Category Archives: Notice to CRAs

Colorado

Who Is Covered?

A covered entity that maintains, owns, or licenses computerized data that includes personal information about a resident of Colorado. Colo. Rev. Stat. § 6-1-716(2).

“Covered entity” means a person that maintains, owns, or licenses personal information in the course of the person’s business, vocation, or occupation. “Covered entity” does not include a person acting as a third-party service provider. Colo. Rev. Stat. § 6-1-716(1)(b).

What Information Is Protected?

“Personal information” means:

A. A Colorado resident’s first name or first initial and last name in combination with any one or more of the following data elements that relate to the resident, when the data elements are not encrypted, redacted, or secured by any other method rendering the name or the element unreadable or unusable:

  1. Social security number;
  2. Student, military, or passport identification number;
  3. Driver’s license number or identification card number;
  4. Medical information;
  5. Health insurance identification number; or
  6. Biometric data;

B. A Colorado resident’s username or e-mail address, in combination with a password or security questions and answers, that would permit access to an online account; or

C. A Colorado resident’s account number or credit or debit card number in combination with any required security code, access code, or password that would permit access to that account. Colo. Rev. Stat. § 6-1-716(1)(g).

What Is A “Breach”?

“Security breach” means the unauthorized acquisition of unencrypted computerized data that compromises the security, confidentiality, or integrity of personal information maintained by a covered entity. Good faith acquisition of personal information by an employee or agent of a covered entity for the covered entity’s business purposes is not a security breach if the personal information is not used for a purpose unrelated to the lawful operation of the business or is not subject to further unauthorized disclosure. Colo. Rev. Stat. § 6-1-716(1)(h).

What Triggers Notification?

A determination, following investigation, that there is a likelihood that personal information has been or will be misused. 

Likelihood of Harm Analysis: Notification is not required if the investigation determines that the misuse of information about a Colorado resident has not occurred and is not reasonably likely to occur. Colo. Rev. Stat. § 6-1-716(2)(a).

How Is Notice Provided To Individuals?

Timing: Notice must be made in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system. Colo. Rev. Stat. § 6-1-716(2).

Delivery: Notice may be by:

  1. Written notice to the postal address listed in the records of the covered entity;
  2. Telephonic notice;
  3. Electronic notice, if a primary means of communication by the covered entity with a Colorado resident is by electronic means or the notice provided is consistent with the provisions regarding electronic records and signatures set forth in the federal “Electronic Signatures in Global and National Commerce Act”, 15 U.S.C. sec. 7001 et seq.; or
  4. Substitute notice, if the covered entity required to provide notice demonstrates that the cost of providing notice will exceed $250,000, the affected class of persons to be notified exceeds 250,000 Colorado residents, or the covered entity does not have sufficient contact information to provide notice. Substitute notice consists of all of the following: a) E-mail notice if the covered entity has e-mail addresses for the members of the affected class of Colorado residents; b) Conspicuous posting of the notice on the website page of the covered entity if the covered entity maintains one; and c) Notification to major statewide media. Colo. Rev. Stat. § 6-1-716(1)(f).

Content: In the case of a breach of personal information, notice must include the following information:

  1. The date, estimated date, or estimated date range of the security breach;
  2. A description of the personal information that was acquired or reasonably believed to have been acquired as part of the security breach;
  3. Information that the resident can use to contact the covered entity to inquire about the security breach;
  4. The toll-free numbers, addresses, and websites for consumer reporting agencies;
  5. The toll-free number, address, and website for the Federal Trade Commission; and
  6. A statement that the resident can obtain information from the Federal Trade Commission and the credit reporting agencies about fraud alerts and security freezes. Colo. Rev. Stat. § 6-1-716(2)(a.2).

Is Notice To The Government Required?

Yes. A covered entity that must notify Colorado residents of a data breach must provide notice of any security breach to the Colorado attorney general in the most expedient time possible and without unreasonable delay, but not later than 30 days after the date of determination that a security breach occurred, if the security breach is reasonably believed to have affected 500 Colorado residents or more, unless the investigation determines that the misuse of information about a Colorado resident has not occurred and is not likely to occur. Colo. Rev. Stat. § 6-1-716(2)(f).

Is Notice To Credit Reporting Agencies Required?

Yes. If a covered entity is required to notify more than 1,000 Colorado residents of a security breach pursuant to this section, the covered entity shall also notify, in the most expedient time possible and without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the anticipated date of the notification to the residents and the approximate number of residents who are to be notified. Colo. Rev. Stat. § 6-1-716(2)(d).

Are There Security Measure Standards?

Yes. To protect personal identifying information from unauthorized access, use, modification, disclosure, or destruction, a covered entity that maintains, owns, or licenses personal identifying information of an individual residing in the state shall implement and maintain reasonable security procedures and practices that are appropriate to the nature of the personal identifying information and the nature and size of the business and its operations. Colo. Rev. Stat. § 6-1-713.5(1).

Additionally, unless a covered entity agrees to provide its own security protection for the information it discloses to a third-party service provider, the covered entity shall require that the third-party service provider implement and maintain reasonable security procedures and practices that are:

  1. Appropriate to the nature of the personal identifying information disclosed to the third-party service provider; and
  2. Reasonably designed to help protect the personal identifying information from unauthorized access, use, modification, disclosure, or destruction. Colo. Rev. Stat. § 6-1-713.5(2)

What Are The Possible Consequences Of A Violation?

The attorney general may bring an action in law or equity to address violations of this section, § 6-1-713 [protection of personal identifying information] or § 6-1-715 [confidentiality of social security numbers] and for other relief that may be appropriate to ensure compliance with this section or to recover direct economic damages resulting from a violation, or both. Colo. Rev. Stat. § 6-1-716(4).

Are There Any Exemptions/Exceptions?

Not per se, but a covered entity that maintains its own notification procedures as part of an information security policy for the treatment of personal information and whose procedures are otherwise consistent with the timing requirements of this section is in compliance with the notice requirements of this section if the covered entity notifies affected Colorado residents in accordance with its policies in the event of a security breach; except that notice to the attorney general is still required. Colo. Rev. Stat. § 6-1-716(3)(a).

Additionally, a covered entity that is regulated by state or federal law and that maintains procedures for a security breach pursuant to the laws, rules, regulations, guidances, or guidelines established by its state or federal regulator is in compliance with this section; except that notice to the attorney general is still required. Colo. Rev. Stat. § 6-1-716(3)(b).

Confidentiality Of Social Security Numbers

Note: Additional restrictions apply to the use of social security numbers. See Colo. Rev. Stat. § 6-1-715.

Wisconsin

Who Is Covered?

“Entity” means a person, other than an individual, that does any of the following:

  1. Conducts business in this state and maintains personal information in the ordinary course of business.
  2. Licenses personal information in this state.
  3. Maintains for a resident of this state a depository account as defined in s. 815.18 (2) (e).
  4. Lends money to a resident of this state. Wis. Stat. Ann. § 134.98(1)(a).

What Information Is Protected?

“Personal information” means an individual’s last name and the individual’s first name or first initial, in combination with and linked to any of the following elements, if the element is not publicly available information and is not encrypted, redacted, or altered in a manner that renders the element unreadable:

  1. The individual’s social security number.
  2. The individual’s driver’s license number or state identification number.
  3. The number of the individual’s financial account number, including a credit or debit card account number, or any security code, access code, or password that would permit access to the individual’s financial account.
  4. The individual’s deoxyribonucleic acid profile, as defined in s. 939.74 (2d) (a).
  5. The individual’s unique biometric data, including fingerprint, voice print, retina or iris image, or any other unique physical representation. Wis. Stat. Ann. § 134.98(1)(b).

What Is A “Breach”?

Knowledge that personal information of a resident of Wisconsin has been acquired by a person not authorized to acquire the personal information by:

  1. An entity whose principal place of business is located in this state or an entity that maintains or licenses personal information in this state; or
  2. An entity whose principal place of business is not located in this state. Wis. Stat. Ann. § 134.98(2)(a), (b).

What Triggers Notification?

Knowledge that personal information in the entity’s possession has been acquired by a person not authorized to acquire the personal information. Wis. Stat. Ann. § 134.98(2)(a), (b).

