the major consumer reporting agencies; and
  4. The toll-free telephone numbers, addresses, and website addresses for the Federal Trade Commission and the Office of the Attorney General, and a statement that an individual can obtain information from these sources about steps the individual can take to avoid identity theft. Md. Code Ann., Com. Law § 14-3504(g).

If the breach involves only an email account, notification may be made in electronic or other form, subject to several restrictions, that directs the individual whose personal information has been breached promptly to:

  1. Change the individual’s password and security question or answer, as applicable; or
  2. Take other steps appropriate to protect the email account with the business and all other online accounts for which the individual uses the same user name or email and password or security question or answer. Md. Code Ann., Com. Law § 14-3504(i).

 

Is Notice To The Government Required?

Yes, notice must be provided to the Attorney General prior to providing notice to affected residents. The notice shall include, at a minimum: (i) The number of affected individuals residing in the State; (ii) A description of the breach of the security of a system, including when and how it occurred; (iii) Any steps the business has taken or plans to take relating to the breach of the security of a system; and (iv) The form of notice that will be sent to affected individuals and a sample notice. Md. Code Ann., Com. Law § 14-3504(h).

 

Is Notice To Credit Reporting Agencies Required?

Yes. If a business is required under § 14-3504 of this subtitle to give notice of a breach of the security of a system to 1,000 or more individuals, the business also shall notify, without unreasonable delay, each consumer reporting agency that compiles and maintains files on consumers on a nationwide basis of the timing, distribution, and content of the notices. Md. Code Ann., Com. Law § 14-3506(a).

 

Are There Security Measure Standards?

Yes. To protect personal information from unauthorized access, use, modification, or disclosure, a business that owns or licenses personal information of an individual residing in the state shall implement and maintain reasonable security procedures and practices that are appropriate to the nature of the personal information owned or licensed and the nature and size of the business and its operations. Md. Code Ann., Com. Law § 14-3503(a).

Additionally, a business that uses a nonaffiliated third party as a service provider to perform services for the business and discloses personal information about an individual residing in the state under a written contract with the third party shall require by contract that the third party implement and maintain reasonable security procedures and practices that are:

 

  1. Appropriate to the nature of the personal information disclosed to the nonaffiliated third party; and
  2. Reasonably designed to help protect the personal information from unauthorized access, use, modification, disclosure, or destruction.

Data Destruction Standards: When a business is destroying a customer’s, an employee’s, or a former employee’s records that contain personal information of the customer, employee, or former employee, the business shall take reasonable steps to protect against unauthorized access to or use of the personal information, taking into account:

 

  1. The sensitivity of the records;
  2. The nature and size of the business and its operations;
  3. The costs and benefits of different destruction methods; and
  4. Available technology.

 

What Are The Possible Consequences Of A Violation?

A violation is an unfair or deceptive trade practice which allows for enforcement action by the Attorney General and a private right of action for any injury or loss sustained. Md. Code Ann., Com. Law §§ 14-3508; 13-401.

 

Are There Any Exemptions/Exceptions?

A business that complies with the requirements for notification procedures, the protection or security of personal information, or the destruction of personal information under the rules, regulations, procedures, or guidelines established by the primary or functional federal or state regulator of the business shall be deemed to be in compliance with this subtitle. Md. Code Ann., Com. Law § 14-3507(b).

Additionally, businesses that are subject to and in compliance with GLBA, FACTA or HIPAA, among other acts, are deemed to be in compliance. Md. Code Ann., Com. Law § 14-3507(c), (d).

Illinois

Who Is Covered?

“Data Collector” may include, but is not limited to, government agencies, public and private universities, privately and publicly held corporations, financial institutions, retail operators, and any other entity that, for any purpose, handles, collects, disseminates, or otherwise deals with nonpublic personal information. 815 Ill. Comp. Stat. Ann. 530/5.

What Information Is Protected?

“Personal information” means either of the following:

A. User name or email address, in combination with a password or security question and answer that would permit access to an online account, when either the user name or email address or password or security question and answer are not encrypted or redacted or are encrypted or redacted but the keys to unencrypt or unredact or otherwise read the data elements have been obtained through the breach of security.

