Category Archives: Likelihood of Harm Analysis

Colorado

Who Is Covered?

A covered entity that maintains, owns, or licenses computerized data that includes personal information about a resident of Colorado. Colo. Rev. Stat. § 6-1-716(2).

“Covered entity” means a person that maintains, owns, or licenses personal information in the course of the person’s business, vocation, or occupation. “Covered entity” does not include a person acting as a third-party service provider. Colo. Rev. Stat. § 6-1-716(1)(b).

What Information Is Protected?

“Personal information” means:

A. A Colorado resident’s first name or first initial and last name in combination with any one or more of the following data elements that relate to the resident, when the data elements are not encrypted, redacted, or secured by any other method rendering the name or the element unreadable or unusable:

  1. Social security number;
  2. Student, military, or passport identification number;
  3. Driver’s license number or identification card number;
  4. Medical information;
  5. Health insurance identification number; or
  6. Biometric data;

B. A Colorado resident’s username or e-mail address, in combination with a password or security questions and answers, that would permit access to an online account; or

C. A Colorado resident’s account number or credit or debit card number in combination with any required security code, access code, or password that would permit access to that account. Colo. Rev. Stat. § 6-1-716(1)(g).

What Is A “Breach”?

“Security breach” means the unauthorized acquisition of unencrypted computerized data that compromises the security, confidentiality, or integrity of personal information maintained by a covered entity. Good faith acquisition of personal information by an employee or agent of a covered entity for the covered entity’s business purposes is not a security breach if the personal information is not used for a purpose unrelated to the lawful operation of the business or is not subject to further unauthorized disclosure. Colo. Rev. Stat. § 6-1-716(1)(h).

What Triggers Notification?

A determination, following investigation, that there is a likelihood that personal information has been or will be misused. 

Likelihood of Harm Analysis: Notification is not required if the investigation determines that the misuse of information about a Colorado resident has not occurred and is not reasonably likely to occur. Colo. Rev. Stat. § 6-1-716(2)(a).

How Is Notice Provided To Individuals?

Timing: Notice must be made in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system. Colo. Rev. Stat. § 6-1-716(2).

Delivery: Notice may be by:

  1. Written notice to the postal address listed in the records of the covered entity;
  2. Telephonic notice;
  3. Electronic notice, if a primary means of communication by the covered entity with a Colorado resident is by electronic means or the notice provided is consistent with the provisions regarding electronic records and signatures set forth in the federal “Electronic Signatures in Global and National Commerce Act”, 15 U.S.C. sec. 7001 et seq.; or
  4. Substitute notice, if the covered entity required to provide notice demonstrates that the cost of providing notice will exceed $250,000, the affected class of persons to be notified exceeds 250,000 Colorado residents, or the covered entity does not have sufficient contact information to provide notice. Substitute notice consists of all of the following: a) E-mail notice if the covered entity has e-mail addresses for the members of the affected class of Colorado residents; b) Conspicuous posting of the notice on the website page of the covered entity if the covered entity maintains one; and c) Notification to major statewide media. Colo. Rev. Stat. § 6-1-716(1)(f).

Content: In the case of a breach of personal information, notice must include the following information:

  1. The date, estimated date, or estimated date range of the security breach;
  2. A description of the personal information that was acquired or reasonably believed to have been acquired as part of the security breach;
  3. Information that the resident can use to contact the covered entity to inquire about the security breach;
  4. The toll-free numbers, addresses, and websites for consumer reporting agencies;
  5. The toll-free number, address, and website for the Federal Trade Commission; and
  6. A statement that the resident can obtain information from the Federal Trade Commission and the credit reporting agencies about fraud alerts and security freezes. Colo. Rev. Stat. § 6-1-716(2)(a.2).

Is Notice To The Government Required?

Yes. A covered entity that must notify Colorado residents of a data breach must provide notice of any security breach to the Colorado attorney general in the most expedient time possible and without unreasonable delay, but not later than 30 days after the date of determination that a security breach occurred, if the security breach is reasonably believed to have affected 500 Colorado residents or more, unless the investigation determines that the misuse of information about a Colorado resident has not occurred and is not likely to occur. Colo. Rev. Stat. § 6-1-716(2)(f).

Is Notice To Credit Reporting Agencies Required?

Yes. If a covered entity is required to notify more than 1,000 Colorado residents of a security breach pursuant to this section, the covered entity shall also notify, in the most expedient time possible and without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the anticipated date of the notification to the residents and the approximate number of residents who are to be notified. Colo. Rev. Stat. § 6-1-716(2)(d).

Are There Security Measure Standards?

Yes. To protect personal identifying information from unauthorized access, use, modification, disclosure, or destruction, a covered entity that maintains, owns, or licenses personal identifying information of an individual residing in the state shall implement and maintain reasonable security procedures and practices that are appropriate to the nature of the personal identifying information and the nature and size of the business and its operations. Colo. Rev. Stat. § 6-1-713.5(1).

Additionally, unless a covered entity agrees to provide its own security protection for the information it discloses to a third-party service provider, the covered entity shall require that the third-party service provider implement and maintain reasonable security procedures and practices that are:

  1. Appropriate to the nature of the personal identifying information disclosed to the third-party service provider; and
  2. Reasonably designed to help protect the personal identifying information from unauthorized access, use, modification, disclosure, or destruction. Colo. Rev. Stat. § 6-1-713.5(2)

What Are The Possible Consequences Of A Violation?

The attorney general may bring an action in law or equity to address violations of this section, § 6-1-713 [protection of personal identifying information] or § 6-1-715 [confidentiality of social security numbers] and for other relief that may be appropriate to ensure compliance with this section or to recover direct economic damages resulting from a violation, or both. Colo. Rev. Stat. § 6-1-716(4).

Are There Any Exemptions/Exceptions?

Not per se, but a covered entity that maintains its own notification procedures as part of an information security policy for the treatment of personal information and whose procedures are otherwise consistent with the timing requirements of this section is in compliance with the notice requirements of this section if the covered entity notifies affected Colorado residents in accordance with its policies in the event of a security breach; except that notice to the attorney general is still required. Colo. Rev. Stat. § 6-1-716(3)(a).

Additionally, a covered entity that is regulated by state or federal law and that maintains procedures for a security breach pursuant to the laws, rules, regulations, guidances, or guidelines established by its state or federal regulator is in compliance with this section; except that notice to the attorney general is still required. Colo. Rev. Stat. § 6-1-716(3)(b).

Confidentiality Of Social Security Numbers

Note: Additional restrictions apply to the use of social security numbers. See Colo. Rev. Stat. § 6-1-715.

Wyoming

Who Is Covered?

An individual or commercial entity that conducts business in Wyoming and that owns or licenses computerized data that includes personal identifying information about a resident of Wyoming. Wyo. Stat. Ann. § 40-12-502(a).

What Information Is Protected?

“Personal identifying information” means the first name or first initial and last name of a person in combination with one or more of the following data elements when the data elements are not redacted:

  1. Social security number;
  2. Driver’s license number;
  3. Account number, credit card number or debit card number in combination with any security code, access code or password that would allow access to a financial account of the person;
  4. Tribal identification card;
  5. Federal or state government issued identification card;
  6. Shared secrets or security tokens that are known to be used for data based authentication;
  7. A username or email address, in combination with a password or security question and answer that would permit access to an online account;
  8. A birth or marriage certificate;
  9. Medical information, meaning a person’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional;
  10. Health insurance information, meaning a person’s health insurance policy number or subscriber identification number or any unique identifier used by a health insurer to identify the person or information related to a person’s application and claims history;
  11. Unique biometric data, meaning data generated from measurements or analysis of human body characteristics for authentication purposes;
  12. An individual taxpayer identification number. Wyo. Stat. Ann. §§ 40-12-501(a)(vii); 6-3-901(b)(iii)-(xiv).

What Is A “Breach”?

“Breach of the security of the data system” means unauthorized acquisition of computerized data that materially compromises the security, confidentiality or integrity of personal identifying information maintained by a person or business and causes or is reasonably believed to cause loss or injury to a resident of this state. Good faith acquisition of personal identifying information by an employee or agent of a person or business for the purposes of the person or business is not a breach of the security of the data system, provided that the personal identifying information is not used or subject to further unauthorized disclosure. Wyo. Stat. Ann. § 40-12-501(a)(i).

What Triggers Notification?

A determination that the misuse of personal identifying information about a Wyoming resident has occurred or is reasonably likely to occur, following a reasonable and prompt investigation to determine the likelihood that personal identifying information has been or will be misused. Wyo. Stat. Ann. § 40-12-502(a).

How Is Notice Provided To Individuals?

Timing: Notice must be given as soon as possible to the affected Wyoming resident. Notice must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system. Wyo. Stat. Ann. § 40-12-502(a).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic mail notice;
  3. Substitute notice, if the person demonstrates: a) That the cost of providing notice would exceed $10,000 for Wyoming-based persons or businesses, and $250,000 for all other businesses operating but not based in Wyoming; b) That the affected class of subject persons to be notified exceeds 10,000 for Wyoming-based persons or businesses and 500,000 for all other businesses operating but not based in Wyoming; or c) The person does not have sufficient contact information.