However, an entity is not required to provide notice of the acquisition of personal information if any of the following applies:

  1. The acquisition of personal information does not create a material risk of identity theft or fraud to the subject of the personal information. 
  2. The personal information was acquired in good faith by an employee or agent of the entity, if the personal information is used for a lawful purpose of the entity. Wis. Stat. Ann. § 134.98(2)(cm).

How Is Notice Provided To Individuals?

Timing: Subject to the needs of law enforcement, an entity shall provide the notice within a reasonable time, not to exceed 45 days after the entity learns of the acquisition of personal information. A determination as to reasonableness under this paragraph shall include consideration of the number of notices that an entity must provide and the methods of communication available to the entity. Wis. Stat. Ann. § 134.98(3)(a).

Delivery: An entity must provide notice by mail or by a method the entity has previously employed to communicate with the subject of the personal information. If an entity cannot with reasonable diligence determine the mailing address of the subject of the personal information, and if the entity has not previously communicated with the subject of the personal information, the entity shall provide notice by a method reasonably calculated to provide actual notice to the subject of the personal information. Wis. Stat. Ann. § 134.98(3)(b).

Content: The notice shall indicate that the entity knows of the unauthorized acquisition of personal information pertaining to the subject of the personal information. Wis. Stat. Ann. § 134.98(2)(b).

Is Notice To The Government Required?

No.

Is Notice To Credit Reporting Agencies Required?

Yes. If, as the result of a single incident, an entity is required to notify 1,000 or more individuals that personal information pertaining to the individuals has been acquired, the entity shall without unreasonable delay notify all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notices sent to the individuals. Wis. Stat. Ann. § 134.98(2)(br).

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

Failure to comply with this section is not negligence or a breach of any duty, but may be evidence of negligence or a breach of a legal duty. Wis. Stat. Ann. § 134.98(4).

Are There Any Exemptions/Exceptions?

This section does not apply to any of the following: a) An entity that is subject to, and in compliance with, the privacy and security requirements of 15 USC 6801 to 6827, or a person that has a contractual obligation to such an entity, if the entity or person has in effect a policy concerning breaches of information security. b) An entity that is described in 45 CFR 164.104 (a), if the entity complies with the requirements of 45 CFR part 164. Wis. Stat. Ann. § 134.98(3m).

West Virginia

Who Is Covered?

An individual or entity that owns or licenses computerized data that includes personal information. W. Va. Code § 46A-2A-102(a).

What Information Is Protected?

“Personal information” means the first name or first initial and last name linked to any one or more of the following data elements that relate to a resident of this state, when the data elements are neither encrypted nor redacted:

  1. Social security number;
  2. Driver’s license number or state identification card number issued in lieu of a driver’s license; or
  3. Financial account number, or credit card, or debit card number in combination with any required security code, access code or password that would permit access to a resident’s financial accounts. W. Va. Code § 46A-2A-101(6).

What Is A “Breach”?

“Breach of the security of a system” means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information maintained by an individual or entity as part of a database of personal information regarding multiple individuals and that causes the individual or entity to reasonably believe that the breach of security has caused or will cause identity theft or other fraud to any resident of this state. Good faith acquisition of personal information by an employee or agent of an individual or entity for the purposes of the individual or the entity is not a breach of the security of the system, provided that the personal information is not used for a purpose other than a lawful purpose of the individual or entity or subject to further unauthorized disclosure. W. Va. Code § 46A-2A-101(1).

What Triggers Notification?

The discovery or notification of the breach of the security of the system involving any resident of this state whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person and that causes, or the individual or entity reasonably believes has caused or will cause, identity theft or other fraud to any resident of this state. W. Va. Code § 46A-2A-102(a).

An individual or entity must give notice of the breach of the security of the system if encrypted information is accessed and acquired in an unencrypted form or if the security breach involves a person with access to the encryption key and the individual or entity reasonably believes that such breach has caused or will cause identity theft or other fraud to any resident of this state. W. Va. Code § 46A-2A-102(b).

How Is Notice Provided To Individuals?

Timing: The notice must be made without reasonable delay, subject to the needs of law enforcement. W. Va. Code § 46A-2A-102(a).

Delivery: Notice may be by:

  1. Written notice to the postal address in the records of the individual or entity;
  2. Telephonic notice;
  3. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures, set forth in Section 7001, United States Code Title 15, Electronic Signatures in Global and National Commerce Act;
  4. Substitute notice, if the individual or the entity required to provide notice demonstrates that the cost of providing notice will exceed $50,000 or that the affected class of residents to be notified exceeds 100,000 persons or that the individual or the entity does not have sufficient contact information or to provide notice as described [above]. Substitute notice consists of any two of the following: (i) E-mail notice if the individual or the entity has e-mail addresses for the members of the affected class of residents; (ii) Conspicuous posting of the notice on the website of the individual or the entity if the individual or the entity maintains a website; or (iii) Notice to major statewide media. W. Va. Code § 46A-2A-101(7).

Content: The notice must include:

  1. To the extent possible, a description of the categories of information that were reasonably believed to have been accessed or acquired by an unauthorized person, including social security numbers, driver’s licenses or state identification numbers and financial data;
  2. A telephone number or website address that the individual may use to contact the entity or the agent of the entity and from whom the individual may learn: a) What types of information the entity maintained about that individual or about individuals in general; and b) Whether or not the entity maintained information about that individual.
  3. The toll-free contact telephone numbers and addresses for the major credit reporting agencies and information on how to place a fraud alert or security freeze. W. Va. Code § 46A-2A-102(d).

Is Notice To The Government Required?

No.

Is Notice To Credit Reporting Agencies Required?

Yes. If an entity is required to notify more than one thousand persons of a breach of security pursuant to this article, the entity shall also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on a nationwide basis of the timing, distribution and content of the notices. Nothing in this subsection shall be construed to require the entity to provide to the consumer reporting agency the names or other personal identifying information of breach notice recipients. This subsection shall not apply to an entity who is subject to Title V of the Gramm Leach Bliley Act. W. Va. Code § 46A-2A-102(f).

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

Failure to comply with the notice provisions constitutes an unfair or deceptive act or practice and may be enforced by the Attorney General pursuant to the enforcement provisions of this chapter. W. Va. Code § 46A-2A-104(a).

No civil penalty may be assessed in an action unless the court finds that the defendant has engaged in a course of repeated and willful violations of this article. No civil penalty shall exceed $150,000 per breach of security of the system or series of breaches of a similar nature that are discovered in a single investigation. W. Va. Code § 46A-2A-104(b).

A violation by a licensed financial institution is enforceable exclusively by the financial institution’s primary functional regulator. W. Va. Code § 46A-2A-104(c).

Are There Any Exemptions/Exceptions?

An entity that maintains its own notification procedures as part of an information privacy or security policy for the treatment of personal information and that are consistent with the timing requirements of this article shall be deemed to be in compliance with the notification requirements of this article if it notifies residents of this state in accordance with its procedures in the event of a breach of security of the system. W. Va. Code § 46A-2A-103(a).

Additionally, a financial institution that responds in accordance with the notification guidelines prescribed by the Federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice is deemed to be in compliance with this article. W. Va. Code § 46A-2A-103(b).

Also, an entity that complies with the notification requirements or procedures pursuant to the rules, regulations, procedures or guidelines established by the entity’s primary or functional regulator shall be in compliance with this article. W. Va. Code § 46A-2A-103(c).

Virginia

Who Is Covered?

An individual or entity that owns or licenses computerized data that includes personal information. Va. Code Ann. § 18.2-186.6(B).

What Information Is Protected?

“Personal information” means the first name or first initial and last name in combination with and linked to any one or more of the following data elements that relate to a resident of the Commonwealth, when the data elements are neither encrypted nor redacted:

  1. Social security number.
  2. Driver’s license number or state identification card number issued in lieu of a driver’s license number;
  3. Financial account number, or credit card or debit card number, in combination with any required security code, access code, or password that would permit access to a resident’s financial accounts;
  4. Passport number; or
  5. Military identification number. Va. Code Ann. § 18.2-186.6(A).

What Is A “Breach”?