B. An individual’s first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted or redacted or are encrypted or redacted but the keys to unencrypt or unredact or otherwise read the name or data elements have been acquired without authorization through the breach of security:

  1. Social security number.
  2. Driver’s license number or state identification card number.
  3. Account number or credit or debit card number, or an account number or credit card number in combination with any required security code, access code, or password that would permit access to an individual’s financial account.
  4. Medical information.*
  5. Health insurance information.**
  6. Unique biometric data generated from measurements or technical analysis of human body characteristics used by the owner or licensee to authenticate an individual, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data. 815 Ill. Comp. Stat. Ann. 530/5.

*“Medical information” means any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a healthcare professional, including such information provided to a website or mobile application. 815 Ill. Comp. Stat. Ann. 530/5.

**“Health insurance information” means an individual’s health insurance policy number or subscriber identification number, any unique identifier used by a health insurer to identify the individual, or any medical information in an individual’s health insurance application and claims history, including any appeals records. 815 Ill. Comp. Stat. Ann. 530/5.

What Is A “Breach”?

“Breach of the security of the system data” or “breach” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the data collector. “Breach of the security of the system data” does not include good faith acquisition of personal information by an employee or agent of the data collector for a legitimate purpose of the data collector, provided that the personal information is not used for a purpose unrelated to the data collector’s business or subject to further unauthorized disclosure. 815 Ill. Comp. Stat. Ann. 530/5.

What Triggers Notification?

Discovery or notification of a breach. 815 Ill. Comp. Stat. Ann. 530/10(a).

How Is Notice Provided To Individuals?

Timing: The disclosure notification shall be made in the most expedient time possible and without unreasonable delay, consistent with any measures necessary to determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system. 815 Ill. Comp. Stat. Ann. 530/10(a).

Delivery: Notification may be made by:

  1. Written notice;
  2. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures for notices legally required to be in writing as set forth in Section 7001 of Title 15 of the United States Code; or
  3. Substitute notice, in certain circumstances. 815 Ill. Comp. Stat. Ann. 530/10(c).

Content: The notice must include:

  1. The toll-free numbers and addresses for consumer reporting agencies;
  2. The toll-free number, address, and website address for the Federal Trade Commission; and
  3. A statement that the individual can obtain information from these sources about fraud alerts and security freezes. 815 Ill. Comp. Stat. Ann. 530/10(a)(1).

If the breach involves a user name or email address, in combination with a password or security question and answer that would permit access to an online account, when either the user name or email address or password or security question and answer are not encrypted or redacted or are encrypted or redacted but the keys to unencrypt or unredact or otherwise read the data elements have been obtained through the breach of security, notice may be provided in electronic or other form directing the Illinois resident whose personal information has been breached to promptly change his or her user name or password and security question or answer, as applicable, or to take other steps appropriate to protect all online accounts for which the resident uses the same user name or email address and password or security question and answer. 815 Ill. Comp. Stat. Ann. 530/10(a)(2).

Is Notice To The Government Required?

Yes. If notice must be sent to more than 500 Illinois residents as a result of a single breach, notification must also be sent to the Attorney General in the most expedient time possible and without unreasonable delay but in no event later than when the data collector provides notice to consumers. The notice must include:

  1. A description of the nature of the breach of security or unauthorized acquisition or use.
  2. The number of Illinois residents affected by such incident at the time of notification.
  3. Any steps the data collector has taken or plans to take relating to the incident. 815 Ill. Comp. Stat. Ann. 530/10(e).

Is Notice To Credit Reporting Agencies Required?

No.

Are There Security Measure Standards?

Yes. A data collector that owns or licenses, or maintains or stores but does not own or license, records that contain personal information concerning an Illinois resident shall implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification, or disclosure. 815 Ill. Comp. Stat. Ann. 530/45(a).

Contract Requirements: Additionally, a contract for the disclosure of personal information concerning an Illinois resident that is maintained by a data collector must include a provision requiring the person to whom the information is disclosed to implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification, or disclosure. 815 Ill. Comp. Stat. Ann. 530/45(b).

