Category Archives: Applicable to Paper Records

Wisconsin

Who Is Covered?

“Entity” means a person, other than an individual, that does any of the following:

  1. Conducts business in this state and maintains personal information in the ordinary course of business.
  2. Licenses personal information in this state.
  3. Maintains for a resident of this state a depository account as defined in s. 815.18 (2) (e).
  4. Lends money to a resident of this state. Wis. Stat. Ann. § 134.98(1)(a).

What Information Is Protected?

“Personal information” means an individual’s last name and the individual’s first name or first initial, in combination with and linked to any of the following elements, if the element is not publicly available information and is not encrypted, redacted, or altered in a manner that renders the element unreadable:

  1. The individual’s social security number.
  2. The individual’s driver’s license number or state identification number.
  3. The number of the individual’s financial account number, including a credit or debit card account number, or any security code, access code, or password that would permit access to the individual’s financial account.
  4. The individual’s deoxyribonucleic acid profile, as defined in s. 939.74 (2d) (a).
  5. The individual’s unique biometric data, including fingerprint, voice print, retina or iris image, or any other unique physical representation. Wis. Stat. Ann. § 134.98(1)(b).

What Is A “Breach”?

Knowledge that personal information of a resident of Wisconsin has been acquired by a person not authorized to acquire the personal information by:

  1. An entity whose principal place of business is located in this state or an entity that maintains or licenses personal information in this state; or
  2. An entity whose principal place of business is not located in this state. Wis. Stat. Ann. § 134.98(2)(a), (b).

What Triggers Notification?

Knowledge that personal information in the entity’s possession has been acquired by a person not authorized to acquire the personal information. Wis. Stat. Ann. § 134.98(2)(a), (b).

However, an entity is not required to provide notice of the acquisition of personal information if any of the following applies:

  1. The acquisition of personal information does not create a material risk of identity theft or fraud to the subject of the personal information. 
  2. The personal information was acquired in good faith by an employee or agent of the entity, if the personal information is used for a lawful purpose of the entity. Wis. Stat. Ann. § 134.98(2)(cm).

How Is Notice Provided To Individuals?

Timing: Subject to the needs of law enforcement, an entity shall provide the notice within a reasonable time, not to exceed 45 days after the entity learns of the acquisition of personal information. A determination as to reasonableness under this paragraph shall include consideration of the number of notices that an entity must provide and the methods of communication available to the entity. Wis. Stat. Ann. § 134.98(3)(a).

Delivery: An entity must provide notice by mail or by a method the entity has previously employed to communicate with the subject of the personal information. If an entity cannot with reasonable diligence determine the mailing address of the subject of the personal information, and if the entity has not previously communicated with the subject of the personal information, the entity shall provide notice by a method reasonably calculated to provide actual notice to the subject of the personal information. Wis. Stat. Ann. § 134.98(3)(b).

Content: The notice shall indicate that the entity knows of the unauthorized acquisition of personal information pertaining to the subject of the personal information. Wis. Stat. Ann. § 134.98(2)(b).

Is Notice To The Government Required?

No.

Is Notice To Credit Reporting Agencies Required?

Yes. If, as the result of a single incident, an entity is required to notify 1,000 or more individuals that personal information pertaining to the individuals has been acquired, the entity shall without unreasonable delay notify all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notices sent to the individuals. Wis. Stat. Ann. § 134.98(2)(br).

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

Failure to comply with this section is not negligence or a breach of any duty, but may be evidence of negligence or a breach of a legal duty. Wis. Stat. Ann. § 134.98(4).

Are There Any Exemptions/Exceptions?

This section does not apply to any of the following: a) An entity that is subject to, and in compliance with, the privacy and security requirements of 15 USC 6801 to 6827, or a person that has a contractual obligation to such an entity, if the entity or person has in effect a policy concerning breaches of information security. b) An entity that is described in 45 CFR 164.104 (a), if the entity complies with the requirements of 45 CFR part 164. Wis. Stat. Ann. § 134.98(3m).

Washington

Who Is Covered?

Any person or business that conducts business in Washington and that owns or licenses data that includes personal information. Wash. Rev. Code Ann. § 19.255.010(1).

What Information Is Protected?

“Personal information” is:

A. An individual’s first name or first initial and last name in combination with any one or more of the following data elements:

  1. Social security number;
  2. Driver’s license number or Washington identification card number;
  3. Account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account, or any other numbers or information that can be used to access a person’s financial account;
  4. Full date of birth;
  5. Private key that is unique to an individual and that is used to authenticate or sign an electronic record;
  6. Student, military, or passport identification number;
  7. Health insurance policy number or health insurance identification number;
  8. Any information about a consumer’s medical history or mental or physical condition or about a health care professional’s medical diagnosis or treatment of the consumer; or
  9. Biometric data generated by automatic measurements of an individual’s biological characteristics such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that is used to identify a specific individual;

B. Username or email address in combination with a password or security questions and answers that would permit access to an online account; and

C. Any of the data elements or any combination of the data elements described in subsection A, above, without the consumer’s first name or first initial and last name if:

  1. Encryption, redaction, or other methods have not rendered the data element or combination of data elements unusable; and
  2. The data element or combination of data elements would enable a person to commit identity theft against a consumer. Rev. Code Wash. (ARCW) § 19.255.005(2)(a).

What Is A “Breach”?