“Breach of the security of the system” means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information maintained by an individual or entity as part of a database of personal information regarding multiple individuals and that causes, or the individual or entity reasonably believes has caused, or will cause, identity theft or other fraud to any resident of the Commonwealth. Good faith acquisition of personal information by an employee or agent of an individual or entity for the purposes of the individual or entity is not a breach of the security of the system, provided that the personal information is not used for a purpose other than a lawful purpose of the individual or entity or subject to further unauthorized disclosure. Va. Code Ann. § 18.2-186.6(A).

What Triggers Notification?

If unencrypted or unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person and causes, or the individual or entity reasonably believes has caused or will cause, identity theft or another fraud to any resident. Va. Code Ann. § 18.2-186.6(B).

How Is Notice Provided To Individuals?

Timing: Notification must be made without unreasonable delay. Notice may be reasonably delayed to allow the individual or entity to determine the scope of the breach of the security of the system and restore the reasonable integrity of the system. Notice required by this section may be delayed if, after the individual or entity notifies a law-enforcement agency, the law-enforcement agency determines and advises the individual or entity that the notice will impede a criminal or civil investigation, or homeland or national security. Notice shall be made without unreasonable delay after the law-enforcement agency determines that the notification will no longer impede the investigation or jeopardize national or homeland security. Va. Code Ann. § 18.2-186.6(B).

Delivery: Notice may be by:

  1. Written notice to the last known postal address in the records of the individual or entity;
  2. Telephone notice;
  3. Electronic notice; or
  4. Substitute notice, if the individual or the entity required to provide notice demonstrates that the cost of providing notice will exceed $50,000, the affected class of Virginia residents to be notified exceeds 100,000 residents, or the individual or the entity does not have sufficient contact information or consent to provide notice as described in subdivisions 1, 2, or 3 of this definition. Substitute notice consists of all of the following: a) E-mail notice if the individual or the entity has e-mail addresses for the members of the affected class of residents; b) Conspicuous posting of the notice on the website of the individual or the entity if the individual or the entity maintains a website; and  c) Notice to major statewide media. Va. Code Ann. § 18.2-186.6(A).

Content: The notice must contain a description of:

  1. The incident in general terms; 
  2. The type of personal information that was subject to the unauthorized access and acquisition;
  3. The general acts of the individual or entity to protect the personal information from further unauthorized access;
  4. A telephone number that the person may call for further information and assistance, if one exists; and
  5. Advice that directs the person to remain vigilant by reviewing account statements and monitoring free credit reports. Va. Code Ann. § 18.2-186.6(A).

Is Notice To The Government Required?

Yes. In the event an individual or entity provides notice to more than 1,000 persons at one time pursuant to this section, the individual or entity shall notify, without unreasonable delay, the Office of the Attorney General and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notice.

Is Notice To Credit Reporting Agencies Required?

Yes. See above.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

The Attorney General may bring an action to address violations of this section. The Office of the Attorney General may impose a civil penalty not to exceed $150,000 per breach of the security of the system or a series of breaches of a similar nature that are discovered in a single investigation. Nothing in this section shall limit an individual from recovering direct economic damages from a violation of this section. A violation of this section by a state-chartered or licensed financial institution shall be enforceable exclusively by the financial institution’s primary state regulator. Va. Code Ann. § 18.2-186.6(I), (J).

Are There Any Exemptions/Exceptions?

An entity that maintains its own notification procedures as part of an information privacy or security policy for the treatment of personal information that are consistent with the timing requirements of this section shall be deemed to be in compliance with the notification requirements of this section if it notifies residents of the Commonwealth in accordance with its procedures in the event of a breach of the security of the system. Va. Code Ann. § 18.2-186.6(F).

Additionally, an entity that is subject to Title V of the Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.) and maintains procedures for notification of a breach of the security of the system in accordance with the provision of that Act and any rules, regulations, or guidelines promulgated thereto shall be deemed to be in compliance with this section. Va. Code Ann. § 18.2-186.6(G).

Finally, an entity that complies with the notification requirements or procedures pursuant to the rules, regulations, procedures, or guidelines established by the entity’s primary or functional state or federal regulator shall be in compliance with this section. Va. Code Ann. § 18.2-186.6(H).

Breach of Medication Information

NOTE: Similar notification requirements apply to a breach of medical information. See Va. Code Ann. § 32.1-127.1:05.

Vermont

Who Is Covered?

“Data collector” means a person who, for any purpose, whether by automated collection or otherwise, handles, collects, disseminates, or otherwise deals with personally identifiable information, and includes the state, state agencies, political subdivisions of the state, public and private universities, privately and publicly held corporations, limited liability companies, financial institutions, and retail operators. Vt. Stat. Ann. tit. 9, § 2430(6).

What Information Is Protected?

“Personally identifiable information” means a consumer’s first name or first initial and last name in combination with one or more of the following digital data elements, when the data elements are not encrypted, redacted, or protected by another method that renders them unreadable or unusable by unauthorized persons:

  1. A Social Security number;
  2. A driver license or nondriver state identification card number, individual taxpayer identification number, passport number, military identification card number, or other identification number that originates from a government identification document that is commonly used to verify identity for a commercial transaction;
  3. A financial account number or credit or debit card number, if the number could be used without additional identifying information, access codes, or passwords;
  4. A password, personal identification number, or other access code for a financial account;
  5. Unique biometric data generated from measurements or technical analysis of human body characteristics used by the owner or licensee of the data to identify or authenticate the consumer, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data;
  6. Genetic information; and
  7. (a) health records or records of a wellness program or similar program of health promotion or disease prevention; (b) a health care professional’s medical diagnosis or treatment of the consumer; or (c) a health insurance policy number. Vt. Stat. Ann. tit. 9, § 2430(10).

“Login credentials” means a consumer’s user name or email address, in combination with a password or an answer to a security question, that together permit access to an online account. Vt. Stat. Ann. tit. 9, § 2430(9).

What Is A “Breach”?

“Security breach” means unauthorized acquisition of electronic data or a reasonable belief of an unauthorized acquisition of electronic data that compromises the security, confidentiality, or integrity of a consumer’s personally identifiable information or login credentials maintained by a data collector. Vt. Stat. Ann. tit. 9, § 2430(13).

In determining whether personally identifiable information or login credentials have been acquired or is reasonably believed to have been acquired by a person without valid authorization, a data collector may consider the following factors, among others:

  1. Indications that the information is in the physical possession and control of a person without valid authorization, such as a lost or stolen computer or other device containing information;
  2. Indications that the information has been downloaded or copied;
  3. Indications that the information was used by an unauthorized person, such as fraudulent accounts opened or instances of identity theft reported; or
  4. That the information has been made public. Vt. Stat. Ann. tit. 9, § 2430(13)(C).

Likelihood of Harm Analysis: Notice of a security breach is not required if the data collector establishes that misuse of personally identifiable information or login credentials is not reasonably possible and the data collector provides notice of the determination that the misuse of the personally identifiable information or login credentials is not reasonably possible pursuant to the requirements of this subsection. If the data collector establishes that misuse of the personally identifiable information or login credentials is not reasonably possible, the data collector shall provide notice of its determination that misuse of the personally identifiable information or login credentials is not reasonably possible and a detailed explanation for said determination to the Vermont Attorney General or to the Department of Financial Regulation in the event that the data collector is a person or entity licensed or registered with the Department under Title 8 or this title. Vt. Stat. Ann. tit. 9, § 2435(d)(1).

What Triggers Notification?

Discovery or notification to the data collector of the breach. Vt. Stat. Ann. tit. 9, § 2435(b)(1).

How Is Notice Provided To Individuals?

Timing: Notice of the security breach shall be made in the most expedient time possible and without unreasonable delay, but not later than 45 days after the discovery or notification, consistent with the legitimate needs of the law enforcement agency or with any measures necessary to determine the scope of the security breach and restore the reasonable integrity, security, and confidentiality of the data system. Vt. Stat. Ann. tit. 9, § 2435(b)(1).

Delivery: Delivery may be by direct notice or substitute notice. If by direct notice, it may be by:

  1. Written notice mailed to the consumer’s residence;
  2. Electronic notice, for those consumers for whom the data collector has a valid email address if: a) the data collector’s primary method of communication with the consumer is by electronic means, the electronic notice does not request or contain a hypertext link to a request that the consumer provide personal information, and the electronic notice conspicuously warns consumers not to provide personal information in response to electronic communications regarding security breaches; or b) the notice is consistent with the provisions regarding electronic records and signatures for notices in 15 U.S.C. § 7001; or
  3. Telephonic notice, provided that telephonic contact is made directly with each affected consumer and not through a prerecorded message.