Substitute notice must include all of the following:

  1. Conspicuous posting of the notice on the Internet, the World Wide Web or a similar proprietary or common carrier electronic system site of the person collecting the data, if the person maintains a public Internet, the World Wide Web or a similar proprietary or common carrier electronic system site; and
  2. Notification to major statewide media. The notice to media shall include a toll-free phone number where an individual can learn whether or not that individual’s personal data is included in the security breach. Wyo. Stat. Ann. § 40-12-502(d).

Content: Notice must be clear and conspicuous and shall include, at a minimum:

  1. A toll-free number: a) That the individual may use to contact the person collecting the data, or his agent; and b) From which the individual may learn the toll-free contact telephone numbers and addresses for the major credit reporting agencies.
  2. The types of personal identifying information that were or are reasonably believed to have been the subject of the breach;
  3. A general description of the breach incident;
  4. The approximate date of the breach of security, if that information is reasonably possible to determine at the time notice is provided;
  5. In general terms, the actions taken by the individual or commercial entity to protect the system containing the personal identifying information from further breaches;
  6. Advice that directs the person to remain vigilant by reviewing account statements and monitoring credit reports;
  7. Whether notification was delayed as a result of a law enforcement investigation, if that information is reasonably possible to determine at the time the notice is provided. W.S. 6-3-901(b)(iii) through (xiv).

Is Notice To The Government Required?

No.

Is Notice To Credit Reporting Agencies Required?

No.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

The attorney general may bring an action in law or equity to address any violation of this section and for other relief that may be appropriate to ensure proper compliance with this section, to recover damages, or both. Wyo. Stat. Ann. § 40-12-502(f).

Are There Any Exemptions/Exceptions?

Any financial institution as defined in 15 U.S.C. 6809 or federal credit union as defined by 12 U.S.C. 1752 that maintains notification procedures subject to the requirements of 15 U.S.C. 6801(b)(3) and 12 C.F.R. Part 364 Appendix B or Part 748 Appendix B, is deemed to be in compliance with this section if the financial institution notifies affected Wyoming customers in compliance with the requirements of 15 U.S.C. 6801 through 6809 and 12 C.F.R. Part 364 Appendix B or Part 748 Appendix B. Wyo. Stat. Ann. § 40-12-502(c).

Wisconsin

Who Is Covered?

“Entity” means a person, other than an individual, that does any of the following:

  1. Conducts business in this state and maintains personal information in the ordinary course of business.
  2. Licenses personal information in this state.
  3. Maintains for a resident of this state a depository account as defined in s. 815.18 (2) (e).
  4. Lends money to a resident of this state. Wis. Stat. Ann. § 134.98(1)(a).

What Information Is Protected?

“Personal information” means an individual’s last name and the individual’s first name or first initial, in combination with and linked to any of the following elements, if the element is not publicly available information and is not encrypted, redacted, or altered in a manner that renders the element unreadable:

  1. The individual’s social security number.
  2. The individual’s driver’s license number or state identification number.
  3. The number of the individual’s financial account number, including a credit or debit card account number, or any security code, access code, or password that would permit access to the individual’s financial account.
  4. The individual’s deoxyribonucleic acid profile, as defined in s. 939.74 (2d) (a).
  5. The individual’s unique biometric data, including fingerprint, voice print, retina or iris image, or any other unique physical representation. Wis. Stat. Ann. § 134.98(1)(b).

What Is A “Breach”?

Knowledge that personal information of a resident of Wisconsin has been acquired by a person not authorized to acquire the personal information by:

  1. An entity whose principal place of business is located in this state or an entity that maintains or licenses personal information in this state; or
  2. An entity whose principal place of business is not located in this state. Wis. Stat. Ann. § 134.98(2)(a), (b).

What Triggers Notification?

Knowledge that personal information in the entity’s possession has been acquired by a person not authorized to acquire the personal information. Wis. Stat. Ann. § 134.98(2)(a), (b).

However, an entity is not required to provide notice of the acquisition of personal information if any of the following applies:

  1. The acquisition of personal information does not create a material risk of identity theft or fraud to the subject of the personal information. 
  2. The personal information was acquired in good faith by an employee or agent of the entity, if the personal information is used for a lawful purpose of the entity. Wis. Stat. Ann. § 134.98(2)(cm).

How Is Notice Provided To Individuals?

Timing: Subject to the needs of law enforcement, an entity shall provide the notice within a reasonable time, not to exceed 45 days after the entity learns of the acquisition of personal information. A determination as to reasonableness under this paragraph shall include consideration of the number of notices that an entity must provide and the methods of communication available to the entity. Wis. Stat. Ann. § 134.98(3)(a).

Delivery: An entity must provide notice by mail or by a method the entity has previously employed to communicate with the subject of the personal information. If an entity cannot with reasonable diligence determine the mailing address of the subject of the personal information, and if the entity has not previously communicated with the subject of the personal information, the entity shall provide notice by a method reasonably calculated to provide actual notice to the subject of the personal information. Wis. Stat. Ann. § 134.98(3)(b).

Content: The notice shall indicate that the entity knows of the unauthorized acquisition of personal information pertaining to the subject of the personal information. Wis. Stat. Ann. § 134.98(2)(b).

Is Notice To The Government Required?

No.

Is Notice To Credit Reporting Agencies Required?

Yes. If, as the result of a single incident, an entity is required to notify 1,000 or more individuals that personal information pertaining to the individuals has been acquired, the entity shall without unreasonable delay notify all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notices sent to the individuals. Wis. Stat. Ann. § 134.98(2)(br).

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

Failure to comply with this section is not negligence or a breach of any duty, but may be evidence of negligence or a breach of a legal duty. Wis. Stat. Ann. § 134.98(4).

Are There Any Exemptions/Exceptions?

This section does not apply to any of the following: a) An entity that is subject to, and in compliance with, the privacy and security requirements of 15 USC 6801 to 6827, or a person that has a contractual obligation to such an entity, if the entity or person has in effect a policy concerning breaches of information security. b) An entity that is described in 45 CFR 164.104 (a), if the entity complies with the requirements of 45 CFR part 164. Wis. Stat. Ann. § 134.98(3m).

West Virginia

Who Is Covered?

An individual or entity that owns or licenses computerized data that includes personal information. W. Va. Code § 46A-2A-102(a).

What Information Is Protected?

“Personal information” means the first name or first initial and last name linked to any one or more of the following data elements that relate to a resident of this state, when the data elements are neither encrypted nor redacted:

  1. Social security number;
  2. Driver’s license number or state identification card number issued in lieu of a driver’s license; or
  3. Financial account number, or credit card, or debit card number in combination with any required security code, access code or password that would permit access to a resident’s financial accounts. W. Va. Code § 46A-2A-101(6).

What Is A “Breach”?

“Breach of the security of a system” means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information maintained by an individual or entity as part of a database of personal information regarding multiple individuals and that causes the individual or entity to reasonably believe that the breach of security has caused or will cause identity theft or other fraud to any resident of this state. Good faith acquisition of personal information by an employee or agent of an individual or entity for the purposes of the individual or the entity is not a breach of the security of the system, provided that the personal information is not used for a purpose other than a lawful purpose of the individual or entity or subject to further unauthorized disclosure. W. Va. Code § 46A-2A-101(1).

What Triggers Notification?

The discovery or notification of the breach of the security of the system involving any resident of this state whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person and that causes, or the individual or entity reasonably believes has caused or will cause, identity theft or other fraud to any resident of this state. W. Va. Code § 46A-2A-102(a).

An individual or entity must give notice of the breach of the security of the system if encrypted information is accessed and acquired in an unencrypted form or if the security breach involves a person with access to the encryption key and the individual or entity reasonably believes that such breach has caused or will cause identity theft or other fraud to any resident of this state. W. Va. Code § 46A-2A-102(b).

How Is Notice Provided To Individuals?

Timing: The notice must be made without reasonable delay, subject to the needs of law enforcement. W. Va. Code § 46A-2A-102(a).

Delivery: Notice may be by:

  1. Written notice to the postal address in the records of the individual or entity;
  2. Telephonic notice;
  3. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures, set forth in Section 7001, United States Code Title 15, Electronic Signatures in Global and National Commerce Act;
  4. Substitute notice, if the individual or the entity required to provide notice demonstrates that the cost of providing notice will exceed $50,000 or that the affected class of residents to be notified exceeds 100,000 persons or that the individual or the entity does not have sufficient contact information or to provide notice as described [above]. Substitute notice consists of any two of the following: (i) E-mail notice if the individual or the entity has e-mail addresses for the members of the affected class of residents; (ii) Conspicuous posting of the notice on the website of the individual or the entity if the individual or the entity maintains a website; or (iii) Notice to major statewide media. W. Va. Code § 46A-2A-101(7).