“Breach of the security of the system” means unauthorized acquisition of data that compromises the security, confidentiality, or integrity of personal information maintained by the person or business. Good faith acquisition of personal information by an employee or agent of the person or business for the purposes of the person or business is not a breach of the security of the system when the personal information is not used or subject to further unauthorized disclosure. Wash. Rev. Code Ann. § 19.255.005(1).

What Triggers Notification?

Any breach of the security of the system involving a resident’s personal information that was, or is reasonably believed to have been, acquired by an unauthorized person and the personal information was not secured. Wash. Rev. Code Ann. § 19.255.010(1).

Likelihood of Harm Analysis: Notice is not required if the breach of the security of the system is not reasonably likely to subject consumers to a risk of harm. The breach of secured personal information must be disclosed if the information acquired and accessed is not secured during a security breach or if the confidential process, encryption key, or other means to decipher the secured information was acquired by an unauthorized person. Wash. Rev. Code Ann. § 19.255.010(1).

How Is Notice Provided To Individuals?

Timing: Notification to affected consumers must be made in the most expedient time possible, without unreasonable delay, and no more than 30 calendar days after the breach was discovered, unless the delay is at the request of law enforcement or the delay is due to any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Wash. Rev. Code Ann. § 19.255.010(8).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. Sec. 7001;
  3. Substitute notice, if the person or business demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars, or that the affected class of subject persons to be notified exceeds five hundred thousand, or the person or business does not have sufficient contact information. Substitute notice shall consist of all of the following: (i) Email notice when the person or business has an email address for the subject persons; (ii) Conspicuous posting of the notice on the website page of the person or business, if the person or business maintains one; and (iii) Notification to major statewide media. Wash. Rev. Code Ann. § 19.255.010(4)(a)-(c).

If the breach of the security of the system involves personal information including a user name or password, notice may be provided electronically or by email. The notice must inform the person whose personal information has been breached to promptly change his or her password and security question or answer, as applicable, or to take other appropriate steps to protect the online account with the person or business and all other online accounts for which the person whose personal information has been breached uses the same user name or email address and password or security question or answer. Wash. Rev. Code Ann. § 19.255.010(4)(d)(i).

However, when the breach of the security of the system involves login credentials of an email account furnished by the person or business, the person or business may not provide the notification to that email address, but must provide notice using another method described [above]. The notice must inform the person whose personal information has been breached to promptly change his or her password and security question or answer, as applicable, or to take other appropriate steps to protect the online account with the person or business and all other online accounts for which the person whose personal information has been breached uses the same user name or email address and password or security question or answer. Wash. Rev. Code Ann. § 19.255.010(4)(d)(ii).

Content: The notice must be written in plain language and include the following information:

  1. The name and contact information of the reporting person or business subject to this section;
  2. A list of the types of personal information that were or are reasonably believed to have been the subject of a breach;
  3. A time frame of exposure, if known, including the date of the breach and the date of the discovery of the breach; and
  4. The toll-free telephone numbers and addresses of the major credit reporting agencies if the breach exposed personal information. Wash. Rev. Code Ann. § 19.255.010(6).

Is Notice To The Government Required?

Yes. Any person or business that is required to issue a notification pursuant to this section to more than 500 Washington residents as a result of a single breach shall notify the attorney general of the breach no more than 30 days after the breach was discovered. The notice must include:

  1. The number of Washington consumers affected by the breach, or an estimate if the exact number is not known;
  2. A list of the types of personal information that were or are reasonably believed to have been the subject of a breach;
  3. A time frame of exposure, if known, including the date of the breach and the date of the discovery of the breach;
  4. A summary of steps taken to contain the breach; and
  5. A single sample copy of the security breach notification, excluding any personally identifiable information. Wash. Rev. Code Ann. § 19.255.010(7).

Is Notice To Credit Reporting Agencies Required?

No.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

The attorney general may bring an action in the name of the state, or as parens patriae on behalf of persons residing in the state, to enforce this chapter. For actions brought by the attorney general to enforce this chapter, the legislature finds that the practices covered by this chapter are matters vitally affecting the public interest for the purpose of applying the consumer protection act, chapter 19.86 RCW. For actions brought by the attorney general to enforce this chapter, a violation of this chapter is not reasonable in relation to the development and preservation of business and is an unfair or deceptive act in trade or commerce and an unfair method of competition for purposes of applying the consumer protection act, chapter 19.86 RCW. Wash. Rev. Code Ann. § 19.255.040(2).

Additionally, any consumer injured by a violation of this chapter may institute a civil action to recover damages. Wash. Rev. Code Ann. § 19.255.040(3).

Are There Any Exemptions/Exceptions?

A covered entity under the federal Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. Sec. 1320d et seq., is deemed to have complied with the requirements of this chapter with respect to protected health information if it has complied with section 13402 of the federal Health Information Technology for Economic and Clinical Health Act, P.L. 111-5 as it existed on July 24, 2015. Covered entities shall notify the attorney general pursuant to RCW 19.255.010(7) in compliance with the timeliness of notification requirements of section 13402 of the federal Health Information Technology for Economic and Clinical Health Act, P.L. 111-5 as it existed on July 24, 2015, notwithstanding the timeline in RCW 19.255.010(7). Wash. Rev. Code Ann. § 19.255.030(1).