Substitute notice may be made by conspicuously posting the notice on the data collector’s website if the data collector maintains one and notifying major statewide and regional media if:

  1. The data collector demonstrates that the lowest cost of providing notice to affected consumers pursuant to subdivision (6)(A) of this subsection among written, email, or telephonic notice would exceed $10,000; or
  2. The data collector does not have sufficient contact information. Vt. Stat. Ann. tit. 9, § 2435(b)(6).

Content: The notice sent to consumers must be clear and conspicuous and include each of the following, if known:

  1. The incident in general terms;
  2. The type of personally identifiable information that was subject to the security breach;
  3. The general acts of the data collector to protect the personally identifiable information from further security breach;
  4. A telephone number, toll-free if available, that the consumer may call for further information and assistance;
  5. Advice that directs the consumer to remain vigilant by reviewing account statements and monitoring free credit reports; and
  6. The approximate date of the security breach. Vt. Stat. Ann. tit. 9, § 2435(b)(5).

If a security breach is limited to an unauthorized acquisition of login credentials for an online account other than an email account the data collector shall provide notice of the security breach to the consumer electronically or through one or more of the methods specified above and shall advise the consumer to take steps necessary to protect the online account, including to change his or her login credentials for the account and for any other account for which the consumer uses the same login credentials. Vt. Stat. Ann. tit. 9, § 2435(d)(3).

If a security breach is limited to an unauthorized acquisition of login credentials for an email account: (A) the data collector shall not provide notice of the security breach through the email account; and (B) the data collector shall provide notice of the security breach through one or more of the methods specified above or by clear and conspicuous notice delivered to the consumer online when the consumer is connected to the online account from an Internet protocol address or online location from which the data collector knows the consumer customarily accesses the account. Vt. Stat. Ann. tit. 9, § 2435(d)(4).

Is Notice To The Government Required?

Yes. A data collector or other entity regulated by the Department of Financial Regulation under Title 8 or this title shall provide notice of a breach to the Department. All other data collectors or other entities subject to this subchapter shall provide notice of a breach to the Attorney General. The data collector shall notify the Attorney General or the Department, as applicable, of the date of the security breach and the date of discovery of the breach and shall provide a preliminary description of the breach within 14 business days, consistent with the legitimate needs of the law enforcement agency, of the data collector’s discovery of the security breach or when the data collector provides notice to consumers pursuant to this section, whichever is sooner. Vt. Stat. Ann. tit. 9, § 2435(b)(3).

When the data collector provides notice of the breach pursuant to subdivision (1) of this subsection (b), the data collector shall notify the Attorney General or the Department, as applicable, of the number of Vermont consumers affected, if known to the data collector, and shall provide a copy of the notice provided to consumers. The data collector may send to the Attorney General or the Department, as applicable, a second copy of the consumer notice, from which is redacted the type of personally identifiable information or login credentials that was subject to the breach, and which the Attorney General or the Department shall use for any public disclosure of the breach. Vt. Stat. Ann. tit. 9, § 2435(b)(3)(C).

Is Notice To Credit Reporting Agencies Required?

Yes. In the event a data collector provides notice to more than 1,000 consumers at one time pursuant to this section, the data collector shall notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notice. This subsection shall not apply to a person who is licensed or registered under Title 8 by the Department of Financial Regulation. Vt. Stat. Ann. tit. 9, § 2435(c).

Are There Security Measure Standards?

The Social Security Number Protection Act, Vt. Stat. Ann. tit. 9, § 2440, restricts the use of individuals’ social security numbers, and the Document Safe Destruction Act, Vt. Stat. Ann. tit. 9, § 2445, requires that businesses take all reasonable steps to destroy or arrange for the destruction of a customer’s records within its custody or control containing personal information that are no longer to be retained by the business.

What Are The Possible Consequences Of A Violation?

With respect to all data collectors and other entities subject to this subchapter, other than a person or entity licensed or registered with the Department of Financial Regulation under Title 8 or this title, the Attorney General and State’s Attorney shall have sole and full authority to investigate potential violations of this subchapter and to enforce, prosecute, obtain, and impose remedies for a violation of this subchapter or any rules or regulations made pursuant to this chapter as the Attorney General and State’s Attorney have under chapter 63 of this title. Vt. Stat. Ann. tit. 9, § 2435(h)(1).

With respect to a data collector that is a person or entity licensed or registered with the Department of Financial Regulation under Title 8 or this title, the Department of Financial Regulation shall have the full authority to investigate potential violations of this subchapter and to prosecute, obtain, and impose remedies for a violation of this subchapter or any rules or regulations adopted pursuant to this subchapter, as the Department has under Title 8 or this title or any other applicable law or regulation. Vt. Stat. Ann. tit. 9, § 2435(h)(2).

Are There Any Exemptions/Exceptions?

A data collector that is subject to the privacy, security, and breach notification rules adopted pursuant to the federal Health Insurance Portability and Accountability Act is deemed to be in compliance with this subchapter if: a) the data collector experiences a security breach that is limited to personally identifiable information specified in 2430(10)(A)(vii); and b) the data collector provides notice to affected consumers pursuant to the requirements of the breach notification rule in 45 C.F.R. Part 164, Subpart D. Vt. Stat. Ann. tit. 9, § 2435(e).

Additionally, a financial institution that is subject to the following guidances, and any revisions, additions, or substitutions relating to an interagency guidance shall be exempt from this section: 

  1. The Federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information and Customer Notice, issued on March 7, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision. 
  2. Final Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice, issued on April 14, 2005, by the National Credit Union Administration. 
  3. A financial institution regulated by the Department of Financial Regulation that is subject to subdivision (1) or (2) of this subsection (g) shall notify the Department as soon as possible after it becomes aware of an incident involving unauthorized access to or use of personally identifiable information. Vt. Stat. Ann. tit. 9, § 2435(g).

Texas

Who Is Covered?

A person who conducts business in Texas and owns or licenses computerized data that includes sensitive personal information. Tex. Bus. & Com. Code § 521.053(b).

 

What Information Is Protected?

“Personal identifying information” means information that alone or in conjunction with other information identifies an individual, including an individual’s:

 

  1. Name, social security number, date of birth, or government-issued identification number;
  2. Mother’s maiden name;
  3. Unique biometric data, including the individual’s fingerprint, voice print, and retina or iris image;
  4. Unique electronic identification number, address, or routing code; and
  5. Telecommunication access device as defined by Section 32.51, Penal Code. Tex. Bus. & Com. Code § 521.002(a)(1).

“Sensitive personal information” means:

 

  1. An individual’s first name or first initial and last name in combination with any one or more of the following items, if the name and the items are not encrypted: (i) social security number; (ii) driver’s license number or government-issued identification number; or (iii) account number or credit or debit card number in combination with any required security code, access code, or password that would permit access to an individual’s financial account; or
  2. Information that identifies an individual and relates to: (i) the physical or mental health or condition of the individual; (ii) the provision of health care to the individual; or (iii) payment for the provision of health care to the individual. Tex. Bus. & Com. Code § 521.002(a)(2).

 

What Is A “Breach”?

“Breach of system security” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of sensitive personal information maintained by a person, including data that is encrypted if the person accessing the data has the key required to decrypt the data. Good faith acquisition of sensitive personal information by an employee or agent of the person for the purposes of the person is not a breach of system security unless the person uses or discloses the sensitive personal information in an unauthorized manner. Tex. Bus. & Com. Code § 521.053(a).

 

What Triggers Notification?

Discovering or receiving notification of the breach where any individual’s sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Tex. Bus. & Com. Code § 521.053(b).

 

How Is Notice Provided To Individuals?

Non-Residents: If the individual whose sensitive personal information was or is reasonably believed to have been acquired by an unauthorized person is a resident of a state that requires a person [under Texas law] to provide notice of a breach of system security, the notice of the breach of system security may be provided under that state’s law or under Texas law. Tex. Bus. & Com. Code § 521.053(b-1).

Timing: The disclosure shall be made without unreasonable delay and in each case not later than the 60th day after the date on which the person determines that the breach occurred, except as necessary for the needs of law enforcement or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Tex. Bus. & Com. Code § 521.053(b), (d).