Content: The notice must include:

  1. To the extent possible, a description of the categories of information that were reasonably believed to have been accessed or acquired by an unauthorized person, including social security numbers, driver’s licenses or state identification numbers and financial data;
  2. A telephone number or website address that the individual may use to contact the entity or the agent of the entity and from whom the individual may learn: a) What types of information the entity maintained about that individual or about individuals in general; and b) Whether or not the entity maintained information about that individual.
  3. The toll-free contact telephone numbers and addresses for the major credit reporting agencies and information on how to place a fraud alert or security freeze. W. Va. Code § 46A-2A-102(d).

Is Notice To The Government Required?

No.

Is Notice To Credit Reporting Agencies Required?

Yes. If an entity is required to notify more than one thousand persons of a breach of security pursuant to this article, the entity shall also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on a nationwide basis of the timing, distribution and content of the notices. Nothing in this subsection shall be construed to require the entity to provide to the consumer reporting agency the names or other personal identifying information of breach notice recipients. This subsection shall not apply to an entity who is subject to Title V of the Gramm Leach Bliley Act. W. Va. Code § 46A-2A-102(f).

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

Failure to comply with the notice provisions constitutes an unfair or deceptive act or practice and may be enforced by the Attorney General pursuant to the enforcement provisions of this chapter. W. Va. Code § 46A-2A-104(a).

No civil penalty may be assessed in an action unless the court finds that the defendant has engaged in a course of repeated and willful violations of this article. No civil penalty shall exceed $150,000 per breach of security of the system or series of breaches of a similar nature that are discovered in a single investigation. W. Va. Code § 46A-2A-104(b).

A violation by a licensed financial institution is enforceable exclusively by the financial institution’s primary functional regulator. W. Va. Code § 46A-2A-104(c).

Are There Any Exemptions/Exceptions?

An entity that maintains its own notification procedures as part of an information privacy or security policy for the treatment of personal information and that are consistent with the timing requirements of this article shall be deemed to be in compliance with the notification requirements of this article if it notifies residents of this state in accordance with its procedures in the event of a breach of security of the system. W. Va. Code § 46A-2A-103(a).

Additionally, a financial institution that responds in accordance with the notification guidelines prescribed by the Federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice is deemed to be in compliance with this article. W. Va. Code § 46A-2A-103(b).

Also, an entity that complies with the notification requirements or procedures pursuant to the rules, regulations, procedures or guidelines established by the entity’s primary or functional regulator shall be in compliance with this article. W. Va. Code § 46A-2A-103(c).

Washington

Who Is Covered?

Any person or business that conducts business in Washington and that owns or licenses data that includes personal information. Wash. Rev. Code Ann. § 19.255.010(1).

What Information Is Protected?

“Personal information” is:

A. An individual’s first name or first initial and last name in combination with any one or more of the following data elements:

  1. Social security number;
  2. Driver’s license number or Washington identification card number;
  3. Account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account, or any other numbers or information that can be used to access a person’s financial account;
  4. Full date of birth;
  5. Private key that is unique to an individual and that is used to authenticate or sign an electronic record;
  6. Student, military, or passport identification number;
  7. Health insurance policy number or health insurance identification number;
  8. Any information about a consumer’s medical history or mental or physical condition or about a health care professional’s medical diagnosis or treatment of the consumer; or
  9. Biometric data generated by automatic measurements of an individual’s biological characteristics such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that is used to identify a specific individual;

B. Username or email address in combination with a password or security questions and answers that would permit access to an online account; and

C. Any of the data elements or any combination of the data elements described in subsection A, above, without the consumer’s first name or first initial and last name if:

  1. Encryption, redaction, or other methods have not rendered the data element or combination of data elements unusable; and
  2. The data element or combination of data elements would enable a person to commit identity theft against a consumer. Rev. Code Wash. (ARCW) § 19.255.005(2)(a).

What Is A “Breach”?

“Breach of the security of the system” means unauthorized acquisition of data that compromises the security, confidentiality, or integrity of personal information maintained by the person or business. Good faith acquisition of personal information by an employee or agent of the person or business for the purposes of the person or business is not a breach of the security of the system when the personal information is not used or subject to further unauthorized disclosure. Wash. Rev. Code Ann. § 19.255.005(1).

What Triggers Notification?

Any breach of the security of the system involving a resident’s personal information that was, or is reasonably believed to have been, acquired by an unauthorized person and the personal information was not secured. Wash. Rev. Code Ann. § 19.255.010(1).

Likelihood of Harm Analysis: Notice is not required if the breach of the security of the system is not reasonably likely to subject consumers to a risk of harm. The breach of secured personal information must be disclosed if the information acquired and accessed is not secured during a security breach or if the confidential process, encryption key, or other means to decipher the secured information was acquired by an unauthorized person. Wash. Rev. Code Ann. § 19.255.010(1).

How Is Notice Provided To Individuals?

Timing: Notification to affected consumers must be made in the most expedient time possible, without unreasonable delay, and no more than 30 calendar days after the breach was discovered, unless the delay is at the request of law enforcement or the delay is due to any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Wash. Rev. Code Ann. § 19.255.010(8).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. Sec. 7001;
  3. Substitute notice, if the person or business demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars, or that the affected class of subject persons to be notified exceeds five hundred thousand, or the person or business does not have sufficient contact information. Substitute notice shall consist of all of the following: (i) Email notice when the person or business has an email address for the subject persons; (ii) Conspicuous posting of the notice on the website page of the person or business, if the person or business maintains one; and (iii) Notification to major statewide media. Wash. Rev. Code Ann. § 19.255.010(4)(a)-(c).

If the breach of the security of the system involves personal information including a user name or password, notice may be provided electronically or by email. The notice must inform the person whose personal information has been breached to promptly change his or her password and security question or answer, as applicable, or to take other appropriate steps to protect the online account with the person or business and all other online accounts for which the person whose personal information has been breached uses the same user name or email address and password or security question or answer. Wash. Rev. Code Ann. § 19.255.010(4)(d)(i).

However, when the breach of the security of the system involves login credentials of an email account furnished by the person or business, the person or business may not provide the notification to that email address, but must provide notice using another method described [above]. The notice must inform the person whose personal information has been breached to promptly change his or her password and security question or answer, as applicable, or to take other appropriate steps to protect the online account with the person or business and all other online accounts for which the person whose personal information has been breached uses the same user name or email address and password or security question or answer. Wash. Rev. Code Ann. § 19.255.010(4)(d)(ii).

Content: The notice must be written in plain language and include the following information:

  1. The name and contact information of the reporting person or business subject to this section;
  2. A list of the types of personal information that were or are reasonably believed to have been the subject of a breach;
  3. A time frame of exposure, if known, including the date of the breach and the date of the discovery of the breach; and
  4. The toll-free telephone numbers and addresses of the major credit reporting agencies if the breach exposed personal information. Wash. Rev. Code Ann. § 19.255.010(6).

Is Notice To The Government Required?

Yes. Any person or business that is required to issue a notification pursuant to this section to more than 500 Washington residents as a result of a single breach shall notify the attorney general of the breach no more than 30 days after the breach was discovered. The notice must include:

  1. The number of Washington consumers affected by the breach, or an estimate if the exact number is not known;
  2. A list of the types of personal information that were or are reasonably believed to have been the subject of a breach;
  3. A time frame of exposure, if known, including the date of the breach and the date of the discovery of the breach;
  4. A summary of steps taken to contain the breach; and
  5. A single sample copy of the security breach notification, excluding any personally identifiable information. Wash. Rev. Code Ann. § 19.255.010(7).

Is Notice To Credit Reporting Agencies Required?

No.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

The attorney general may bring an action in the name of the state, or as parens patriae on behalf of persons residing in the state, to enforce this chapter. For actions brought by the attorney general to enforce this chapter, the legislature finds that the practices covered by this chapter are matters vitally affecting the public interest for the purpose of applying the consumer protection act, chapter 19.86 RCW. For actions brought by the attorney general to enforce this chapter, a violation of this chapter is not reasonable in relation to the development and preservation of business and is an unfair or deceptive act in trade or commerce and an unfair method of competition for purposes of applying the consumer protection act, chapter 19.86 RCW. Wash. Rev. Code Ann. § 19.255.040(2).

Additionally, any consumer injured by a violation of this chapter may institute a civil action to recover damages. Wash. Rev. Code Ann. § 19.255.040(3).

Are There Any Exemptions/Exceptions?

A covered entity under the federal Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. Sec. 1320d et seq., is deemed to have complied with the requirements of this chapter with respect to protected health information if it has complied with section 13402 of the federal Health Information Technology for Economic and Clinical Health Act, P.L. 111-5 as it existed on July 24, 2015. Covered entities shall notify the attorney general pursuant to RCW 19.255.010(7) in compliance with the timeliness of notification requirements of section 13402 of the federal Health Information Technology for Economic and Clinical Health Act, P.L. 111-5 as it existed on July 24, 2015, notwithstanding the timeline in RCW 19.255.010(7). Wash. Rev. Code Ann. § 19.255.030(1).

