Category Archives: Security Measure Standards

Colorado

Who Is Covered?

A covered entity that maintains, owns, or licenses computerized data that includes personal information about a resident of Colorado. Colo. Rev. Stat. § 6-1-716(2).

“Covered entity” means a person that maintains, owns, or licenses personal information in the course of the person’s business, vocation, or occupation. “Covered entity” does not include a person acting as a third-party service provider. Colo. Rev. Stat. § 6-1-716(1)(b).

What Information Is Protected?

“Personal information” means:

A. A Colorado resident’s first name or first initial and last name in combination with any one or more of the following data elements that relate to the resident, when the data elements are not encrypted, redacted, or secured by any other method rendering the name or the element unreadable or unusable:

  1. Social security number;
  2. Student, military, or passport identification number;
  3. Driver’s license number or identification card number;
  4. Medical information;
  5. Health insurance identification number; or
  6. Biometric data;

B. A Colorado resident’s username or e-mail address, in combination with a password or security questions and answers, that would permit access to an online account; or

C. A Colorado resident’s account number or credit or debit card number in combination with any required security code, access code, or password that would permit access to that account. Colo. Rev. Stat. § 6-1-716(1)(g).

What Is A “Breach”?

“Security breach” means the unauthorized acquisition of unencrypted computerized data that compromises the security, confidentiality, or integrity of personal information maintained by a covered entity. Good faith acquisition of personal information by an employee or agent of a covered entity for the covered entity’s business purposes is not a security breach if the personal information is not used for a purpose unrelated to the lawful operation of the business or is not subject to further unauthorized disclosure. Colo. Rev. Stat. § 6-1-716(1)(h).

What Triggers Notification?

A determination, following investigation, that there is a likelihood that personal information has been or will be misused. 

Likelihood of Harm Analysis: Notification is not required if the investigation determines that the misuse of information about a Colorado resident has not occurred and is not reasonably likely to occur. Colo. Rev. Stat. § 6-1-716(2)(a).

How Is Notice Provided To Individuals?

Timing: Notice must be made in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system. Colo. Rev. Stat. § 6-1-716(2).

Delivery: Notice may be by:

  1. Written notice to the postal address listed in the records of the covered entity;
  2. Telephonic notice;
  3. Electronic notice, if a primary means of communication by the covered entity with a Colorado resident is by electronic means or the notice provided is consistent with the provisions regarding electronic records and signatures set forth in the federal “Electronic Signatures in Global and National Commerce Act”, 15 U.S.C. sec. 7001 et seq.; or
  4. Substitute notice, if the covered entity required to provide notice demonstrates that the cost of providing notice will exceed $250,000, the affected class of persons to be notified exceeds 250,000 Colorado residents, or the covered entity does not have sufficient contact information to provide notice. Substitute notice consists of all of the following: a) E-mail notice if the covered entity has e-mail addresses for the members of the affected class of Colorado residents; b) Conspicuous posting of the notice on the website page of the covered entity if the covered entity maintains one; and c) Notification to major statewide media. Colo. Rev. Stat. § 6-1-716(1)(f).

Content: In the case of a breach of personal information, notice must include the following information:

  1. The date, estimated date, or estimated date range of the security breach;
  2. A description of the personal information that was acquired or reasonably believed to have been acquired as part of the security breach;
  3. Information that the resident can use to contact the covered entity to inquire about the security breach;
  4. The toll-free numbers, addresses, and websites for consumer reporting agencies;
  5. The toll-free number, address, and website for the Federal Trade Commission; and
  6. A statement that the resident can obtain information from the Federal Trade Commission and the credit reporting agencies about fraud alerts and security freezes. Colo. Rev. Stat. § 6-1-716(2)(a.2).

Is Notice To The Government Required?

Yes. A covered entity that must notify Colorado residents of a data breach must provide notice of any security breach to the Colorado attorney general in the most expedient time possible and without unreasonable delay, but not later than 30 days after the date of determination that a security breach occurred, if the security breach is reasonably believed to have affected 500 Colorado residents or more, unless the investigation determines that the misuse of information about a Colorado resident has not occurred and is not likely to occur. Colo. Rev. Stat. § 6-1-716(2)(f).

Is Notice To Credit Reporting Agencies Required?

Yes. If a covered entity is required to notify more than 1,000 Colorado residents of a security breach pursuant to this section, the covered entity shall also notify, in the most expedient time possible and without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the anticipated date of the notification to the residents and the approximate number of residents who are to be notified. Colo. Rev. Stat. § 6-1-716(2)(d).

