Category Archives: Private Right of Action

Wisconsin

Who Is Covered?

“Entity” means a person, other than an individual, that does any of the following:

  1. Conducts business in this state and maintains personal information in the ordinary course of business.
  2. Licenses personal information in this state.
  3. Maintains for a resident of this state a depository account as defined in s. 815.18 (2) (e).
  4. Lends money to a resident of this state. Wis. Stat. Ann. § 134.98(1)(a).

What Information Is Protected?

“Personal information” means an individual’s last name and the individual’s first name or first initial, in combination with and linked to any of the following elements, if the element is not publicly available information and is not encrypted, redacted, or altered in a manner that renders the element unreadable:

  1. The individual’s social security number.
  2. The individual’s driver’s license number or state identification number.
  3. The number of the individual’s financial account number, including a credit or debit card account number, or any security code, access code, or password that would permit access to the individual’s financial account.
  4. The individual’s deoxyribonucleic acid profile, as defined in s. 939.74 (2d) (a).
  5. The individual’s unique biometric data, including fingerprint, voice print, retina or iris image, or any other unique physical representation. Wis. Stat. Ann. § 134.98(1)(b).

What Is A “Breach”?

Knowledge that personal information of a resident of Wisconsin has been acquired by a person not authorized to acquire the personal information by:

  1. An entity whose principal place of business is located in this state or an entity that maintains or licenses personal information in this state; or
  2. An entity whose principal place of business is not located in this state. Wis. Stat. Ann. § 134.98(2)(a), (b).

What Triggers Notification?

Knowledge that personal information in the entity’s possession has been acquired by a person not authorized to acquire the personal information. Wis. Stat. Ann. § 134.98(2)(a), (b).

However, an entity is not required to provide notice of the acquisition of personal information if any of the following applies:

  1. The acquisition of personal information does not create a material risk of identity theft or fraud to the subject of the personal information. 
  2. The personal information was acquired in good faith by an employee or agent of the entity, if the personal information is used for a lawful purpose of the entity. Wis. Stat. Ann. § 134.98(2)(cm).

How Is Notice Provided To Individuals?

Timing: Subject to the needs of law enforcement, an entity shall provide the notice within a reasonable time, not to exceed 45 days after the entity learns of the acquisition of personal information. A determination as to reasonableness under this paragraph shall include consideration of the number of notices that an entity must provide and the methods of communication available to the entity. Wis. Stat. Ann. § 134.98(3)(a).

Delivery: An entity must provide notice by mail or by a method the entity has previously employed to communicate with the subject of the personal information. If an entity cannot with reasonable diligence determine the mailing address of the subject of the personal information, and if the entity has not previously communicated with the subject of the personal information, the entity shall provide notice by a method reasonably calculated to provide actual notice to the subject of the personal information. Wis. Stat. Ann. § 134.98(3)(b).

Content: The notice shall indicate that the entity knows of the unauthorized acquisition of personal information pertaining to the subject of the personal information. Wis. Stat. Ann. § 134.98(2)(b).

Is Notice To The Government Required?

No.

Is Notice To Credit Reporting Agencies Required?

Yes. If, as the result of a single incident, an entity is required to notify 1,000 or more individuals that personal information pertaining to the individuals has been acquired, the entity shall without unreasonable delay notify all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notices sent to the individuals. Wis. Stat. Ann. § 134.98(2)(br).

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

Failure to comply with this section is not negligence or a breach of any duty, but may be evidence of negligence or a breach of a legal duty. Wis. Stat. Ann. § 134.98(4).

Are There Any Exemptions/Exceptions?

This section does not apply to any of the following: a) An entity that is subject to, and in compliance with, the privacy and security requirements of 15 USC 6801 to 6827, or a person that has a contractual obligation to such an entity, if the entity or person has in effect a policy concerning breaches of information security. b) An entity that is described in 45 CFR 164.104 (a), if the entity complies with the requirements of 45 CFR part 164. Wis. Stat. Ann. § 134.98(3m).

Washington

Who Is Covered?

Any person or business that conducts business in Washington and that owns or licenses data that includes personal information. Wash. Rev. Code Ann. § 19.255.010(1).

What Information Is Protected?

“Personal information” is:

A. An individual’s first name or first initial and last name in combination with any one or more of the following data elements:

  1. Social security number;
  2. Driver’s license number or Washington identification card number;
  3. Account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account, or any other numbers or information that can be used to access a person’s financial account;
  4. Full date of birth;
  5. Private key that is unique to an individual and that is used to authenticate or sign an electronic record;
  6. Student, military, or passport identification number;
  7. Health insurance policy number or health insurance identification number;
  8. Any information about a consumer’s medical history or mental or physical condition or about a health care professional’s medical diagnosis or treatment of the consumer; or
  9. Biometric data generated by automatic measurements of an individual’s biological characteristics such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that is used to identify a specific individual;

B. Username or email address in combination with a password or security questions and answers that would permit access to an online account; and

C. Any of the data elements or any combination of the data elements described in subsection A, above, without the consumer’s first name or first initial and last name if:

  1. Encryption, redaction, or other methods have not rendered the data element or combination of data elements unusable; and
  2. The data element or combination of data elements would enable a person to commit identity theft against a consumer. Rev. Code Wash. (ARCW) § 19.255.005(2)(a).

What Is A “Breach”?

“Breach of the security of the system” means unauthorized acquisition of data that compromises the security, confidentiality, or integrity of personal information maintained by the person or business. Good faith acquisition of personal information by an employee or agent of the person or business for the purposes of the person or business is not a breach of the security of the system when the personal information is not used or subject to further unauthorized disclosure. Wash. Rev. Code Ann. § 19.255.005(1).

What Triggers Notification?

Any breach of the security of the system involving a resident’s personal information that was, or is reasonably believed to have been, acquired by an unauthorized person and the personal information was not secured. Wash. Rev. Code Ann. § 19.255.010(1).

Likelihood of Harm Analysis: Notice is not required if the breach of the security of the system is not reasonably likely to subject consumers to a risk of harm. The breach of secured personal information must be disclosed if the information acquired and accessed is not secured during a security breach or if the confidential process, encryption key, or other means to decipher the secured information was acquired by an unauthorized person. Wash. Rev. Code Ann. § 19.255.010(1).

How Is Notice Provided To Individuals?

Timing: Notification to affected consumers must be made in the most expedient time possible, without unreasonable delay, and no more than 30 calendar days after the breach was discovered, unless the delay is at the request of law enforcement or the delay is due to any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Wash. Rev. Code Ann. § 19.255.010(8).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. Sec. 7001;
  3. Substitute notice, if the person or business demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars, or that the affected class of subject persons to be notified exceeds five hundred thousand, or the person or business does not have sufficient contact information. Substitute notice shall consist of all of the following: (i) Email notice when the person or business has an email address for the subject persons; (ii) Conspicuous posting of the notice on the website page of the person or business, if the person or business maintains one; and (iii) Notification to major statewide media. Wash. Rev. Code Ann. § 19.255.010(4)(a)-(c).

If the breach of the security of the system involves personal information including a user name or password, notice may be provided electronically or by email. The notice must inform the person whose personal information has been breached to promptly change his or her password and security question or answer, as applicable, or to take other appropriate steps to protect the online account with the person or business and all other online accounts for which the person whose personal information has been breached uses the same user name or email address and password or security question or answer. Wash. Rev. Code Ann. § 19.255.010(4)(d)(i).

However, when the breach of the security of the system involves login credentials of an email account furnished by the person or business, the person or business may not provide the notification to that email address, but must provide notice using another method described [above]. The notice must inform the person whose personal information has been breached to promptly change his or her password and security question or answer, as applicable, or to take other appropriate steps to protect the online account with the person or business and all other online accounts for which the person whose personal information has been breached uses the same user name or email address and password or security question or answer. Wash. Rev. Code Ann. § 19.255.010(4)(d)(ii).

Content: The notice must be written in plain language and include the following information:

  1. The name and contact information of the reporting person or business subject to this section;
  2. A list of the types of personal information that were or are reasonably believed to have been the subject of a breach;
  3. A time frame of exposure, if known, including the date of the breach and the date of the discovery of the breach; and
  4. The toll-free telephone numbers and addresses of the major credit reporting agencies if the breach exposed personal information. Wash. Rev. Code Ann. § 19.255.010(6).

