Category Archives: Data Destruction Standards

Vermont

Who Is Covered?

“Data collector” means a person who, for any purpose, whether by automated collection or otherwise, handles, collects, disseminates, or otherwise deals with personally identifiable information, and includes the state, state agencies, political subdivisions of the state, public and private universities, privately and publicly held corporations, limited liability companies, financial institutions, and retail operators. Vt. Stat. Ann. tit. 9, § 2430(6).

What Information Is Protected?

“Personally identifiable information” means a consumer’s first name or first initial and last name in combination with one or more of the following digital data elements, when the data elements are not encrypted, redacted, or protected by another method that renders them unreadable or unusable by unauthorized persons:

  1. A Social Security number;
  2. A driver license or nondriver state identification card number, individual taxpayer identification number, passport number, military identification card number, or other identification number that originates from a government identification document that is commonly used to verify identity for a commercial transaction;
  3. A financial account number or credit or debit card number, if the number could be used without additional identifying information, access codes, or passwords;
  4. A password, personal identification number, or other access code for a financial account;
  5. Unique biometric data generated from measurements or technical analysis of human body characteristics used by the owner or licensee of the data to identify or authenticate the consumer, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data;
  6. Genetic information; and
  7. (a) health records or records of a wellness program or similar program of health promotion or disease prevention; (b) a health care professional’s medical diagnosis or treatment of the consumer; or (c) a health insurance policy number. Vt. Stat. Ann. tit. 9, § 2430(10).

“Login credentials” means a consumer’s user name or email address, in combination with a password or an answer to a security question, that together permit access to an online account. Vt. Stat. Ann. tit. 9, § 2430(9).

What Is A “Breach”?

“Security breach” means unauthorized acquisition of electronic data or a reasonable belief of an unauthorized acquisition of electronic data that compromises the security, confidentiality, or integrity of a consumer’s personally identifiable information or login credentials maintained by a data collector. Vt. Stat. Ann. tit. 9, § 2430(13).

In determining whether personally identifiable information or login credentials have been acquired or is reasonably believed to have been acquired by a person without valid authorization, a data collector may consider the following factors, among others:

  1. Indications that the information is in the physical possession and control of a person without valid authorization, such as a lost or stolen computer or other device containing information;
  2. Indications that the information has been downloaded or copied;
  3. Indications that the information was used by an unauthorized person, such as fraudulent accounts opened or instances of identity theft reported; or
  4. That the information has been made public. Vt. Stat. Ann. tit. 9, § 2430(13)(C).

Likelihood of Harm Analysis: Notice of a security breach is not required if the data collector establishes that misuse of personally identifiable information or login credentials is not reasonably possible and the data collector provides notice of the determination that the misuse of the personally identifiable information or login credentials is not reasonably possible pursuant to the requirements of this subsection. If the data collector establishes that misuse of the personally identifiable information or login credentials is not reasonably possible, the data collector shall provide notice of its determination that misuse of the personally identifiable information or login credentials is not reasonably possible and a detailed explanation for said determination to the Vermont Attorney General or to the Department of Financial Regulation in the event that the data collector is a person or entity licensed or registered with the Department under Title 8 or this title. Vt. Stat. Ann. tit. 9, § 2435(d)(1).

What Triggers Notification?

Discovery or notification to the data collector of the breach. Vt. Stat. Ann. tit. 9, § 2435(b)(1).

How Is Notice Provided To Individuals?

Timing: Notice of the security breach shall be made in the most expedient time possible and without unreasonable delay, but not later than 45 days after the discovery or notification, consistent with the legitimate needs of the law enforcement agency or with any measures necessary to determine the scope of the security breach and restore the reasonable integrity, security, and confidentiality of the data system. Vt. Stat. Ann. tit. 9, § 2435(b)(1).

Delivery: Delivery may be by direct notice or substitute notice. If by direct notice, it may be by:

  1. Written notice mailed to the consumer’s residence;
  2. Electronic notice, for those consumers for whom the data collector has a valid email address if: a) the data collector’s primary method of communication with the consumer is by electronic means, the electronic notice does not request or contain a hypertext link to a request that the consumer provide personal information, and the electronic notice conspicuously warns consumers not to provide personal information in response to electronic communications regarding security breaches; or b) the notice is consistent with the provisions regarding electronic records and signatures for notices in 15 U.S.C. § 7001; or
  3. Telephonic notice, provided that telephonic contact is made directly with each affected consumer and not through a prerecorded message.

Substitute notice may be made by conspicuously posting the notice on the data collector’s website if the data collector maintains one and notifying major statewide and regional media if:

  1. The data collector demonstrates that the lowest cost of providing notice to affected consumers pursuant to subdivision (6)(A) of this subsection among written, email, or telephonic notice would exceed $10,000; or
  2. The data collector does not have sufficient contact information. Vt. Stat. Ann. tit. 9, § 2435(b)(6).

Content: The notice sent to consumers must be clear and conspicuous and include each of the following, if known:

  1. The incident in general terms;
  2. The type of personally identifiable information that was subject to the security breach;
  3. The general acts of the data collector to protect the personally identifiable information from further security breach;
  4. A telephone number, toll-free if available, that the consumer may call for further information and assistance;
  5. Advice that directs the consumer to remain vigilant by reviewing account statements and monitoring free credit reports; and
  6. The approximate date of the security breach. Vt. Stat. Ann. tit. 9, § 2435(b)(5).

If a security breach is limited to an unauthorized acquisition of login credentials for an online account other than an email account the data collector shall provide notice of the security breach to the consumer electronically or through one or more of the methods specified above and shall advise the consumer to take steps necessary to protect the online account, including to change his or her login credentials for the account and for any other account for which the consumer uses the same login credentials. Vt. Stat. Ann. tit. 9, § 2435(d)(3).

If a security breach is limited to an unauthorized acquisition of login credentials for an email account: (A) the data collector shall not provide notice of the security breach through the email account; and (B) the data collector shall provide notice of the security breach through one or more of the methods specified above or by clear and conspicuous notice delivered to the consumer online when the consumer is connected to the online account from an Internet protocol address or online location from which the data collector knows the consumer customarily accesses the account. Vt. Stat. Ann. tit. 9, § 2435(d)(4).

Is Notice To The Government Required?

Yes. A data collector or other entity regulated by the Department of Financial Regulation under Title 8 or this title shall provide notice of a breach to the Department. All other data collectors or other entities subject to this subchapter shall provide notice of a breach to the Attorney General. The data collector shall notify the Attorney General or the Department, as applicable, of the date of the security breach and the date of discovery of the breach and shall provide a preliminary description of the breach within 14 business days, consistent with the legitimate needs of the law enforcement agency, of the data collector’s discovery of the security breach or when the data collector provides notice to consumers pursuant to this section, whichever is sooner. Vt. Stat. Ann. tit. 9, § 2435(b)(3).

When the data collector provides notice of the breach pursuant to subdivision (1) of this subsection (b), the data collector shall notify the Attorney General or the Department, as applicable, of the number of Vermont consumers affected, if known to the data collector, and shall provide a copy of the notice provided to consumers. The data collector may send to the Attorney General or the Department, as applicable, a second copy of the consumer notice, from which is redacted the type of personally identifiable information or login credentials that was subject to the breach, and which the Attorney General or the Department shall use for any public disclosure of the breach. Vt. Stat. Ann. tit. 9, § 2435(b)(3)(C).

Is Notice To Credit Reporting Agencies Required?

Yes. In the event a data collector provides notice to more than 1,000 consumers at one time pursuant to this section, the data collector shall notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notice. This subsection shall not apply to a person who is licensed or registered under Title 8 by the Department of Financial Regulation. Vt. Stat. Ann. tit. 9, § 2435(c).

Are There Security Measure Standards?

The Social Security Number Protection Act, Vt. Stat. Ann. tit. 9, § 2440, restricts the use of individuals’ social security numbers, and the Document Safe Destruction Act, Vt. Stat. Ann. tit. 9, § 2445, requires that businesses take all reasonable steps to destroy or arrange for the destruction of a customer’s records within its custody or control containing personal information that are no longer to be retained by the business.

What Are The Possible Consequences Of A Violation?

With respect to all data collectors and other entities subject to this subchapter, other than a person or entity licensed or registered with the Department of Financial Regulation under Title 8 or this title, the Attorney General and State’s Attorney shall have sole and full authority to investigate potential violations of this subchapter and to enforce, prosecute, obtain, and impose remedies for a violation of this subchapter or any rules or regulations made pursuant to this chapter as the Attorney General and State’s Attorney have under chapter 63 of this title. Vt. Stat. Ann. tit. 9, § 2435(h)(1).

With respect to a data collector that is a person or entity licensed or registered with the Department of Financial Regulation under Title 8 or this title, the Department of Financial Regulation shall have the full authority to investigate potential violations of this subchapter and to prosecute, obtain, and impose remedies for a violation of this subchapter or any rules or regulations adopted pursuant to this subchapter, as the Department has under Title 8 or this title or any other applicable law or regulation. Vt. Stat. Ann. tit. 9, § 2435(h)(2).

Are There Any Exemptions/Exceptions?

A data collector that is subject to the privacy, security, and breach notification rules adopted pursuant to the federal Health Insurance Portability and Accountability Act is deemed to be in compliance with this subchapter if: a) the data collector experiences a security breach that is limited to personally identifiable information specified in 2430(10)(A)(vii); and b) the data collector provides notice to affected consumers pursuant to the requirements of the breach notification rule in 45 C.F.R. Part 164, Subpart D. Vt. Stat. Ann. tit. 9, § 2435(e).