Additionally, a financial institution under the authority of the Office of the Comptroller of the Currency, the Federal Deposit Insurance Corporation, the National Credit Union Administration, or the Federal Reserve System is deemed to have complied with the requirements of this chapter with respect to “sensitive customer information” as defined in the Interagency Guidelines Establishing Information Security Standards, 12 C.F.R. Part 30, Appendix B, 12 C.F.R. Part 208, Appendix D-2, 12 C.F.R. Part 225, Appendix F, and 12 C.F.R. Part 364, Appendix B, and 12 C.F.R. Part 748, Appendices A and B, as they existed on July 24, 2015, if the financial institution provides notice to affected consumers pursuant to the interagency guidelines and the notice complies with the customer notice provisions of the Interagency Guidelines Establishing Information Security Standards and the Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice under 12 C.F.R. Part 364 as it existed on July 24, 2015. The entity shall notify the attorney general pursuant to RCW 19.255.010 in addition to providing notice to its primary federal regulator. Wash. Rev. Code Ann. § 19.255.030(2).

Payment Processors

Note: Additional requirements apply to a person or entity “that directly processes or transmits account information for or on behalf of another person as part of a payment processing service.” See Wash. Rev. Code Ann. § 19.255.020.

North Carolina

Who Is Covered?

Any business that owns or licenses personal information of residents of North Carolina or any business that conducts business in North Carolina that owns or licenses personal information in any form (whether computerized, paper, or otherwise). N.C. Gen. Stat. § 75-65(a).

What Information Is Protected?

A person’s first name or first initial and last name in combination with identifying information including the following:

  1. Social security or employer taxpayer identification numbers.   
  2. Drivers license, State identification card, or passport numbers.  
  3. Checking account numbers.  
  4. Savings account numbers.  
  5. Credit card numbers. 
  6. Debit card numbers.  
  7. Personal Identification (PIN) Code.    
  8. Digital signatures.  
  9. Any other numbers or information that can be used to access a person’s financial resources.  
  10. Biometric data.  
  11. Fingerprints.  
  12. Passwords if they would permit access to a person’s financial account or resources. N.C. Gen. Stat. §§ 75.61(10); 14-113.20(b).

What Is A “Breach”?

An incident of unauthorized access to and acquisition of unencrypted and unredacted records or data containing personal information where illegal use of the personal information has occurred or is reasonably likely to occur or that creates a material risk of harm to a consumer. Any incident of unauthorized access to and acquisition of encrypted records or data containing personal information along with the confidential process or key shall constitute a security breach. Good faith acquisition of personal information by an employee or agent of the business for a legitimate purpose is not a security breach, provided that the personal information is not used for a purpose other than a lawful purpose of the business and is not subject to further unauthorized disclosure. N.C. Gen. Stat. § 75-61(14).

What Triggers Notification?

Discovery or notification of the breach. N.C. Gen. Stat. § 75-65(a).

How Is Notice Provided To Individuals?

Timing: Notice must be made without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine sufficient contact information, determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system. N.C. Gen. Stat. § 75-65(a).

Delivery: Delivery may be by:

  1. Written notice.  
  2. Electronic notice, for those persons for whom it has a valid e-mail address and who have agreed to receive communications electronically if the notice provided is consistent with the provisions of the E-Sign Act.  
  3. Telephonic notice provided that contact is made directly with the affected persons.  
  4. Substitute notice, if the business demonstrates that the cost of providing notice would exceed $250,000 or that the affected class of subject persons to be notified exceeds 500,000, or if the business does not have sufficient contact information or consent to satisfy subdivisions (1), (2), or (3) of this subsection, for only those affected persons without sufficient contact information or consent, or if the business is unable to identify particular affected persons, for only those unidentifiable affected persons. Substitute notice shall consist of all the following: a)  E-mail notice when the business has an electronic mail address for the subject persons. b)  Conspicuous posting of the notice on the Web site page of the business, if one is maintained. c)  Notification to major statewide media. N.C. Gen. Stat. § 75-65(e).

Content: The notice must be clear and conspicuous and include:

  1. A description of the incident in general terms.  
  2. A description of the type of personal information that was subject to the unauthorized access and acquisition.  
  3. A description of the general acts of the business to protect the personal information from further unauthorized access.  
  4. A telephone number for the business that the person may call for further information and assistance, if one exists.  
  5. Advice that directs the person to remain vigilant by reviewing account statements and monitoring free credit reports.  
  6. The toll-free numbers and addresses for the major consumer reporting agencies.  
  7. The toll-free numbers, addresses, and Web site addresses for the Federal Trade Commission and the North Carolina Attorney General’s Office, along with a statement that the individual can obtain information from these sources about preventing identity theft. N.C. Gen. Stat. § 75-65(d).

Is Notice To The Government Required?

Yes. In the event a business provides notice to an affected person pursuant to this section, the business shall notify without unreasonable delay the Consumer Protection Division of the Attorney General’s Office of the nature of the breach, the number of consumers affected by the breach, steps taken to investigate the breach, steps taken to prevent a similar breach in the future, and information regarding the timing, distribution, and content of the notice. N.C. Gen. Stat. § 75-65(e1).

Is Notice To Credit Reporting Agencies Required?

Yes. In the event a business provides notice to more than 1,000 persons at one time pursuant to this section, the business shall notify, without unreasonable delay, the Consumer Protection Division of the Attorney General’s Office and all consumer reporting agencies of the timing, distribution, and content of the notice. N.C. Gen. Stat. § 75-65(f).

Are There Security Measure Standards?