Are There Security Measure Standards?

Yes. To protect personal identifying information from unauthorized access, use, modification, disclosure, or destruction, a covered entity that maintains, owns, or licenses personal identifying information of an individual residing in the state shall implement and maintain reasonable security procedures and practices that are appropriate to the nature of the personal identifying information and the nature and size of the business and its operations. Colo. Rev. Stat. § 6-1-713.5(1).

Additionally, unless a covered entity agrees to provide its own security protection for the information it discloses to a third-party service provider, the covered entity shall require that the third-party service provider implement and maintain reasonable security procedures and practices that are:

  1. Appropriate to the nature of the personal identifying information disclosed to the third-party service provider; and
  2. Reasonably designed to help protect the personal identifying information from unauthorized access, use, modification, disclosure, or destruction. Colo. Rev. Stat. § 6-1-713.5(2)

What Are The Possible Consequences Of A Violation?

The attorney general may bring an action in law or equity to address violations of this section, § 6-1-713 [protection of personal identifying information] or § 6-1-715 [confidentiality of social security numbers] and for other relief that may be appropriate to ensure compliance with this section or to recover direct economic damages resulting from a violation, or both. Colo. Rev. Stat. § 6-1-716(4).

Are There Any Exemptions/Exceptions?

Not per se, but a covered entity that maintains its own notification procedures as part of an information security policy for the treatment of personal information and whose procedures are otherwise consistent with the timing requirements of this section is in compliance with the notice requirements of this section if the covered entity notifies affected Colorado residents in accordance with its policies in the event of a security breach; except that notice to the attorney general is still required. Colo. Rev. Stat. § 6-1-716(3)(a).

Additionally, a covered entity that is regulated by state or federal law and that maintains procedures for a security breach pursuant to the laws, rules, regulations, guidances, or guidelines established by its state or federal regulator is in compliance with this section; except that notice to the attorney general is still required. Colo. Rev. Stat. § 6-1-716(3)(b).

Confidentiality Of Social Security Numbers

Note: Additional restrictions apply to the use of social security numbers. See Colo. Rev. Stat. § 6-1-715.

Vermont

Who Is Covered?

“Data collector” means a person who, for any purpose, whether by automated collection or otherwise, handles, collects, disseminates, or otherwise deals with personally identifiable information, and includes the state, state agencies, political subdivisions of the state, public and private universities, privately and publicly held corporations, limited liability companies, financial institutions, and retail operators. Vt. Stat. Ann. tit. 9, § 2430(6).

What Information Is Protected?

“Personally identifiable information” means a consumer’s first name or first initial and last name in combination with one or more of the following digital data elements, when the data elements are not encrypted, redacted, or protected by another method that renders them unreadable or unusable by unauthorized persons:

  1. A Social Security number;
  2. A driver license or nondriver state identification card number, individual taxpayer identification number, passport number, military identification card number, or other identification number that originates from a government identification document that is commonly used to verify identity for a commercial transaction;
  3. A financial account number or credit or debit card number, if the number could be used without additional identifying information, access codes, or passwords;
  4. A password, personal identification number, or other access code for a financial account;
  5. Unique biometric data generated from measurements or technical analysis of human body characteristics used by the owner or licensee of the data to identify or authenticate the consumer, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data;
  6. Genetic information; and
  7. (a) health records or records of a wellness program or similar program of health promotion or disease prevention; (b) a health care professional’s medical diagnosis or treatment of the consumer; or (c) a health insurance policy number. Vt. Stat. Ann. tit. 9, § 2430(10).

“Login credentials” means a consumer’s user name or email address, in combination with a password or an answer to a security question, that together permit access to an online account. Vt. Stat. Ann. tit. 9, § 2430(9).

What Is A “Breach”?

“Security breach” means unauthorized acquisition of electronic data or a reasonable belief of an unauthorized acquisition of electronic data that compromises the security, confidentiality, or integrity of a consumer’s personally identifiable information or login credentials maintained by a data collector. Vt. Stat. Ann. tit. 9, § 2430(13).