Is Notice To The Government Required?

Yes. Any person or business that is required to issue a notification pursuant to this section to more than 500 Washington residents as a result of a single breach shall notify the attorney general of the breach no more than 30 days after the breach was discovered. The notice must include:

  1. The number of Washington consumers affected by the breach, or an estimate if the exact number is not known;
  2. A list of the types of personal information that were or are reasonably believed to have been the subject of a breach;
  3. A time frame of exposure, if known, including the date of the breach and the date of the discovery of the breach;
  4. A summary of steps taken to contain the breach; and
  5. A single sample copy of the security breach notification, excluding any personally identifiable information. Wash. Rev. Code Ann. § 19.255.010(7).

Is Notice To Credit Reporting Agencies Required?

No.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

The attorney general may bring an action in the name of the state, or as parens patriae on behalf of persons residing in the state, to enforce this chapter. For actions brought by the attorney general to enforce this chapter, the legislature finds that the practices covered by this chapter are matters vitally affecting the public interest for the purpose of applying the consumer protection act, chapter 19.86 RCW. For actions brought by the attorney general to enforce this chapter, a violation of this chapter is not reasonable in relation to the development and preservation of business and is an unfair or deceptive act in trade or commerce and an unfair method of competition for purposes of applying the consumer protection act, chapter 19.86 RCW. Wash. Rev. Code Ann. § 19.255.040(2).

Additionally, any consumer injured by a violation of this chapter may institute a civil action to recover damages. Wash. Rev. Code Ann. § 19.255.040(3).

Are There Any Exemptions/Exceptions?

A covered entity under the federal Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. Sec. 1320d et seq., is deemed to have complied with the requirements of this chapter with respect to protected health information if it has complied with section 13402 of the federal Health Information Technology for Economic and Clinical Health Act, P.L. 111-5 as it existed on July 24, 2015. Covered entities shall notify the attorney general pursuant to RCW 19.255.010(7) in compliance with the timeliness of notification requirements of section 13402 of the federal Health Information Technology for Economic and Clinical Health Act, P.L. 111-5 as it existed on July 24, 2015, notwithstanding the timeline in RCW 19.255.010(7). Wash. Rev. Code Ann. § 19.255.030(1).

Additionally, a financial institution under the authority of the Office of the Comptroller of the Currency, the Federal Deposit Insurance Corporation, the National Credit Union Administration, or the Federal Reserve System is deemed to have complied with the requirements of this chapter with respect to “sensitive customer information” as defined in the Interagency Guidelines Establishing Information Security Standards, 12 C.F.R. Part 30, Appendix B, 12 C.F.R. Part 208, Appendix D-2, 12 C.F.R. Part 225, Appendix F, and 12 C.F.R. Part 364, Appendix B, and 12 C.F.R. Part 748, Appendices A and B, as they existed on July 24, 2015, if the financial institution provides notice to affected consumers pursuant to the interagency guidelines and the notice complies with the customer notice provisions of the Interagency Guidelines Establishing Information Security Standards and the Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice under 12 C.F.R. Part 364 as it existed on July 24, 2015. The entity shall notify the attorney general pursuant to RCW 19.255.010 in addition to providing notice to its primary federal regulator. Wash. Rev. Code Ann. § 19.255.030(2).

Payment Processors

Note: Additional requirements apply to a person or entity “that directly processes or transmits account information for or on behalf of another person as part of a payment processing service.” See Wash. Rev. Code Ann. § 19.255.020.

Virginia

Who Is Covered?

An individual or entity that owns or licenses computerized data that includes personal information. Va. Code Ann. § 18.2-186.6(B).

What Information Is Protected?

“Personal information” means the first name or first initial and last name in combination with and linked to any one or more of the following data elements that relate to a resident of the Commonwealth, when the data elements are neither encrypted nor redacted:

  1. Social security number.
  2. Driver’s license number or state identification card number issued in lieu of a driver’s license number;
  3. Financial account number, or credit card or debit card number, in combination with any required security code, access code, or password that would permit access to a resident’s financial accounts;
  4. Passport number; or
  5. Military identification number. Va. Code Ann. § 18.2-186.6(A).

What Is A “Breach”?

“Breach of the security of the system” means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information maintained by an individual or entity as part of a database of personal information regarding multiple individuals and that causes, or the individual or entity reasonably believes has caused, or will cause, identity theft or other fraud to any resident of the Commonwealth. Good faith acquisition of personal information by an employee or agent of an individual or entity for the purposes of the individual or entity is not a breach of the security of the system, provided that the personal information is not used for a purpose other than a lawful purpose of the individual or entity or subject to further unauthorized disclosure. Va. Code Ann. § 18.2-186.6(A).

What Triggers Notification?

If unencrypted or unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person and causes, or the individual or entity reasonably believes has caused or will cause, identity theft or another fraud to any resident. Va. Code Ann. § 18.2-186.6(B).

How Is Notice Provided To Individuals?

Timing: Notification must be made without unreasonable delay. Notice may be reasonably delayed to allow the individual or entity to determine the scope of the breach of the security of the system and restore the reasonable integrity of the system. Notice required by this section may be delayed if, after the individual or entity notifies a law-enforcement agency, the law-enforcement agency determines and advises the individual or entity that the notice will impede a criminal or civil investigation, or homeland or national security. Notice shall be made without unreasonable delay after the law-enforcement agency determines that the notification will no longer impede the investigation or jeopardize national or homeland security. Va. Code Ann. § 18.2-186.6(B).

Delivery: Notice may be by:

  1. Written notice to the last known postal address in the records of the individual or entity;
  2. Telephone notice;
  3. Electronic notice; or
  4. Substitute notice, if the individual or the entity required to provide notice demonstrates that the cost of providing notice will exceed $50,000, the affected class of Virginia residents to be notified exceeds 100,000 residents, or the individual or the entity does not have sufficient contact information or consent to provide notice as described in subdivisions 1, 2, or 3 of this definition. Substitute notice consists of all of the following: a) E-mail notice if the individual or the entity has e-mail addresses for the members of the affected class of residents; b) Conspicuous posting of the notice on the website of the individual or the entity if the individual or the entity maintains a website; and  c) Notice to major statewide media. Va. Code Ann. § 18.2-186.6(A).

Content: The notice must contain a description of:

  1. The incident in general terms; 
  2. The type of personal information that was subject to the unauthorized access and acquisition;
  3. The general acts of the individual or entity to protect the personal information from further unauthorized access;
  4. A telephone number that the person may call for further information and assistance, if one exists; and
  5. Advice that directs the person to remain vigilant by reviewing account statements and monitoring free credit reports. Va. Code Ann. § 18.2-186.6(A).

Is Notice To The Government Required?

Yes. In the event an individual or entity provides notice to more than 1,000 persons at one time pursuant to this section, the individual or entity shall notify, without unreasonable delay, the Office of the Attorney General and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notice.

Is Notice To Credit Reporting Agencies Required?

Yes. See above.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

The Attorney General may bring an action to address violations of this section. The Office of the Attorney General may impose a civil penalty not to exceed $150,000 per breach of the security of the system or a series of breaches of a similar nature that are discovered in a single investigation. Nothing in this section shall limit an individual from recovering direct economic damages from a violation of this section. A violation of this section by a state-chartered or licensed financial institution shall be enforceable exclusively by the financial institution’s primary state regulator. Va. Code Ann. § 18.2-186.6(I), (J).

Are There Any Exemptions/Exceptions?

An entity that maintains its own notification procedures as part of an information privacy or security policy for the treatment of personal information that are consistent with the timing requirements of this section shall be deemed to be in compliance with the notification requirements of this section if it notifies residents of the Commonwealth in accordance with its procedures in the event of a breach of the security of the system. Va. Code Ann. § 18.2-186.6(F).

Additionally, an entity that is subject to Title V of the Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.) and maintains procedures for notification of a breach of the security of the system in accordance with the provision of that Act and any rules, regulations, or guidelines promulgated thereto shall be deemed to be in compliance with this section. Va. Code Ann. § 18.2-186.6(G).