Yes, with regard to destruction of records. Any business that conducts business in North Carolina and any business that maintains or otherwise possesses personal information of a resident of North Carolina must take reasonable measures to protect against unauthorized access to or use of the information in connection with or after its disposal, which must include:

  1. Implementing and monitoring compliance with policies and procedures that require the burning, pulverizing, or shredding of papers containing personal information so that information cannot be practicably read or reconstructed.  
  2. Implementing and monitoring compliance with policies and procedures that require the destruction or erasure of electronic media and other nonpaper media containing personal information so that the information cannot practicably be read or reconstructed.  
  3. Describing procedures relating to the adequate destruction or proper disposal of personal records as official policy in the writings of the business entity. N.C. Gen. Stat. § 75-64(a), (b).

What Are The Possible Consequences Of A Violation?

A violation is an unfair or deceptive act or practice under N.C. Gen. Stat. § 75-1.1 which can result in a civil penalty of up to $5,000 per violation for knowing violations. No private right of action may be brought by an individual for a violation of this section unless such individual is injured as a result of the violation. N.C. Gen. Stat. §§ 75-65(i); 75-15.2; 75.16.

Are There Any Exemptions/Exceptions?

A financial institution that is subject to and in compliance with the Federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information and Customer Notice, issued on March 7, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision; or a credit union that is subject to and in compliance with the Final Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice, issued on April 14, 2005, by the National Credit Union Administration; and any revisions, additions, or substitutions relating to any of the said interagency guidance, shall be deemed to be in compliance with this section. N.C. Gen. Stat. § 75-65(h).

Massachusetts

Who Is Covered?

A person or agency that owns or licenses data that includes personal information about a resident of Massachusetts. Mass. Ann. Laws ch. 93H, § 3(b).

“Agency” means any agency, executive office, department, board, commission, bureau, division or authority of the commonwealth, or any of its branches, or of any political subdivision thereof. Mass. Ann. Laws ch. 93H, § 1.

What Information Is Protected?

“Personal information” means a resident’s first name and last name or first initial and last name in combination with any one or more of the following data elements that relate to such resident:

  1. Social security number;
  2. Driver’s license number or state-issued identification card number; or
  3. Financial account number, or credit or debit card number, with or without any required security code, access code, personal identification number or password, that would permit access to a resident’s financial account; provided, however, that “Personal information” shall not include information that is lawfully obtained from publicly available information, or from federal, state or local government records lawfully made available to the general public. Mass. Ann. Laws ch. 93H, § 1.

What Is A “Breach”?

“Breach of security” is the unauthorized acquisition or unauthorized use of unencrypted data or, encrypted electronic data and the confidential process or key that is capable of compromising the security, confidentiality, or integrity of personal information, maintained by a person or agency that creates a substantial risk of identity theft or fraud against a resident of the commonwealth. A good faith but unauthorized acquisition of personal information by a person or agency, or employee or agent thereof, for the lawful purposes of such person or agency, is not a breach of security unless the personal information is used in an unauthorized manner or subject to further unauthorized disclosure. Mass. Ann. Laws ch. 93H, § 1.

“Data” is any material upon which written, drawn, spoken, visual, or electromagnetic information or images are recorded or preserved, regardless of physical form or characteristics. Mass. Ann. Laws ch. 93H, § 1.

What Triggers Notification?

When the person or agency:

  1. Knows or has reason to know of a breach of security; or
  2. Knows or has reason to know that the personal information of such resident was acquired or used by an unauthorized person or used for an unauthorized purpose. Mass. Ann. Laws ch. 93H, § 3(b).

How Is Notice Provided To Individuals?

Timing: As soon as practicable and without unreasonable delay. Mass. Ann. Laws ch. 93H, § 3(b).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic notice, if notice provided is consistent with the provisions regarding electronic records and signatures set forth in § 7001 (c) of Title 15 of the United States Code; and chapter 110G; or
  3. Substitute notice, if the person or agency required to provide notice demonstrates that the cost of providing written notice will exceed $250,000, or that the affected class of Massachusetts residents to be notified exceeds 500,000 residents, or that the person or agency does not have sufficient contact information to provide notice. Mass. Ann. Laws ch. 93H, § 1.

Content: The notice to be provided to the resident shall include, but shall not be limited to:

  1. The resident’s right to obtain a police report;
  2. How a resident may request a security freeze and the necessary information to be provided when requesting the security freeze;
  3. That there shall be no charge for a security freeze; and
  4. Mitigation services to be provided pursuant to this chapter.

The notice must not include the nature of the breach of security or unauthorized acquisition or use, or the number of residents of the commonwealth affected by said breach of security or unauthorized access or use. Mass. Ann. Laws ch. 93H, § 3(b).

If the breach involves a social security number, the covered person must contract with a third party to offer to each resident whose social security number was disclosed in the breach of security or is reasonably believed to have been disclosed in the breach of security, credit monitoring services at no cost to said resident for a period of not less than 18 months. A person that experienced a breach of security shall not require a resident to waive the resident’s right to a private right of action as a condition of the offer of credit monitoring services. Mass. Ann. Laws ch. 93H, § 3A(a), (b).

Is Notice To The Government Required?

Yes. The person or agency that experienced the breach of security shall provide a sample copy of the notice it sent to consumers to the attorney general and the office of consumer affairs and business regulation. A notice provided pursuant to this section shall not be delayed on grounds that the total number of residents affected is not yet ascertained. In such case, and where otherwise necessary to update or correct the information required, a person or agency shall provide additional notice as soon as practicable and without unreasonable delay upon learning such additional information. Mass. Ann. Laws ch. 93H, § 3(b).