Additionally, a financial institution that is subject to the following guidances, and any revisions, additions, or substitutions relating to an interagency guidance shall be exempt from this section: 

  1. The Federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information and Customer Notice, issued on March 7, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision. 
  2. Final Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice, issued on April 14, 2005, by the National Credit Union Administration. 
  3. A financial institution regulated by the Department of Financial Regulation that is subject to subdivision (1) or (2) of this subsection (g) shall notify the Department as soon as possible after it becomes aware of an incident involving unauthorized access to or use of personally identifiable information. Vt. Stat. Ann. tit. 9, § 2435(g).

Texas

Who Is Covered?

A person who conducts business in Texas and owns or licenses computerized data that includes sensitive personal information. Tex. Bus. & Com. Code § 521.053(b).

 

What Information Is Protected?

“Personal identifying information” means information that alone or in conjunction with other information identifies an individual, including an individual’s:

 

  1. Name, social security number, date of birth, or government-issued identification number;
  2. Mother’s maiden name;
  3. Unique biometric data, including the individual’s fingerprint, voice print, and retina or iris image;
  4. Unique electronic identification number, address, or routing code; and
  5. Telecommunication access device as defined by Section 32.51, Penal Code. Tex. Bus. & Com. Code § 521.002(a)(1).

“Sensitive personal information” means:

 

  1. An individual’s first name or first initial and last name in combination with any one or more of the following items, if the name and the items are not encrypted: (i) social security number; (ii) driver’s license number or government-issued identification number; or (iii) account number or credit or debit card number in combination with any required security code, access code, or password that would permit access to an individual’s financial account; or
  2. Information that identifies an individual and relates to: (i) the physical or mental health or condition of the individual; (ii) the provision of health care to the individual; or (iii) payment for the provision of health care to the individual. Tex. Bus. & Com. Code § 521.002(a)(2).

 

What Is A “Breach”?

“Breach of system security” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of sensitive personal information maintained by a person, including data that is encrypted if the person accessing the data has the key required to decrypt the data. Good faith acquisition of sensitive personal information by an employee or agent of the person for the purposes of the person is not a breach of system security unless the person uses or discloses the sensitive personal information in an unauthorized manner. Tex. Bus. & Com. Code § 521.053(a).

 

What Triggers Notification?

Discovering or receiving notification of the breach where any individual’s sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Tex. Bus. & Com. Code § 521.053(b).

 

How Is Notice Provided To Individuals?

Non-Residents: If the individual whose sensitive personal information was or is reasonably believed to have been acquired by an unauthorized person is a resident of a state that requires a person [under Texas law] to provide notice of a breach of system security, the notice of the breach of system security may be provided under that state’s law or under Texas law. Tex. Bus. & Com. Code § 521.053(b-1).

Timing: The disclosure shall be made without unreasonable delay and in each case not later than the 60th day after the date on which the person determines that the breach occurred, except as necessary for the needs of law enforcement or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Tex. Bus. & Com. Code § 521.053(b), (d).

Delivery: Notice may be provided by:

 

  1. Written notice at the last known address of the individual;
  2. Electronic notice, if the notice is provided in accordance with 15 U.S.C. Section 7001; or
  3. Substitute notice if it is demonstrated that the cost of providing notice would exceed $250,000, the number of affected persons exceeds 500,000, or the person does not have sufficient contact information, in which case the notice may be given by: a) electronic mail, if the person has electronic mail addresses for the affected persons; b) conspicuous posting of the notice on the person’s website; or c) notice published in or broadcast on major statewide media. Tex. Bus. & Com. Code § 521.053(e), (f).

Content: None specified.

 

Is Notice To The Government Required?

Yes. A person who is required to disclose or provide notification of a breach of system security under this section shall notify the attorney general of that breach as soon as practicable and not later than the 30th day after the date on which the person determines that the breach occurred if the breach involves at least 250 residents of this state. The notification under this subsection must be submitted electronically using a form accessed through the attorney general’s Internet website and must include:

 

  1. A detailed description of the nature and circumstances of the breach or the use of sensitive personal information acquired as a result of the breach;
  2. The number of residents of this state affected by the breach at the time of notification;
  3. the number of affected residents that have been sent a disclosure of the breach by mail or other direct method of communication at the time of notification;
  4. The measures taken by the person regarding the breach;
  5. Any measures the person intends to take regarding the breach after the notification under this subsection; and
  6. Information regarding whether law enforcement is engaged in investigating the breach. Tex. Bus. & Com. Code § 521.053(i).

 

Is Notice To Credit Reporting Agencies Required?

Yes. If a person is required by this section to notify at one time more than 10,000 persons of a breach of system security, the person shall also notify each consumer reporting agency of the timing, distribution, and content of the notices. The person shall provide the notice required by this subsection without unreasonable delay. Tex. Bus. & Com. Code § 521.053(h).

 

Are There Security Measure Standards?

Yes. A business shall implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect from unlawful use or disclosure any sensitive personal information collected or maintained by the business in the regular course of business. Tex. Bus. & Com. Code § 521.052(a).

Additionally, a business shall destroy or arrange for the destruction of customer records containing sensitive personal information within the business’s custody or control that are not to be retained by the business by:(1) shredding; (2) erasing; or (3) otherwise modifying the sensitive personal information in the records to make the information unreadable or indecipherable through any means. Tex. Bus. & Com. Code § 521.052(b).

 

What Are The Possible Consequences Of A Violation?

A person who violates this chapter is liable to this state for a civil penalty of at least $2,000 but not more than $50,000 for each violation. The attorney general may bring an action to recover the civil penalty imposed under this subsection. Tex. Bus. & Com. Code § 521.151(a).

In addition to penalties assessed under Subsection (a), a person who fails to take reasonable action to comply with Section 521.053(b) is liable to this state for a civil penalty of not more than $100 for each individual to whom notification is due under that subsection for each consecutive day that the person fails to take reasonable action to comply with that subsection. Civil penalties under this section may not exceed $250,000 for all individuals to whom notification is due after a single breach. The attorney general may bring an action to recover the civil penalties imposed under this subsection. Tex. Bus. & Com. Code § 521.151(a-1).

 

Are There Any Exemptions/Exceptions?

A person who maintains the person’s own notification procedures as part of an information security policy for the treatment of sensitive personal information that complies with the timing requirements for notice under this section complies with this section if the person notifies affected persons in accordance with that policy. Tex. Bus. & Com. Code § 521.053(g).

Utah

Who Is Covered?

A person who owns or licenses computerized data that includes personal information concerning a Utah resident. Utah Code Ann. § 13-44-202(1)(a).

 

What Information Is Protected?

“Personal information” means a person’s first name or first initial and last name, combined with any one or more of the following data elements relating to that person when either the name or date element is unencrypted or not protected by another method that renders the data unreadable or unusable:

 

  1. Social Security number;
  2. (A) financial account number, or credit or debit card number; and (b) any required security code, access code, or password that would permit access to the person’s account; or
  3. Driver license number or state identification card number. Utah Code Ann. § 13-44-102(4).

 

What Is A “Breach”?

“Breach of system security” means an unauthorized acquisition of computerized data maintained by a person that compromises the security, confidentiality, or integrity of personal information. Utah Code Ann. § 13-44-102(1)(a).

 

What Triggers Notification?

When a person becomes aware of a breach of system security, the person must conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be misused for identity theft or fraud purposes. Notification must be provided if the investigation reveals that the misuse of personal information for identity theft or fraud purposes has occurred, or is reasonably likely to occur, the person shall provide notification to each affected Utah resident. Utah Code Ann. § 13-44-202(1).

 

How Is Notice Provided To Individuals?

Timing: Notification must be made in the most expedient time possible without unreasonable delay considering the legitimate investigative needs of law enforcement, after determining the scope of the breach of system security and after restoring the reasonable integrity of the system. Utah Code Ann. § 13-44-202(2).

Delivery: Notification may be provided:

 

  1. In writing by first-class mail to the most recent address the person has for the resident;
  2. Electronically, if the person’s primary method of communication with the resident is by electronic means, or if provided in accordance with the consumer disclosure provisions of 15 U.S.C. Section 7001;
  3. By telephone, including through the use of automatic dialing technology not prohibited by other law; or
  4. For residents of the state for whom notification in a manner described above is not feasible, by publishing notice of the breach of system security: (A) in a newspaper of general circulation; and (B) as required in Section 45-1-101 [legal notice publication requirements]. Utah Code Ann. § 13-44-202.

Content: None specified.

 

Is Notice To The Government Required?

Yes. If the investigation reveals that the misuse of personal information relating to 500 or more Utah residents, for identity theft or fraud purposes, has occurred or is reasonably likely to occur, the person shall, in addition to the notification required in Subsection (1)(b), provide notification to: 

  1. the office of the Attorney General; and
  2. the Utah Cyber Center. Utah Code Ann. § 13-44-202(1)(c).

 

Is Notice To Credit Reporting Agencies Required?

Yes, if the investigation reveals that the misuse of personal information relating to 1,000 or more Utah residents, for identity theft or fraud purposes, has occurred or is reasonably likely to occur.
Utah Code Ann. § 13-44-202(1)(d).

 

Are There Security Measure Standards?

Yes. Any person who conducts business in the state and maintains personal information shall implement and maintain reasonable procedures to:

 

  1. Prevent unlawful use or disclosure of personal information collected or maintained in the regular course of business; and
  2. Destroy, or arrange for the destruction of, records containing personal information that are not to be retained by the person. 