Finally, an entity that complies with the notification requirements or procedures pursuant to the rules, regulations, procedures, or guidelines established by the entity’s primary or functional state or federal regulator shall be in compliance with this section. Va. Code Ann. § 18.2-186.6(H).

Breach of Medication Information

NOTE: Similar notification requirements apply to a breach of medical information. See Va. Code Ann. § 32.1-127.1:05.

Tennessee

Who Is Covered?

“Information holder” means any person or business that conducts business in Tennessee, or any agency of this state or any of its political subdivisions, that owns or licenses computerized personal information of residents of this state. Tenn. Code Ann. § 47-18-2107(a)(3).

What Information Is Protected?

“Personal information” means an individual’s first name or first initial and last name, in combination with any one (1) or more of the following data elements:

  1. Social security number;
  2. Driver license number; or
  3. Account, credit card, or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account. Tenn. Code Ann. § 47-18-2107(a)(4).

What Is A Breach?

“Breach of system security” means the acquisition of the following information by an unauthorized person that materially compromises the security, confidentiality, or integrity of personal information maintained by the information holder:

  1. Unencrypted computerized data; or
  2. Encrypted computerized data and the encryption key. Tenn. Code Ann. § 47-18-2107(a)(1).

What Triggers Notification?

Discovery or notification of a breach of system security by an information holder where the personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Tenn. Code Ann. § 47-18-2107(b).

How Is Notice Provided To Individuals?

Timing: The disclosure must be made no later than forty-five (45) days from the discovery or notification of the breach of system security, unless a longer period of time is required due to the legitimate needs of law enforcement. Tenn. Code Ann. § 47-18-2107(b).

Delivery: Notification may be by:

  1. Written notice;
  2. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001 or if the information holder’s primary method of communication with the resident of this state has been by electronic means; or
  3. Substitute notice, if the information holder demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars ($250,000), that the affected class of subject persons to be notified exceeds five hundred thousand (500,000) persons, or the information holder does not have sufficient contact information and the notice consists of all of the following: (A) Email notice, when the information holder has an email address for the subject persons; (B) Conspicuous posting of the notice on the information holder’s website, if the information holder maintains a website page; and (C) Notification to major statewide media. Tenn. Code Ann. § 47-18-2107(e).

Content: None specified.

Is Notice To The Government Required?

No.

Is Notice To Credit Reporting Agencies Required?

Yes. If an information holder discovers circumstances requiring notification pursuant to this section of more than 1,000 persons at one time, the information holder must also notify, without unreasonable delay, all consumer reporting agencies and credit bureaus that compile and maintain files on consumers on a nationwide basis, of the timing, distribution, and content of the notices. Tenn. Code Ann. § 47-18-2107(g).

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

Any customer of an information holder who is a person or business entity, but who is not an agency of this state or any political subdivision of this state, and who is injured by a violation of this section, may institute a civil action to recover damages and to enjoin the information holder from further action in violation of this section. The rights and remedies available under this section are cumulative to each other and to any other rights and remedies available under law. Tenn. Code Ann. § 47-18-2107(h).

Additionally, in addition to injunctive relief and attorney fees, the attorney general may seek a civil penalty of whichever of the following is greater: a) $10,000; b) $5,000 per day for each day that a person’s identity has been assumed; or c) 10 times the amount obtained or attempted to be obtained by the person using the identity theft.  Tenn. Code Ann. § 47-18-2105.

Are There Any Exemptions/Exceptions?

If an information holder maintains its own notification procedures as part of an information security policy for the treatment of personal information and if the policy is otherwise consistent with the timing requirements of this section, the information holder is in compliance with the notification requirements of this section, as long as the information holder notifies subject persons in accordance with its policies in the event of a breach of system security. Tenn. Code Ann. § 47-18-2107(f).

Additionally, the requirements do not apply to any information holder subject to:

  1. Title V of the Gramm-Leach-Bliley Act; or 
  2. The Health Insurance Portability and Accountability Act. Tenn. Code Ann. § 47-18-2107(i).

South Carolina

Who Is Covered?

A person conducting business in South Carolina and owning or licensing computerized data or other data that includes personal identifying information. S.C. Code Ann. § 39-1-90(A).

What Information Is Protected?

“Personal identifying information” means the first name or first initial and last name in combination with and linked to any one or more of the following data elements that relate to a resident of this State, when the data elements are neither encrypted nor redacted:

  1. Social security number;
  2. Driver’s license number or state identification card number issued instead of a driver’s license;
  3. Financial account number, or credit card or debit card number in combination with any required security code, access code, or password that would permit access to a resident’s financial account; or
  4. Other numbers or information which may be used to access a person’s financial accounts or numbers or information issued by a governmental or regulatory entity that uniquely will identify an individual. S.C. Code Ann. § 39-1-90(D)(3).

What Is A “Breach”?

“Breach of the security of the system” means unauthorized access to and acquisition of computerized data that was not rendered unusable through encryption, redaction, or other methods that compromises the security, confidentiality, or integrity of personal identifying information maintained by the person, when illegal use of the information has occurred or is reasonably likely to occur or use of the information creates a material risk of harm to a resident. Good faith acquisition of personal identifying information by an employee or agent of the person for the purposes of its business is not a breach of the security of the system if the personal identifying information is not used or subject to further unauthorized disclosure. S.C. Code Ann. § 39-1-90(D)(1).

What Triggers Notification?

The discovery or notification of the breach in the security of the data to a resident whose personal identifying information that was not rendered unusable through encryption, redaction, or other methods was, or is reasonably believed to have been, acquired by an unauthorized person when the illegal use of the information has occurred or is reasonably likely to occur or use of the information creates a material risk of harm to the resident. S.C. Code Ann. § 39-1-90(A).

How Is Notice Provided To Individuals?

Timing: The disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement or with measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. S.C. Code Ann. § 39-1-90(A).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic notice, if the person’s primary method of communication with the individual is by electronic means or is consistent with the provisions regarding electronic records and signatures in Section 7001 of Title 15 USC and Chapter 6, Title 11 of the 1976 Code;
  3. Telephonic notice; or
  4. Substitute notice, if the person demonstrates that the cost of providing notice exceeds two hundred fifty thousand dollars or that the affected class of subject persons to be notified exceeds five hundred thousand or the person has insufficient contact information. Substitute notice consists of: (a) e-mail notice when the person has an e-mail address for the subject persons; (b) conspicuous posting of the notice on the web site page of the person, if the person maintains one; or (c) notification to major statewide media. S.C. Code Ann. § 39-1-90(E).

Content: Not specified.

Is Notice To The Government Required?

Yes. If a business provides notice to more than 1,000 persons at one time pursuant to this section, the business shall notify, without unreasonable delay, the Consumer Protection Division of the Department of Consumer Affairs and all consumer reporting agencies that compile and maintain files on a nationwide basis of the timing, distribution, and content of the notice. S.C. Code Ann. § 39-1-90(K).

Is Notice To Credit Reporting Agencies Required?

Yes. See above.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

A resident of South Carolina who is injured by a violation of this section, in addition to and cumulative of all other rights and remedies available at law, may: (1) institute a civil action to recover damages in case of a willful and knowing violation; (2) institute a civil action that must be limited to actual damages resulting from a violation in case of a negligent violation of this section; (3) seek an injunction to enforce compliance; and (4) recover attorney’s fees and court costs, if successful. S.C. Code Ann. § 39-1-90(G).

Additionally, a person who knowingly and wilfully violates this section is subject to an administrative fine in the amount of one thousand dollars for each resident whose information was accessible by reason of the breach, the amount to be decided by the Department of Consumer Affairs. S.C. Code Ann. § 39-1-90(H).

Are There Any Exemptions/Exceptions?

This section does not apply to a bank or financial institution that is subject to and in compliance with the privacy and security provision of the Gramm-Leach-Bliley Act. S.C. Code Ann. § 39-1-90(I).

Also, a financial institution that is subject to and in compliance with the federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information and Customer Notice, issued March 7, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision, as amended, is considered to be in compliance with this section. S.C. Code Ann. § 39-1-90(J).