Additionally, a financial institution under the authority of the Office of the Comptroller of the Currency, the Federal Deposit Insurance Corporation, the National Credit Union Administration, or the Federal Reserve System is deemed to have complied with the requirements of this chapter with respect to “sensitive customer information” as defined in the Interagency Guidelines Establishing Information Security Standards, 12 C.F.R. Part 30, Appendix B, 12 C.F.R. Part 208, Appendix D-2, 12 C.F.R. Part 225, Appendix F, and 12 C.F.R. Part 364, Appendix B, and 12 C.F.R. Part 748, Appendices A and B, as they existed on July 24, 2015, if the financial institution provides notice to affected consumers pursuant to the interagency guidelines and the notice complies with the customer notice provisions of the Interagency Guidelines Establishing Information Security Standards and the Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice under 12 C.F.R. Part 364 as it existed on July 24, 2015. The entity shall notify the attorney general pursuant to RCW 19.255.010 in addition to providing notice to its primary federal regulator. Wash. Rev. Code Ann. § 19.255.030(2).

Payment Processors

Note: Additional requirements apply to a person or entity “that directly processes or transmits account information for or on behalf of another person as part of a payment processing service.” See Wash. Rev. Code Ann. § 19.255.020.

Virginia

Who Is Covered?

An individual or entity that owns or licenses computerized data that includes personal information. Va. Code Ann. § 18.2-186.6(B).

What Information Is Protected?

“Personal information” means the first name or first initial and last name in combination with and linked to any one or more of the following data elements that relate to a resident of the Commonwealth, when the data elements are neither encrypted nor redacted:

  1. Social security number.
  2. Driver’s license number or state identification card number issued in lieu of a driver’s license number;
  3. Financial account number, or credit card or debit card number, in combination with any required security code, access code, or password that would permit access to a resident’s financial accounts;
  4. Passport number; or
  5. Military identification number. Va. Code Ann. § 18.2-186.6(A).

What Is A “Breach”?

“Breach of the security of the system” means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information maintained by an individual or entity as part of a database of personal information regarding multiple individuals and that causes, or the individual or entity reasonably believes has caused, or will cause, identity theft or other fraud to any resident of the Commonwealth. Good faith acquisition of personal information by an employee or agent of an individual or entity for the purposes of the individual or entity is not a breach of the security of the system, provided that the personal information is not used for a purpose other than a lawful purpose of the individual or entity or subject to further unauthorized disclosure. Va. Code Ann. § 18.2-186.6(A).

What Triggers Notification?

If unencrypted or unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person and causes, or the individual or entity reasonably believes has caused or will cause, identity theft or another fraud to any resident. Va. Code Ann. § 18.2-186.6(B).

How Is Notice Provided To Individuals?

Timing: Notification must be made without unreasonable delay. Notice may be reasonably delayed to allow the individual or entity to determine the scope of the breach of the security of the system and restore the reasonable integrity of the system. Notice required by this section may be delayed if, after the individual or entity notifies a law-enforcement agency, the law-enforcement agency determines and advises the individual or entity that the notice will impede a criminal or civil investigation, or homeland or national security. Notice shall be made without unreasonable delay after the law-enforcement agency determines that the notification will no longer impede the investigation or jeopardize national or homeland security. Va. Code Ann. § 18.2-186.6(B).

Delivery: Notice may be by:

  1. Written notice to the last known postal address in the records of the individual or entity;
  2. Telephone notice;
  3. Electronic notice; or
  4. Substitute notice, if the individual or the entity required to provide notice demonstrates that the cost of providing notice will exceed $50,000, the affected class of Virginia residents to be notified exceeds 100,000 residents, or the individual or the entity does not have sufficient contact information or consent to provide notice as described in subdivisions 1, 2, or 3 of this definition. Substitute notice consists of all of the following: a) E-mail notice if the individual or the entity has e-mail addresses for the members of the affected class of residents; b) Conspicuous posting of the notice on the website of the individual or the entity if the individual or the entity maintains a website; and  c) Notice to major statewide media. Va. Code Ann. § 18.2-186.6(A).

Content: The notice must contain a description of:

  1. The incident in general terms; 
  2. The type of personal information that was subject to the unauthorized access and acquisition;
  3. The general acts of the individual or entity to protect the personal information from further unauthorized access;
  4. A telephone number that the person may call for further information and assistance, if one exists; and
  5. Advice that directs the person to remain vigilant by reviewing account statements and monitoring free credit reports. Va. Code Ann. § 18.2-186.6(A).

Is Notice To The Government Required?

Yes. In the event an individual or entity provides notice to more than 1,000 persons at one time pursuant to this section, the individual or entity shall notify, without unreasonable delay, the Office of the Attorney General and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notice.

Is Notice To Credit Reporting Agencies Required?

Yes. See above.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

The Attorney General may bring an action to address violations of this section. The Office of the Attorney General may impose a civil penalty not to exceed $150,000 per breach of the security of the system or a series of breaches of a similar nature that are discovered in a single investigation. Nothing in this section shall limit an individual from recovering direct economic damages from a violation of this section. A violation of this section by a state-chartered or licensed financial institution shall be enforceable exclusively by the financial institution’s primary state regulator. Va. Code Ann. § 18.2-186.6(I), (J).

Are There Any Exemptions/Exceptions?

An entity that maintains its own notification procedures as part of an information privacy or security policy for the treatment of personal information that are consistent with the timing requirements of this section shall be deemed to be in compliance with the notification requirements of this section if it notifies residents of the Commonwealth in accordance with its procedures in the event of a breach of the security of the system. Va. Code Ann. § 18.2-186.6(F).

Additionally, an entity that is subject to Title V of the Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.) and maintains procedures for notification of a breach of the security of the system in accordance with the provision of that Act and any rules, regulations, or guidelines promulgated thereto shall be deemed to be in compliance with this section. Va. Code Ann. § 18.2-186.6(G).

Finally, an entity that complies with the notification requirements or procedures pursuant to the rules, regulations, procedures, or guidelines established by the entity’s primary or functional state or federal regulator shall be in compliance with this section. Va. Code Ann. § 18.2-186.6(H).

Breach of Medication Information

NOTE: Similar notification requirements apply to a breach of medical information. See Va. Code Ann. § 32.1-127.1:05.

Vermont

Who Is Covered?

“Data collector” means a person who, for any purpose, whether by automated collection or otherwise, handles, collects, disseminates, or otherwise deals with personally identifiable information, and includes the state, state agencies, political subdivisions of the state, public and private universities, privately and publicly held corporations, limited liability companies, financial institutions, and retail operators. Vt. Stat. Ann. tit. 9, § 2430(6).

What Information Is Protected?

“Personally identifiable information” means a consumer’s first name or first initial and last name in combination with one or more of the following digital data elements, when the data elements are not encrypted, redacted, or protected by another method that renders them unreadable or unusable by unauthorized persons:

  1. A Social Security number;
  2. A driver license or nondriver state identification card number, individual taxpayer identification number, passport number, military identification card number, or other identification number that originates from a government identification document that is commonly used to verify identity for a commercial transaction;
  3. A financial account number or credit or debit card number, if the number could be used without additional identifying information, access codes, or passwords;
  4. A password, personal identification number, or other access code for a financial account;
  5. Unique biometric data generated from measurements or technical analysis of human body characteristics used by the owner or licensee of the data to identify or authenticate the consumer, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data;
  6. Genetic information; and
  7. (a) health records or records of a wellness program or similar program of health promotion or disease prevention; (b) a health care professional’s medical diagnosis or treatment of the consumer; or (c) a health insurance policy number. Vt. Stat. Ann. tit. 9, § 2430(10).

“Login credentials” means a consumer’s user name or email address, in combination with a password or an answer to a security question, that together permit access to an online account. Vt. Stat. Ann. tit. 9, § 2430(9).

What Is A “Breach”?

“Security breach” means unauthorized acquisition of electronic data or a reasonable belief of an unauthorized acquisition of electronic data that compromises the security, confidentiality, or integrity of a consumer’s personally identifiable information or login credentials maintained by a data collector. Vt. Stat. Ann. tit. 9, § 2430(13).

In determining whether personally identifiable information or login credentials have been acquired or is reasonably believed to have been acquired by a person without valid authorization, a data collector may consider the following factors, among others:

  1. Indications that the information is in the physical possession and control of a person without valid authorization, such as a lost or stolen computer or other device containing information;
  2. Indications that the information has been downloaded or copied;
  3. Indications that the information was used by an unauthorized person, such as fraudulent accounts opened or instances of identity theft reported; or
  4. That the information has been made public. Vt. Stat. Ann. tit. 9, § 2430(13)(C).

Likelihood of Harm Analysis: Notice of a security breach is not required if the data collector establishes that misuse of personally identifiable information or login credentials is not reasonably possible and the data collector provides notice of the determination that the misuse of the personally identifiable information or login credentials is not reasonably possible pursuant to the requirements of this subsection. If the data collector establishes that misuse of the personally identifiable information or login credentials is not reasonably possible, the data collector shall provide notice of its determination that misuse of the personally identifiable information or login credentials is not reasonably possible and a detailed explanation for said determination to the Vermont Attorney General or to the Department of Financial Regulation in the event that the data collector is a person or entity licensed or registered with the Department under Title 8 or this title. Vt. Stat. Ann. tit. 9, § 2435(d)(1).