The destruction of records shall be by: (a) shredding; (b) erasing; or (c) otherwise modifying the personal information to make the information indecipherable. Utah Code Ann. § 13-44-201.

 

What Are The Possible Consequences Of A Violation?

In addition to injunctive relief and attorney fees and costs, the attorney general may seek a civil penalty of:

 

  1. No greater than $2,500 for a violation or series of violations concerning a specific consumer; and
  2. No greater than $100,000 in the aggregate for related violations concerning more than one consumer, unless: a) the violations concern: (i) 10,000 or more consumers who are residents of the state; and (ii) 10,000 or more consumers who are residents of other states; or b) the person agrees to settle for a greater amount. Utah Code Ann. § 13-44-301(3), (4).

 

Are There Any Exemptions/Exceptions?

If a person maintains the person’s own notification procedures as part of an information security policy for the treatment of personal information the person is considered to be in compliance with this chapter’s notification requirements if the procedures are otherwise consistent with this chapter’s timing requirements and the person notifies each affected Utah resident in accordance with the person’s information security policy in the event of a breach. Utah Code Ann. § 13-44-202(5)(b).

Also, a person who is regulated by state or federal law and maintains procedures for a breach of system security under applicable law established by the primary state or federal regulator is considered to be in compliance with this part if the person notifies each affected Utah resident in accordance with the other applicable law in the event of a breach. Utah Code Ann. § 13-44-202(5)(c).

Rhode Island

Who Is Covered?

Any municipal agency, state agency, or person that stores, owns, collects, processes, maintains, acquires, uses, or licenses data that includes personal information. R.I. Gen. Laws Section 11-49.3-4(a)(1).

What Information Is Protected?

“Personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements, when the name and the data elements are not encrypted or are in hard copy, paper format:

  1. Social security number;
  2. Driver’s license number, Rhode Island identification card number, or tribal identification number;
  3. Account number, credit, or debit card number, in combination with any required security code, access code, password, or personal identification number, that would permit access to an individual’s financial account;
  4. Medical or health insurance information; or
  5. Email address with any required security code, access code, or password that would permit access to an individual’s personal, medical, insurance, or financial account. R.I. Gen. Laws Section 11-49.3-3(a)(8).

“Health insurance information” means an individual’s health insurance policy number, subscriber identification number, or any unique identifier used by a health insurer to identify the individual. R.I. Gen. Laws Section 11-49.3-3(a)(3).

“Medical information” means any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional or provider. R.I. Gen. Laws Section 11-49.3-3(a)(4).

What Is A “Breach”?

“Breach of the security of the system” means unauthorized access or acquisition of unencrypted, computerized data information that compromises the security, confidentiality, or integrity of personal information maintained by the municipal agency, state agency, or person. Good-faith acquisition of personal information by an employee or agent of the agency for the purposes of the agency is not a breach of the security of the system; provided, that the personal information is not used or subject to further unauthorized disclosure. R.I. Gen. Laws Section 11-49.3-3(a)(1).

What Triggers Notification?

The disclosure of personal information, or any breach of the security of the system, that poses a significant risk of identity theft to any resident of Rhode Island whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person or entity. R.I. Gen. Laws Section 11-49.3-4(a)(1).

How Is Notice Provided To Individuals?

Timing: The notification must be made in the most expedient time possible, but no later than 45 calendar days after confirmation of the breach and the ability to ascertain the information required to be included in the notification. R.I. Gen. Laws § 11-49.3-4(a)(2).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001; or
  3. Substitute notice, if the municipal agency, state agency, or person demonstrates that the cost of providing notice would exceed $25,000, or that the affected class of subject persons to be notified exceeds 50,000, or the municipal agency, state agency, or person does not have sufficient contact information. Substitute notice shall consist of all of the following: (A) Email notice when the municipal agency, state agency, or person has an email address for the subject persons; (B) Conspicuous posting of the notice on the municipal agency’s, state agency’s or person’s website page, if the municipal agency, state agency, or person maintains one; and (C) Notification to major statewide media. R.I. Gen. Laws Section 11-49.3-3(c).

Content: The notice must include:

  1. A general and brief description of the incident, including how the security breach occurred and the number of affected individuals;
  2. The type of information that was subject to the breach;
  3. Date of breach, estimated date of breach, or the date range within which the breach occurred;
  4. Date that the breach was discovered;
  5. A clear and concise description of any remediation services offered to affected individuals including toll free numbers and websites to contact: (i) The credit reporting agencies; (ii) Remediation service providers; (iii) The attorney general; and
  6. A clear and concise description of the consumer’s ability to file or obtain a police report; how a consumer requests a security freeze and the necessary information to be provided when requesting the security freeze; and that fees may be required to be paid to the consumer reporting agencies. R.I. Gen. Laws § 11-49.3-4(d).

Is Notice To The Government Required?

Yes. In the event that more than 500 Rhode Island residents are to be notified, the municipal agency, state agency, or person shall notify the attorney general and the major credit reporting agencies as to the timing, content, and distribution of the notices and the approximate number of affected individuals. Notification to the attorney general and the major credit reporting agencies shall be made without delaying notice to affected Rhode Island residents. R.I. Gen. Laws Section 11-49.3-4(a)(2).

Is Notice To Credit Reporting Agencies Required?

Yes. See above.

Are There Security Measure Standards?

Yes. A municipal agency, state agency, or person who or that stores, collects, processes, maintains, acquires, uses, owns, or licenses personal information about a Rhode Island resident shall implement and maintain a risk-based information security program that contains reasonable security procedures and practices appropriate to the size and scope of the organization; the nature of the information; and the purpose for which the information was collected in order to protect the personal information from unauthorized access, use, modification, destruction, or disclosure and to preserve the confidentiality, integrity, and availability of such information. A municipal agency, state agency, or person shall not retain personal information for a period longer than is reasonably required to provide the services requested; to meet the purpose for which it was collected; or in accordance with a written retention policy or as may be required by law. A municipal agency, state agency, or person shall destroy all personal information, regardless of the medium that such information is in, in a secure manner, including, but not limited to, shredding, pulverization, incineration, or erasure. R.I. Gen. Laws Section 11-49.3-2(a).

Additionally, a municipal agency, state agency, or person who or that discloses personal information about a Rhode Island resident to a nonaffiliated third party shall require by written contract that the third party implement and maintain reasonable security procedures and practices appropriate to the size and scope of the organization; the nature of the information; and the purpose for which the information was collected in order to protect the personal information from unauthorized access, use, modification, destruction, or disclosure. The provisions of this section shall apply to contracts entered into after the effective date of this act. R.I. Gen. Laws Section 11-49.3-2(b).

What Are The Possible Consequences Of A Violation?

Each reckless violation of this chapter is a civil violation for which a penalty of not more than $100 per record may be adjudged against a defendant. Each knowing and willful violation of this chapter is a civil violation for which a penalty of not more than $200 per record may be adjudged against a defendant. Additionally, whenever the attorney general has reason to believe that a violation has occurred and that proceedings would be in the public interest, the attorney general may bring an action in the name of the state against the business or person in violation. R.I. Gen. Laws Section 11-49.3-5.

Are There Any Exemptions/Exceptions?

  1. Any municipal agency, state agency, or person shall be deemed to be in compliance with the security breach notification requirements of § 11-49.3-4 if: a) The municipal agency, state agency, or person maintains its own security breach procedures as part of an information security policy for the treatment of personal information and otherwise complies with the timing requirements of § 11-49.3-4, and notifies subject persons in accordance with such municipal agency’s, state agency’s, or person’s notification policies in the event of a breach of security; or b) The person maintains a security breach procedure pursuant to the rules, regulations, procedures, or guidelines established by the primary or functional regulator, as defined in 15 U.S.C. § 6809(2), and notifies subject persons in accordance with the policies or the rules, regulations, procedures, or guidelines established by the primary or functional regulator in the event of a breach of security of the system.
  2. A financial institution, trust company, credit union, or its affiliates that is subject to and examined for, and found in compliance with, the Federal Interagency Guidelines on Response Programs for Unauthorized Access to Customer Information and Customer Notice shall be deemed in compliance with this chapter.
  3. A provider of health care, health care service plan, health insurer, or a covered entity governed by the medical privacy and security rules issued by the Federal Department of Health and Human Services, Parts 160 and 164 of Title 45 of the Code of Federal Regulations, established pursuant to the Health Insurance Portability and Accountability Act of 1996 shall be deemed in compliance with this chapter. R.I. Gen. Laws Section 11-49.3-6.

Oregon

Who Is Covered?

“Covered entity” means a person that owns, licenses, maintains, stores, manages, collects, processes, acquires or otherwise possesses personal information in the course of the person’s business, vocation, occupation or volunteer activities. Or. Rev. Stat. Ann. § 646A.602(5)(a).

What Information Is Protected?

“Personal information” means:

A. A consumer’s first name or first initial and last name in combination with any one or more of the following data elements, if encryption, redaction or other methods have not rendered the data elements unusable or if the data elements are encrypted and the encryption key has been acquired:

  1. A consumer’s social security number;
  2. A consumer’s driver license number or state identification card number issued by the Department of Transportation;
  3. A consumer’s passport number or other identification number issued by the United States;
  4. A consumer’s financial account number, credit card number or debit card number, in combination with any required security code, access code or password that would permit access to a consumer’s financial account, or any other information or combination of information that a person reasonably knows or should know would permit access to the consumer’s financial account;
  5. Data from automatic measurements of a consumer’s physical characteristics, such as an image of a fingerprint, retina or iris, that are used to authenticate the consumer’s identity in the course of a financial transaction or other transaction;
  6. A consumer’s health insurance policy number or health insurance subscriber identification number in combination with any other unique identifier that a health insurer uses to identify the consumer; or
  7. Any information about a consumer’s medical history or mental or physical condition or about a health care professional’s medical diagnosis or treatment of the consumer.