North Carolina

Who Is Covered?

Any business that owns or licenses personal information of residents of North Carolina or any business that conducts business in North Carolina that owns or licenses personal information in any form (whether computerized, paper, or otherwise). N.C. Gen. Stat. § 75-65(a).

What Information Is Protected?

A person’s first name or first initial and last name in combination with identifying information including the following:

  1. Social security or employer taxpayer identification numbers.   
  2. Drivers license, State identification card, or passport numbers.  
  3. Checking account numbers.  
  4. Savings account numbers.  
  5. Credit card numbers. 
  6. Debit card numbers.  
  7. Personal Identification (PIN) Code.    
  8. Digital signatures.  
  9. Any other numbers or information that can be used to access a person’s financial resources.  
  10. Biometric data.  
  11. Fingerprints.  
  12. Passwords if they would permit access to a person’s financial account or resources. N.C. Gen. Stat. §§ 75.61(10); 14-113.20(b).

What Is A “Breach”?

An incident of unauthorized access to and acquisition of unencrypted and unredacted records or data containing personal information where illegal use of the personal information has occurred or is reasonably likely to occur or that creates a material risk of harm to a consumer. Any incident of unauthorized access to and acquisition of encrypted records or data containing personal information along with the confidential process or key shall constitute a security breach. Good faith acquisition of personal information by an employee or agent of the business for a legitimate purpose is not a security breach, provided that the personal information is not used for a purpose other than a lawful purpose of the business and is not subject to further unauthorized disclosure. N.C. Gen. Stat. § 75-61(14).

What Triggers Notification?

Discovery or notification of the breach. N.C. Gen. Stat. § 75-65(a).

How Is Notice Provided To Individuals?

Timing: Notice must be made without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine sufficient contact information, determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system. N.C. Gen. Stat. § 75-65(a).

Delivery: Delivery may be by:

  1. Written notice.  
  2. Electronic notice, for those persons for whom it has a valid e-mail address and who have agreed to receive communications electronically if the notice provided is consistent with the provisions of the E-Sign Act.  
  3. Telephonic notice provided that contact is made directly with the affected persons.  
  4. Substitute notice, if the business demonstrates that the cost of providing notice would exceed $250,000 or that the affected class of subject persons to be notified exceeds 500,000, or if the business does not have sufficient contact information or consent to satisfy subdivisions (1), (2), or (3) of this subsection, for only those affected persons without sufficient contact information or consent, or if the business is unable to identify particular affected persons, for only those unidentifiable affected persons. Substitute notice shall consist of all the following: a)  E-mail notice when the business has an electronic mail address for the subject persons. b)  Conspicuous posting of the notice on the Web site page of the business, if one is maintained. c)  Notification to major statewide media. N.C. Gen. Stat. § 75-65(e).

Content: The notice must be clear and conspicuous and include:

  1. A description of the incident in general terms.  
  2. A description of the type of personal information that was subject to the unauthorized access and acquisition.  
  3. A description of the general acts of the business to protect the personal information from further unauthorized access.  
  4. A telephone number for the business that the person may call for further information and assistance, if one exists.  
  5. Advice that directs the person to remain vigilant by reviewing account statements and monitoring free credit reports.  
  6. The toll-free numbers and addresses for the major consumer reporting agencies.  
  7. The toll-free numbers, addresses, and Web site addresses for the Federal Trade Commission and the North Carolina Attorney General’s Office, along with a statement that the individual can obtain information from these sources about preventing identity theft. N.C. Gen. Stat. § 75-65(d).

Is Notice To The Government Required?

Yes. In the event a business provides notice to an affected person pursuant to this section, the business shall notify without unreasonable delay the Consumer Protection Division of the Attorney General’s Office of the nature of the breach, the number of consumers affected by the breach, steps taken to investigate the breach, steps taken to prevent a similar breach in the future, and information regarding the timing, distribution, and content of the notice. N.C. Gen. Stat. § 75-65(e1).

Is Notice To Credit Reporting Agencies Required?

Yes. In the event a business provides notice to more than 1,000 persons at one time pursuant to this section, the business shall notify, without unreasonable delay, the Consumer Protection Division of the Attorney General’s Office and all consumer reporting agencies of the timing, distribution, and content of the notice. N.C. Gen. Stat. § 75-65(f).

Are There Security Measure Standards?

Yes, with regard to destruction of records. Any business that conducts business in North Carolina and any business that maintains or otherwise possesses personal information of a resident of North Carolina must take reasonable measures to protect against unauthorized access to or use of the information in connection with or after its disposal, which must include:

  1. Implementing and monitoring compliance with policies and procedures that require the burning, pulverizing, or shredding of papers containing personal information so that information cannot be practicably read or reconstructed.  
  2. Implementing and monitoring compliance with policies and procedures that require the destruction or erasure of electronic media and other nonpaper media containing personal information so that the information cannot practicably be read or reconstructed.  
  3. Describing procedures relating to the adequate destruction or proper disposal of personal records as official policy in the writings of the business entity. N.C. Gen. Stat. § 75-64(a), (b).

What Are The Possible Consequences Of A Violation?

A violation is an unfair or deceptive act or practice under N.C. Gen. Stat. § 75-1.1 which can result in a civil penalty of up to $5,000 per violation for knowing violations. No private right of action may be brought by an individual for a violation of this section unless such individual is injured as a result of the violation. N.C. Gen. Stat. §§ 75-65(i); 75-15.2; 75.16.

Are There Any Exemptions/Exceptions?

A financial institution that is subject to and in compliance with the Federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information and Customer Notice, issued on March 7, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision; or a credit union that is subject to and in compliance with the Final Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice, issued on April 14, 2005, by the National Credit Union Administration; and any revisions, additions, or substitutions relating to any of the said interagency guidance, shall be deemed to be in compliance with this section. N.C. Gen. Stat. § 75-65(h).

New Hampshire

Who Is Covered?

Any person doing business in New Hampshire who owns or licenses computerized data that includes personal information. N.H. Rev. Stat. Ann. § 359-C:20(I)(a).

What Information Is Protected?

“Personal information” means an individual’s first name or initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted:

  1. Social security number.
  2. Driver’s license number or other government identification number.
  3. Account number, credit card number, or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account. N.H. Rev. Stat. Ann. § 359-C:19(IV).

What Is A “Breach”?

“Security breach” means unauthorized acquisition of computerized data that compromises the security or confidentiality of personal information maintained by a person doing business in this state. Good faith acquisition of personal information by an employee or agent of a person for the purposes of the person’s business shall not be considered a security breach, provided that the personal information is not used or subject to further unauthorized disclosure. N.H. Rev. Stat. Ann. § 359-C:19(V).

What Triggers Notification?

After becoming aware of a security breach, a determination that misuse of the information has occurred or is reasonably likely to occur, or such a determination cannot be made. N.H. Rev. Stat. Ann. § 359-C:20(I)(a).

How Is Notice Provided To Individuals?

Timing: As soon as possible. N.H. Rev. Stat. Ann. § 359-C:20(I)(a).

Delivery: Notification may be made by:

  1. Written notice. 
  2. Electronic notice, if the agency’s or business’s primary means of communication with affected individuals is by electronic means.
  3. Telephonic notice, provided that a log of each such notification is kept by the person or business who notifies affected persons. 
  4. Substitute notice, if the person demonstrates that the cost of providing notice would exceed $5,000, that the affected class of subject individuals to be notified exceeds 1,000, or the person does not have sufficient contact information or consent to provide notice pursuant to subparagraphs 1-3 above. N.H. Rev. Stat. Ann. § 359-C:20(III).

Content: The notice must include:

  1. A description of the incident in general terms.
  2. The approximate date of breach.
  3. The type of personal information obtained as a result of the security breach.
  4. The telephonic contact information of the person subject to this section. N.H. Rev. Stat. Ann. § 359-C:20(IV).

Is Notice To The Government Required?

Yes. Those subject to the jurisdiction of the bank commissioner, the director of securities regulation, the insurance commissioner, the public utilities commission, the financial institutions and insurance regulators of other states, or federal banking or securities regulators must notify the regulator who possesses primary regulatory authority.