What Triggers Notification?

Discovery or notification to the data collector of the breach. Vt. Stat. Ann. tit. 9, § 2435(b)(1).

How Is Notice Provided To Individuals?

Timing: Notice of the security breach shall be made in the most expedient time possible and without unreasonable delay, but not later than 45 days after the discovery or notification, consistent with the legitimate needs of the law enforcement agency or with any measures necessary to determine the scope of the security breach and restore the reasonable integrity, security, and confidentiality of the data system. Vt. Stat. Ann. tit. 9, § 2435(b)(1).

Delivery: Delivery may be by direct notice or substitute notice. If by direct notice, it may be by:

  1. Written notice mailed to the consumer’s residence;
  2. Electronic notice, for those consumers for whom the data collector has a valid email address if: a) the data collector’s primary method of communication with the consumer is by electronic means, the electronic notice does not request or contain a hypertext link to a request that the consumer provide personal information, and the electronic notice conspicuously warns consumers not to provide personal information in response to electronic communications regarding security breaches; or b) the notice is consistent with the provisions regarding electronic records and signatures for notices in 15 U.S.C. § 7001; or
  3. Telephonic notice, provided that telephonic contact is made directly with each affected consumer and not through a prerecorded message.

Substitute notice may be made by conspicuously posting the notice on the data collector’s website if the data collector maintains one and notifying major statewide and regional media if:

  1. The data collector demonstrates that the lowest cost of providing notice to affected consumers pursuant to subdivision (6)(A) of this subsection among written, email, or telephonic notice would exceed $10,000; or
  2. The data collector does not have sufficient contact information. Vt. Stat. Ann. tit. 9, § 2435(b)(6).

Content: The notice sent to consumers must be clear and conspicuous and include each of the following, if known:

  1. The incident in general terms;
  2. The type of personally identifiable information that was subject to the security breach;
  3. The general acts of the data collector to protect the personally identifiable information from further security breach;
  4. A telephone number, toll-free if available, that the consumer may call for further information and assistance;
  5. Advice that directs the consumer to remain vigilant by reviewing account statements and monitoring free credit reports; and
  6. The approximate date of the security breach. Vt. Stat. Ann. tit. 9, § 2435(b)(5).

If a security breach is limited to an unauthorized acquisition of login credentials for an online account other than an email account the data collector shall provide notice of the security breach to the consumer electronically or through one or more of the methods specified above and shall advise the consumer to take steps necessary to protect the online account, including to change his or her login credentials for the account and for any other account for which the consumer uses the same login credentials. Vt. Stat. Ann. tit. 9, § 2435(d)(3).

If a security breach is limited to an unauthorized acquisition of login credentials for an email account: (A) the data collector shall not provide notice of the security breach through the email account; and (B) the data collector shall provide notice of the security breach through one or more of the methods specified above or by clear and conspicuous notice delivered to the consumer online when the consumer is connected to the online account from an Internet protocol address or online location from which the data collector knows the consumer customarily accesses the account. Vt. Stat. Ann. tit. 9, § 2435(d)(4).

Is Notice To The Government Required?

Yes. A data collector or other entity regulated by the Department of Financial Regulation under Title 8 or this title shall provide notice of a breach to the Department. All other data collectors or other entities subject to this subchapter shall provide notice of a breach to the Attorney General. The data collector shall notify the Attorney General or the Department, as applicable, of the date of the security breach and the date of discovery of the breach and shall provide a preliminary description of the breach within 14 business days, consistent with the legitimate needs of the law enforcement agency, of the data collector’s discovery of the security breach or when the data collector provides notice to consumers pursuant to this section, whichever is sooner. Vt. Stat. Ann. tit. 9, § 2435(b)(3).

When the data collector provides notice of the breach pursuant to subdivision (1) of this subsection (b), the data collector shall notify the Attorney General or the Department, as applicable, of the number of Vermont consumers affected, if known to the data collector, and shall provide a copy of the notice provided to consumers. The data collector may send to the Attorney General or the Department, as applicable, a second copy of the consumer notice, from which is redacted the type of personally identifiable information or login credentials that was subject to the breach, and which the Attorney General or the Department shall use for any public disclosure of the breach. Vt. Stat. Ann. tit. 9, § 2435(b)(3)(C).

Is Notice To Credit Reporting Agencies Required?

Yes. In the event a data collector provides notice to more than 1,000 consumers at one time pursuant to this section, the data collector shall notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notice. This subsection shall not apply to a person who is licensed or registered under Title 8 by the Department of Financial Regulation. Vt. Stat. Ann. tit. 9, § 2435(c).

Are There Security Measure Standards?

The Social Security Number Protection Act, Vt. Stat. Ann. tit. 9, § 2440, restricts the use of individuals’ social security numbers, and the Document Safe Destruction Act, Vt. Stat. Ann. tit. 9, § 2445, requires that businesses take all reasonable steps to destroy or arrange for the destruction of a customer’s records within its custody or control containing personal information that are no longer to be retained by the business.

What Are The Possible Consequences Of A Violation?

With respect to all data collectors and other entities subject to this subchapter, other than a person or entity licensed or registered with the Department of Financial Regulation under Title 8 or this title, the Attorney General and State’s Attorney shall have sole and full authority to investigate potential violations of this subchapter and to enforce, prosecute, obtain, and impose remedies for a violation of this subchapter or any rules or regulations made pursuant to this chapter as the Attorney General and State’s Attorney have under chapter 63 of this title. Vt. Stat. Ann. tit. 9, § 2435(h)(1).

With respect to a data collector that is a person or entity licensed or registered with the Department of Financial Regulation under Title 8 or this title, the Department of Financial Regulation shall have the full authority to investigate potential violations of this subchapter and to prosecute, obtain, and impose remedies for a violation of this subchapter or any rules or regulations adopted pursuant to this subchapter, as the Department has under Title 8 or this title or any other applicable law or regulation. Vt. Stat. Ann. tit. 9, § 2435(h)(2).

Are There Any Exemptions/Exceptions?

A data collector that is subject to the privacy, security, and breach notification rules adopted pursuant to the federal Health Insurance Portability and Accountability Act is deemed to be in compliance with this subchapter if: a) the data collector experiences a security breach that is limited to personally identifiable information specified in 2430(10)(A)(vii); and b) the data collector provides notice to affected consumers pursuant to the requirements of the breach notification rule in 45 C.F.R. Part 164, Subpart D. Vt. Stat. Ann. tit. 9, § 2435(e).

Additionally, a financial institution that is subject to the following guidances, and any revisions, additions, or substitutions relating to an interagency guidance shall be exempt from this section: 

  1. The Federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information and Customer Notice, issued on March 7, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision. 
  2. Final Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice, issued on April 14, 2005, by the National Credit Union Administration. 
  3. A financial institution regulated by the Department of Financial Regulation that is subject to subdivision (1) or (2) of this subsection (g) shall notify the Department as soon as possible after it becomes aware of an incident involving unauthorized access to or use of personally identifiable information. Vt. Stat. Ann. tit. 9, § 2435(g).

South Dakota

Who Is Covered?

“Information holder,” any person or business that conducts business in this state, and that owns or licenses computerized personal or protected information of residents of this state; S.D. Codified Laws § 22-40-19(3).

What Information Is Protected?

“Personal information” is a person’s first name or first initial and last name, in combination with any one or more of the following data elements:

  1. Social security number;
  2. Driver license number or other unique identification number created or collected by a government body;
  3. Account, credit card, or debit card number, in combination with any required security code, access code, password, routing number, PIN, or any additional information that would permit access to a person’s financial account;
  4. Health information as defined in 45 CFR 160.103; or
  5. An identification number assigned to a person by the person’s employer in combination with any required security code, access code, password, or biometric data generated from measurements or analysis of human body characteristics for authentication purposes. S.D. Codified Laws § 22-40-19(4).

“Protected information” includes:

  1. A user name or email address, in combination with a password, security question answer, or other information that permits access to an online account; and
  2. Account number or credit or debit card number, in combination with any required security code, access code, or password that permits access to a person’s financial account. S.D. Codified Laws § 22-40-19(5).

What Is A “Breach”?

“Breach of system security,” the unauthorized acquisition of unencrypted computerized data or encrypted computerized data and the encryption key by any person that materially compromises the security, confidentiality, or integrity of personal or protected information maintained by the information holder. The term does not include the good faith acquisition of personal or protected information by an employee or agent of the information holder for the purposes of the information holder if the personal or protected information is not used or subject to further unauthorized disclosure S.D. Codified Laws § 22-40-19(1).

What Triggers Notification?

Discovery by or notification to an information holder of a breach of system security where personal or protected information was, or is reasonably believed to have been, acquired by an unauthorized person. S.D. Codified Laws § 22-40-20.

An information holder is not required to make a disclosure under this section if, following an appropriate investigation and notice to the attorney general, the information holder reasonably determines that the breach will not likely result in harm to the affected person. The information holder shall document the determination under this section in writing and maintain the documentation for not less than three years. S.D. Codified Laws § 22-40-20.