The notice to be provided to the attorney general and said director, and consumer reporting agencies or state agencies if any, shall include, but not be limited to:

  1. The nature of the breach of security or unauthorized acquisition or use;
  2. The number of residents of the commonwealth affected by such incident at the time of notification;
  3. The name and address of the person or agency that experienced the breach of security;
  4. Name and title of the person or agency reporting the breach of security, and their relationship to the person or agency that experienced the breach of security;
  5. The type of person or agency reporting the breach of security;
  6. The person responsible for the breach of security, if known;
  7. The type of personal information compromised, including, but not limited to, social security number, driver’s license number, financial account number, credit or debit card number or other data;
  8. Whether the person or agency maintains a written information security program; and
  9. Any steps the person or agency has taken or plans to take relating to the incident, including updating the written information security program.

Is Notice To Credit Reporting Agencies Required?

Yes. See above.

Are There Security Measure Standards?

No, but see Mass. Ann. Laws ch. 93I, §§ 1, 2 and 3 for the standards for disposal of records containing personal information.

What Are The Possible Consequences Of A Violation?

The attorney general may bring an action pursuant to Mass. Ann. Laws ch. 93A, § 4 [temporary restraining order or preliminary or permanent injunction] against a person or otherwise to remedy violations of this chapter and for other relief that may be appropriate. Mass. Ann. Laws ch. 93H, § 6.

Are There Any Exemptions/Exceptions?

A person who maintains procedures for responding to a breach of security pursuant to federal laws, rules, regulations, guidance, or guidelines, is deemed to be in compliance with this chapter if the person notifies affected Massachusetts residents in accordance with the maintained or required procedures when a breach occurs; provided further that the person also notifies the attorney general and the director of the office of consumer affairs and business regulation of the breach as soon as practicable and without unreasonable delay following the breach. The notice to be provided to the attorney general and the director of the office of consumer affairs and business regulation shall consist of, but not be limited to, any steps the person or agency has taken or plans to take relating to the breach pursuant to the applicable federal law, rule, regulation, guidance or guidelines; provided further that if said person or agency does not comply with applicable federal laws, rules, regulations, guidance or guidelines, then it shall be subject to the provisions of this chapter. Mass. Ann. Laws ch. 93H, § 5.

Iowa

Who Is Covered?

Any person who owns or licenses computerized data that includes a consumer’s [Iowa resident’s] personal information that is used in the course of the person’s business, vocation, occupation, or volunteer activities. Iowa Code § 715C.2(1).

What Information Is Protected?

“Personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements that relate to the individual if any of the data elements are not encrypted, redacted, or otherwise altered by any method or technology in such a manner that the name or data elements are unreadable or are encrypted, redacted, or otherwise altered by any method or technology but the keys to unencrypt, unredact, or otherwise read the data elements have been obtained through the breach of security:

  1. Social security number.
  2. Driver’s license number or other unique identification number created or collected by a government body.
  3. Financial account number, credit card number, or debit card number in combination with any required expiration date, security code, access code, or password that would permit access to an individual’s financial account.
  4. Unique electronic identifier or routing code, in combination with any required security code, access code, or password that would permit access to an individual’s financial account.
  5. Unique biometric data, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data. Iowa Code § 715C.1(11).

What Is A “Breach”?

“Breach of security” means unauthorized acquisition of personal information maintained in computerized form by a person that compromises the security, confidentiality, or integrity of the personal information. Iowa Code § 715C.1(1).

“Breach of security” also means unauthorized acquisition of personal information maintained by a person in any medium, including on paper, that was transferred by the person to that medium from computerized form and that compromises the security, confidentiality, or integrity of the personal information. Good faith acquisition of personal information by a person or that person’s employee or agent for a legitimate purpose of that person is not a breach of security, provided that the personal information is not used in violation of applicable law or in a manner that harms or poses an actual threat to the security, confidentiality, or integrity of the personal information. Iowa Code § 715C.1(1).

What Triggers Notification?

Discovery of a breach of security. Iowa Code § 715C.2(1).

Likelihood of Harm Analysis: Notification is not required if, after an appropriate investigation or after consultation with the relevant federal, state, or local agencies responsible for law enforcement, the person determined that no reasonable likelihood of financial harm to the consumers whose personal information has been acquired has resulted or will result from the breach. Such a determination must be documented in writing and the documentation must be maintained for five years. Iowa Code § 715C.2(6).

How Is Notice Provided To Individuals?

Timing: The consumer notification shall be made in the most expeditious manner possible and without unreasonable delay, consistent with the legitimate needs of law enforcement as provided in subsection 3, and consistent with any measures necessary to sufficiently determine contact information for the affected consumers, determine the scope of the breach, and restore the reasonable integrity, security, and confidentiality of the data. Iowa Code § 715C.2(1).

Delivery: Notice may be made by:

  1. Written notice to the last available address the person has in the person’s records.
  2. Electronic notice if the person’s customary method of communication with the consumer is by electronic means or is consistent with the provisions of the E-Sign Act.
  3. Substitute notice, in certain circumstances. Iowa Code § 715C.2(4).