Otherwise the Attorney General must be notified. The notice must include the anticipated date of the notice to the individuals and the approximate number of individuals in this state who will be notified. N.H. Rev. Stat. Ann. § 359-C:20(I)(b).

Is Notice To Credit Reporting Agencies Required?

No.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

Any person injured by any violation under this subdivision may bring an action for damages and for such equitable relief, including an injunction, as the court deems necessary and proper. If the court finds for the plaintiff, recovery shall be in the amount of actual damages. If the court finds that the act or practice was a willful or knowing violation of this chapter, it shall award as much as three times, but not less than two times, such amount. In addition, a prevailing plaintiff shall be awarded the costs of the suit and reasonable attorney’s fees, as determined by the court. Any attempted waiver of the right to the damages set forth in this paragraph shall be void and unenforceable. Injunctive relief shall be available to private individuals under this chapter without bond, subject to the discretion of the court. N.H. Rev. Stat. Ann. § 359-C:21(I).

The New Hampshire attorney general’s office shall enforce the provisions of this subdivision pursuant to N.H. Rev. Stat. Ann. § 358-A:4 which allows for injunctive relief and civil penalties up to $10,000 per violation. N.H. Rev. Stat. Ann. § 359-C:21(II).

Are There Any Exemptions/Exceptions?

Any person engaged in trade or commerce that is subject to RSA 358-A:3, I which maintains procedures for security breach notification pursuant to the laws, rules, regulations, guidances, or guidelines issued by a state or federal regulator shall be deemed to be in compliance with this subdivision if it acts in accordance with such laws, rules, regulations, guidances, or guidelines. N.H. Rev. Stat. Ann. § 359-C:20(V).

Maryland

Who Is Covered?

A business that owns, licenses, or maintains computerized data that includes personal information of an individual residing in Maryland. Md. Code Ann., Com. Law § 14-3504(b).

 

What Information Is Protected?

“Personal information” means:

A. An individual’s first name or first initial and last name in combination with any one or more of the following data elements, when the data elements are not encrypted, redacted, or otherwise protected by another method that renders the information unreadable or unusable:

  1. A social security number, an individual taxpayer identification number, a passport number, or other identification number issued by the federal government;
  2. A driver’s license number or state identification card number;
  3. An account number, a credit card number, or a debit card number, in combination with any required security code, access code, or password, that permits access to an individual’s financial account;
  4. Health information, including information about an individual’s mental health;
  5. A health insurance policy or certificate number or health insurance subscriber identification number, in combination with a unique identifier used by an insurer or an employer that is self-insured, that permits access to an individual’s health information; 
  6. Biometric data of an individual generated by automatic measurements of an individual’s biological characteristics such as a fingerprint, voice print, genetic print, retina or iris image, or other unique biological characteristic, that can be used to uniquely authenticate the individual’s identity when the individual accesses a system or account; or
  7. For purposes of the notifications required under § 14-3504(b)(2), (c), (d), (e), (f), and (g) of this subtitle, genetic information with respect to an individual;Md. Code Ann., Com. Law § 14-3501(e).

B. A user name or e-mail address in combination with a password or security question and answer that permits access to an individual’s e-mail account; or

C. For the purposes of the requirements of this title other than the notifications required under § 14-3504(b)(2), (c), (d), (e), (f), and (g) of this subtitle, genetic information with respect to an individual when the genetic information is not encrypted, redacted, or otherwise protected by another method that renders the information unreadable or unusable, including:

  1. Data, regardless of its format, that results from the analysis of a biological sample of the individual or from another source that enables equivalent information to be obtained and that concerns genetic material;
  2. Deoxyribonucleic acids;
  3. Ribonucleic acids;
  4. Genes;
  5. Chromosomes;
  6. Alleles;
  7. Genomes;
  8. Alterations or modifications to deoxyribonucleic acids or ribonucleic acids;
  9. Single nucleotide polymorphisms;
  10. Uninterrupted data that results from the analysis of a biological sample from the individual or other sources; and
  11. Information extrapolated, derived, or inferred from item 1, 2, 3, 4, 5, 6, 7, 8, 9, or 10 of this item. Md. Code Ann., Com. Law § 14-3501

 

What Is A “Breach”?

“Breach of the security of a system” means the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of the personal information maintained by a business. Md. Code Ann., Com. Law § 14-3504(a).

 

What Triggers Notification?

A determination following an investigation that the breach of the security of the system creates a likelihood that personal information has been or will be misused. Md. Code Ann., Com. Law § 14-3504(b).

 

Likelihood of Harm Analysis

Notification to the individual in not necessary if the business reasonably determines that the breach of the security of the system does not create a likelihood that personal information has been or will be misused. Md. Code Ann., Com. Law § 14-3504(c)(2).

 

How Is Notice Provided To Individuals?

Timing: Notice must be given as soon as reasonably practicable, but not later than 45 days after the business discovers or is notified of the breach of the security system. Md. Code Ann., Com. Law § 14-3504(b)(3).

 

Delivery: Notice may be made by:

  1. Written notice sent to the most recent address of the individual in the records of the business;
  2. Electronic mail to the most recent electronic mail address of the individual in the records of the business, if: (i)  The individual has expressly consented to receive electronic notice; or (ii)  The business conducts its business primarily through Internet account transactions or the Internet;
  3. Telephonic notice, to the most recent telephone number of the individual in the records of the business; or
  4. Substitute notice if the business does not have sufficient contact information to give notice in accordance with item (1), (2), or (3) of this subsection. Substitute notice shall consist of: shall consist of: (a) Electronically mailing the notice to an individual entitled to notification under subsection (b) of this section, if the business has an electronic mail address for the individual to be notified; (b) Conspicuous posting of the notice on the website of the business, if the business maintains a website; and (c) Notification to major print or broadcast media in geographic areas where the individuals affected by the breach likely reside.

 

Content: Except for a breach involving only an email account, notification must include:

  1. To the extent possible, a description of the categories of information that were, or are reasonably believed to have been, acquired by an unauthorized person, including which of the elements of personal information were, or are reasonably believed to have been, acquired;
  2. Contact information for the business making the notification, including the business’s address, telephone number, and toll-free telephone number if one is maintained;
  3. The toll-free telephone numbers and addresses for the major consumer reporting agencies; and
  4. The toll-free telephone numbers, addresses, and website addresses for the Federal Trade Commission and the Office of the Attorney General, and a statement that an individual can obtain information from these sources about steps the individual can take to avoid identity theft. Md. Code Ann., Com. Law § 14-3504(g).

If the breach involves only an email account, notification may be made in electronic or other form, subject to several restrictions, that directs the individual whose personal information has been breached promptly to:

  1. Change the individual’s password and security question or answer, as applicable; or
  2. Take other steps appropriate to protect the email account with the business and all other online accounts for which the individual uses the same user name or email and password or security question or answer. Md. Code Ann., Com. Law § 14-3504(i).

 

Is Notice To The Government Required?

Yes, notice must be provided to the Attorney General prior to providing notice to affected residents. The notice shall include, at a minimum: (i) The number of affected individuals residing in the State; (ii) A description of the breach of the security of a system, including when and how it occurred; (iii) Any steps the business has taken or plans to take relating to the breach of the security of a system; and (iv) The form of notice that will be sent to affected individuals and a sample notice. Md. Code Ann., Com. Law § 14-3504(h).

 

Is Notice To Credit Reporting Agencies Required?

Yes. If a business is required under § 14-3504 of this subtitle to give notice of a breach of the security of a system to 1,000 or more individuals, the business also shall notify, without unreasonable delay, each consumer reporting agency that compiles and maintains files on consumers on a nationwide basis of the timing, distribution, and content of the notices. Md. Code Ann., Com. Law § 14-3506(a).

 

Are There Security Measure Standards?

Yes. To protect personal information from unauthorized access, use, modification, or disclosure, a business that owns or licenses personal information of an individual residing in the state shall implement and maintain reasonable security procedures and practices that are appropriate to the nature of the personal information owned or licensed and the nature and size of the business and its operations. Md. Code Ann., Com. Law § 14-3503(a).