In determining whether personally identifiable information or login credentials have been acquired or is reasonably believed to have been acquired by a person without valid authorization, a data collector may consider the following factors, among others:

  1. Indications that the information is in the physical possession and control of a person without valid authorization, such as a lost or stolen computer or other device containing information;
  2. Indications that the information has been downloaded or copied;
  3. Indications that the information was used by an unauthorized person, such as fraudulent accounts opened or instances of identity theft reported; or
  4. That the information has been made public. Vt. Stat. Ann. tit. 9, § 2430(13)(C).

Likelihood of Harm Analysis: Notice of a security breach is not required if the data collector establishes that misuse of personally identifiable information or login credentials is not reasonably possible and the data collector provides notice of the determination that the misuse of the personally identifiable information or login credentials is not reasonably possible pursuant to the requirements of this subsection. If the data collector establishes that misuse of the personally identifiable information or login credentials is not reasonably possible, the data collector shall provide notice of its determination that misuse of the personally identifiable information or login credentials is not reasonably possible and a detailed explanation for said determination to the Vermont Attorney General or to the Department of Financial Regulation in the event that the data collector is a person or entity licensed or registered with the Department under Title 8 or this title. Vt. Stat. Ann. tit. 9, § 2435(d)(1).

What Triggers Notification?

Discovery or notification to the data collector of the breach. Vt. Stat. Ann. tit. 9, § 2435(b)(1).

How Is Notice Provided To Individuals?

Timing: Notice of the security breach shall be made in the most expedient time possible and without unreasonable delay, but not later than 45 days after the discovery or notification, consistent with the legitimate needs of the law enforcement agency or with any measures necessary to determine the scope of the security breach and restore the reasonable integrity, security, and confidentiality of the data system. Vt. Stat. Ann. tit. 9, § 2435(b)(1).

Delivery: Delivery may be by direct notice or substitute notice. If by direct notice, it may be by:

  1. Written notice mailed to the consumer’s residence;
  2. Electronic notice, for those consumers for whom the data collector has a valid email address if: a) the data collector’s primary method of communication with the consumer is by electronic means, the electronic notice does not request or contain a hypertext link to a request that the consumer provide personal information, and the electronic notice conspicuously warns consumers not to provide personal information in response to electronic communications regarding security breaches; or b) the notice is consistent with the provisions regarding electronic records and signatures for notices in 15 U.S.C. § 7001; or
  3. Telephonic notice, provided that telephonic contact is made directly with each affected consumer and not through a prerecorded message.

Substitute notice may be made by conspicuously posting the notice on the data collector’s website if the data collector maintains one and notifying major statewide and regional media if:

  1. The data collector demonstrates that the lowest cost of providing notice to affected consumers pursuant to subdivision (6)(A) of this subsection among written, email, or telephonic notice would exceed $10,000; or
  2. The data collector does not have sufficient contact information. Vt. Stat. Ann. tit. 9, § 2435(b)(6).

Content: The notice sent to consumers must be clear and conspicuous and include each of the following, if known:

  1. The incident in general terms;
  2. The type of personally identifiable information that was subject to the security breach;
  3. The general acts of the data collector to protect the personally identifiable information from further security breach;
  4. A telephone number, toll-free if available, that the consumer may call for further information and assistance;
  5. Advice that directs the consumer to remain vigilant by reviewing account statements and monitoring free credit reports; and
  6. The approximate date of the security breach. Vt. Stat. Ann. tit. 9, § 2435(b)(5).

If a security breach is limited to an unauthorized acquisition of login credentials for an online account other than an email account the data collector shall provide notice of the security breach to the consumer electronically or through one or more of the methods specified above and shall advise the consumer to take steps necessary to protect the online account, including to change his or her login credentials for the account and for any other account for which the consumer uses the same login credentials. Vt. Stat. Ann. tit. 9, § 2435(d)(3).

If a security breach is limited to an unauthorized acquisition of login credentials for an email account: (A) the data collector shall not provide notice of the security breach through the email account; and (B) the data collector shall provide notice of the security breach through one or more of the methods specified above or by clear and conspicuous notice delivered to the consumer online when the consumer is connected to the online account from an Internet protocol address or online location from which the data collector knows the consumer customarily accesses the account. Vt. Stat. Ann. tit. 9, § 2435(d)(4).

Is Notice To The Government Required?

Yes. A data collector or other entity regulated by the Department of Financial Regulation under Title 8 or this title shall provide notice of a breach to the Department. All other data collectors or other entities subject to this subchapter shall provide notice of a breach to the Attorney General. The data collector shall notify the Attorney General or the Department, as applicable, of the date of the security breach and the date of discovery of the breach and shall provide a preliminary description of the breach within 14 business days, consistent with the legitimate needs of the law enforcement agency, of the data collector’s discovery of the security breach or when the data collector provides notice to consumers pursuant to this section, whichever is sooner. Vt. Stat. Ann. tit. 9, § 2435(b)(3).