Content: The notice must include:

  1. A description of the breach of security.
  2. The approximate date of the breach of security.
  3. The type of personal information obtained as a result of the breach of security.
  4. Contact information for consumer reporting agencies. Advice to the consumer to report suspected incidents of identity theft to local law enforcement or the attorney general. Iowa Code § 715C.2(5).

Is Notice To The Government Required?

Yes. Any person who owns or licenses computerized data that includes a consumer’s personal information that is used in the course of the person’s business, vocation, occupation, or volunteer activities and that was subject to a breach of security requiring notification to more than five hundred residents of this state pursuant to this section shall give written notice of the breach of security to the director of the consumer protection division of the office of the attorney general within five business days after giving notice of the breach of security to any consumer pursuant to this section. Iowa Code § 715C.2(8).

Is Notice To Credit Reporting Agencies Required?

No.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

A violation of this chapter is an unlawful practice pursuant to Iowa Code § 714.16 and, in addition to the remedies provided to the attorney general pursuant to Iowa Code § 714.16, the attorney general may seek and obtain an order that a party held to violate this section pay damages to the attorney general on behalf of a person injured by the violation. Iowa Code § 715C.2(9).

Are There Any Exemptions/Exceptions?

The notification requirements do not apply to any of the following:

  1. A person who complies with notification requirements or breach of security procedures that provide greater protection to personal information and at least as thorough disclosure requirements than that provided by this section pursuant to the rules, regulations, procedures, guidance, or guidelines established by the person’s primary or functional federal regulator.
  2. A person who complies with a state or federal law that provides greater protection to personal information and at least as thorough disclosure requirements for breach of security or personal information than that provided by this section.
  3. A person who is subject to and complies with regulations promulgated pursuant to Tit. V of the federal Gramm-Leach-Bliley Act.
  4. A person who is subject to and complies with regulations promulgated pursuant to Tit. II, subtit. F of the federal Health Insurance Portability and Accountability Act. Iowa Code § 715C.2(7).

Indiana

Who Is Covered?

“Data base owner” means a person that owns or licenses computerized data that includes personal information. Ind. Code Ann. § 24-4.9-2-3.

 

What Information Is Protected?

“Personal information” means:

 

  1. A Social Security number that is not encrypted or redacted; or
  2. An individual’s first and last names, or first initial and last name, and one or more of the following data elements that are not encrypted or redacted: (A) A driver’s license number; (B) A state identification card number; (C) A credit card number; (D) A financial account number or debit card number in combination with a security code, password, or access code that would permit access to the person’s account. Ind. Code Ann. § 24-4.9-2-10.

 

What Is A “Breach”?

“Breach of the security of data” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by a person. The term includes the unauthorized acquisition of computerized data that have been transferred to another medium, including paper, microfilm, or a similar medium, even if the transferred data are no longer in a computerized format. Ind. Code Ann. § 24-4.9-2-2(a).

The term does not include the following:

 

  1. Good faith acquisition of personal information by an employee or agent of the person for lawful purposes of the person, if the personal information is not used or subject to further unauthorized disclosure.
  2. Unauthorized acquisition of a portable electronic device on which personal information is stored, if all personal information on the device is protected by encryption and the encryption key: (A) has not been compromised or disclosed; and (B) is not in the possession of or known to the person who, without authorization, acquired or has access to the portable electronic device. Ind. Code Ann. § 24-4.9-2-2(a).

 

What Triggers Notification?

Discovering or being notified of a breach of the security of data involving an Indiana resident where: 1) unencrypted personal information was or may have been acquired by an unauthorized person; or 2) encrypted personal information was or may have been acquired by an unauthorized person with access to the encryption key; provided, the data base owner knows, should know, or should have known that the unauthorized acquisition constituting the breach has resulted in or could result in identity deception, identity theft, or fraud affecting the Indiana resident. Ind. Code Ann. § 24-4.9-3-1.

 

How Is Notice Provided To Individuals?

Timing: A person required to make a disclosure or notification under this chapter shall make the disclosure or notification without unreasonable delay, but more than 45 days after the discovery of the breach, subject to certain exceptions. Ind. Code Ann. § 24-4.9-3-1(a).

Delivery: Disclosure may be made by:

 

  1. Mail;
  2. Telephone;
  3. Fax;
  4. Email, if the data base owner has the email address of the affected Indiana resident; or
  5. Substitute service in certain circumstances. Ind. Code Ann. § 24-4.9-3-4(a).

Content: None specified.

 

Is Notice To The Government Required?

Yes. Notice to the Attorney General is required whenever disclosure is required to Indiana residents. Ind. Code Ann. § 24-4.9-3-1(c).

 

Is Notice To Credit Reporting Agencies Required?

Yes. A data base owner required to make a disclosure to more than 1,000 consumers shall also disclose to each consumer reporting agency information necessary to assist the consumer reporting agency in preventing fraud, including personal information of an Indiana resident affected by the breach of the security of a system. Ind. Code Ann. § 24-4.9-3-1(b).

 

Are There Security Measure Standards?

Yes. Subject to certain exceptions [see § 24-4.9-3-3.5(a)], a data base owner shall implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect and safeguard from unlawful use or disclosure any personal information of Indiana residents collected or maintained by the data base owner. Ind. Code Ann. § 24-4.9-3-3.5(c).

Additionally, a data base owner shall not dispose of or abandon records or documents containing unencrypted and unredacted personal information of Indiana residents without shredding, incinerating, mutilating, erasing, or otherwise rendering the personal information illegible or unusable. Ind. Code Ann. § 24-4.9-3-3.5(d).