Data Disposal Requirements: A person must dispose of the materials containing personal information in a manner that renders the personal information unreadable, unusable, and undecipherable. Proper disposal methods include, but are not limited to, the following:

  1. Paper documents containing personal information may be either redacted, burned, pulverized, or shredded so that personal information cannot practicably be read or reconstructed.
  2. Electronic media and other non-paper media containing personal information may be destroyed or erased so that personal information cannot practicably be read or reconstructed. 815 Ill. Comp. Stat. Ann. 530/40(b).

What Are The Possible Consequences Of A Violation?

A violation of the breach notification laws constitutes an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act, 815 Ill. Comp. Stat. Ann. 505/1, et seq., which allows for the imposition of civil penalties by the Attorney General and a private right of action for individuals that have suffered actual damages. 815 Ill. Comp. Stat. Ann. 530/20.

Failure to properly dispose of records containing personal information may result in a civil penalty of not more than $100 for each individual with respect to whom personal information is disposed of in violation of the law. A civil penalty may not, however, exceed $50,000 for each instance of improper disposal of materials containing personal information. The Attorney General may impose a civil penalty after notice to the person accused of violating this Section and an opportunity for that person to be heard in the matter. The Attorney General may file a civil action in the circuit court to recover any penalty imposed under this Section. 815 Ill. Comp. Stat. Ann. 530/40(d).

Are There Any Exemptions/Exceptions?

Any covered entity or business associate that is subject to and in compliance with the privacy and security standards for the protection of electronic health information established pursuant to the federal Health Insurance Portability and Accountability Act of 1996 and the Health Information Technology for Economic and Clinical Health Act shall be deemed to be in compliance with the provisions of this Act, provided that any covered entity or business associate required to provide notification of a breach to the Secretary of Health and Human Services pursuant to the Health Information Technology for Economic and Clinical Health Act also provides such notification to the Attorney General within five business days of notifying the Secretary. 815 Ill. Comp. Stat. Ann. 530/50.

Alabama

Who Is Covered?

A “covered entity” is a person, sole proprietorship, partnership, government entity, corporation, nonprofit, trust, estate, cooperative association, or other business entity that acquires or uses sensitive personally identifying information. Ala. Code § 8-38-2(2).

What Information Is Protected?

“Sensitive Personally Identifying Information” is an Alabama resident’s first name or first initial and last name in combination with one or more of the following with respect to the same Alabama resident:

  1. A non-truncated social security number or tax identification number.
  2. A non-truncated driver’s license number, state-issued identification card number, passport number, military identification number, or other unique identification number issued on a government document used to verify the identity of a specific individual.
  3. A financial account number, including a bank account number, credit card number, or debit card number, in combination with any security code, access code, password, expiration date, or PIN, that is necessary to access the financial account or to conduct a transaction that will credit or debit the financial account.
  4. Any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional.
  5. An individual’s health insurance policy number or subscriber identification number and any unique identifier used by a health insurer to identify the individual.
  6. A user name or email address, in combination with a password or security question and answer that would permit access to an online account affiliated with the covered entity that is reasonably likely to contain or is used to obtain sensitive personally identifying information. Ala. Code § 8-38-2(6)(a).

What Is A “Breach”?

A “breach of security” or “breach” is the unauthorized acquisition of data in electronic form containing sensitive personally identifying information. Acquisition occurring over a period of time committed by the same entity constitutes one breach. Ala. Code § 8-38-2(1).

What Triggers Notification?

Notification is required when a covered entity determines that, as a result of a breach of security, sensitive personally identifying information has been acquired or is reasonably believed to have been acquired by an unauthorized person, and is reasonably likely to cause substantial harm to the individuals to whom the information relates, it shall give notice of the breach to each individual. Ala. Code § 8-38-5(a).

How Is Notice Provided To Individuals?

Timing: Notice to individuals shall be made as expeditiously as possible and without unreasonable delay. Ala. Code § 8-38-5(b).