B. A user name or other means of identifying a consumer for the purpose of permitting access to the consumer’s account, together with any other method necessary to authenticate the user name or means of identification.

C. Any of the data elements or any combination of the data elements described in subparagraph (A) or (B) of this paragraph without the consumer’s user name, or the consumer’s first name or first initial and last name, if: (i) Encryption, redaction or other methods have not rendered the data element or combination of data elements unusable; and (ii) The data element or combination of data elements would enable a person to commit identity theft against a consumer. Or. Rev. Stat. Ann. § 646A.602(12)(A)(a).

What Is A “Breach”?

“Breach of security” means an unauthorized acquisition of computerized data that materially compromises the security, confidentiality or integrity of personal information that a person maintains or possesses. Or. Rev. Stat. Ann. § 646A.602(1)(a).

What Triggers Notification?

The covered entity being subjected to a breach of security or receiving notice of a breach of security from a vendor. Or. Rev. Stat. Ann. § 646A.604(1).

Likelihood of Harm Analysis: A covered entity does not need to notify consumers of a breach of security if, after an appropriate investigation or after consultation with relevant federal, state or local law enforcement agencies, the covered entity reasonably determines that the consumers whose personal information was subject to the breach of security are unlikely to suffer harm. The covered entity must document the determination in writing and maintain the documentation for at least five years. Or. Rev. Stat. Ann. § 646A.604(8).

How Is Notice Provided To Individuals?

Timing: Notice must be provided in the most expeditious manner possible, without unreasonable delay, but not later than 45 days after discovering or receiving notification of the breach of security, but only after the covered entity undertakes reasonable measures that are necessary to:

  1. Determine sufficient contact information for the intended recipient of the notice;
  2. Determine the scope of the breach of security; and
  3. Restore the reasonable integrity, security and confidentiality of the personal information. Or. Rev. Stat. Ann. § 646A.604(3).

Delivery: Notice may be made:

  1. In writing;
  2. Electronically, if the covered entity customarily communicates with the consumer electronically or if the notice is consistent with the provisions of the E-Sign Act;
  3. By telephone, if the covered entity contacts the affected consumer directly; or
  4. With substitute notice, if the covered entity demonstrates that the cost of notification otherwise would exceed $250,000 or that the affected class of consumers exceeds 350,000, or if the covered entity does not have sufficient contact information to notify affected consumers. For the purposes of this paragraph, “substitute notice” means: (A) Posting the notice or a link to the notice conspicuously on the covered entity’s website if the covered entity maintains a website; and (B) Notifying major statewide television and newspaper media. Or. Rev. Stat. Ann. § 646A.604(4).

Content: Notice must include:

  1. A description of the breach of security in general terms;
  2. The approximate date of the breach of security;
  3. The type of personal information that was subject to the breach of security;
  4. Contact information for the covered entity;
  5. Contact information for national consumer reporting agencies; and
  6. Advice to the consumer to report suspected identity theft to law enforcement, including the Attorney General and the Federal Trade Commission. Or. Rev. Stat. Ann. § 646A.604(5).

Is Notice To The Government Required?

Yes, if the number of consumers to whom the covered entity must send the notice exceeds 250. Or. Rev. Stat. Ann. § 646A.604(1)(b).

Is Notice To Credit Reporting Agencies Required?

Yes. If a covered entity discovers or receives notice of a breach of security that affects more than 1,000 consumers, the covered entity shall notify, without unreasonable delay, all consumer reporting agencies that compile and maintain reports on consumers on a nationwide basis of the timing, distribution and content of the notice the covered entity gave to affected consumers and shall include in the notice any police report number assigned to the breach of security. A covered entity may not delay notifying affected consumers of a breach of security in order to notify consumer reporting agencies. Or. Rev. Stat. Ann. § 646A.604(6).

Are There Security Measure Standards?

Yes. A covered entity and a vendor shall develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of personal information, including safeguards that protect the personal information when the covered entity or vendor disposes of the personal information. In addition to complying with any federal law that provides greater protection to personal information than the protections that this section provides or with the HIPAA, a covered entity or vendor is in compliance if it implements an information security program that includes:

A. Administrative safeguards such as:

  1. Designating one or more employees to coordinate the security program;
  2. Identifying reasonably foreseeable internal and external risks with reasonable regularity;
  3. Assessing whether existing safeguards adequately control the identified risks;
  4. Training and managing employees in security program practices and procedures with reasonable regularity;
  5. Selecting service providers that are capable of maintaining appropriate safeguards and practices, and requiring the service providers by contract to maintain the safeguards and practices;  
  6. Adjusting the security program in light of business changes, potential threats or new circumstances; and
  7. Reviewing user access privileges with reasonable regularity.

B. Technical safeguards such as:

  1. Assessing risks and vulnerabilities in network and software design and taking reasonably timely action to address the risks and vulnerabilities;
  2. Applying security updates and a reasonable security patch management program to software that might reasonably be at risk of or vulnerable to a breach of security;
  3. Monitoring, detecting, preventing and responding to attacks or system failures; and
  4. Regularly testing, monitoring and taking action to address the effectiveness of key controls, systems and procedures.

C. Physical safeguards such as:

  1. Assessing, in light of current technology, risks of information collection, storage, usage, retention, access and disposal and implementing reasonable methods to remedy or mitigate identified risks;
  2. Monitoring, detecting, preventing, isolating and responding to intrusions timely and with reasonable regularity;
  3. Protecting against unauthorized access to or use of personal information during or after collecting, using, storing, transporting, retaining, destroying or disposing of the personal information; and
  4. Disposing of personal information, whether the covered entity or vendor disposes of the personal information on or off the covered entity’s or vendor’s premises or property, after the covered entity or vendor no longer needs the personal information for business purposes or as required by local, state or federal law by burning, pulverizing, shredding or modifying a physical record and by destroying or erasing electronic media so that the information cannot be read or reconstructed. Or. Rev. Stat. Ann. § 646A.622(1), (2).

What Are The Possible Consequences Of A Violation?

In addition to all other penalties and enforcement provisions provided by law, any person who violates or who procures, aids or abets in a violation shall be subject to a penalty of not more than $1,000 for every violation, which shall be paid to the General Fund of the State Treasury. Every violation is a separate offense and, in the case of a continuing violation, each day’s continuance is a separate violation, but the maximum penalty for any occurrence shall not exceed $500,000.  Additionally, a violation is an unlawful practice under Or. Rev. Stat. Ann. § 646.607. Or. Rev. Stat. Ann. §§ 646A.624(4); 646A.604(11)(a).

If the director has reason to believe that any person has engaged or is engaging in any violation, the director may issue an order, subject to ORS chapter 183, directed to the person to cease and desist from the violation, or require the person to pay compensation to consumers injured by the violation. The director may order compensation to consumers only upon a finding that enforcement of the rights of the consumers by private civil action would be so burdensome or expensive as to be impractical. Or. Rev. Stat. Ann. § 646A.624(3).

Are There Any Exemptions/Exceptions?

With the exception of the requirement to send notice to the attorney general, the breach notification requirements do not apply to:

  1. Personal information that is subject to, and a person that complies with, notification requirements or procedures for a breach of security that the person’s primary or functional federal regulator adopts, promulgates or issues in rules, regulations, procedures, guidelines or guidance.
  2. Personal information that is subject to, and a person that complies with, a state or federal law that provides greater protection to personal information and disclosure requirements at least as thorough as the protections and disclosure requirements provided under this section.
  3. A covered entity or vendor that complies with regulations promulgated under Title V of the Gramm-Leach-Bliley Act.
  4. A covered entity or vendor that complies with regulations promulgated under the Health Insurance Portability and Accountability Act. Or. Rev. Stat. Ann. § 646A.604(9).

North Carolina

Who Is Covered?

Any business that owns or licenses personal information of residents of North Carolina or any business that conducts business in North Carolina that owns or licenses personal information in any form (whether computerized, paper, or otherwise). N.C. Gen. Stat. § 75-65(a).

What Information Is Protected?

A person’s first name or first initial and last name in combination with identifying information including the following:

  1. Social security or employer taxpayer identification numbers.   
  2. Drivers license, State identification card, or passport numbers.  
  3. Checking account numbers.  
  4. Savings account numbers.  
  5. Credit card numbers. 
  6. Debit card numbers.  
  7. Personal Identification (PIN) Code.    
  8. Digital signatures.  
  9. Any other numbers or information that can be used to access a person’s financial resources.  
  10. Biometric data.  
  11. Fingerprints.  
  12. Passwords if they would permit access to a person’s financial account or resources. N.C. Gen. Stat. §§ 75.61(10); 14-113.20(b).

What Is A “Breach”?

An incident of unauthorized access to and acquisition of unencrypted and unredacted records or data containing personal information where illegal use of the personal information has occurred or is reasonably likely to occur or that creates a material risk of harm to a consumer. Any incident of unauthorized access to and acquisition of encrypted records or data containing personal information along with the confidential process or key shall constitute a security breach. Good faith acquisition of personal information by an employee or agent of the business for a legitimate purpose is not a security breach, provided that the personal information is not used for a purpose other than a lawful purpose of the business and is not subject to further unauthorized disclosure. N.C. Gen. Stat. § 75-61(14).