Delivery: Notice may be provided by:

 

  1. Written notice at the last known address of the individual;
  2. Electronic notice, if the notice is provided in accordance with 15 U.S.C. Section 7001; or
  3. Substitute notice if it is demonstrated that the cost of providing notice would exceed $250,000, the number of affected persons exceeds 500,000, or the person does not have sufficient contact information, in which case the notice may be given by: a) electronic mail, if the person has electronic mail addresses for the affected persons; b) conspicuous posting of the notice on the person’s website; or c) notice published in or broadcast on major statewide media. Tex. Bus. & Com. Code § 521.053(e), (f).

Content: None specified.

 

Is Notice To The Government Required?

Yes. A person who is required to disclose or provide notification of a breach of system security under this section shall notify the attorney general of that breach as soon as practicable and not later than the 30th day after the date on which the person determines that the breach occurred if the breach involves at least 250 residents of this state. The notification under this subsection must be submitted electronically using a form accessed through the attorney general’s Internet website and must include:

 

  1. A detailed description of the nature and circumstances of the breach or the use of sensitive personal information acquired as a result of the breach;
  2. The number of residents of this state affected by the breach at the time of notification;
  3. the number of affected residents that have been sent a disclosure of the breach by mail or other direct method of communication at the time of notification;
  4. The measures taken by the person regarding the breach;
  5. Any measures the person intends to take regarding the breach after the notification under this subsection; and
  6. Information regarding whether law enforcement is engaged in investigating the breach. Tex. Bus. & Com. Code § 521.053(i).

 

Is Notice To Credit Reporting Agencies Required?

Yes. If a person is required by this section to notify at one time more than 10,000 persons of a breach of system security, the person shall also notify each consumer reporting agency of the timing, distribution, and content of the notices. The person shall provide the notice required by this subsection without unreasonable delay. Tex. Bus. & Com. Code § 521.053(h).

 

Are There Security Measure Standards?

Yes. A business shall implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect from unlawful use or disclosure any sensitive personal information collected or maintained by the business in the regular course of business. Tex. Bus. & Com. Code § 521.052(a).

Additionally, a business shall destroy or arrange for the destruction of customer records containing sensitive personal information within the business’s custody or control that are not to be retained by the business by:(1) shredding; (2) erasing; or (3) otherwise modifying the sensitive personal information in the records to make the information unreadable or indecipherable through any means. Tex. Bus. & Com. Code § 521.052(b).

 

What Are The Possible Consequences Of A Violation?

A person who violates this chapter is liable to this state for a civil penalty of at least $2,000 but not more than $50,000 for each violation. The attorney general may bring an action to recover the civil penalty imposed under this subsection. Tex. Bus. & Com. Code § 521.151(a).

In addition to penalties assessed under Subsection (a), a person who fails to take reasonable action to comply with Section 521.053(b) is liable to this state for a civil penalty of not more than $100 for each individual to whom notification is due under that subsection for each consecutive day that the person fails to take reasonable action to comply with that subsection. Civil penalties under this section may not exceed $250,000 for all individuals to whom notification is due after a single breach. The attorney general may bring an action to recover the civil penalties imposed under this subsection. Tex. Bus. & Com. Code § 521.151(a-1).

 

Are There Any Exemptions/Exceptions?

A person who maintains the person’s own notification procedures as part of an information security policy for the treatment of sensitive personal information that complies with the timing requirements for notice under this section complies with this section if the person notifies affected persons in accordance with that policy. Tex. Bus. & Com. Code § 521.053(g).

Tennessee

Who Is Covered?

“Information holder” means any person or business that conducts business in Tennessee, or any agency of this state or any of its political subdivisions, that owns or licenses computerized personal information of residents of this state. Tenn. Code Ann. § 47-18-2107(a)(3).

What Information Is Protected?

“Personal information” means an individual’s first name or first initial and last name, in combination with any one (1) or more of the following data elements:

  1. Social security number;
  2. Driver license number; or
  3. Account, credit card, or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account. Tenn. Code Ann. § 47-18-2107(a)(4).

What Is A Breach?

“Breach of system security” means the acquisition of the following information by an unauthorized person that materially compromises the security, confidentiality, or integrity of personal information maintained by the information holder:

  1. Unencrypted computerized data; or
  2. Encrypted computerized data and the encryption key. Tenn. Code Ann. § 47-18-2107(a)(1).

What Triggers Notification?

Discovery or notification of a breach of system security by an information holder where the personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Tenn. Code Ann. § 47-18-2107(b).

How Is Notice Provided To Individuals?

Timing: The disclosure must be made no later than forty-five (45) days from the discovery or notification of the breach of system security, unless a longer period of time is required due to the legitimate needs of law enforcement. Tenn. Code Ann. § 47-18-2107(b).

Delivery: Notification may be by:

  1. Written notice;
  2. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001 or if the information holder’s primary method of communication with the resident of this state has been by electronic means; or
  3. Substitute notice, if the information holder demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars ($250,000), that the affected class of subject persons to be notified exceeds five hundred thousand (500,000) persons, or the information holder does not have sufficient contact information and the notice consists of all of the following: (A) Email notice, when the information holder has an email address for the subject persons; (B) Conspicuous posting of the notice on the information holder’s website, if the information holder maintains a website page; and (C) Notification to major statewide media. Tenn. Code Ann. § 47-18-2107(e).

Content: None specified.

Is Notice To The Government Required?

No.

Is Notice To Credit Reporting Agencies Required?

Yes. If an information holder discovers circumstances requiring notification pursuant to this section of more than 1,000 persons at one time, the information holder must also notify, without unreasonable delay, all consumer reporting agencies and credit bureaus that compile and maintain files on consumers on a nationwide basis, of the timing, distribution, and content of the notices. Tenn. Code Ann. § 47-18-2107(g).

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

Any customer of an information holder who is a person or business entity, but who is not an agency of this state or any political subdivision of this state, and who is injured by a violation of this section, may institute a civil action to recover damages and to enjoin the information holder from further action in violation of this section. The rights and remedies available under this section are cumulative to each other and to any other rights and remedies available under law. Tenn. Code Ann. § 47-18-2107(h).

Additionally, in addition to injunctive relief and attorney fees, the attorney general may seek a civil penalty of whichever of the following is greater: a) $10,000; b) $5,000 per day for each day that a person’s identity has been assumed; or c) 10 times the amount obtained or attempted to be obtained by the person using the identity theft.  Tenn. Code Ann. § 47-18-2105.

Are There Any Exemptions/Exceptions?

If an information holder maintains its own notification procedures as part of an information security policy for the treatment of personal information and if the policy is otherwise consistent with the timing requirements of this section, the information holder is in compliance with the notification requirements of this section, as long as the information holder notifies subject persons in accordance with its policies in the event of a breach of system security. Tenn. Code Ann. § 47-18-2107(f).

Additionally, the requirements do not apply to any information holder subject to:

  1. Title V of the Gramm-Leach-Bliley Act; or 
  2. The Health Insurance Portability and Accountability Act. Tenn. Code Ann. § 47-18-2107(i).

South Dakota

Who Is Covered?

“Information holder,” any person or business that conducts business in this state, and that owns or licenses computerized personal or protected information of residents of this state; S.D. Codified Laws § 22-40-19(3).

What Information Is Protected?

“Personal information” is a person’s first name or first initial and last name, in combination with any one or more of the following data elements:

  1. Social security number;
  2. Driver license number or other unique identification number created or collected by a government body;
  3. Account, credit card, or debit card number, in combination with any required security code, access code, password, routing number, PIN, or any additional information that would permit access to a person’s financial account;
  4. Health information as defined in 45 CFR 160.103; or
  5. An identification number assigned to a person by the person’s employer in combination with any required security code, access code, password, or biometric data generated from measurements or analysis of human body characteristics for authentication purposes. S.D. Codified Laws § 22-40-19(4).

“Protected information” includes:

  1. A user name or email address, in combination with a password, security question answer, or other information that permits access to an online account; and
  2. Account number or credit or debit card number, in combination with any required security code, access code, or password that permits access to a person’s financial account. S.D. Codified Laws § 22-40-19(5).

What Is A “Breach”?