Delivery: Notice must be given in writing, sent to the mailing address of the individual in the records of the covered entity, or by email notice sent to the email address of the individual in the records of the covered entity. Ala. Code § 8-38-5(d).

Substitute notice is allowed if direct notice is not feasible due to any of the following:

  1. Excessive cost. The term includes either of the following: a) Excessive cost to the covered entity relative to the resources of the covered entity. b) The cost to the covered entity exceeds $500,000.
  2. Lack of sufficient contact information for the individual required to be notified.
  3. The affected individuals exceed 100,000 persons.

Substitute notice must be by both:

  1. A conspicuous notice on the Internet website of the covered entity, if the covered entity maintains a website, for a period of 30 days; and
  2. Notice in print and in broadcast media, including major media in urban and rural areas where the affected individuals reside. Ala. Code § 8-38-6(e).

Content: The notice must include, at a minimum, all of the following:

  1. The date, estimated date, or estimated date range of the breach.
  2. A description of the sensitive personally identifying information that was acquired by an unauthorized person as part of the breach.
  3. A general description of the actions taken by a covered entity to restore the security and confidentiality of the personal information involved in the breach.
  4. A general description of steps an affected individual can take to protect himself or herself from identity theft.
  5. Information that the individual can use to contact the covered entity to inquire about the breach. Ala. Code § 8-38-5(d).

Is Notice To The Government Required?

Yes. If the number of individuals a covered entity is required to notify exceeds 1,000, the entity must provide written notice of the breach to the Attorney General as expeditiously as possible and without unreasonable delay. Ala. Code § 8-38-6(a).

The written notice must include:

  1. A synopsis of the events surrounding the breach at the time that notice is provided.
  2. The approximate number of individuals in the state who were affected by the breach.
  3. Any services related to the breach being offered or scheduled to be offered, without charge, by the covered entity to individuals, and instructions on how to use the services.
  4. The name, address, telephone number, and email address of the employee or agent of the covered entity from whom additional information may be obtained about the breach. Ala. Code § 8-38-6(b).

Is Notice To Credit Reporting Agencies Required?

Yes. If a covered entity discovers circumstances requiring notice of more than 1,000 individuals at a single time, the entity shall also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notices. Ala. Code § 8-38-7.

Are There Security Measure Standards?

Yes. “Reasonable security measures” means security measures practicable for the covered entity to implement and maintain, including consideration of all of the following:

  1. Designation of an employee or employees to coordinate the covered entity’s security measures to protect against a breach of security. An owner or manager may designate himself or herself.
  2. Identification of internal and external risks of a breach of security.
  3. Adoption of appropriate information safeguards to address identified risks of a breach of security and assess the effectiveness of such safeguards.
  4. Retention of service providers, if any, that are contractually required to maintain appropriate safeguards for sensitive personally identifying information.
  5. Evaluation and adjustment of security measures to account for changes in circumstances affecting the security of sensitive personally identifying information.
  6. Keeping the management of the covered entity, including its board of directors, if any, appropriately informed of the overall status of its security measures. Ala. Code § 8-38-3(b).

Additionally, an assessment of a covered entity’s security must be based upon the entity’s reasonable security measures as a whole and shall place an emphasis on data security failures that are multiple or systemic, including consideration of all of the following:

  1. The size of the covered entity.
  2. The amount of sensitive personally identifying information and the type of activities for which the sensitive personally identifying information is accessed, acquired, maintained, stored, utilized, or communicated by, or on behalf of, the covered entity.
  3. The covered entity’s cost to implement and maintain the reasonable security measures to protect against a breach of security relative to its resources. Ala. Code § 8-38-3(c).

Furthermore, a covered entity or third-party agent shall take reasonable measures to dispose, or arrange for the disposal, of records containing sensitive personally identifying information within its custody or control when the records are no longer to be retained pursuant to applicable law, regulations, or business needs. Disposal shall include shredding, erasing, or otherwise modifying the personal information in the records to make it unreadable or undecipherable through any reasonable means consistent with industry standards. Ala. Code § 8-38-10.

What Are The Possible Consequences Of A Violation?