What Triggers Notification?

Discovery or notification of the breach. N.C. Gen. Stat. § 75-65(a).

How Is Notice Provided To Individuals?

Timing: Notice must be made without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine sufficient contact information, determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system. N.C. Gen. Stat. § 75-65(a).

Delivery: Delivery may be by:

  1. Written notice.  
  2. Electronic notice, for those persons for whom it has a valid e-mail address and who have agreed to receive communications electronically if the notice provided is consistent with the provisions of the E-Sign Act.  
  3. Telephonic notice provided that contact is made directly with the affected persons.  
  4. Substitute notice, if the business demonstrates that the cost of providing notice would exceed $250,000 or that the affected class of subject persons to be notified exceeds 500,000, or if the business does not have sufficient contact information or consent to satisfy subdivisions (1), (2), or (3) of this subsection, for only those affected persons without sufficient contact information or consent, or if the business is unable to identify particular affected persons, for only those unidentifiable affected persons. Substitute notice shall consist of all the following: a)  E-mail notice when the business has an electronic mail address for the subject persons. b)  Conspicuous posting of the notice on the Web site page of the business, if one is maintained. c)  Notification to major statewide media. N.C. Gen. Stat. § 75-65(e).

Content: The notice must be clear and conspicuous and include:

  1. A description of the incident in general terms.  
  2. A description of the type of personal information that was subject to the unauthorized access and acquisition.  
  3. A description of the general acts of the business to protect the personal information from further unauthorized access.  
  4. A telephone number for the business that the person may call for further information and assistance, if one exists.  
  5. Advice that directs the person to remain vigilant by reviewing account statements and monitoring free credit reports.  
  6. The toll-free numbers and addresses for the major consumer reporting agencies.  
  7. The toll-free numbers, addresses, and Web site addresses for the Federal Trade Commission and the North Carolina Attorney General’s Office, along with a statement that the individual can obtain information from these sources about preventing identity theft. N.C. Gen. Stat. § 75-65(d).

Is Notice To The Government Required?

Yes. In the event a business provides notice to an affected person pursuant to this section, the business shall notify without unreasonable delay the Consumer Protection Division of the Attorney General’s Office of the nature of the breach, the number of consumers affected by the breach, steps taken to investigate the breach, steps taken to prevent a similar breach in the future, and information regarding the timing, distribution, and content of the notice. N.C. Gen. Stat. § 75-65(e1).

Is Notice To Credit Reporting Agencies Required?

Yes. In the event a business provides notice to more than 1,000 persons at one time pursuant to this section, the business shall notify, without unreasonable delay, the Consumer Protection Division of the Attorney General’s Office and all consumer reporting agencies of the timing, distribution, and content of the notice. N.C. Gen. Stat. § 75-65(f).

Are There Security Measure Standards?

Yes, with regard to destruction of records. Any business that conducts business in North Carolina and any business that maintains or otherwise possesses personal information of a resident of North Carolina must take reasonable measures to protect against unauthorized access to or use of the information in connection with or after its disposal, which must include:

  1. Implementing and monitoring compliance with policies and procedures that require the burning, pulverizing, or shredding of papers containing personal information so that information cannot be practicably read or reconstructed.  
  2. Implementing and monitoring compliance with policies and procedures that require the destruction or erasure of electronic media and other nonpaper media containing personal information so that the information cannot practicably be read or reconstructed.  
  3. Describing procedures relating to the adequate destruction or proper disposal of personal records as official policy in the writings of the business entity. N.C. Gen. Stat. § 75-64(a), (b).

What Are The Possible Consequences Of A Violation?

A violation is an unfair or deceptive act or practice under N.C. Gen. Stat. § 75-1.1 which can result in a civil penalty of up to $5,000 per violation for knowing violations. No private right of action may be brought by an individual for a violation of this section unless such individual is injured as a result of the violation. N.C. Gen. Stat. §§ 75-65(i); 75-15.2; 75.16.

Are There Any Exemptions/Exceptions?

A financial institution that is subject to and in compliance with the Federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information and Customer Notice, issued on March 7, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision; or a credit union that is subject to and in compliance with the Final Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice, issued on April 14, 2005, by the National Credit Union Administration; and any revisions, additions, or substitutions relating to any of the said interagency guidance, shall be deemed to be in compliance with this section. N.C. Gen. Stat. § 75-65(h).

New York

Who Is Covered?

Any person or business which owns or licenses computerized data which includes private information. N.Y. Gen. Bus. Law § 899-aa(2).

 

What Information Is Protected?

“Private information” means either:

A. Personal information consisting of any information in combination with any one or more of the following data elements, when either the data element or the combination of personal information plus the data element is not encrypted, or is encrypted with an encryption key that has also been accessed or acquired:

 

  1. Social security number;
  2. Driver’s license number or non-driver identification card number;
  3. Account number, credit or debit card number, in combination with any required security code, access code, password or other information that would permit access to an individual’s financial account;
  4. Account number, credit or debit card number, if circumstances exist wherein such number could be used to access an individual’s financial account without additional identifying information, security code, access code, or password; or
  5. Biometric information, meaning data generated by electronic measurements of an individual’s unique physical characteristics, such as a fingerprint, voice print, retina or iris image, or other unique physical representation or digital representation of biometric data which are used to authenticate or ascertain the individual’s identity; or

B. A user name or email address in combination with a password or security question and answer that would permit access to an online account. N.Y. Gen. Bus. Law § 899-aa(1)(b).

 

What Is A “Breach”?

“Breach of the security of the system” shall mean unauthorized access to or acquisition of, or access to or acquisition without valid authorization, of computerized data that compromises the security, confidentiality, or integrity of private information maintained by a business. 

In determining whether information has been accessed, or is reasonably believed to have been accessed, by an unauthorized person or a person without valid authorization, such business may consider, among other factors, indications that the information was viewed, communicated with, used, or altered by a person without valid authorization or by an unauthorized person. In determining whether information has been acquired, or is reasonably believed to have been acquired, by an unauthorized person or a person without valid authorization, such business may consider the following factors, among others:

 

  1. Indications that the information is in the physical possession and control of an unauthorized person, such as a lost or stolen computer or other device containing information; or
  2. Indications that the information has been downloaded or copied; or
  3. Indications that the information was used by an unauthorized person, such as fraudulent accounts opened or instances of identity theft reported. N.Y. Gen. Bus. Law § 899-aa(1)(c).

 

What Triggers Notification?

Discovery or notification of the breach in the security of the system involving the private information of any resident of New York state whose private information was, or is reasonably believed to have been, accessed or acquired by a person without valid authorization. N.Y. Gen. Bus. Law § 899-aa(2).

Likelihood of Harm Exception: Notice to affected persons is not required if the exposure of private information was an inadvertent disclosure by persons authorized to access private information, and the person or business reasonably determines such exposure will not likely result in misuse of such information, or financial harm to the affected persons or emotional harm in the case of unknown disclosure of online credentials. N.Y. Gen. Bus. Law § 899-aa(2)(a).

 

How Is Notice Provided To Individuals?

Timing: In the most expedient time possible and without unreasonable delay, provided that such notification is made within 30 days after the breach is discovered, except for the legitimate needs of law enforcement. N.Y. Gen. Bus. Law § 899-aa(2).

Delivery: Notice may be provided by:

 

  1. Written notice;
  2. Electronic notice, provided that the person to whom notice is required has expressly consented to receiving said notice in electronic form and a log of each such notification is kept by the person or business who notifies affected persons in such form; provided further, however, that in no case shall any person or business require a person to consent to accepting said notice in said form as a condition of establishing any business relationship or engaging in any transaction.
  3. Telephone notification provided that a log of each such notification is kept by the person or business who notifies affected persons; or
  4. Substitute notice, if a business demonstrates to the state attorney general that the cost of providing notice would exceed two hundred fifty thousand dollars, or that the affected class of subject persons to be notified exceeds five hundred thousand, or such business does not have sufficient contact information. Substitute notice shall consist of all of the following: (a) email notice when such business has an email address for the subject persons, except if the breached information includes an email address in combination with a password or security question and answer that would permit access to the online account, in which case the person or business shall instead provide clear and conspicuous notice delivered to the consumer online when the consumer is connected to the online account from an internet protocol address or from an online location which the person or business knows the consumer customarily uses to access the online account; (b) conspicuous posting of the notice on such business’s website page, if such business maintains one; and (c) notification to major statewide media. N.Y. Gen. Bus. Law § 899-aa(5).

Content: Notice must include:

 

  1. Contact information for the person or business making the notification;
  2. The telephone numbers and websites of the relevant state and federal agencies that provide information regarding security breach response and identity theft prevention and protection information; and
  3. A description of the categories of information that were, or are reasonably believed to have been, accessed or acquired by a person without valid authorization, including specification of which of the elements of personal information and private information were, or are reasonably believed to have been, so accessed or acquired. N.Y. Gen. Bus. Law § 899-aa(7).

 

Is Notice To The Government Required?

Yes. In the event that any New York residents are to be notified, the person or business shall notify the state attorney general, the department of state and the division of state police, and the department of financial services as to the timing, content and distribution of the notices and approximate number of affected persons and shall provide a copy of the template of the notice sent to affected persons. Such notice shall be made without delaying notice to affected New York residents. However, notice to the department of financial services shall only be required if the person or business is a covered entity, as defined in 23 NYCRR 500l1. N.Y. Gen. Bus. Law § 899-aa(8)(a).