“Breach of system security,” the unauthorized acquisition of unencrypted computerized data or encrypted computerized data and the encryption key by any person that materially compromises the security, confidentiality, or integrity of personal or protected information maintained by the information holder. The term does not include the good faith acquisition of personal or protected information by an employee or agent of the information holder for the purposes of the information holder if the personal or protected information is not used or subject to further unauthorized disclosure S.D. Codified Laws § 22-40-19(1).

What Triggers Notification?

Discovery by or notification to an information holder of a breach of system security where personal or protected information was, or is reasonably believed to have been, acquired by an unauthorized person. S.D. Codified Laws § 22-40-20.

An information holder is not required to make a disclosure under this section if, following an appropriate investigation and notice to the attorney general, the information holder reasonably determines that the breach will not likely result in harm to the affected person. The information holder shall document the determination under this section in writing and maintain the documentation for not less than three years. S.D. Codified Laws § 22-40-20.

How Is Notice Provided To Individuals?

Timing: The disclosure must be made not later than sixty days from the discovery or notification of the breach of system security, unless a longer period of time is required due to the legitimate needs of law enforcement. S.D. Codified Laws § 22-40-20.

Delivery: The disclosure may be provided by:

  1. Written notice;
  2. Electronic notice, if the electronic notice is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. Section 7001 in effect as of January 1, 2018, or if the information holder’s primary method of communication with the resident of this state has been by electronic means; or
  3. Substitute notice, if the information holder demonstrates that the cost of providing notice would exceed 250,000, that the affected class of persons to be notified exceeds five hundred thousand persons, or that the information holder does not have sufficient contact information and the notice consists of each of the following: (a) Email notice, if the information holder has an email address for the subject persons; (b) Conspicuous posting of the notice on the information holder’s website, if the information holder maintains a website page; and (c) Notification to statewide media. S.D. Codified Laws § 22-40-22.

Content: None specified.

Is Notice To The Government Required?

Yes. Any information holder that experiences a breach of system security under this section shall disclose to the attorney general by mail or electronic mail any breach of system security that exceeds 250 residents of this state. S.D. Codified Laws § 22-40-20.

Is Notice To Credit Reporting Agencies Required?

Yes. If an information holder discovers circumstances that require notification, the information holder shall also notify, without unreasonable delay, all consumer reporting agencies and any other credit bureau or agency that compiles and maintains files on consumers on a nationwide basis, of the timing, distribution, and content of the notice. S.D. Codified Laws § 22-40-24.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

The attorney general may prosecute each failure to disclose under the provisions of this Act as a deceptive act or practice under Section 37-24-6. In addition to any remedy provided under chapter 37-24, the attorney general may bring an action to recover on behalf of the state a civil penalty of not more than $10,000 per day per violation. The attorney general may recover attorney’s fees and any costs associated with any action brought under this section. S.D. Codified Laws § 22-40-25.

Are There Any Exemptions/Exceptions?

Notwithstanding any other provisions in this Act, any information holder that is regulated by federal law or regulation, including the Health Insurance Portability and Accountability Act or the Gramm Leach Bliley Act and that maintains procedures for a breach of system security pursuant to the laws, rules, regulations, guidance, or guidelines established by its primary or functional federal regulator is deemed to be in compliance with this chapter if the information holder notifies affected South Dakota residents in accordance with the provisions of the applicable federal law or regulation. S.D. Codified Laws § 22-40-26.

Utah

Who Is Covered?

A person who owns or licenses computerized data that includes personal information concerning a Utah resident. Utah Code Ann. § 13-44-202(1)(a).

 

What Information Is Protected?

“Personal information” means a person’s first name or first initial and last name, combined with any one or more of the following data elements relating to that person when either the name or date element is unencrypted or not protected by another method that renders the data unreadable or unusable:

 

  1. Social Security number;
  2. (A) financial account number, or credit or debit card number; and (b) any required security code, access code, or password that would permit access to the person’s account; or
  3. Driver license number or state identification card number. Utah Code Ann. § 13-44-102(4).

 

What Is A “Breach”?

“Breach of system security” means an unauthorized acquisition of computerized data maintained by a person that compromises the security, confidentiality, or integrity of personal information. Utah Code Ann. § 13-44-102(1)(a).

 

What Triggers Notification?

When a person becomes aware of a breach of system security, the person must conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be misused for identity theft or fraud purposes. Notification must be provided if the investigation reveals that the misuse of personal information for identity theft or fraud purposes has occurred, or is reasonably likely to occur, the person shall provide notification to each affected Utah resident. Utah Code Ann. § 13-44-202(1).

 

How Is Notice Provided To Individuals?

Timing: Notification must be made in the most expedient time possible without unreasonable delay considering the legitimate investigative needs of law enforcement, after determining the scope of the breach of system security and after restoring the reasonable integrity of the system. Utah Code Ann. § 13-44-202(2).

Delivery: Notification may be provided:

 

  1. In writing by first-class mail to the most recent address the person has for the resident;
  2. Electronically, if the person’s primary method of communication with the resident is by electronic means, or if provided in accordance with the consumer disclosure provisions of 15 U.S.C. Section 7001;
  3. By telephone, including through the use of automatic dialing technology not prohibited by other law; or
  4. For residents of the state for whom notification in a manner described above is not feasible, by publishing notice of the breach of system security: (A) in a newspaper of general circulation; and (B) as required in Section 45-1-101 [legal notice publication requirements]. Utah Code Ann. § 13-44-202.

Content: None specified.

 

Is Notice To The Government Required?

Yes. If the investigation reveals that the misuse of personal information relating to 500 or more Utah residents, for identity theft or fraud purposes, has occurred or is reasonably likely to occur, the person shall, in addition to the notification required in Subsection (1)(b), provide notification to: 

  1. the office of the Attorney General; and
  2. the Utah Cyber Center. Utah Code Ann. § 13-44-202(1)(c).

 

Is Notice To Credit Reporting Agencies Required?

Yes, if the investigation reveals that the misuse of personal information relating to 1,000 or more Utah residents, for identity theft or fraud purposes, has occurred or is reasonably likely to occur.
Utah Code Ann. § 13-44-202(1)(d).

 

Are There Security Measure Standards?

Yes. Any person who conducts business in the state and maintains personal information shall implement and maintain reasonable procedures to:

 

  1. Prevent unlawful use or disclosure of personal information collected or maintained in the regular course of business; and
  2. Destroy, or arrange for the destruction of, records containing personal information that are not to be retained by the person. 

The destruction of records shall be by: (a) shredding; (b) erasing; or (c) otherwise modifying the personal information to make the information indecipherable. Utah Code Ann. § 13-44-201.

 

What Are The Possible Consequences Of A Violation?

In addition to injunctive relief and attorney fees and costs, the attorney general may seek a civil penalty of:

 

  1. No greater than $2,500 for a violation or series of violations concerning a specific consumer; and
  2. No greater than $100,000 in the aggregate for related violations concerning more than one consumer, unless: a) the violations concern: (i) 10,000 or more consumers who are residents of the state; and (ii) 10,000 or more consumers who are residents of other states; or b) the person agrees to settle for a greater amount. Utah Code Ann. § 13-44-301(3), (4).

 

Are There Any Exemptions/Exceptions?

If a person maintains the person’s own notification procedures as part of an information security policy for the treatment of personal information the person is considered to be in compliance with this chapter’s notification requirements if the procedures are otherwise consistent with this chapter’s timing requirements and the person notifies each affected Utah resident in accordance with the person’s information security policy in the event of a breach. Utah Code Ann. § 13-44-202(5)(b).

Also, a person who is regulated by state or federal law and maintains procedures for a breach of system security under applicable law established by the primary state or federal regulator is considered to be in compliance with this part if the person notifies each affected Utah resident in accordance with the other applicable law in the event of a breach. Utah Code Ann. § 13-44-202(5)(c).

South Carolina

Who Is Covered?

A person conducting business in South Carolina and owning or licensing computerized data or other data that includes personal identifying information. S.C. Code Ann. § 39-1-90(A).

What Information Is Protected?