A violation of the notification provisions is an unlawful trade practice under the Alabama Deceptive Trade Practices Act, with penalties not to exceed $500,000 per breach. Additionally, civil penalties of not more than $5,000 per day may be assessed for each consecutive day that the covered entity fails to take reasonable action to comply with the notice provisions. Ala. Code § 8-38-9.

Are There Any Exemptions?

Yes. A) An entity subject to or regulated by federal laws, rules, regulations, procedures, or guidance on data breach notification established or enforced by the federal government; or B) is subject to or regulated by state laws, rules, regulations, procedures, or guidance on data breach notification that are established or enforced by state government, and are at least as thorough as the notice requirements provided in Alabama’s breach notification law, is exempt from this chapter as long as the entity does all of the following:

  1. Maintains procedures pursuant to those laws, rules, regulations, procedures, or guidance.
  2. Provides notice to affected individuals pursuant to those laws, rules, regulations, procedures, or guidance.
  3. Timely provides a copy of the notice to the Attorney General when the number of individuals the entity notified exceeds 1,000.

California

Who Is Covered?

A person or business doing business in California that: (a) owns or licenses computerized data that includes personal information; or (b) maintains computerized data that includes personal information that the person or business does not own. Cal Civ Code § 1798.82(a), (b).

What Information Is Protected?

For the purposes of providing disclosure of a breach, “personal information” is defined as:

A. An individual’s first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted:

  1. Social security number.
  2. Driver’s license number, California identification card number, tax identification number, passport number, military identification number, or other unique identification number issued on a government document commonly used to verify the identity of a specific individual.
  3. Account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account.
  4. Medical information.
  5. Health insurance information.
  6. Unique biometric data generated from measurements or technical analysis of human body characteristics, such as a fingerprint, retina, or iris image, used to authenticate a specific individual. Unique biometric data does not include a physical or digital photograph, unless used or stored for facial recognition purposes.
  7. Information or data collected through the use or operation of an automated license plate recognition system, or

B. A username or email address, in combination with a password or security question and answer that would permit access to an online account. Cal Civ Code § 1798.82(h).

What Is A “Breach”?

“Breach of the security of the system” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the person or business. Good faith acquisition of personal information by an employee or agent of the person or business for the purposes of the person or business is not a breach of the security of the system, provided that the personal information is not used or subject to further unauthorized disclosure. Cal Civ Code § 1798.82(g).

What Triggers Notification?

Discovery or notification of the breach in the security of the data to a resident of California (1) whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, or, (2) whose encrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person and the encryption key or security credential was, or is reasonably believed to have been, acquired by an unauthorized person and the person or business that owns or licenses the encrypted information has a reasonable belief that the encryption key or security credential could render that personal information readable or usable. Cal Civ Code § 1798.82(a).

How Is Notice Provided To Individuals?

Timing: The disclosure shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Cal Civ Code § 1798.82(a).

Delivery: Notice may be provided by one of the following:

  1. Written notice.
  2. Electronic notice, if the notice provided is consistent with the provisions of the E-Sign Act.
  3. Substitute notice, if the person or business demonstrates that the cost of providing notice would exceed $250,000, or that the affected class of subject persons to be notified exceeds 500,000, or the person or business does not have sufficient contact information. Substitute notice must consist of all of the following: a) Email notice when the person or business has an email address for the subject persons. b) Conspicuous posting, for a minimum of 30 days, of the notice on the internet website page of the person or business, if the person or business maintains one. For purposes of this subparagraph, conspicuous posting on the person’s or business’s internet website means providing a link to the notice on the home page or first significant page after entering the internet website that is in larger type than the surrounding text, or in contrasting type, font, or color to the surrounding text of the same size, or set off from the surrounding text of the same size by symbols or other marks that call attention to the link. c) Notification to major statewide media. Cal Civ Code § 1798.82(j).

Content: The statute provides a sample notification form that must include the following information, and the Attorney General provides online forms.