How Is Notice Provided To Individuals?

Timing: The disclosure must be made not later than sixty days from the discovery or notification of the breach of system security, unless a longer period of time is required due to the legitimate needs of law enforcement. S.D. Codified Laws § 22-40-20.

Delivery: The disclosure may be provided by:

  1. Written notice;
  2. Electronic notice, if the electronic notice is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. Section 7001 in effect as of January 1, 2018, or if the information holder’s primary method of communication with the resident of this state has been by electronic means; or
  3. Substitute notice, if the information holder demonstrates that the cost of providing notice would exceed 250,000, that the affected class of persons to be notified exceeds five hundred thousand persons, or that the information holder does not have sufficient contact information and the notice consists of each of the following: (a) Email notice, if the information holder has an email address for the subject persons; (b) Conspicuous posting of the notice on the information holder’s website, if the information holder maintains a website page; and (c) Notification to statewide media. S.D. Codified Laws § 22-40-22.

Content: None specified.

Is Notice To The Government Required?

Yes. Any information holder that experiences a breach of system security under this section shall disclose to the attorney general by mail or electronic mail any breach of system security that exceeds 250 residents of this state. S.D. Codified Laws § 22-40-20.

Is Notice To Credit Reporting Agencies Required?

Yes. If an information holder discovers circumstances that require notification, the information holder shall also notify, without unreasonable delay, all consumer reporting agencies and any other credit bureau or agency that compiles and maintains files on consumers on a nationwide basis, of the timing, distribution, and content of the notice. S.D. Codified Laws § 22-40-24.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

The attorney general may prosecute each failure to disclose under the provisions of this Act as a deceptive act or practice under Section 37-24-6. In addition to any remedy provided under chapter 37-24, the attorney general may bring an action to recover on behalf of the state a civil penalty of not more than $10,000 per day per violation. The attorney general may recover attorney’s fees and any costs associated with any action brought under this section. S.D. Codified Laws § 22-40-25.

Are There Any Exemptions/Exceptions?

Notwithstanding any other provisions in this Act, any information holder that is regulated by federal law or regulation, including the Health Insurance Portability and Accountability Act or the Gramm Leach Bliley Act and that maintains procedures for a breach of system security pursuant to the laws, rules, regulations, guidance, or guidelines established by its primary or functional federal regulator is deemed to be in compliance with this chapter if the information holder notifies affected South Dakota residents in accordance with the provisions of the applicable federal law or regulation. S.D. Codified Laws § 22-40-26.

Utah

Who Is Covered?

A person who owns or licenses computerized data that includes personal information concerning a Utah resident. Utah Code Ann. § 13-44-202(1)(a).

 

What Information Is Protected?

“Personal information” means a person’s first name or first initial and last name, combined with any one or more of the following data elements relating to that person when either the name or date element is unencrypted or not protected by another method that renders the data unreadable or unusable:

 

  1. Social Security number;
  2. (A) financial account number, or credit or debit card number; and (b) any required security code, access code, or password that would permit access to the person’s account; or
  3. Driver license number or state identification card number. Utah Code Ann. § 13-44-102(4).

 

What Is A “Breach”?

“Breach of system security” means an unauthorized acquisition of computerized data maintained by a person that compromises the security, confidentiality, or integrity of personal information. Utah Code Ann. § 13-44-102(1)(a).

 

What Triggers Notification?

When a person becomes aware of a breach of system security, the person must conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be misused for identity theft or fraud purposes. Notification must be provided if the investigation reveals that the misuse of personal information for identity theft or fraud purposes has occurred, or is reasonably likely to occur, the person shall provide notification to each affected Utah resident. Utah Code Ann. § 13-44-202(1).

 

How Is Notice Provided To Individuals?

Timing: Notification must be made in the most expedient time possible without unreasonable delay considering the legitimate investigative needs of law enforcement, after determining the scope of the breach of system security and after restoring the reasonable integrity of the system. Utah Code Ann. § 13-44-202(2).

Delivery: Notification may be provided:

 

  1. In writing by first-class mail to the most recent address the person has for the resident;
  2. Electronically, if the person’s primary method of communication with the resident is by electronic means, or if provided in accordance with the consumer disclosure provisions of 15 U.S.C. Section 7001;
  3. By telephone, including through the use of automatic dialing technology not prohibited by other law; or
  4. For residents of the state for whom notification in a manner described above is not feasible, by publishing notice of the breach of system security: (A) in a newspaper of general circulation; and (B) as required in Section 45-1-101 [legal notice publication requirements]. Utah Code Ann. § 13-44-202.

Content: None specified.

 

Is Notice To The Government Required?

Yes. If the investigation reveals that the misuse of personal information relating to 500 or more Utah residents, for identity theft or fraud purposes, has occurred or is reasonably likely to occur, the person shall, in addition to the notification required in Subsection (1)(b), provide notification to: 

  1. the office of the Attorney General; and
  2. the Utah Cyber Center. Utah Code Ann. § 13-44-202(1)(c).

 

Is Notice To Credit Reporting Agencies Required?

Yes, if the investigation reveals that the misuse of personal information relating to 1,000 or more Utah residents, for identity theft or fraud purposes, has occurred or is reasonably likely to occur.
Utah Code Ann. § 13-44-202(1)(d).

 

Are There Security Measure Standards?

Yes. Any person who conducts business in the state and maintains personal information shall implement and maintain reasonable procedures to:

 

  1. Prevent unlawful use or disclosure of personal information collected or maintained in the regular course of business; and
  2. Destroy, or arrange for the destruction of, records containing personal information that are not to be retained by the person. 

The destruction of records shall be by: (a) shredding; (b) erasing; or (c) otherwise modifying the personal information to make the information indecipherable. Utah Code Ann. § 13-44-201.

 

What Are The Possible Consequences Of A Violation?

In addition to injunctive relief and attorney fees and costs, the attorney general may seek a civil penalty of:

 

  1. No greater than $2,500 for a violation or series of violations concerning a specific consumer; and
  2. No greater than $100,000 in the aggregate for related violations concerning more than one consumer, unless: a) the violations concern: (i) 10,000 or more consumers who are residents of the state; and (ii) 10,000 or more consumers who are residents of other states; or b) the person agrees to settle for a greater amount. Utah Code Ann. § 13-44-301(3), (4).

 

Are There Any Exemptions/Exceptions?

If a person maintains the person’s own notification procedures as part of an information security policy for the treatment of personal information the person is considered to be in compliance with this chapter’s notification requirements if the procedures are otherwise consistent with this chapter’s timing requirements and the person notifies each affected Utah resident in accordance with the person’s information security policy in the event of a breach. Utah Code Ann. § 13-44-202(5)(b).

Also, a person who is regulated by state or federal law and maintains procedures for a breach of system security under applicable law established by the primary state or federal regulator is considered to be in compliance with this part if the person notifies each affected Utah resident in accordance with the other applicable law in the event of a breach. Utah Code Ann. § 13-44-202(5)(c).

South Carolina

Who Is Covered?

A person conducting business in South Carolina and owning or licensing computerized data or other data that includes personal identifying information. S.C. Code Ann. § 39-1-90(A).

What Information Is Protected?

“Personal identifying information” means the first name or first initial and last name in combination with and linked to any one or more of the following data elements that relate to a resident of this State, when the data elements are neither encrypted nor redacted:

  1. Social security number;
  2. Driver’s license number or state identification card number issued instead of a driver’s license;
  3. Financial account number, or credit card or debit card number in combination with any required security code, access code, or password that would permit access to a resident’s financial account; or
  4. Other numbers or information which may be used to access a person’s financial accounts or numbers or information issued by a governmental or regulatory entity that uniquely will identify an individual. S.C. Code Ann. § 39-1-90(D)(3).

What Is A “Breach”?

“Breach of the security of the system” means unauthorized access to and acquisition of computerized data that was not rendered unusable through encryption, redaction, or other methods that compromises the security, confidentiality, or integrity of personal identifying information maintained by the person, when illegal use of the information has occurred or is reasonably likely to occur or use of the information creates a material risk of harm to a resident. Good faith acquisition of personal identifying information by an employee or agent of the person for the purposes of its business is not a breach of the security of the system if the personal identifying information is not used or subject to further unauthorized disclosure. S.C. Code Ann. § 39-1-90(D)(1).

What Triggers Notification?

The discovery or notification of the breach in the security of the data to a resident whose personal identifying information that was not rendered unusable through encryption, redaction, or other methods was, or is reasonably believed to have been, acquired by an unauthorized person when the illegal use of the information has occurred or is reasonably likely to occur or use of the information creates a material risk of harm to the resident. S.C. Code Ann. § 39-1-90(A).

How Is Notice Provided To Individuals?

Timing: The disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement or with measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. S.C. Code Ann. § 39-1-90(A).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic notice, if the person’s primary method of communication with the individual is by electronic means or is consistent with the provisions regarding electronic records and signatures in Section 7001 of Title 15 USC and Chapter 6, Title 11 of the 1976 Code;
  3. Telephonic notice; or
  4. Substitute notice, if the person demonstrates that the cost of providing notice exceeds two hundred fifty thousand dollars or that the affected class of subject persons to be notified exceeds five hundred thousand or the person has insufficient contact information. Substitute notice consists of: (a) e-mail notice when the person has an e-mail address for the subject persons; (b) conspicuous posting of the notice on the web site page of the person, if the person maintains one; or (c) notification to major statewide media. S.C. Code Ann. § 39-1-90(E).