“Personal identifying information” means the first name or first initial and last name in combination with and linked to any one or more of the following data elements that relate to a resident of this State, when the data elements are neither encrypted nor redacted:

  1. Social security number;
  2. Driver’s license number or state identification card number issued instead of a driver’s license;
  3. Financial account number, or credit card or debit card number in combination with any required security code, access code, or password that would permit access to a resident’s financial account; or
  4. Other numbers or information which may be used to access a person’s financial accounts or numbers or information issued by a governmental or regulatory entity that uniquely will identify an individual. S.C. Code Ann. § 39-1-90(D)(3).

What Is A “Breach”?

“Breach of the security of the system” means unauthorized access to and acquisition of computerized data that was not rendered unusable through encryption, redaction, or other methods that compromises the security, confidentiality, or integrity of personal identifying information maintained by the person, when illegal use of the information has occurred or is reasonably likely to occur or use of the information creates a material risk of harm to a resident. Good faith acquisition of personal identifying information by an employee or agent of the person for the purposes of its business is not a breach of the security of the system if the personal identifying information is not used or subject to further unauthorized disclosure. S.C. Code Ann. § 39-1-90(D)(1).

What Triggers Notification?

The discovery or notification of the breach in the security of the data to a resident whose personal identifying information that was not rendered unusable through encryption, redaction, or other methods was, or is reasonably believed to have been, acquired by an unauthorized person when the illegal use of the information has occurred or is reasonably likely to occur or use of the information creates a material risk of harm to the resident. S.C. Code Ann. § 39-1-90(A).

How Is Notice Provided To Individuals?

Timing: The disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement or with measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. S.C. Code Ann. § 39-1-90(A).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic notice, if the person’s primary method of communication with the individual is by electronic means or is consistent with the provisions regarding electronic records and signatures in Section 7001 of Title 15 USC and Chapter 6, Title 11 of the 1976 Code;
  3. Telephonic notice; or
  4. Substitute notice, if the person demonstrates that the cost of providing notice exceeds two hundred fifty thousand dollars or that the affected class of subject persons to be notified exceeds five hundred thousand or the person has insufficient contact information. Substitute notice consists of: (a) e-mail notice when the person has an e-mail address for the subject persons; (b) conspicuous posting of the notice on the web site page of the person, if the person maintains one; or (c) notification to major statewide media. S.C. Code Ann. § 39-1-90(E).

Content: Not specified.

Is Notice To The Government Required?

Yes. If a business provides notice to more than 1,000 persons at one time pursuant to this section, the business shall notify, without unreasonable delay, the Consumer Protection Division of the Department of Consumer Affairs and all consumer reporting agencies that compile and maintain files on a nationwide basis of the timing, distribution, and content of the notice. S.C. Code Ann. § 39-1-90(K).

Is Notice To Credit Reporting Agencies Required?

Yes. See above.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

A resident of South Carolina who is injured by a violation of this section, in addition to and cumulative of all other rights and remedies available at law, may: (1) institute a civil action to recover damages in case of a willful and knowing violation; (2) institute a civil action that must be limited to actual damages resulting from a violation in case of a negligent violation of this section; (3) seek an injunction to enforce compliance; and (4) recover attorney’s fees and court costs, if successful. S.C. Code Ann. § 39-1-90(G).

Additionally, a person who knowingly and wilfully violates this section is subject to an administrative fine in the amount of one thousand dollars for each resident whose information was accessible by reason of the breach, the amount to be decided by the Department of Consumer Affairs. S.C. Code Ann. § 39-1-90(H).

Are There Any Exemptions/Exceptions?

This section does not apply to a bank or financial institution that is subject to and in compliance with the privacy and security provision of the Gramm-Leach-Bliley Act. S.C. Code Ann. § 39-1-90(I).

Also, a financial institution that is subject to and in compliance with the federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information and Customer Notice, issued March 7, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision, as amended, is considered to be in compliance with this section. S.C. Code Ann. § 39-1-90(J).

Rhode Island

Who Is Covered?

Any municipal agency, state agency, or person that stores, owns, collects, processes, maintains, acquires, uses, or licenses data that includes personal information. R.I. Gen. Laws Section 11-49.3-4(a)(1).

What Information Is Protected?

“Personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements, when the name and the data elements are not encrypted or are in hard copy, paper format:

  1. Social security number;
  2. Driver’s license number, Rhode Island identification card number, or tribal identification number;
  3. Account number, credit, or debit card number, in combination with any required security code, access code, password, or personal identification number, that would permit access to an individual’s financial account;
  4. Medical or health insurance information; or
  5. Email address with any required security code, access code, or password that would permit access to an individual’s personal, medical, insurance, or financial account. R.I. Gen. Laws Section 11-49.3-3(a)(8).

“Health insurance information” means an individual’s health insurance policy number, subscriber identification number, or any unique identifier used by a health insurer to identify the individual. R.I. Gen. Laws Section 11-49.3-3(a)(3).

“Medical information” means any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional or provider. R.I. Gen. Laws Section 11-49.3-3(a)(4).

What Is A “Breach”?

“Breach of the security of the system” means unauthorized access or acquisition of unencrypted, computerized data information that compromises the security, confidentiality, or integrity of personal information maintained by the municipal agency, state agency, or person. Good-faith acquisition of personal information by an employee or agent of the agency for the purposes of the agency is not a breach of the security of the system; provided, that the personal information is not used or subject to further unauthorized disclosure. R.I. Gen. Laws Section 11-49.3-3(a)(1).

What Triggers Notification?

The disclosure of personal information, or any breach of the security of the system, that poses a significant risk of identity theft to any resident of Rhode Island whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person or entity. R.I. Gen. Laws Section 11-49.3-4(a)(1).

How Is Notice Provided To Individuals?

Timing: The notification must be made in the most expedient time possible, but no later than 45 calendar days after confirmation of the breach and the ability to ascertain the information required to be included in the notification. R.I. Gen. Laws § 11-49.3-4(a)(2).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001; or
  3. Substitute notice, if the municipal agency, state agency, or person demonstrates that the cost of providing notice would exceed $25,000, or that the affected class of subject persons to be notified exceeds 50,000, or the municipal agency, state agency, or person does not have sufficient contact information. Substitute notice shall consist of all of the following: (A) Email notice when the municipal agency, state agency, or person has an email address for the subject persons; (B) Conspicuous posting of the notice on the municipal agency’s, state agency’s or person’s website page, if the municipal agency, state agency, or person maintains one; and (C) Notification to major statewide media. R.I. Gen. Laws Section 11-49.3-3(c).

Content: The notice must include:

  1. A general and brief description of the incident, including how the security breach occurred and the number of affected individuals;
  2. The type of information that was subject to the breach;
  3. Date of breach, estimated date of breach, or the date range within which the breach occurred;
  4. Date that the breach was discovered;
  5. A clear and concise description of any remediation services offered to affected individuals including toll free numbers and websites to contact: (i) The credit reporting agencies; (ii) Remediation service providers; (iii) The attorney general; and
  6. A clear and concise description of the consumer’s ability to file or obtain a police report; how a consumer requests a security freeze and the necessary information to be provided when requesting the security freeze; and that fees may be required to be paid to the consumer reporting agencies. R.I. Gen. Laws § 11-49.3-4(d).

Is Notice To The Government Required?

Yes. In the event that more than 500 Rhode Island residents are to be notified, the municipal agency, state agency, or person shall notify the attorney general and the major credit reporting agencies as to the timing, content, and distribution of the notices and the approximate number of affected individuals. Notification to the attorney general and the major credit reporting agencies shall be made without delaying notice to affected Rhode Island residents. R.I. Gen. Laws Section 11-49.3-4(a)(2).

Is Notice To Credit Reporting Agencies Required?

Yes. See above.

Are There Security Measure Standards?

Yes. A municipal agency, state agency, or person who or that stores, collects, processes, maintains, acquires, uses, owns, or licenses personal information about a Rhode Island resident shall implement and maintain a risk-based information security program that contains reasonable security procedures and practices appropriate to the size and scope of the organization; the nature of the information; and the purpose for which the information was collected in order to protect the personal information from unauthorized access, use, modification, destruction, or disclosure and to preserve the confidentiality, integrity, and availability of such information. A municipal agency, state agency, or person shall not retain personal information for a period longer than is reasonably required to provide the services requested; to meet the purpose for which it was collected; or in accordance with a written retention policy or as may be required by law. A municipal agency, state agency, or person shall destroy all personal information, regardless of the medium that such information is in, in a secure manner, including, but not limited to, shredding, pulverization, incineration, or erasure. R.I. Gen. Laws Section 11-49.3-2(a).