A person that knowingly or intentionally fails to comply with [the safeguard provisions] commits a deceptive act that is actionable only by the attorney general under this section, who may obtain:

 

  1. An injunction to enjoin further violations of this section.
  2. A civil penalty of not more than $5,000 per deceptive act.
  3. The attorney general’s reasonable costs in: a) the investigation of the deceptive act; and b) maintaining the action. Ind. Code Ann. § 24-4.9-3-3.5(e), (f).

 

What Are The Possible Consequences Of A Violation?

A person that fails to make a disclosure or notification commits a deceptive act that is actionable only by the attorney general under this chapter, and a failure to make a required disclosure or notification in connection with a related series of breaches of the security of data constitutes one deceptive act. Burns Ind. Code Ann. § 24-4.9-4-1.

The Attorney General may bring an action to obtain:

 

  1. An injunction to enjoin future violations of IC 24-4.9-3.
  2. A civil penalty of not more than $150,000 per deceptive act.
  3. The attorney general’s reasonable costs in: a) the investigation of the deceptive act; and b) maintaining the action. Burns Ind. Code Ann. § 24-4.9-4-2.

 

Are There Any Exemptions/Exceptions?

A data base owner that maintains its own disclosure procedures as part of an information privacy policy or a security policy is not required to make a separate disclosure under this chapter if the data base owner’s information privacy policy or security policy is at least as stringent as the disclosure requirements described in [the Indiana law]. Burns Ind. Code Ann. § 24-4.9-3-4(c).

Also, a data base owner that maintains its own disclosure procedures as part of an information privacy, security policy, or compliance plan under any of the following acts is not required to make a disclosure under this chapter if the data base owner’s information privacy, security policy, or compliance plan requires that Indiana residents be notified of a breach of the security of data without unreasonable delay and the data base owner complies with the data base owner’s information privacy, security policy, or compliance plan:

 

  1. The federal USA PATRIOT Act;
  2. Executive Order 13224;
  3. The federal Driver’s Privacy Protection Act;
  4. The federal Fair Credit Reporting Act;
  5. The federal Financial Modernization Act of 1999; or
  6. The federal Health Insurance Portability and Accountability Act. Burns Ind. Code Ann. § 24-4.9-3-4(d)

Hawaii

Who Is Covered?

Any business that owns or licenses personal information of residents of Hawaii, any business that conducts business in Hawaii that owns or licenses personal information in any form (whether computerized, paper, or otherwise), or any government agency that collects personal information for specific government purposes. Haw. Rev. Stat. Ann. § 487N-2(a).

What Information Is Protected?

“Personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted:

  1. Social security number;
  2. Driver’s license number or Hawaii identification card number; or
  3. Account number, credit or debit card number, access code, or password that would permit access to an individual’s financial account. Haw. Rev. Stat. Ann. § 487N-1.

What Is A “Breach”?

“Security breach” means an incident of unauthorized access to and acquisition of unencrypted or unredacted records or data containing personal information where illegal use of the personal information has occurred, or is reasonably likely to occur and that creates a risk of harm to a person. Any incident of unauthorized access to and acquisition of encrypted records or data containing personal information along with the confidential process or key constitutes a security breach. Good faith acquisition of personal information by an employee or agent of the business for a legitimate purpose is not a security breach; provided that the personal information is not used for a purpose other than a lawful purpose of the business and is not subject to further unauthorized disclosure. Haw. Rev. Stat. Ann. § 487N-1.

“Records” means any material on which written, drawn, spoken, visual, or electromagnetic information is recorded or preserved, regardless of physical form or characteristics. Haw. Rev. Stat. Ann. § 487N-1.

What Triggers Notification?

Discovery or notification of a breach. Haw. Rev. Stat. Ann. § 487N-2(a).

How Is Notice Provided To Individuals?

Timing: The disclosure notification shall be made without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine sufficient contact information, determine the scope of the breach, and restore the reasonable integrity, security, and confidentiality of the data system. Haw. Rev. Stat. Ann. § 487N-2(a).

Delivery: Notice may be made by:

  1. Written notice to the last available address the business or government agency has on record;
  2. Electronic mail notice, for those persons for whom a business or government agency has a valid electronic mail address and who have agreed to receive communications electronically if the notice provided is consistent with the provisions regarding electronic records and signatures for notices legally required to be in writing set forth in 15 U.S.C. section 7001;
  3. Telephonic notice, provided that contact is made directly with the affected persons; and
  4. Substitute notice in certain circumstances. Haw. Rev. Stat. Ann. § 487N-2(e).

Content: The notice must be clear and conspicuous and include a description of:

  1. The incident in general terms;
  2. The type of personal information that was subject to the unauthorized access and acquisition;
  3. The general acts of the business or government agency to protect the personal information from further unauthorized access;
  4. A telephone number that the person may call for further information and assistance, if one exists; and
  5. Advice that directs the person to remain vigilant by reviewing account statements and monitoring free credit reports. Haw. Rev. Stat. Ann. § 487N-2(d).

Is Notice To The Government Required?

Yes. In the event a business provides notice to more than one thousand persons at one time pursuant to this section, the business shall notify in writing, without unreasonable delay, the State of Hawaii’s office of consumer protection and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, of the timing, distribution, and content of the notice. Haw. Rev. Stat. Ann. § 487N-2(f).

Is Notice To Credit Reporting Agencies Required?