Additionally, any covered entity required to provide notification of a breach, including breach of information that is not “private information,” to the secretary of health and human services pursuant to HIPAA shall provide such notification to the state attorney general within five business days of notifying the secretary. N.Y. Gen. Bus. Law § 899-aa(9).

 

Is Notice To Credit Reporting Agencies Required?

Yes. In the event that more than five thousand New York residents are to be notified at one time, the person or business shall also notify consumer reporting agencies as to the timing, content and distribution of the notices and approximate number of affected persons. Such notice shall be made without delaying notice to affected New York residents. N.Y. Gen. Bus. Law § 899-aa(8)(b).

 

Are There Security Measure Standards?

Yes. Any person or business that owns or licenses computerized data which includes private information of a resident of New York must develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of the private information including, but not limited to, disposal of data. A person or business will be deemed to be in compliance with paragraph (a) of this subdivision if it is a compliant regulated entity [N.Y. Gen. Bus. Law § 899-bb(1)], or implements a data security program that includes:

A. Reasonable administrative safeguards such as the following, in which the person or business:

 

  1. Designates one or more employees to coordinate the security program;
  2. Identifies reasonably foreseeable internal and external risks;
  3. Assesses the sufficiency of safeguards in place to control the identified risks;
  4. Trains and manages employees in the security program practices and procedures;
  5. Selects service providers capable of maintaining appropriate safeguards, and requires those safeguards by contract; and
  6. Adjusts the security program in light of business changes or new circumstances; and

B. Reasonable technical safeguards such as the following, in which the person or business:

 

  1. Assesses risks in network and software design;
  2. Assesses risks in information processing, transmission and storage;
  3. Detects, prevents and responds to attacks or system failures; and
  4. Regularly tests and monitors the effectiveness of key controls, systems and procedures; and

C. Reasonable physical safeguards such as the following, in which the person or business:

 

  1. Assesses risks of information storage and disposal;
  2. Detects, prevents and responds to intrusions;
  3. Protects against unauthorized access to or use of private information during or after the collection, transportation and destruction or disposal of the information; and
  4. Disposes of private information within a reasonable amount of time after it is no longer needed for business purposes by erasing electronic media so that the information cannot be read or reconstructed. N.Y. Gen. Bus. Law § 899-bb(2).

 

What Are The Possible Consequences Of A Violation?

The attorney general may seek injunctive relief and damages for actual costs or losses incurred by a person entitled to notice if notification was not provided to such person, including consequential financial losses.

Additionally, if a court determines that a person or business violated the article knowingly or recklessly, the court may impose a civil penalty of the greater of $5,000 or up to $20 per instance of failed notification, provided that the latter amount shall not exceed $250,000. N.Y. Gen. Bus. Law § 899-aa(6)(a).

 

Are There Any Exemptions/Exceptions?

If notice of the breach of the security of the system is made to affected persons pursuant to the breach notification requirements under any of the following laws, nothing in this section shall require any additional notice to those affected persons, but notice still shall be provided to the state attorney general, the department of state and the division of state police and to consumer reporting agencies:

 

  1. Regulations promulgated pursuant to Title V of the federal Gramm-Leach-Bliley Act;
  2. Regulations implementing the Health Insurance Portability and Accountability Act and the Health Information Technology for Economic and Clinical Health Act;
  3. Part five hundred of title twenty-three of the official compilation of codes, rules and regulations of the state of New York; or
  4. Any other data security rules and regulations of, and the statutes administered by, any official department, division, commission or agency of the federal or New York state government as such rules, regulations or statutes are interpreted by such department, division, commission or agency or by the federal or New York state courts. N.Y. Gen. Bus. Law § 899-aa(2)(b).

New Mexico

Who Is Covered?

 Any person that owns or licenses elements that include personal identifying information of a New Mexico resident. N.M. Stat. Ann. § 57-12C-2(C)(6).

What Information Is Protected?

“Personal identifying information” means an individual’s first name or first initial and last name in combination with one or more of the following data elements that relate to the individual, when the data elements are not protected through encryption or redaction or otherwise rendered unreadable or unusable:

  1. Social security number;
  2. Driver’s license number;
  3. Government-issued identification number;
  4. Account number, credit card number or debit card number in combination with any required security code, access code or password that would permit access to a person’s financial account; or
  5. Biometric data N.M. Stat. Ann. § 57-12C-2(C)(1).

What Is A “Breach”?

“Security breach” means the unauthorized acquisition of unencrypted computerized data, or of encrypted computerized data and the confidential process or key used to decrypt the encrypted computerized data, that compromises the security, confidentiality or integrity of personal identifying information maintained by a person. N.M. Stat. Ann. § 57-12C-2(D).

What Triggers Notification?

A reasonable belief that the personal information of a New Mexico resident has been subject to a security breach. N.M. Stat. Ann. § 57-12C-6(A).

Likelihood of Harm Analysis: Notification to affected New Mexico residents is not required if, after an appropriate investigation, the person determines that the security breach does not give rise to a significant risk of identity theft or fraud. N.M. Stat. Ann. § 57-12C-6(B).

How Is Notice Provided To Individuals?

Timing: Notification must be made in the most expedient time possible, but not later than 45 calendar days following discovery of the security breach, except as provided in N.M. Stat. Ann. § 57-12C-9. N.M. Stat. Ann. § 57-12C-6(A).

Delivery: Notification may be by:

  1. United States mail;
  2. Electronic notification, if the person required to make the notification primarily communicates with the New Mexico resident by electronic means or if the notice provided is consistent with the requirements of 15 U.S.C. Section 7001; or
  3. A substitute notification, if the person demonstrates that: (a) the cost of providing notification would exceed $100,000; (b) the number of residents to be notified exceeds fifty thousand; or (c) the person does not have on record a physical address or sufficient contact information for the residents that the person or business is required to notify. N.M. Stat. Ann. § 57-12C-6(D).

Content: The notification must include:

  1. The name and contact information of the notifying person;
  2. A list of the types of personal identifying information that are reasonably believed to have been the subject of a security breach, if known;
  3. The date of the security breach, the estimated date of the breach or the range of dates within which the security breach occurred, if known;
  4. A general description of the security breach incident;
  5. The toll-free telephone numbers and addresses of the major consumer reporting agencies;
  6. Advice that directs the recipient to review personal account statements and credit reports, as applicable, to detect errors resulting from the security breach; and
  7. Advice that informs the recipient of the notification of the recipient’s rights pursuant to the federal Fair Credit Reporting Act. N.M. Stat. Ann. § 57-12C-7.

Is Notice To The Government Required?

Yes. A person that is required to issue notification of a security breach pursuant to the Data Breach Notification Act to more than 1,000 New Mexico residents as a result of a single security breach shall notify the office of the attorney general and major consumer reporting agencies of the security breach in the most expedient time possible, and no later than 45 calendar days, except as provided in N.M. Stat. Ann. § 57-12C-9. A person required to notify the attorney general and consumer reporting agencies pursuant to this section shall notify the attorney general of the number of New Mexico residents that received notification and shall provide a copy of the notification that was sent to affected residents within 45 calendar days following discovery of the security breach, except as provided in N.M. Stat. Ann. § 57-12C-9.

Is Notice To Credit Reporting Agencies Required?

Yes. See above.

Are There Security Measure Standards?

Yes. A person that owns or licenses personal identifying information of a New Mexico resident shall implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal identifying information from unauthorized access, destruction, use, modification or disclosure. N.M. Stat. Ann. § 57-12C-4.

Additionally, a person that owns or licenses records containing personal identifying information of a New Mexico resident shall arrange for proper disposal of the records when they are no longer reasonably needed for business purposes. As used in this section, “proper disposal” means shredding, erasing or otherwise modifying the personal identifying information contained in the records to make the personal identifying information unreadable or undecipherable. N.M. Stat. Ann. § 57-12C-3.

What Are The Possible Consequences Of A Violation?

When the attorney general has a reasonable belief that a violation of the Data Breach Notification Act has occurred, the attorney general may bring an action on the behalf of individuals and in the name of the state alleging a violation of that act. 

In any action filed by the attorney general pursuant to the Data Breach Notification Act, the court may: (1) issue an injunction; and (2) award damages for actual costs or losses, including consequential financial losses.

If the court determines that a person violated the Data Breach Notification Act knowingly or recklessly, the court may impose a civil penalty of the greater of $25,000 or, in the case of failed notification, $10 per instance of failed notification up to a maximum of $150,000. N.M. Stat. Ann. § 57-12C-11.

Are There Any Exemptions/Exceptions?

Any person that is licensed to maintain or possess computerized data containing personal identifying information of a New Mexico resident that the person does not own or license shall notify the owner or licensee of the information of any security breach in the most expedient time possible, but not later than forty-five calendar days following discovery of the breach, except as provided in Section 9 of the Data Breach Notification Act; provided that notification to the owner or licensee of the information is not required if, after an appropriate investigation, the person determines that the security breach does not give rise to a significant risk of identity theft or fraud. N.M. Stat. Ann. § 57-12C-6(C).

New Jersey

Who Is Covered?

Any business that conducts business in New Jersey, or any public entity that compiles or maintains computerized records that include personal information. N.J. Stat. § 56:8-163(a).

 

What Information Is Protected?