Content: Not specified.

Is Notice To The Government Required?

Yes. If a business provides notice to more than 1,000 persons at one time pursuant to this section, the business shall notify, without unreasonable delay, the Consumer Protection Division of the Department of Consumer Affairs and all consumer reporting agencies that compile and maintain files on a nationwide basis of the timing, distribution, and content of the notice. S.C. Code Ann. § 39-1-90(K).

Is Notice To Credit Reporting Agencies Required?

Yes. See above.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

A resident of South Carolina who is injured by a violation of this section, in addition to and cumulative of all other rights and remedies available at law, may: (1) institute a civil action to recover damages in case of a willful and knowing violation; (2) institute a civil action that must be limited to actual damages resulting from a violation in case of a negligent violation of this section; (3) seek an injunction to enforce compliance; and (4) recover attorney’s fees and court costs, if successful. S.C. Code Ann. § 39-1-90(G).

Additionally, a person who knowingly and wilfully violates this section is subject to an administrative fine in the amount of one thousand dollars for each resident whose information was accessible by reason of the breach, the amount to be decided by the Department of Consumer Affairs. S.C. Code Ann. § 39-1-90(H).

Are There Any Exemptions/Exceptions?

This section does not apply to a bank or financial institution that is subject to and in compliance with the privacy and security provision of the Gramm-Leach-Bliley Act. S.C. Code Ann. § 39-1-90(I).

Also, a financial institution that is subject to and in compliance with the federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information and Customer Notice, issued March 7, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision, as amended, is considered to be in compliance with this section. S.C. Code Ann. § 39-1-90(J).

Rhode Island

Who Is Covered?

Any municipal agency, state agency, or person that stores, owns, collects, processes, maintains, acquires, uses, or licenses data that includes personal information. R.I. Gen. Laws Section 11-49.3-4(a)(1).

What Information Is Protected?

“Personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements, when the name and the data elements are not encrypted or are in hard copy, paper format:

  1. Social security number;
  2. Driver’s license number, Rhode Island identification card number, or tribal identification number;
  3. Account number, credit, or debit card number, in combination with any required security code, access code, password, or personal identification number, that would permit access to an individual’s financial account;
  4. Medical or health insurance information; or
  5. Email address with any required security code, access code, or password that would permit access to an individual’s personal, medical, insurance, or financial account. R.I. Gen. Laws Section 11-49.3-3(a)(8).

“Health insurance information” means an individual’s health insurance policy number, subscriber identification number, or any unique identifier used by a health insurer to identify the individual. R.I. Gen. Laws Section 11-49.3-3(a)(3).

“Medical information” means any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional or provider. R.I. Gen. Laws Section 11-49.3-3(a)(4).

What Is A “Breach”?

“Breach of the security of the system” means unauthorized access or acquisition of unencrypted, computerized data information that compromises the security, confidentiality, or integrity of personal information maintained by the municipal agency, state agency, or person. Good-faith acquisition of personal information by an employee or agent of the agency for the purposes of the agency is not a breach of the security of the system; provided, that the personal information is not used or subject to further unauthorized disclosure. R.I. Gen. Laws Section 11-49.3-3(a)(1).

What Triggers Notification?

The disclosure of personal information, or any breach of the security of the system, that poses a significant risk of identity theft to any resident of Rhode Island whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person or entity. R.I. Gen. Laws Section 11-49.3-4(a)(1).

How Is Notice Provided To Individuals?

Timing: The notification must be made in the most expedient time possible, but no later than 45 calendar days after confirmation of the breach and the ability to ascertain the information required to be included in the notification. R.I. Gen. Laws § 11-49.3-4(a)(2).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001; or
  3. Substitute notice, if the municipal agency, state agency, or person demonstrates that the cost of providing notice would exceed $25,000, or that the affected class of subject persons to be notified exceeds 50,000, or the municipal agency, state agency, or person does not have sufficient contact information. Substitute notice shall consist of all of the following: (A) Email notice when the municipal agency, state agency, or person has an email address for the subject persons; (B) Conspicuous posting of the notice on the municipal agency’s, state agency’s or person’s website page, if the municipal agency, state agency, or person maintains one; and (C) Notification to major statewide media. R.I. Gen. Laws Section 11-49.3-3(c).

Content: The notice must include:

  1. A general and brief description of the incident, including how the security breach occurred and the number of affected individuals;
  2. The type of information that was subject to the breach;
  3. Date of breach, estimated date of breach, or the date range within which the breach occurred;
  4. Date that the breach was discovered;
  5. A clear and concise description of any remediation services offered to affected individuals including toll free numbers and websites to contact: (i) The credit reporting agencies; (ii) Remediation service providers; (iii) The attorney general; and
  6. A clear and concise description of the consumer’s ability to file or obtain a police report; how a consumer requests a security freeze and the necessary information to be provided when requesting the security freeze; and that fees may be required to be paid to the consumer reporting agencies. R.I. Gen. Laws § 11-49.3-4(d).

Is Notice To The Government Required?

Yes. In the event that more than 500 Rhode Island residents are to be notified, the municipal agency, state agency, or person shall notify the attorney general and the major credit reporting agencies as to the timing, content, and distribution of the notices and the approximate number of affected individuals. Notification to the attorney general and the major credit reporting agencies shall be made without delaying notice to affected Rhode Island residents. R.I. Gen. Laws Section 11-49.3-4(a)(2).

Is Notice To Credit Reporting Agencies Required?

Yes. See above.

Are There Security Measure Standards?

Yes. A municipal agency, state agency, or person who or that stores, collects, processes, maintains, acquires, uses, owns, or licenses personal information about a Rhode Island resident shall implement and maintain a risk-based information security program that contains reasonable security procedures and practices appropriate to the size and scope of the organization; the nature of the information; and the purpose for which the information was collected in order to protect the personal information from unauthorized access, use, modification, destruction, or disclosure and to preserve the confidentiality, integrity, and availability of such information. A municipal agency, state agency, or person shall not retain personal information for a period longer than is reasonably required to provide the services requested; to meet the purpose for which it was collected; or in accordance with a written retention policy or as may be required by law. A municipal agency, state agency, or person shall destroy all personal information, regardless of the medium that such information is in, in a secure manner, including, but not limited to, shredding, pulverization, incineration, or erasure. R.I. Gen. Laws Section 11-49.3-2(a).

Additionally, a municipal agency, state agency, or person who or that discloses personal information about a Rhode Island resident to a nonaffiliated third party shall require by written contract that the third party implement and maintain reasonable security procedures and practices appropriate to the size and scope of the organization; the nature of the information; and the purpose for which the information was collected in order to protect the personal information from unauthorized access, use, modification, destruction, or disclosure. The provisions of this section shall apply to contracts entered into after the effective date of this act. R.I. Gen. Laws Section 11-49.3-2(b).

What Are The Possible Consequences Of A Violation?

Each reckless violation of this chapter is a civil violation for which a penalty of not more than $100 per record may be adjudged against a defendant. Each knowing and willful violation of this chapter is a civil violation for which a penalty of not more than $200 per record may be adjudged against a defendant. Additionally, whenever the attorney general has reason to believe that a violation has occurred and that proceedings would be in the public interest, the attorney general may bring an action in the name of the state against the business or person in violation. R.I. Gen. Laws Section 11-49.3-5.

Are There Any Exemptions/Exceptions?

  1. Any municipal agency, state agency, or person shall be deemed to be in compliance with the security breach notification requirements of § 11-49.3-4 if: a) The municipal agency, state agency, or person maintains its own security breach procedures as part of an information security policy for the treatment of personal information and otherwise complies with the timing requirements of § 11-49.3-4, and notifies subject persons in accordance with such municipal agency’s, state agency’s, or person’s notification policies in the event of a breach of security; or b) The person maintains a security breach procedure pursuant to the rules, regulations, procedures, or guidelines established by the primary or functional regulator, as defined in 15 U.S.C. § 6809(2), and notifies subject persons in accordance with the policies or the rules, regulations, procedures, or guidelines established by the primary or functional regulator in the event of a breach of security of the system.
  2. A financial institution, trust company, credit union, or its affiliates that is subject to and examined for, and found in compliance with, the Federal Interagency Guidelines on Response Programs for Unauthorized Access to Customer Information and Customer Notice shall be deemed in compliance with this chapter.
  3. A provider of health care, health care service plan, health insurer, or a covered entity governed by the medical privacy and security rules issued by the Federal Department of Health and Human Services, Parts 160 and 164 of Title 45 of the Code of Federal Regulations, established pursuant to the Health Insurance Portability and Accountability Act of 1996 shall be deemed in compliance with this chapter. R.I. Gen. Laws Section 11-49.3-6.