When the data collector provides notice of the breach pursuant to subdivision (1) of this subsection (b), the data collector shall notify the Attorney General or the Department, as applicable, of the number of Vermont consumers affected, if known to the data collector, and shall provide a copy of the notice provided to consumers. The data collector may send to the Attorney General or the Department, as applicable, a second copy of the consumer notice, from which is redacted the type of personally identifiable information or login credentials that was subject to the breach, and which the Attorney General or the Department shall use for any public disclosure of the breach. Vt. Stat. Ann. tit. 9, § 2435(b)(3)(C).

Is Notice To Credit Reporting Agencies Required?

Yes. In the event a data collector provides notice to more than 1,000 consumers at one time pursuant to this section, the data collector shall notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notice. This subsection shall not apply to a person who is licensed or registered under Title 8 by the Department of Financial Regulation. Vt. Stat. Ann. tit. 9, § 2435(c).

Are There Security Measure Standards?

The Social Security Number Protection Act, Vt. Stat. Ann. tit. 9, § 2440, restricts the use of individuals’ social security numbers, and the Document Safe Destruction Act, Vt. Stat. Ann. tit. 9, § 2445, requires that businesses take all reasonable steps to destroy or arrange for the destruction of a customer’s records within its custody or control containing personal information that are no longer to be retained by the business.

What Are The Possible Consequences Of A Violation?

With respect to all data collectors and other entities subject to this subchapter, other than a person or entity licensed or registered with the Department of Financial Regulation under Title 8 or this title, the Attorney General and State’s Attorney shall have sole and full authority to investigate potential violations of this subchapter and to enforce, prosecute, obtain, and impose remedies for a violation of this subchapter or any rules or regulations made pursuant to this chapter as the Attorney General and State’s Attorney have under chapter 63 of this title. Vt. Stat. Ann. tit. 9, § 2435(h)(1).

With respect to a data collector that is a person or entity licensed or registered with the Department of Financial Regulation under Title 8 or this title, the Department of Financial Regulation shall have the full authority to investigate potential violations of this subchapter and to prosecute, obtain, and impose remedies for a violation of this subchapter or any rules or regulations adopted pursuant to this subchapter, as the Department has under Title 8 or this title or any other applicable law or regulation. Vt. Stat. Ann. tit. 9, § 2435(h)(2).

Are There Any Exemptions/Exceptions?

A data collector that is subject to the privacy, security, and breach notification rules adopted pursuant to the federal Health Insurance Portability and Accountability Act is deemed to be in compliance with this subchapter if: a) the data collector experiences a security breach that is limited to personally identifiable information specified in 2430(10)(A)(vii); and b) the data collector provides notice to affected consumers pursuant to the requirements of the breach notification rule in 45 C.F.R. Part 164, Subpart D. Vt. Stat. Ann. tit. 9, § 2435(e).

Additionally, a financial institution that is subject to the following guidances, and any revisions, additions, or substitutions relating to an interagency guidance shall be exempt from this section: 

  1. The Federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information and Customer Notice, issued on March 7, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision. 
  2. Final Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice, issued on April 14, 2005, by the National Credit Union Administration. 
  3. A financial institution regulated by the Department of Financial Regulation that is subject to subdivision (1) or (2) of this subsection (g) shall notify the Department as soon as possible after it becomes aware of an incident involving unauthorized access to or use of personally identifiable information. Vt. Stat. Ann. tit. 9, § 2435(g).

Texas

Who Is Covered?

A person who conducts business in Texas and owns or licenses computerized data that includes sensitive personal information. Tex. Bus. & Com. Code § 521.053(b).

 

What Information Is Protected?

“Personal identifying information” means information that alone or in conjunction with other information identifies an individual, including an individual’s:

 

  1. Name, social security number, date of birth, or government-issued identification number;
  2. Mother’s maiden name;
  3. Unique biometric data, including the individual’s fingerprint, voice print, and retina or iris image;
  4. Unique electronic identification number, address, or routing code; and
  5. Telecommunication access device as defined by Section 32.51, Penal Code. Tex. Bus. & Com. Code § 521.002(a)(1).