Additionally, a business that uses a nonaffiliated third party as a service provider to perform services for the business and discloses personal information about an individual residing in the state under a written contract with the third party shall require by contract that the third party implement and maintain reasonable security procedures and practices that are:

 

  1. Appropriate to the nature of the personal information disclosed to the nonaffiliated third party; and
  2. Reasonably designed to help protect the personal information from unauthorized access, use, modification, disclosure, or destruction.

Data Destruction Standards: When a business is destroying a customer’s, an employee’s, or a former employee’s records that contain personal information of the customer, employee, or former employee, the business shall take reasonable steps to protect against unauthorized access to or use of the personal information, taking into account:

 

  1. The sensitivity of the records;
  2. The nature and size of the business and its operations;
  3. The costs and benefits of different destruction methods; and
  4. Available technology.

 

What Are The Possible Consequences Of A Violation?

A violation is an unfair or deceptive trade practice which allows for enforcement action by the Attorney General and a private right of action for any injury or loss sustained. Md. Code Ann., Com. Law §§ 14-3508; 13-401.

 

Are There Any Exemptions/Exceptions?

A business that complies with the requirements for notification procedures, the protection or security of personal information, or the destruction of personal information under the rules, regulations, procedures, or guidelines established by the primary or functional federal or state regulator of the business shall be deemed to be in compliance with this subtitle. Md. Code Ann., Com. Law § 14-3507(b).

Additionally, businesses that are subject to and in compliance with GLBA, FACTA or HIPAA, among other acts, are deemed to be in compliance. Md. Code Ann., Com. Law § 14-3507(c), (d).

Louisiana

Who Is Covered?

Any person that owns or licenses computerized data that includes personal information, or any agency that owns or licenses computerized data that includes personal information. La. Rev. Stat. Ann. § 51:3074

What Information Is Protected?

“Personal information” means the first name or first initial and last name of an individual resident of this state in combination with any one or more of the following data elements, when the name or the data element is not encrypted or redacted:

  1. Social security number.
  2. Driver’s license number or state identification card number.
  3. Account number, credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account.
  4. Passport number.
  5. Biometric data, meaning data generated by automatic measurements of an individual’s biological characteristics, such as fingerprints, voice print, eye retina or iris, or other unique biological characteristic that is used by the owner or licensee to uniquely authenticate an individual’s identity when the individual accesses a system or account. La. Rev. Stat. Ann. § 51:3073(4).

What Is A “Breach”?

“Breach of the security of the system” means the compromise of the security, confidentiality, or integrity of computerized data that results in, or there is a reasonable likelihood to result in, the unauthorized acquisition of and access to personal information maintained by an agency or person. Good faith acquisition of personal information by an employee or agent of an agency or person for the purposes of the agency or person is not a breach of the security of the system, provided that the personal information is not used for, or is subject to, unauthorized disclosure. La. Rev. Stat. Ann. § 51:3073(2).

What Triggers Notification?

Discovery of a breach in the security of the system involving a resident’s personal information that was, or is reasonably believed to have been, acquired by an unauthorized person. La. Rev. Stat. Ann. § 51:3074(C).

Likelihood of Harm Analysis: Notification as provided in this Section shall not be required if after a reasonable investigation, the person or business determines that there is no reasonable likelihood of harm to the residents of this state. The person or business shall retain a copy of the written determination and supporting documentation for five years from the date of discovery of the breach of the security system. If requested in writing, the person or business shall send a copy of the written determination and supporting documentation to the attorney general no later than thirty days from the date of receipt of the request. La. Rev. Stat. Ann. § 51:3074(I).

How Is Notice Provided To Individuals?

Timing: Notification must be made in the most expedient time possible and without unreasonable delay but not later than sixty days from the discovery of the breach, consistent with the legitimate needs of law enforcement or any measures necessary to determine the scope of the breach, prevent further disclosures, and restore the reasonable integrity of the data system. La. Rev. Stat. Ann. § 51:3074(E).

Delivery: Notification may be made by:

  1. Written notification.
  2. Electronic notification, if the notification provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. 7001.
  3. Substitute notification, if an agency or person demonstrates that the cost of providing notification would exceed one hundred thousand dollars, or that the affected class of persons to be notified exceeds one hundred thousand, or the agency or person does not have sufficient contact information. La. Rev. Stat. Ann. § 51:3074(G).

Content: None specified.

Is Notice To The Government Required?

Yes. When notice to Louisiana citizens is required, the person or agency shall provide written notice detailing the breach of the security of the system to the Consumer Protection Section of the Attorney General’s Office. Notice shall include the names of all Louisiana citizens affected by the breach. La. Admin. Code tit.16 § III.701(A).

Is Notice To Credit Reporting Agencies Required?

No.

Are There Security Measure Standards?

Yes. Any person that conducts business in the state or that owns or licenses computerized data that includes personal information, or any agency that owns or licenses computerized data that includes personal information, shall implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. La. Rev. Stat. Ann. § 51:3074(A).

Also, any person that conducts business in the state or that owns or licenses computerized data that includes personal information, or any agency that owns or licenses computerized data that includes personal information shall take all reasonable steps to destroy or arrange for the destruction of the records within its custody or control containing personal information that is no longer to be retained by the person or business by shredding, erasing, or otherwise modifying the personal information in the records to make it unreadable or undecipherable through any means. La. Rev. Stat. Ann. § 51:3074(B).

What Are The Possible Consequences Of A Violation?

A civil action may be instituted to recover actual damages resulting from the failure to disclose in a timely manner to a person that there has been a breach of the security system resulting in the disclosure of a person’s personal information. La. Rev. Stat. Ann. § 51:3075.

Additionally, failure to provide timely notice may be punishable by a fine not to exceed $5,000 per violation. Notice to the attorney general shall be timely if received within 10 days of distribution of notice to Louisiana citizens. Each day notice is not received by the attorney general shall be deemed a separate violation. La. Admin. Code tit.16 § III.701(B).

Are There Any Exemptions/Exceptions?

An agency or person that maintains a notification procedure as part of its information security policy for the treatment of personal information which is otherwise consistent with the timing requirements of this Section shall be considered to be in compliance with the notification requirements of this Section if the agency or person notifies subject persons in accordance with the policy and procedure in the event of a breach of security of the system. La. Rev. Stat. Ann. § 51:3074(H).

Also, a financial institution that is subject to and in compliance with the Federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice, issued on March 7, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency and the Office of Thrift Supervision, and any revisions, additions, or substitutions relating to said interagency guidance, shall be deemed to be in compliance with this Chapter. La. Rev. Stat. Ann. § 51:3076.

Illinois

Who Is Covered?

“Data Collector” may include, but is not limited to, government agencies, public and private universities, privately and publicly held corporations, financial institutions, retail operators, and any other entity that, for any purpose, handles, collects, disseminates, or otherwise deals with nonpublic personal information. 815 Ill. Comp. Stat. Ann. 530/5.

What Information Is Protected?

“Personal information” means either of the following:

A. User name or email address, in combination with a password or security question and answer that would permit access to an online account, when either the user name or email address or password or security question and answer are not encrypted or redacted or are encrypted or redacted but the keys to unencrypt or unredact or otherwise read the data elements have been obtained through the breach of security.

B. An individual’s first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted or redacted or are encrypted or redacted but the keys to unencrypt or unredact or otherwise read the name or data elements have been acquired without authorization through the breach of security:

  1. Social security number.
  2. Driver’s license number or state identification card number.
  3. Account number or credit or debit card number, or an account number or credit card number in combination with any required security code, access code, or password that would permit access to an individual’s financial account.
  4. Medical information.*
  5. Health insurance information.**
  6. Unique biometric data generated from measurements or technical analysis of human body characteristics used by the owner or licensee to authenticate an individual, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data. 815 Ill. Comp. Stat. Ann. 530/5.

*“Medical information” means any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a healthcare professional, including such information provided to a website or mobile application. 815 Ill. Comp. Stat. Ann. 530/5.