  1. The name and contact information of the reporting person or business subject to this section.
  2. A list of the types of personal information that were or are reasonably believed to have been the subject of a breach.
  3. If the information is possible to determine at the time the notice is provided, then any of the following: (i) the date of the breach, (ii) the estimated date of the breach, or (iii) the date range within which the breach occurred. The notification shall also include the date of the notice.
  4. Whether notification was delayed as a result of a law enforcement investigation, if that information is possible to determine at the time the notice is provided.
  5. A general description of the breach incident, if that information is possible to determine at the time the notice is provided.
  6. The toll-free telephone numbers and addresses of the major credit reporting agencies if the breach exposed a social security number or a driver’s license or California identification card number.
  7. If the person or business providing the notification was the source of the breach, an offer to provide appropriate identity theft prevention and mitigation services, if any, shall be provided at no cost to the affected person for not less than 12 months along with all information necessary to take advantage of the offer to any person whose information was or may have been breached if the breach exposed or may have exposed personal information. Cal Civ Code § 1798.82(d).

Is Notice To The Government Required?

Yes. A person or business that is required to issue a security breach notification pursuant to this section to more than 500 California residents as a result of a single breach of the security system shall electronically submit a single sample copy of that security breach notification, excluding any personally identifiable information, to the Attorney General. Cal Civ Code § 1798.82(f).

Is Notice To Consumer Reporting Agencies Required?

No.

Are There Security Measure Standards?

Yes. A business that owns, licenses, or maintains personal information about a California resident must implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. Cal Civ Code § 1798.81.5(b).

Additionally, a business that discloses personal information about a California resident pursuant to a contract with a nonaffiliated third party that is not subject to subdivision (b) shall require by contract that the third party implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. Cal Civ Code § 1798.81.5(c).

Further, a business shall take all reasonable steps to dispose, or arrange for the disposal, of customer records within its custody or control containing personal information when the records are no longer to be retained by the business by (a) shredding, (b) erasing, or (c) otherwise modifying the personal information in those records to make it unreadable or undecipherable through any means. Cal Civ Code § 1798.81.

These security measure and data disposal requirements do not apply to:

  1. A provider of health care, health care service plan, or contractor regulated by the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1).
  2. A financial institution as defined in Section 4052 of the Financial Code and subject to the California Financial Information Privacy Act (Division 1.2 (commencing with Section 4050) of the Financial Code).
  3. A covered entity governed by the medical privacy and security rules issued by the federal Department of Health and Human Services, Parts 160 and 164 of Title 45 of the Code of Federal Regulations, established pursuant to the Health Insurance Portability and Availability Act of 1996 (HIPAA).
  4. An entity that obtains information under an agreement pursuant to Article 3 (commencing with Section 1800) of Chapter 1 of Division 2 of the Vehicle Code and is subject to the confidentiality requirements of the Vehicle Code.
  5. A business that is regulated by state or federal law providing greater protection to personal information than that provided by this section in regard to the subjects addressed by this section. Compliance with that state or federal law shall be deemed compliance with this section with regard to those subjects. This paragraph does not relieve a business from a duty to comply with any other requirements of other state and federal law regarding the protection and privacy of personal information. Cal Civ Code § 1798.81.5(e).

What Are The Possible Consequences Of A Violation?

Under the breach notification laws, any customer injured by a violation may institute a civil action to recover damages. Additionally, if the business is subject to the California Consumer Privacy Act, a consumer can recover an amount not less than $100 and not greater than $750 per incident or actual damages, whichever is greater, for a violation of the duty to implement and maintain reasonable security procedures and practices. Cal Civ Code § 1798.84(b); Cal Civ Code § 1798.150(a).

The general breach notification law provides for injunctive relief but not civil penalties. Cal Civ Code § 1798.84(e).

Are There Any Exemptions/Exceptions?

The data breach notification law does not contain any exemptions or exceptions, but the California Consumer Privacy Act does not apply to, among other things, personal information collected, processed, sold, or disclosed pursuant to the federal Gramm-Leach-Bliley Act, protected health information that is collected by a covered entity or business associate pursuant to HIPAA and certain activity governed by the FCRA. Cal Civ Code § 1798.145.