“Sensitive personal information” means:

 

  1. An individual’s first name or first initial and last name in combination with any one or more of the following items, if the name and the items are not encrypted: (i) social security number; (ii) driver’s license number or government-issued identification number; or (iii) account number or credit or debit card number in combination with any required security code, access code, or password that would permit access to an individual’s financial account; or
  2. Information that identifies an individual and relates to: (i) the physical or mental health or condition of the individual; (ii) the provision of health care to the individual; or (iii) payment for the provision of health care to the individual. Tex. Bus. & Com. Code § 521.002(a)(2).

 

What Is A “Breach”?

“Breach of system security” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of sensitive personal information maintained by a person, including data that is encrypted if the person accessing the data has the key required to decrypt the data. Good faith acquisition of sensitive personal information by an employee or agent of the person for the purposes of the person is not a breach of system security unless the person uses or discloses the sensitive personal information in an unauthorized manner. Tex. Bus. & Com. Code § 521.053(a).

 

What Triggers Notification?

Discovering or receiving notification of the breach where any individual’s sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Tex. Bus. & Com. Code § 521.053(b).

 

How Is Notice Provided To Individuals?

Non-Residents: If the individual whose sensitive personal information was or is reasonably believed to have been acquired by an unauthorized person is a resident of a state that requires a person [under Texas law] to provide notice of a breach of system security, the notice of the breach of system security may be provided under that state’s law or under Texas law. Tex. Bus. & Com. Code § 521.053(b-1).

Timing: The disclosure shall be made without unreasonable delay and in each case not later than the 60th day after the date on which the person determines that the breach occurred, except as necessary for the needs of law enforcement or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Tex. Bus. & Com. Code § 521.053(b), (d).

Delivery: Notice may be provided by:

 

  1. Written notice at the last known address of the individual;
  2. Electronic notice, if the notice is provided in accordance with 15 U.S.C. Section 7001; or
  3. Substitute notice if it is demonstrated that the cost of providing notice would exceed $250,000, the number of affected persons exceeds 500,000, or the person does not have sufficient contact information, in which case the notice may be given by: a) electronic mail, if the person has electronic mail addresses for the affected persons; b) conspicuous posting of the notice on the person’s website; or c) notice published in or broadcast on major statewide media. Tex. Bus. & Com. Code § 521.053(e), (f).

Content: None specified.

 

Is Notice To The Government Required?

Yes. A person who is required to disclose or provide notification of a breach of system security under this section shall notify the attorney general of that breach as soon as practicable and not later than the 30th day after the date on which the person determines that the breach occurred if the breach involves at least 250 residents of this state. The notification under this subsection must be submitted electronically using a form accessed through the attorney general’s Internet website and must include:

 

  1. A detailed description of the nature and circumstances of the breach or the use of sensitive personal information acquired as a result of the breach;
  2. The number of residents of this state affected by the breach at the time of notification;
  3. the number of affected residents that have been sent a disclosure of the breach by mail or other direct method of communication at the time of notification;
  4. The measures taken by the person regarding the breach;
  5. Any measures the person intends to take regarding the breach after the notification under this subsection; and
  6. Information regarding whether law enforcement is engaged in investigating the breach. Tex. Bus. & Com. Code § 521.053(i).

 

Is Notice To Credit Reporting Agencies Required?

Yes. If a person is required by this section to notify at one time more than 10,000 persons of a breach of system security, the person shall also notify each consumer reporting agency of the timing, distribution, and content of the notices. The person shall provide the notice required by this subsection without unreasonable delay. Tex. Bus. & Com. Code § 521.053(h).

 

Are There Security Measure Standards?

Yes. A business shall implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect from unlawful use or disclosure any sensitive personal information collected or maintained by the business in the regular course of business. Tex. Bus. & Com. Code § 521.052(a).

Additionally, a business shall destroy or arrange for the destruction of customer records containing sensitive personal information within the business’s custody or control that are not to be retained by the business by:(1) shredding; (2) erasing; or (3) otherwise modifying the sensitive personal information in the records to make the information unreadable or indecipherable through any means. Tex. Bus. & Com. Code § 521.052(b).

 

What Are The Possible Consequences Of A Violation?

A person who violates this chapter is liable to this state for a civil penalty of at least $2,000 but not more than $50,000 for each violation. The attorney general may bring an action to recover the civil penalty imposed under this subsection. Tex. Bus. & Com. Code § 521.151(a).