Additionally, a municipal agency, state agency, or person who or that discloses personal information about a Rhode Island resident to a nonaffiliated third party shall require by written contract that the third party implement and maintain reasonable security procedures and practices appropriate to the size and scope of the organization; the nature of the information; and the purpose for which the information was collected in order to protect the personal information from unauthorized access, use, modification, destruction, or disclosure. The provisions of this section shall apply to contracts entered into after the effective date of this act. R.I. Gen. Laws Section 11-49.3-2(b).

What Are The Possible Consequences Of A Violation?

Each reckless violation of this chapter is a civil violation for which a penalty of not more than $100 per record may be adjudged against a defendant. Each knowing and willful violation of this chapter is a civil violation for which a penalty of not more than $200 per record may be adjudged against a defendant. Additionally, whenever the attorney general has reason to believe that a violation has occurred and that proceedings would be in the public interest, the attorney general may bring an action in the name of the state against the business or person in violation. R.I. Gen. Laws Section 11-49.3-5.

Are There Any Exemptions/Exceptions?

  1. Any municipal agency, state agency, or person shall be deemed to be in compliance with the security breach notification requirements of § 11-49.3-4 if: a) The municipal agency, state agency, or person maintains its own security breach procedures as part of an information security policy for the treatment of personal information and otherwise complies with the timing requirements of § 11-49.3-4, and notifies subject persons in accordance with such municipal agency’s, state agency’s, or person’s notification policies in the event of a breach of security; or b) The person maintains a security breach procedure pursuant to the rules, regulations, procedures, or guidelines established by the primary or functional regulator, as defined in 15 U.S.C. § 6809(2), and notifies subject persons in accordance with the policies or the rules, regulations, procedures, or guidelines established by the primary or functional regulator in the event of a breach of security of the system.
  2. A financial institution, trust company, credit union, or its affiliates that is subject to and examined for, and found in compliance with, the Federal Interagency Guidelines on Response Programs for Unauthorized Access to Customer Information and Customer Notice shall be deemed in compliance with this chapter.
  3. A provider of health care, health care service plan, health insurer, or a covered entity governed by the medical privacy and security rules issued by the Federal Department of Health and Human Services, Parts 160 and 164 of Title 45 of the Code of Federal Regulations, established pursuant to the Health Insurance Portability and Accountability Act of 1996 shall be deemed in compliance with this chapter. R.I. Gen. Laws Section 11-49.3-6.

Pennsylvania

Who Is Covered?

An entity that maintains, stores or manages computerized data that includes personal information. 73 Pa. Stat. Ann. § 2303(a).

 

What Information Is Protected?

“Personal information” is an individual’s first name or first initial and last name in combination with and linked to any one or more of the following data elements when the data elements are not encrypted or redacted:

 

  1. Social security number.
  2. Driver’s license number or a State identification card number issued in lieu of a driver’s license.
  3. Financial account number, credit or debit card number, in combination with any required security code, access code or password that would permit access to an individual’s financial account.
  4. Medical information in the possession of a State agency or State agency contractor..
  5. Health insurance information.
  6. A user name or e-mail address, in combination with a password or security question and answer that would permit access to an online account.73 Pa. Stat. Ann. § 2302.

 

What Is A “Breach”?

“Breach of the Security of the System.” The unauthorized access and acquisition of computerized data that materially compromises the security or confidentiality of personal information maintained by the entity as part of a database of personal information regarding multiple individuals and that causes or the entity reasonably believes has caused or will cause loss or injury to any resident of this Commonwealth. Good faith acquisition of personal information by an employee or agent of the entity for the purposes of the entity is not a breach of the security of the system if the personal information is not used for a purpose other than the lawful purpose of the entity and is not subject to further unauthorized disclosure. 73 Pa. Stat. Ann. § 2302.

 

What Triggers Notification?

The determination of the breach of the security of the system involving a resident of Pennsylvania whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person. 73 Pa. Stat. Ann. § 2303(a).

 

How Is Notice Provided To Individuals?

Timing: Notice shall be made without unreasonable delay except as necessary to meet the needs of law enforcement or in order to take any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the data system. 73 Pa. Stat. Ann. § 2303(a).

Delivery: Notice may be by:

 

  1. Written notice to the last known home address for the individual.
  2. Telephonic notice, if the customer can be reasonably expected to receive it and the notice is given in a clear and conspicuous manner, describes the incident in general terms and verifies personal information but does not require the customer to provide personal information and the customer is provided with a telephone number to call or Internet website to visit for further information or assistance.
  3. Email notice, if a prior business relationship exists and the person or entity has a valid email address for the individual.
  4. Electronic notice, if the notice directs the person whose personal information has been materially compromised by a breach of the security of the system to promptly change the person’s password and security question or answer, as applicable or to take other steps appropriate to protect the person’s online account to the extent the entity has sufficient contact information for the person.
  5. Substitute notice, if the entity demonstrates one of the following: a) The cost of providing notice would exceed $100,000; b) The affected class of subject persons to be notified exceeds 175,000; or c) The entity does not have sufficient contact information.

Substitute notice shall consist of all of the following: 

 

  1. Email notice when the entity has an email address for the subject persons.
  2. Conspicuous posting of the notice on the entity’s Internet website if the entity maintains one.
  3. Notification to major statewide media. 73 Pa. Stat. Ann. § 2302.

Content: None specified.

 

Is Notice To The Government Required?

Yes, if notice must be given to more than 500 individuals in Pennsylvania. Notice to the Attorney General must include the following information to the extent known by the notifying entity:

1. The organization name and location.
2. The date of the breach.
3. A summary of the breach incident.
4. An estimated total number of individuals affected.
5. An estimated total number of individuals in Pennsylvania affected.

 

Is Notice To Credit Reporting Agencies Required?

Yes. When an entity provides notification under this act to more than 500 persons at one time, the entity shall also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in section 603 of the Fair Credit Reporting Act (Public Law 91-508, 15 U.S.C. § 1681a), of the timing, distribution and number of notices. 73 Pa. Stat. Ann. § 2305.

 

Are There Security Measure Standards?

Yes, for entities that maintain, store or manage computerized data on behalf of the Commonwealth that constitutes personal information.  Such entities must utilize encryption, or other appropriate security measures, to reasonably protect the transmission of personal information over the Internet from being viewed or modified by an unauthorized third party. 73 P.S. § 2305a(a).

 

What Are The Possible Consequences Of A Violation?

A violation of this act shall be deemed to be an unfair or deceptive act or practice in violation of the Unfair Trade Practices and Consumer Protection Law. The Office of Attorney General shall have exclusive authority to bring an action under the Unfair Trade Practices and Consumer Protection Law for a violation of this act. 73 Pa. Stat. Ann. § 2308

Entities that are required to report the incident to consumer reporting agencies must assume the costs of providing the affected individuals with access to one credit report if an individual is not otherwise eligible for a free report, and access to credit monitoring services for 1 year.

 

Are There Any Exemptions/Exceptions?

Yes. Any covered entity or business associate that is subject to and in compliance with the privacy and security standards for the protection of electronic personal health information established under the Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191, 110 Stat. 1936) and the Health Information Technology for Economic and Clinical Health Act (Public Law 111-5, 123 Stat. 226-279 and 467-496) shall be deemed to be in compliance with the provisions of this act.

Also, the following entities will be deemed to be in compliance:

 

  1. An entity that maintains its own notification procedures as part of an information privacy or security policy for the treatment of personal information and is consistent with the notice requirements of this act shall be deemed to be in compliance with the notification requirements of this act if it notifies subject persons in accordance with its policies in the event of a breach of security of the system. 
  2. A financial institution that complies with the notification requirements prescribed by the Federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice is deemed to be in compliance with this act. 
  3. An entity, a State agency or a State agency’s contractor, that complies with the notification requirements or procedures pursuant to the rules, regulations, procedures or guidelines established by the entity’s, State agency’s or State agency’s contractor’s primary State or functional Federal regulator, shall be in compliance with this act. 73 Pa. Stat. Ann. § 2307.