“Personal information” means an individual’s first name or first initial and last name linked with any one or more of the following data elements:

  1. Social security number;
  2. Driver’s license number or State identification card number;
  3. Account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account; or
  4. User name, email address, or any other account holder identifying information, in combination with any password or security question and answer that would permit access to an online account. N.J. Stat. § 56:8-161.

 

What Is A “Breach”?

“Breach of security” means unauthorized access to electronic files, media or data containing personal information that compromises the security, confidentiality or integrity of personal information when access to the personal information has not been secured by encryption or by any other method or technology that renders the personal information unreadable or unusable. N.J. Stat. § 56:8-161.

 

What Triggers Notification?

Discovery or notification of a breach of a New Jersey resident’s personal information that was, or is reasonably believed to have been, accessed by an unauthorized person. N.J. Stat. § 56:8-163(a).

Likelihood of Harm Analysis: Disclosure of a breach of security to a customer shall not be required under this section if the business or public entity establishes that misuse of the information is not reasonably possible. Any determination shall be documented in writing and retained for five years. N.J. Stat. § 56:8-163(a).

 

How Is Notice Provided To Individuals?

Timing: Following notice to the government described below, in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. N.J. Stat. § 56:8-163(a).

Delivery: Notification may be by:

 

  1. Written notice;
  2. Electronic notice, if the notice provided is consistent with the provisions of the E-Sign Act; or
  3. Substitute notice, if the business or public entity demonstrates that the cost of providing notice would exceed $250,000, or that the affected class of subject persons to be notified exceeds 500,000, or the business or public entity does not have sufficient contact information. Substitute notice shall consist of all of the following: (a) Email notice when the business or public entity has an email address; (b) Conspicuous posting of the notice on the Internet web site page of the business or public entity, if the business or public entity maintains one; and (c) Notification to major statewide media. N.J. Stat. § 56:8-163(d).

In the case of a breach of security involving a user name or password, in combination with any password or security question and answer that would permit access to an online account, the business or public entity may provide the notification in electronic or other form that directs the customer whose personal information has been breached to promptly change any password and security question or answer, as applicable, or to take other appropriate steps to protect the online account with the business or public entity and all other online accounts for which the customer uses the same user name or email address and password or security question or answer. N.J. Stat. § 56:8-163(g)(1).

Content: None specified.

 

Is Notice To The Government Required?

Yes. Any business or public entity required under this section to disclose a breach of security of a customer’s personal information shall, in advance of the disclosure to the customer, report the breach of security and any information pertaining to the breach to the Division of State Police in the Department of Law and Public Safety for investigation or handling, which may include dissemination or referral to other appropriate law enforcement entities. N.J. Stat. § 56:8-163(c).

 

Is Notice To Credit Reporting Agencies Required?

Yes. In addition to any other disclosure or notification required under this section, in the event that a business or public entity discovers circumstances requiring notification pursuant to this section of more than 1,000 persons at one time, the business or public entity shall also notify, without unreasonable delay, all consumer reporting agencies of the timing, distribution and content of the notices. N.J. Stat. § 56:8-163(f).

 

Are There Security Measure Standards?

No. However, a separate section provides that a business or public entity shall destroy, or arrange for the destruction of, a customer’s records within its custody or control containing personal information, which is no longer to be retained by the business or public entity, by shredding, erasing, or otherwise modifying the personal information in those records to make it unreadable, undecipherable or nonreconstructable through generally available means. N.J. Stat. § 56:8-162.

 

What Are The Possible Consequences Of A Violation?

Willfully, knowingly or recklessly violating these provisions is an unlawful practice and a violation of N.J. Stat. § 56:8-1, et seq. N.J. Stat. § 56:8-166.

 

Are There Any Exemptions/Exceptions?

A business or public entity that maintains its own notification procedures as part of an information security policy for the treatment of personal information, and is otherwise consistent with the requirements of this section, shall be deemed to be in compliance with the notification requirements of this section if the business or public entity notifies subject customers in accordance with its policies in the event of a breach of security of the system. N.J. Stat. § 56:8-163(e).

Nevada

Who Is Covered?

Any data collector that owns or licenses computerized data which includes personal information. Nev. Rev. Stat. Ann. § 603A.220(1).

“Data collector” means any governmental agency, institution of higher education, corporation, financial institution or retail operator or any other type of business entity or association that, for any purpose, whether by automated collection or otherwise, handles, collects, disseminates or otherwise deals with nonpublic personal information. Nev. Rev. Stat. Ann. § 603A.030.

What Information Is Protected?

“Personal information” means a natural person’s first name or first initial and last name in combination with any one or more of the following data elements, when the name and data elements are not encrypted:

  1. Social security number.
  2. Driver’s license number, driver authorization card number or identification card number.
  3. Account number, credit card number or debit card number, in combination with any required security code, access code or password that would permit access to the person’s financial account.
  4. A medical identification number or a health insurance identification number.
  5. A user name, unique identifier or electronic mail address in combination with a password, access code or security question and answer that would permit access to an online account. Nev. Rev. Stat. Ann. § 603A.040(1).

What Is A “Breach”?

“Breach of the security of the system data” means unauthorized acquisition of computerized data that materially compromises the security, confidentiality or integrity of personal information maintained by the data collector. The term does not include the good faith acquisition of personal information by an employee or agent of the data collector for a legitimate purpose of the data collector, so long as the personal information is not used for a purpose unrelated to the data collector or subject to further unauthorized disclosure. Nev. Rev. Stat. Ann. § 603A.020.

What Triggers Notification?

The discovery or notification of the breach of data relating to any resident of Nevada whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Nev. Rev. Stat. Ann. § 603A.220(1).

How Is Notice Provided To Individuals?

Timing: The disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the system data. Nev. Rev. Stat. Ann. § 603A.220(1).

Delivery: Notice may be by:

  1. Written notification.
  2. Electronic notification, if the notification provided is consistent with the provisions of the E-Sign Act.
  3. Substitute notification, if the data collector demonstrates that the cost of providing notification would exceed $250,000, the affected class of subject persons to be notified exceeds 500,000 or the data collector does not have sufficient contact information. Nev. Rev. Stat. Ann. § 603A.220(4).

Content: None specified.

Is Notice To The Government Required?

No.

Is Notice To Credit Reporting Agencies Required?

Yes. If a data collector determines that notification is required to be given pursuant to the provisions of this section to more than 1,000 persons at any one time, the data collector shall also notify, without unreasonable delay, any consumer reporting agency that compiles and maintains files on consumers on a nationwide basis, of the time the notification is distributed and the content of the notification. Nev. Rev. Stat. Ann. § 603A.220(6)

Are There Security Measure Standards?

Yes. A data collector that maintains records which contain personal information of a resident of this state shall implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification or disclosure. Nev. Rev. Stat. Ann. § 603A.210(1).

Contract Requirements: Additionally, a contract for the disclosure of the personal information of a resident of this state which is maintained by a data collector must include a provision requiring the person to whom the information is disclosed to implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification or disclosure. Nev. Rev. Stat. Ann. § 603A.210(3).

Payment Cards: If a data collector doing business in this state accepts a payment card in connection with a sale of goods or services, the data collector shall comply with the current version of the Payment Card Industry (PCI) Data Security Standard, as adopted by the PCI Security Standards Council or its successor organization, with respect to those transactions, not later than the date for compliance set forth in the Payment Card Industry (PCI) Data Security Standard or by the PCI Security Standards Council or its successor organization. Nev. Rev. Stat. Ann. § 603A.215(1).

Destruction of Records: A business that maintains records which contain personal information concerning the customers of the business shall take reasonable measures to ensure the destruction of those records when the business decides that it will no longer maintain the records. “Reasonable measures to ensure the destruction” means any method that modifies the records containing the personal information in such a way as to render the personal information contained in the records unreadable or undecipherable, including, without limitation: (1) Shredding of the record containing the personal information; or (2) Erasing of the personal information from the records. Nev. Rev. Stat. Ann. § 603A.200.

What Are The Possible Consequences Of A Violation?

If the Attorney General or a district attorney of any county has reason to believe that any person is violating, proposes to violate or has violated the provisions of Nev. Rev. Stat. Ann. § 603A.010 to 603A.290, inclusive, the Attorney General or district attorney may bring an action against that person to obtain a temporary or permanent injunction against the violation. Nev. Rev. Stat. Ann. § 603A.290.

Are There Any Exemptions/Exceptions?

A data collector will be deemed in compliance with the notification requirements if it:

  1. Maintains its own notification policies and procedures as part of an information security policy for the treatment of personal information that is otherwise consistent with the timing requirements of this section shall be deemed to be in compliance with the notification requirements of this section if the data collector notifies subject persons in accordance with its policies and procedures in the event of a breach of the security of the system data.
  2. Is subject to and complies with the privacy and security provisions of the Gramm-Leach-Bliley Act, 15 U.S.C. §§ 6801, et seq., shall be deemed to be in compliance with the notification requirements of this section. Nev. Rev. Stat. Ann. § 603A.220(5).

Montana

Who Is Covered?

Any person or business that conducts business in Montana and that owns or licenses computerized data that includes personal information. Mont. Code Ann. § 30-14-1704(1).

What Information Is Protected?

 “Personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted:

  1. Social security number;
  2. Driver’s license number, state identification card number, or tribal identification card number;
  3. Account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account;
  4. Medical record information as defined in 33-19-104;
  5. A taxpayer identification number; or an identity protection personal identification number issued by the United States Internal Revenue Service. Mont. Code Ann. § 30-14-1704(4)(b)(i).