**“Health insurance information” means an individual’s health insurance policy number or subscriber identification number, any unique identifier used by a health insurer to identify the individual, or any medical information in an individual’s health insurance application and claims history, including any appeals records. 815 Ill. Comp. Stat. Ann. 530/5.

What Is A “Breach”?

“Breach of the security of the system data” or “breach” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the data collector. “Breach of the security of the system data” does not include good faith acquisition of personal information by an employee or agent of the data collector for a legitimate purpose of the data collector, provided that the personal information is not used for a purpose unrelated to the data collector’s business or subject to further unauthorized disclosure. 815 Ill. Comp. Stat. Ann. 530/5.

What Triggers Notification?

Discovery or notification of a breach. 815 Ill. Comp. Stat. Ann. 530/10(a).

How Is Notice Provided To Individuals?

Timing: The disclosure notification shall be made in the most expedient time possible and without unreasonable delay, consistent with any measures necessary to determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system. 815 Ill. Comp. Stat. Ann. 530/10(a).

Delivery: Notification may be made by:

  1. Written notice;
  2. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures for notices legally required to be in writing as set forth in Section 7001 of Title 15 of the United States Code; or
  3. Substitute notice, in certain circumstances. 815 Ill. Comp. Stat. Ann. 530/10(c).

Content: The notice must include:

  1. The toll-free numbers and addresses for consumer reporting agencies;
  2. The toll-free number, address, and website address for the Federal Trade Commission; and
  3. A statement that the individual can obtain information from these sources about fraud alerts and security freezes. 815 Ill. Comp. Stat. Ann. 530/10(a)(1).

If the breach involves a user name or email address, in combination with a password or security question and answer that would permit access to an online account, when either the user name or email address or password or security question and answer are not encrypted or redacted or are encrypted or redacted but the keys to unencrypt or unredact or otherwise read the data elements have been obtained through the breach of security, notice may be provided in electronic or other form directing the Illinois resident whose personal information has been breached to promptly change his or her user name or password and security question or answer, as applicable, or to take other steps appropriate to protect all online accounts for which the resident uses the same user name or email address and password or security question and answer. 815 Ill. Comp. Stat. Ann. 530/10(a)(2).

Is Notice To The Government Required?

Yes. If notice must be sent to more than 500 Illinois residents as a result of a single breach, notification must also be sent to the Attorney General in the most expedient time possible and without unreasonable delay but in no event later than when the data collector provides notice to consumers. The notice must include:

  1. A description of the nature of the breach of security or unauthorized acquisition or use.
  2. The number of Illinois residents affected by such incident at the time of notification.
  3. Any steps the data collector has taken or plans to take relating to the incident. 815 Ill. Comp. Stat. Ann. 530/10(e).

Is Notice To Credit Reporting Agencies Required?

No.

Are There Security Measure Standards?

Yes. A data collector that owns or licenses, or maintains or stores but does not own or license, records that contain personal information concerning an Illinois resident shall implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification, or disclosure. 815 Ill. Comp. Stat. Ann. 530/45(a).

Contract Requirements: Additionally, a contract for the disclosure of personal information concerning an Illinois resident that is maintained by a data collector must include a provision requiring the person to whom the information is disclosed to implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification, or disclosure. 815 Ill. Comp. Stat. Ann. 530/45(b).

Data Disposal Requirements: A person must dispose of the materials containing personal information in a manner that renders the personal information unreadable, unusable, and undecipherable. Proper disposal methods include, but are not limited to, the following:

  1. Paper documents containing personal information may be either redacted, burned, pulverized, or shredded so that personal information cannot practicably be read or reconstructed.
  2. Electronic media and other non-paper media containing personal information may be destroyed or erased so that personal information cannot practicably be read or reconstructed. 815 Ill. Comp. Stat. Ann. 530/40(b).

What Are The Possible Consequences Of A Violation?

A violation of the breach notification laws constitutes an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act, 815 Ill. Comp. Stat. Ann. 505/1, et seq., which allows for the imposition of civil penalties by the Attorney General and a private right of action for individuals that have suffered actual damages. 815 Ill. Comp. Stat. Ann. 530/20.

Failure to properly dispose of records containing personal information may result in a civil penalty of not more than $100 for each individual with respect to whom personal information is disposed of in violation of the law. A civil penalty may not, however, exceed $50,000 for each instance of improper disposal of materials containing personal information. The Attorney General may impose a civil penalty after notice to the person accused of violating this Section and an opportunity for that person to be heard in the matter. The Attorney General may file a civil action in the circuit court to recover any penalty imposed under this Section. 815 Ill. Comp. Stat. Ann. 530/40(d).

Are There Any Exemptions/Exceptions?

Any covered entity or business associate that is subject to and in compliance with the privacy and security standards for the protection of electronic health information established pursuant to the federal Health Insurance Portability and Accountability Act of 1996 and the Health Information Technology for Economic and Clinical Health Act shall be deemed to be in compliance with the provisions of this Act, provided that any covered entity or business associate required to provide notification of a breach to the Secretary of Health and Human Services pursuant to the Health Information Technology for Economic and Clinical Health Act also provides such notification to the Attorney General within five business days of notifying the Secretary. 815 Ill. Comp. Stat. Ann. 530/50.

Hawaii

Who Is Covered?

Any business that owns or licenses personal information of residents of Hawaii, any business that conducts business in Hawaii that owns or licenses personal information in any form (whether computerized, paper, or otherwise), or any government agency that collects personal information for specific government purposes. Haw. Rev. Stat. Ann. § 487N-2(a).

What Information Is Protected?

“Personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted:

  1. Social security number;
  2. Driver’s license number or Hawaii identification card number; or
  3. Account number, credit or debit card number, access code, or password that would permit access to an individual’s financial account. Haw. Rev. Stat. Ann. § 487N-1.

What Is A “Breach”?

“Security breach” means an incident of unauthorized access to and acquisition of unencrypted or unredacted records or data containing personal information where illegal use of the personal information has occurred, or is reasonably likely to occur and that creates a risk of harm to a person. Any incident of unauthorized access to and acquisition of encrypted records or data containing personal information along with the confidential process or key constitutes a security breach. Good faith acquisition of personal information by an employee or agent of the business for a legitimate purpose is not a security breach; provided that the personal information is not used for a purpose other than a lawful purpose of the business and is not subject to further unauthorized disclosure. Haw. Rev. Stat. Ann. § 487N-1.

“Records” means any material on which written, drawn, spoken, visual, or electromagnetic information is recorded or preserved, regardless of physical form or characteristics. Haw. Rev. Stat. Ann. § 487N-1.

What Triggers Notification?

Discovery or notification of a breach. Haw. Rev. Stat. Ann. § 487N-2(a).

How Is Notice Provided To Individuals?

Timing: The disclosure notification shall be made without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine sufficient contact information, determine the scope of the breach, and restore the reasonable integrity, security, and confidentiality of the data system. Haw. Rev. Stat. Ann. § 487N-2(a).

Delivery: Notice may be made by:

  1. Written notice to the last available address the business or government agency has on record;
  2. Electronic mail notice, for those persons for whom a business or government agency has a valid electronic mail address and who have agreed to receive communications electronically if the notice provided is consistent with the provisions regarding electronic records and signatures for notices legally required to be in writing set forth in 15 U.S.C. section 7001;
  3. Telephonic notice, provided that contact is made directly with the affected persons; and
  4. Substitute notice in certain circumstances. Haw. Rev. Stat. Ann. § 487N-2(e).

Content: The notice must be clear and conspicuous and include a description of:

  1. The incident in general terms;
  2. The type of personal information that was subject to the unauthorized access and acquisition;
  3. The general acts of the business or government agency to protect the personal information from further unauthorized access;
  4. A telephone number that the person may call for further information and assistance, if one exists; and
  5. Advice that directs the person to remain vigilant by reviewing account statements and monitoring free credit reports. Haw. Rev. Stat. Ann. § 487N-2(d).

Is Notice To The Government Required?

Yes. In the event a business provides notice to more than one thousand persons at one time pursuant to this section, the business shall notify in writing, without unreasonable delay, the State of Hawaii’s office of consumer protection and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, of the timing, distribution, and content of the notice. Haw. Rev. Stat. Ann. § 487N-2(f).