In addition to penalties assessed under Subsection (a), a person who fails to take reasonable action to comply with Section 521.053(b) is liable to this state for a civil penalty of not more than $100 for each individual to whom notification is due under that subsection for each consecutive day that the person fails to take reasonable action to comply with that subsection. Civil penalties under this section may not exceed $250,000 for all individuals to whom notification is due after a single breach. The attorney general may bring an action to recover the civil penalties imposed under this subsection. Tex. Bus. & Com. Code § 521.151(a-1).

 

Are There Any Exemptions/Exceptions?

A person who maintains the person’s own notification procedures as part of an information security policy for the treatment of sensitive personal information that complies with the timing requirements for notice under this section complies with this section if the person notifies affected persons in accordance with that policy. Tex. Bus. & Com. Code § 521.053(g).

Utah

Who Is Covered?

A person who owns or licenses computerized data that includes personal information concerning a Utah resident. Utah Code Ann. § 13-44-202(1)(a).

 

What Information Is Protected?

“Personal information” means a person’s first name or first initial and last name, combined with any one or more of the following data elements relating to that person when either the name or date element is unencrypted or not protected by another method that renders the data unreadable or unusable:

 

  1. Social Security number;
  2. (A) financial account number, or credit or debit card number; and (b) any required security code, access code, or password that would permit access to the person’s account; or
  3. Driver license number or state identification card number. Utah Code Ann. § 13-44-102(4).

 

What Is A “Breach”?

“Breach of system security” means an unauthorized acquisition of computerized data maintained by a person that compromises the security, confidentiality, or integrity of personal information. Utah Code Ann. § 13-44-102(1)(a).

 

What Triggers Notification?

When a person becomes aware of a breach of system security, the person must conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be misused for identity theft or fraud purposes. Notification must be provided if the investigation reveals that the misuse of personal information for identity theft or fraud purposes has occurred, or is reasonably likely to occur, the person shall provide notification to each affected Utah resident. Utah Code Ann. § 13-44-202(1).

 

How Is Notice Provided To Individuals?

Timing: Notification must be made in the most expedient time possible without unreasonable delay considering the legitimate investigative needs of law enforcement, after determining the scope of the breach of system security and after restoring the reasonable integrity of the system. Utah Code Ann. § 13-44-202(2).

Delivery: Notification may be provided:

 

  1. In writing by first-class mail to the most recent address the person has for the resident;
  2. Electronically, if the person’s primary method of communication with the resident is by electronic means, or if provided in accordance with the consumer disclosure provisions of 15 U.S.C. Section 7001;
  3. By telephone, including through the use of automatic dialing technology not prohibited by other law; or
  4. For residents of the state for whom notification in a manner described above is not feasible, by publishing notice of the breach of system security: (A) in a newspaper of general circulation; and (B) as required in Section 45-1-101 [legal notice publication requirements]. Utah Code Ann. § 13-44-202.

Content: None specified.

 

Is Notice To The Government Required?

Yes. If the investigation reveals that the misuse of personal information relating to 500 or more Utah residents, for identity theft or fraud purposes, has occurred or is reasonably likely to occur, the person shall, in addition to the notification required in Subsection (1)(b), provide notification to: 

  1. the office of the Attorney General; and
  2. the Utah Cyber Center. Utah Code Ann. § 13-44-202(1)(c).

 

Is Notice To Credit Reporting Agencies Required?

Yes, if the investigation reveals that the misuse of personal information relating to 1,000 or more Utah residents, for identity theft or fraud purposes, has occurred or is reasonably likely to occur.
Utah Code Ann. § 13-44-202(1)(d).

 

Are There Security Measure Standards?

Yes. Any person who conducts business in the state and maintains personal information shall implement and maintain reasonable procedures to:

 

  1. Prevent unlawful use or disclosure of personal information collected or maintained in the regular course of business; and
  2. Destroy, or arrange for the destruction of, records containing personal information that are not to be retained by the person. 

The destruction of records shall be by: (a) shredding; (b) erasing; or (c) otherwise modifying the personal information to make the information indecipherable. Utah Code Ann. § 13-44-201.

 

What Are The Possible Consequences Of A Violation?