Yes. In the event a business provides notice to more than one thousand persons at one time pursuant to this section, the business shall notify in writing, without unreasonable delay, the State of Hawaii’s office of consumer protection and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, of the timing, distribution, and content of the notice. Haw. Rev. Stat. Ann. § 487N-2(f).

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

Any business that violates any provision of this chapter shall be subject to penalties of not more than $2,500 for each violation. The attorney general or the executive director of the office of consumer protection may bring an action pursuant to this section. No such action may be brought against a government agency. Haw. Rev. Stat. Ann. § 487N-3(a).

Additionally, any business that violates any provision of this chapter shall be liable to the injured party in an amount equal to the sum of any actual damages sustained by the injured party as a result of the violation. The court in any action brought under this section may award reasonable attorneys’ fees to the prevailing party. No such action may be brought against a government agency. Haw. Rev. Stat. Ann. § 487N-3(b).

Are There Any Exemptions/Exceptions?

Yes. The following are considered to be in compliance:

  1. A financial institution that is subject to the federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice published in the Federal Register on March 29, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision, or subject to 12 C.F.R. Part 748, and any revisions, additions, or substitutions relating to the interagency guidance; and
  2. Any health plan or healthcare provider that is subject to and in compliance with the standards for privacy or individually identifiable health information and the security standards for the protection of electronic health information of the Health Insurance Portability and Accountability Act of 1996. Haw. Rev. Stat. Ann. § 487N-3(g).

Alaska

Who Is Covered?

An “information collector” is a covered person who owns or licenses personal information in any form if the personal information includes personal information on a state resident; A “covered person” is a:

  1. Person doing business;
  2. Governmental agency; or
  3. Person with more than 10 employees. Alaska Stat. § 45.48.090(2)

What Information Is Protected?

“Personal information” means information in any form on an individual that is not encrypted or redacted, or is encrypted and the encryption key has been accessed or acquired, and that consists of a combination of an individual’s first name or first initial and last name, and:

  1. The individual’s social security number;
  2. The individual’s driver’s license number or state identification card number;
  3. Except as provided in (4) of this subparagraph, the individual’s account number, credit card number, or debit card number;
  4.  If an account can only be accessed with a personal code, the number in (3) of this subparagraph and the personal code; in this sub-subparagraph, “personal code” means a security code, an access code, a personal identification number, or a password;
  5. Passwords, personal identification numbers, or other access codes for financial accounts. Alaska Stat. § 45.48.090(7).

What Is A “Breach”?

“Breach of the security” means unauthorized acquisition, or reasonable belief of unauthorized acquisition, of personal information that compromises the security, confidentiality, or integrity of the personal information maintained by the information collector; in this paragraph, “acquisition” includes acquisition by:

  1. Photocopying, facsimile, or other paper-based method;
  2. A device, including a computer, that can read, write, or store information that is represented in numerical form; or
  3. A method not identified by [1] or [2] of this paragraph.

What Triggers Notification?

Discovery or notification of a breach of the security of the information system that contains personal information. Alaska Stat. § 45.48.010(a).

How Is Notice Provided To Individuals?

Timing: Disclosure must be made in the most expeditious time possible and without unreasonable delay, subject to exceptions related to law enforcement or restoring the integrity of the information system. Alaska Stat. § 45.48.010(b).

However, disclosure is not required if, after an appropriate investigation and after written notification to the attorney general, the covered person determines that there is not a reasonable likelihood that harm to the consumers whose personal information has been acquired has resulted or will result from the breach. Alaska Stat. § 45.48.010(c).

Delivery: An information collector must make the disclosure:

  1. By a written document sent to the most recent address the information collector has for the state resident;
  2. By electronic means if the information collector’s primary method of communication with the state resident is by electronic means or if making the disclosure by the electronic means is consistent with the E-Sign Act; or
  3. If the information collector demonstrates that the cost of providing notice would exceed $150,000, that the affected class of state residents to be notified exceeds 300,000, or that the information collector does not have sufficient contact information to provide notice, by: a) electronic mail if the information collector has an electronic mail address for the state resident; b) conspicuously posting the disclosure on the Internet website of the information collector if the information collector maintains an Internet website; and c) providing a notice to major statewide media. Alaska Stat. § 45.48.030.

Content: None specified.

Is Notice To The Government Required?

No, except as described above to establish there is no reasonable likelihood of harm. Alaska Stat. § 45.48.010(c).

Is Notice To Consumer Reporting Agencies Required?

Yes. If an information collector is required by AS 45.48.010 to notify more than 1,000 state residents of a breach, the information collector shall also notify without unreasonable delay all consumer credit reporting agencies that compile and maintain files on consumers on a nationwide basis and provide the agencies with the timing, distribution, and content of the notices to state residents. This requirement does not apply to an information collector who is subject to the GLBA. Alaska Stat. § 45.48.040(a), (b).

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

An information collector is liable to the state for a civil penalty of up to $500 for each state resident who was not notified, except that the total civil penalty may not exceed $50,000. Alaska Stat. § 45.48.080(b)

Additionally, a violation by an information collector with regard to the personal information of a state resident is an unfair or deceptive act or practice under Alaska Stat. § 45.50.471 – § 45.50.561, allowing for actual economic damages not to exceed $500, whichever is greater, and attorney fees and costs. Alaska Stat. § 45.48.080(b).

Are There Any Exemptions?

No, except as described above regarding notice to CRAs.