Is Notice To Credit Reporting Agencies Required?

Yes. In the event a business provides notice to more than one thousand persons at one time pursuant to this section, the business shall notify in writing, without unreasonable delay, the State of Hawaii’s office of consumer protection and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, of the timing, distribution, and content of the notice. Haw. Rev. Stat. Ann. § 487N-2(f).

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

Any business that violates any provision of this chapter shall be subject to penalties of not more than $2,500 for each violation. The attorney general or the executive director of the office of consumer protection may bring an action pursuant to this section. No such action may be brought against a government agency. Haw. Rev. Stat. Ann. § 487N-3(a).

Additionally, any business that violates any provision of this chapter shall be liable to the injured party in an amount equal to the sum of any actual damages sustained by the injured party as a result of the violation. The court in any action brought under this section may award reasonable attorneys’ fees to the prevailing party. No such action may be brought against a government agency. Haw. Rev. Stat. Ann. § 487N-3(b).

Are There Any Exemptions/Exceptions?

Yes. The following are considered to be in compliance:

  1. A financial institution that is subject to the federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice published in the Federal Register on March 29, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision, or subject to 12 C.F.R. Part 748, and any revisions, additions, or substitutions relating to the interagency guidance; and
  2. Any health plan or healthcare provider that is subject to and in compliance with the standards for privacy or individually identifiable health information and the security standards for the protection of electronic health information of the Health Insurance Portability and Accountability Act of 1996. Haw. Rev. Stat. Ann. § 487N-3(g).

District of Columbia

Who Is Covered?

Any person or entity who conducts business in the District of Columbia, and who, in the course of such business, owns or licenses computerized or other electronic data that includes personal information. D.C. Code § 28-3852(a).

What Information Is Protected?

“Personal information” means:

A. An individual’s first name, first initial and last name, or any other personal identifier, which, in combination with any of the following data elements, can be used to identify a person or the person’s information:

  1. Social security number, individual taxpayer identification number, passport number, driver’s license number, District of Columbia identification card number, military identification number, or other unique identification number issued on a government document commonly used to verify the identity of a specific individual;
  2. Account number, credit card number or debit card number, or any other number or code or combination of numbers or codes, such as an identification number, security code, access code, or password, that allows access to or use of an individual’s financial or credit account;
  3. Medical information;
  4. Genetic information and deoxyribonucleic acid profile;
  5. Health insurance information, including a policy number, subscriber information number, or any unique identifier used by a health insurer to identify the person that permits access to an individual’s health and billing information;
  6. Biometric data of an individual generated by automatic measurements of an individual’s biological characteristics, such as a fingerprint, voice print, genetic print, retina or iris image, or other unique biological characteristic, that is used to uniquely authenticate the individual’s identity when the individual accesses a system or account; or
  7. Any combination of data elements included in paragraphs 1 through 6 above that would enable a person to commit identity theft without reference to a person’s first name or first initial and last name or other independent personal identifier.

B. A user name or e-mail address in combination with a password, security question and answer, or other means of authentication, or any combination of data elements included in paragraphs 1 through 6 above that permits access to an individual’s e-mail account. D.C. Code § 28-3851(3).

What Is A “Breach”?

“Breach of the security of the system” means unauthorized acquisition of computerized or other electronic data or any equipment or device storing such data that compromises the security, confidentiality, or integrity of personal information maintained by the person or entity who conducts business in the District of Columbia. D.C. Code § 28-3851(1)(A).

Likelihood of Harm Exception: A “breach of the security of the system” does not include the acquisition of personal information of an individual that the person or entity reasonably determines, after a reasonable investigation and consultation with the Office of the Attorney General for the District of Columbia and federal law enforcement agencies, will likely not result in harm to the individual. D.C. Code § 28-3851(1)(B)(3).

What Triggers Notification?

Discovery of a breach of the security of the system. D.C. Code § 28-3852(a).

How Is Notice Provided To Individuals?

Timing: Notification must be made promptly and in the most expedient time possible and without unreasonable delay, subject to certain exceptions. D.C. Code § 28-3852(a).

Delivery: Notice may be made by:

  1. Written notice;
  2. Electronic notice if consistent with the requirements of the E-Sign Act;
  3. Substitute notice in certain circumstances. D.C. Code § 28-3851(2).

Content: The notification must include:

  1. To the extent possible, a description of the categories of information that were, or are reasonably believed to have been, acquired by an unauthorized person, including the elements of personal information that were, or are reasonably believed to have been, acquired;
  2. Contact information for the person or entity making the notification, including the business address, telephone number, and toll-free telephone number if one is maintained;
  3. The toll-free telephone numbers and addresses for the major consumer reporting agencies, including a statement notifying the resident of the right to obtain a security freeze free of charge pursuant to 15 U.S.C. § 1681c-1 and information regarding how a resident may request a security freeze; and
  4. The toll-free telephone numbers, addresses, and website addresses for the following entities, including a statement that an individual can obtain information from these sources about steps to take to avoid identity theft: (a) The Federal Trade Commission; and (b) The Office of the Attorney General for the District of Columbia. D.C. Code § 28-3852(a-1).

Additionally, the notification must offer to each District resident whose social security number or tax identification number was released identity theft protection services at no cost to such District resident for a period of not less than 18 months. The person or entity that experienced the breach of the security of its system shall provide all information necessary for District residents to enroll in the services required under this section. D.C. Code § 28-3852b.

Is Notice To The Government Required?

Yes. If the breach involves more than 50 residents, notice must be promptly given to the Attorney General including the following information:

  1. The name and contact information of the person or entity reporting the breach;
  2. The name and contact information of the person or entity that experienced the breach
  3. The nature of the breach of the security of the system, including the name of the person or entity that experienced the breach;
  4. The types of personal information compromised by the breach;
  5. The number of District residents affected by the breach;
  6. The cause of the breach, including the relationship between the person or entity that experienced the breach and the person responsible for the breach, if known;
  7. The remedial action taken by the person or entity to include steps taken to assist District residents affected by the breach;
  8. The date and time frame of the breach, if known;
  9. The address and location of corporate headquarters, if outside of the District;
  10. Any knowledge of foreign country involvement; and
  11. A sample of the notice to be provided to District residents. D.C. Code § 28-3852(b-1).

Is Notice To Credit Reporting Agencies Required?

Yes. If more than 1,000 notices must be sent, notice must also be provided to all national consumer reporting agencies without unreasonable delay. D.C. Code § 28-3852(c).

Are There Security Measure Standards?

Yes. A covered person or entity must implement and maintain reasonable security safeguards, including procedures and practices that are appropriate to the nature of the personal information and the nature and size of the entity or operation. D.C. Code § 28-3852a(a).

Additionally, when a person or entity is destroying records, including computerized or electronic records and devices containing computerized or electronic records, that contain personal information of a consumer, employee, or former employee of the person or entity, the person or entity shall take reasonable steps to protect against unauthorized access to or use of the personal information, taking into account: 1) The sensitivity of the records; 2) The nature and size of the business and its operations; 3) The costs and benefits of different destruction and sanitation methods; and 4) Available technology. D.C. Code § 28-3852a(c).

What Are The Possible Consequences Of A Violation?

A violation is an unfair or deceptive trade practice under D.C. Code § 28-3904(kk), which allows the attorney general to seek injunctive relief and civil penalties up to $5,000 per violation and up to $10,000 for each subsequent violation pursuant to D.C. Code § 28-3909. Consumers may bring a private cause of action pursuant to D.C. Code § 28-3905(k)(1)(A). D.C. Code § 28-3853.

Are There Exemptions/Exceptions?

A person or entity that maintains procedures for a breach notification system under the GLBA or the breach notification rules established pursuant to HIPAA, or HITECH, and provides notice in accordance with such Acts, and any rules, regulations, guidance and guidelines thereto, to each affected resident in the event of a breach, shall be deemed to be in compliance with this section with respect to the notification of residents whose personal information is included in the breach. The person or entity shall, in all cases, provide written notice of the breach of the security of the system to the Office of the Attorney General. D.C. Code § 28-3852(g).