What Is A “Breach”?

“Breach of the security of the data system” means unauthorized acquisition of computerized data that materially compromises the security, confidentiality, or integrity of personal information maintained by the person or business and causes or is reasonably believed to cause loss or injury to a Montana resident. Good faith acquisition of personal information by an employee or agent of the person or business for the purposes of the person or business is not a breach of the security of the data system, provided that the personal information is not used or subject to further unauthorized disclosure. Mont. Code Ann. § 30-14-1704(4)(a).

What Triggers Notification?

Discovery or notification of the breach of data of any resident of Montana whose unencrypted personal information was or is reasonably believed to have been acquired by an unauthorized person. Mont. Code Ann. § 30-14-1704(1).

How Is Notice Provided To Individuals?

Timing: The disclosure must be made without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection (3), or consistent with any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Mont. Code Ann. § 30-14-1704(1).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. 7001;
  3. Telephonic notice; or
  4. Substitute notice, if the person or business demonstrates that: (A) the cost of providing notice would exceed $250,000; (B) the affected class of subject persons to be notified exceeds 500,000; or (C) the person or business does not have sufficient contact information. Mont. Code Ann. § 30-14-1704(5)(a).

Content: None specified, except if a business discloses a security breach to any individual pursuant to this section and gives a notice to the individual that suggests, indicates, or implies to the individual that the individual may obtain a copy of the file on the individual from a consumer credit reporting agency, the business shall coordinate with the consumer reporting agency as to the timing, content, and distribution of the notice to the individual. The coordination may not unreasonably delay the notice to the affected individuals. Mont. Code Ann. § 30-14-1704(7).

Is Notice To The Government Required?

Yes. Any person or business that is required to issue a notification pursuant to this section shall simultaneously submit an electronic copy of the notification and a statement providing the date and method of distribution of the notification to the attorney general’s consumer protection office, excluding any information that personally identifies any individual who is entitled to receive notification. If a notification is made to more than one individual, a single copy of the notification must be submitted that indicates the number of individuals in the state who received notification. Mont. Code Ann. § 30-14-1704(8).

Is Notice To Credit Reporting Agencies Required?

No, unless the notice suggests, indicates, or implies to the individual that the individual may obtain a copy of the file on the individual from a consumer credit reporting agency. See above.

Are There Security Measure Standards?

No, although separate from the breach notification law, Mont. Code Ann. § 30-14-1703 provides that a business shall take all reasonable steps to destroy or arrange for the destruction of a customer’s records within its custody or control containing personal information that is no longer necessary to be retained by the business by shredding, erasing, or otherwise modifying the personal information in those records to make it unreadable or undecipherable.

What Are The Possible Consequences Of A Violation?

Whenever the department has reason to believe that a person has violated this part and that proceeding would be in the public interest, the department may bring an action in the name of the state against the person to restrain by temporary or permanent injunction or temporary restraining order the use of the unlawful method, act, or practice upon giving appropriate notice to that person pursuant to Mont. Code Ann. § 30-14-111(2). A violation is an unlawful practice and the Attorney General may recover on behalf of the state a civil fine of not more than $10,000 for each violation. Mont. Code Ann. § 30-14-142(2).

Are There Any Exemptions/Exceptions?

A person or business that maintains its own notification procedures as part of an information security policy for the treatment of personal information and that does not unreasonably delay notice is considered to be in compliance with the notification requirements of this section if the person or business notifies subject persons in accordance with its policies in the event of a breach of security of the data system. Mont. Code Ann. § 30-14-1704(6).

Michigan

Who Is Covered?

A person or [state] agency that owns or licenses data that are included in a database. Mich. Comp. Laws Serv. § 445.72(1).

What Information Is Protected?

“Personal information” means the first name or first initial and last name linked to one or more of the following data elements of a resident of Michigan:

  1. Social security number.
  2. Driver license number or state personal identification card number.
  3. Demand deposit or other financial account number, or credit card or debit card number, in combination with any required security code, access code, or password that would permit access to any of the resident’s financial accounts. Mich. Comp. Laws Serv. § 445.63(r).

What Is A “Breach”?

“Breach of the security of a database” or “security breach” means the unauthorized access and acquisition of data that compromises the security or confidentiality of personal information maintained by a person or agency as part of a database of personal information regarding multiple individuals. Mich. Comp. Laws Serv. § 445.63(b).

“Data” means computerized personal information. Mich. Comp. Laws Serv. § 445.63(e).

What Triggers Notification?

Discovery or notice of a security breach with respect to one or more residents of Michigan involving:

  1. That resident’s unencrypted and unredacted personal information was accessed and acquired by an unauthorized person.
  2. That resident’s personal information was accessed and acquired in encrypted form by a person with unauthorized access to the encryption key. Mich. Comp. Laws Serv. § 445.72(1).

Risk of Harm Analysis: Notice is not required if the person or agency determines that the security breach has not or is not likely to cause substantial loss or injury to, or result in identity theft with respect to, one or more residents of Michigan. Mich. Comp. Laws Serv. § 445.72(1).

How Is Notice Provided To Individuals?

Timing: Notice must be provided without unreasonable delay. Mich. Comp. Laws Serv. § 445.72(4)(b).

Delivery: Notice may be by:

  1. Written notice sent to the recipient at the recipient’s postal address in the records of the agency or person.
  2. Written notice sent electronically to the recipient if any of the following are met: (i) The recipient has expressly consented to receive electronic notice. (ii) The person or agency has an existing business relationship with the recipient that includes periodic electronic mail communications and based on those communications the person or agency reasonably believes that it has the recipient’s current electronic mail address. (iii) The person or agency conducts its business primarily through internet account transactions or on the internet.
  3. If not otherwise prohibited by state or federal law, notice given by telephone by an individual who represents the person or agency if all of the following are met: (i) The notice is not given in whole or in part by use of a recorded message. (ii) The recipient has expressly consented to receive notice by telephone, or if the recipient has not expressly consented to receive notice by telephone, the person or agency also provides notice under subdivision [1 or 2 above] if the notice by telephone does not result in a live conversation between the individual representing the person or agency and the recipient within three business days after the initial attempt to provide telephonic notice.
  4. Substitute notice, if the person or agency demonstrates that the cost of providing notice under subdivision [1, 2 or 3 above] will exceed $250,000 or that the person or agency has to provide notice to more than 500,000 residents of this state. Mich. Comp. Laws Serv. § 445.72(5).

Content:  Notice shall do all of the following:

  1. For a notice provided in writing and sent by post or electronically, be written in a clear and conspicuous manner and contain the content required under subdivisions 3 to 7 below.
  2. For a notice provided telephonically, clearly communicate the content required under subdivisions 3 to 7 below to the recipient of the telephone call.
  3. Describe the security breach in general terms.
  4. Describe the type of personal information that is the subject of the unauthorized access or use.
  5. If applicable, generally describe what the agency or person providing the notice has done to protect data from further security breaches.
  6. Include a telephone number where a notice recipient may obtain assistance or additional information.
  7. Remind notice recipients of the need to remain vigilant for incidents of fraud and identity theft. Mich. Comp. Laws Serv. § 445.72(6).

Is Notice To The Government Required?

No.

Is Notice To Credit Reporting Agencies Required?

Yes. After a person or agency provides a notice under this section, the person or agency shall notify each consumer reporting agency that compiles and maintains files on consumers on a nationwide basis of the security breach without unreasonable delay. A notification under this subsection shall include the number of notices that the person or agency provided to residents of this state and the timing of those notices. However, this notice is unnecessary if the breach involves 1,000 or fewer residents or the person or agency is subject to 15 U.S.C. 6801, et seq. Mich. Comp. Laws Serv. § 445.72(8).

Are There Security Measure Standards?

No. But separate from the breach notification law, Mich. Comp. Laws Serv. § 445.72a requires that a person or agency that maintains a database that includes personal information regarding multiple individuals shall destroy any data that contain personal information concerning an individual when that data is removed from the database and the person or agency is not retaining the data elsewhere for another purpose not prohibited by state or federal law. This subsection does not prohibit a person or agency from retaining data that contain personal information for purposes of an investigation, audit, or internal review. A person who knowingly violates this section is guilty of a misdemeanor punishable by a fine of not more than $250 for each violation. Mich. Comp. Laws Serv. § 445.72a(1), (2).

What Are The Possible Consequences Of A Violation?

A person that knowingly fails to provide any notice of a security breach required under this section may be ordered to pay a civil fine of not more than $250 for each failure to provide notice. The attorney general or a prosecuting attorney may bring an action to recover a civil fine under this section. The aggregate liability of a person for civil fines for multiple violations that arise from the same security breach shall not exceed $750,000. Mich. Comp. Laws Serv. § 445.72(13), (14).

Are There Any Exemptions/Exceptions

A financial institution that is subject to, and has notification procedures in place that are subject to examination by the financial institution’s appropriate regulator for compliance with, the interagency guidance on response programs for unauthorized access to customer information and customer notice prescribed by the board of governors of the Federal Reserve System and the other federal bank and thrift regulatory agencies, or similar guidance prescribed and adopted by the National Credit Union Administration, and its affiliates, is considered to be in compliance with this section. Mich. Comp. Laws Serv. § 445.72(9).

Also, a person or agency that is subject to and complies with HIPAA for the prevention of unauthorized access to customer information and customer notice is considered to be in compliance with this section. Mich. Comp. Laws Serv. § 445.72(10).