Oregon

Who Is Covered?

“Covered entity” means a person that owns, licenses, maintains, stores, manages, collects, processes, acquires or otherwise possesses personal information in the course of the person’s business, vocation, occupation or volunteer activities. Or. Rev. Stat. Ann. § 646A.602(5)(a).

What Information Is Protected?

“Personal information” means:

A. A consumer’s first name or first initial and last name in combination with any one or more of the following data elements, if encryption, redaction or other methods have not rendered the data elements unusable or if the data elements are encrypted and the encryption key has been acquired:

  1. A consumer’s social security number;
  2. A consumer’s driver license number or state identification card number issued by the Department of Transportation;
  3. A consumer’s passport number or other identification number issued by the United States;
  4. A consumer’s financial account number, credit card number or debit card number, in combination with any required security code, access code or password that would permit access to a consumer’s financial account, or any other information or combination of information that a person reasonably knows or should know would permit access to the consumer’s financial account;
  5. Data from automatic measurements of a consumer’s physical characteristics, such as an image of a fingerprint, retina or iris, that are used to authenticate the consumer’s identity in the course of a financial transaction or other transaction;
  6. A consumer’s health insurance policy number or health insurance subscriber identification number in combination with any other unique identifier that a health insurer uses to identify the consumer; or
  7. Any information about a consumer’s medical history or mental or physical condition or about a health care professional’s medical diagnosis or treatment of the consumer.

B. A user name or other means of identifying a consumer for the purpose of permitting access to the consumer’s account, together with any other method necessary to authenticate the user name or means of identification.

C. Any of the data elements or any combination of the data elements described in subparagraph (A) or (B) of this paragraph without the consumer’s user name, or the consumer’s first name or first initial and last name, if: (i) Encryption, redaction or other methods have not rendered the data element or combination of data elements unusable; and (ii) The data element or combination of data elements would enable a person to commit identity theft against a consumer. Or. Rev. Stat. Ann. § 646A.602(12)(A)(a).

What Is A “Breach”?

“Breach of security” means an unauthorized acquisition of computerized data that materially compromises the security, confidentiality or integrity of personal information that a person maintains or possesses. Or. Rev. Stat. Ann. § 646A.602(1)(a).

What Triggers Notification?

The covered entity being subjected to a breach of security or receiving notice of a breach of security from a vendor. Or. Rev. Stat. Ann. § 646A.604(1).

Likelihood of Harm Analysis: A covered entity does not need to notify consumers of a breach of security if, after an appropriate investigation or after consultation with relevant federal, state or local law enforcement agencies, the covered entity reasonably determines that the consumers whose personal information was subject to the breach of security are unlikely to suffer harm. The covered entity must document the determination in writing and maintain the documentation for at least five years. Or. Rev. Stat. Ann. § 646A.604(8).

How Is Notice Provided To Individuals?

Timing: Notice must be provided in the most expeditious manner possible, without unreasonable delay, but not later than 45 days after discovering or receiving notification of the breach of security, but only after the covered entity undertakes reasonable measures that are necessary to:

  1. Determine sufficient contact information for the intended recipient of the notice;
  2. Determine the scope of the breach of security; and
  3. Restore the reasonable integrity, security and confidentiality of the personal information. Or. Rev. Stat. Ann. § 646A.604(3).

Delivery: Notice may be made:

  1. In writing;
  2. Electronically, if the covered entity customarily communicates with the consumer electronically or if the notice is consistent with the provisions of the E-Sign Act;
  3. By telephone, if the covered entity contacts the affected consumer directly; or
  4. With substitute notice, if the covered entity demonstrates that the cost of notification otherwise would exceed $250,000 or that the affected class of consumers exceeds 350,000, or if the covered entity does not have sufficient contact information to notify affected consumers. For the purposes of this paragraph, “substitute notice” means: (A) Posting the notice or a link to the notice conspicuously on the covered entity’s website if the covered entity maintains a website; and (B) Notifying major statewide television and newspaper media. Or. Rev. Stat. Ann. § 646A.604(4).

Content: Notice must include:

  1. A description of the breach of security in general terms;
  2. The approximate date of the breach of security;
  3. The type of personal information that was subject to the breach of security;
  4. Contact information for the covered entity;
  5. Contact information for national consumer reporting agencies; and
  6. Advice to the consumer to report suspected identity theft to law enforcement, including the Attorney General and the Federal Trade Commission. Or. Rev. Stat. Ann. § 646A.604(5).

Is Notice To The Government Required?

Yes, if the number of consumers to whom the covered entity must send the notice exceeds 250. Or. Rev. Stat. Ann. § 646A.604(1)(b).

Is Notice To Credit Reporting Agencies Required?

Yes. If a covered entity discovers or receives notice of a breach of security that affects more than 1,000 consumers, the covered entity shall notify, without unreasonable delay, all consumer reporting agencies that compile and maintain reports on consumers on a nationwide basis of the timing, distribution and content of the notice the covered entity gave to affected consumers and shall include in the notice any police report number assigned to the breach of security. A covered entity may not delay notifying affected consumers of a breach of security in order to notify consumer reporting agencies. Or. Rev. Stat. Ann. § 646A.604(6).

Are There Security Measure Standards?

Yes. A covered entity and a vendor shall develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of personal information, including safeguards that protect the personal information when the covered entity or vendor disposes of the personal information. In addition to complying with any federal law that provides greater protection to personal information than the protections that this section provides or with the HIPAA, a covered entity or vendor is in compliance if it implements an information security program that includes:

A. Administrative safeguards such as:

  1. Designating one or more employees to coordinate the security program;
  2. Identifying reasonably foreseeable internal and external risks with reasonable regularity;
  3. Assessing whether existing safeguards adequately control the identified risks;
  4. Training and managing employees in security program practices and procedures with reasonable regularity;
  5. Selecting service providers that are capable of maintaining appropriate safeguards and practices, and requiring the service providers by contract to maintain the safeguards and practices;  
  6. Adjusting the security program in light of business changes, potential threats or new circumstances; and
  7. Reviewing user access privileges with reasonable regularity.

B. Technical safeguards such as:

  1. Assessing risks and vulnerabilities in network and software design and taking reasonably timely action to address the risks and vulnerabilities;
  2. Applying security updates and a reasonable security patch management program to software that might reasonably be at risk of or vulnerable to a breach of security;
  3. Monitoring, detecting, preventing and responding to attacks or system failures; and
  4. Regularly testing, monitoring and taking action to address the effectiveness of key controls, systems and procedures.

C. Physical safeguards such as:

  1. Assessing, in light of current technology, risks of information collection, storage, usage, retention, access and disposal and implementing reasonable methods to remedy or mitigate identified risks;
  2. Monitoring, detecting, preventing, isolating and responding to intrusions timely and with reasonable regularity;
  3. Protecting against unauthorized access to or use of personal information during or after collecting, using, storing, transporting, retaining, destroying or disposing of the personal information; and
  4. Disposing of personal information, whether the covered entity or vendor disposes of the personal information on or off the covered entity’s or vendor’s premises or property, after the covered entity or vendor no longer needs the personal information for business purposes or as required by local, state or federal law by burning, pulverizing, shredding or modifying a physical record and by destroying or erasing electronic media so that the information cannot be read or reconstructed. Or. Rev. Stat. Ann. § 646A.622(1), (2).

What Are The Possible Consequences Of A Violation?

In addition to all other penalties and enforcement provisions provided by law, any person who violates or who procures, aids or abets in a violation shall be subject to a penalty of not more than $1,000 for every violation, which shall be paid to the General Fund of the State Treasury. Every violation is a separate offense and, in the case of a continuing violation, each day’s continuance is a separate violation, but the maximum penalty for any occurrence shall not exceed $500,000.  Additionally, a violation is an unlawful practice under Or. Rev. Stat. Ann. § 646.607. Or. Rev. Stat. Ann. §§ 646A.624(4); 646A.604(11)(a).

If the director has reason to believe that any person has engaged or is engaging in any violation, the director may issue an order, subject to ORS chapter 183, directed to the person to cease and desist from the violation, or require the person to pay compensation to consumers injured by the violation. The director may order compensation to consumers only upon a finding that enforcement of the rights of the consumers by private civil action would be so burdensome or expensive as to be impractical. Or. Rev. Stat. Ann. § 646A.624(3).

Are There Any Exemptions/Exceptions?

With the exception of the requirement to send notice to the attorney general, the breach notification requirements do not apply to:

  1. Personal information that is subject to, and a person that complies with, notification requirements or procedures for a breach of security that the person’s primary or functional federal regulator adopts, promulgates or issues in rules, regulations, procedures, guidelines or guidance.
  2. Personal information that is subject to, and a person that complies with, a state or federal law that provides greater protection to personal information and disclosure requirements at least as thorough as the protections and disclosure requirements provided under this section.
  3. A covered entity or vendor that complies with regulations promulgated under Title V of the Gramm-Leach-Bliley Act.
  4. A covered entity or vendor that complies with regulations promulgated under the Health Insurance Portability and Accountability Act. Or. Rev. Stat. Ann. § 646A.604(9).