In addition to injunctive relief and attorney fees and costs, the attorney general may seek a civil penalty of:

 

  1. No greater than $2,500 for a violation or series of violations concerning a specific consumer; and
  2. No greater than $100,000 in the aggregate for related violations concerning more than one consumer, unless: a) the violations concern: (i) 10,000 or more consumers who are residents of the state; and (ii) 10,000 or more consumers who are residents of other states; or b) the person agrees to settle for a greater amount. Utah Code Ann. § 13-44-301(3), (4).

 

Are There Any Exemptions/Exceptions?

If a person maintains the person’s own notification procedures as part of an information security policy for the treatment of personal information the person is considered to be in compliance with this chapter’s notification requirements if the procedures are otherwise consistent with this chapter’s timing requirements and the person notifies each affected Utah resident in accordance with the person’s information security policy in the event of a breach. Utah Code Ann. § 13-44-202(5)(b).

Also, a person who is regulated by state or federal law and maintains procedures for a breach of system security under applicable law established by the primary state or federal regulator is considered to be in compliance with this part if the person notifies each affected Utah resident in accordance with the other applicable law in the event of a breach. Utah Code Ann. § 13-44-202(5)(c).

Rhode Island

Who Is Covered?

Any municipal agency, state agency, or person that stores, owns, collects, processes, maintains, acquires, uses, or licenses data that includes personal information. R.I. Gen. Laws Section 11-49.3-4(a)(1).

What Information Is Protected?

“Personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements, when the name and the data elements are not encrypted or are in hard copy, paper format:

  1. Social security number;
  2. Driver’s license number, Rhode Island identification card number, or tribal identification number;
  3. Account number, credit, or debit card number, in combination with any required security code, access code, password, or personal identification number, that would permit access to an individual’s financial account;
  4. Medical or health insurance information; or
  5. Email address with any required security code, access code, or password that would permit access to an individual’s personal, medical, insurance, or financial account. R.I. Gen. Laws Section 11-49.3-3(a)(8).

“Health insurance information” means an individual’s health insurance policy number, subscriber identification number, or any unique identifier used by a health insurer to identify the individual. R.I. Gen. Laws Section 11-49.3-3(a)(3).

“Medical information” means any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional or provider. R.I. Gen. Laws Section 11-49.3-3(a)(4).

What Is A “Breach”?

“Breach of the security of the system” means unauthorized access or acquisition of unencrypted, computerized data information that compromises the security, confidentiality, or integrity of personal information maintained by the municipal agency, state agency, or person. Good-faith acquisition of personal information by an employee or agent of the agency for the purposes of the agency is not a breach of the security of the system; provided, that the personal information is not used or subject to further unauthorized disclosure. R.I. Gen. Laws Section 11-49.3-3(a)(1).

What Triggers Notification?

The disclosure of personal information, or any breach of the security of the system, that poses a significant risk of identity theft to any resident of Rhode Island whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person or entity. R.I. Gen. Laws Section 11-49.3-4(a)(1).

How Is Notice Provided To Individuals?

Timing: The notification must be made in the most expedient time possible, but no later than 45 calendar days after confirmation of the breach and the ability to ascertain the information required to be included in the notification. R.I. Gen. Laws § 11-49.3-4(a)(2).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001; or
  3. Substitute notice, if the municipal agency, state agency, or person demonstrates that the cost of providing notice would exceed $25,000, or that the affected class of subject persons to be notified exceeds 50,000, or the municipal agency, state agency, or person does not have sufficient contact information. Substitute notice shall consist of all of the following: (A) Email notice when the municipal agency, state agency, or person has an email address for the subject persons; (B) Conspicuous posting of the notice on the municipal agency’s, state agency’s or person’s website page, if the municipal agency, state agency, or person maintains one; and (C) Notification to major statewide media. R.I. Gen. Laws Section 11-49.3-3(c).

Content: The notice must include:

  1. A general and brief description of the incident, including how the security breach occurred and the number of affected individuals;
  2. The type of information that was subject to the breach;
  3. Date of breach, estimated date of breach, or the date range within which the breach occurred;
  4. Date that the breach was discovered;
  5. A clear and concise description of any remediation services offered to affected individuals including toll free numbers and websites to contact: (i) The credit reporting agencies; (ii) Remediation service providers; (iii) The attorney general; and
  6. A clear and concise description of the consumer’s ability to file or obtain a police report; how a consumer requests a security freeze and the necessary information to be provided when requesting the security freeze; and that fees may be required to be paid to the consumer reporting agencies. R.I. Gen. Laws § 11-49.3-4(d).

Is Notice To The Government Required?

Yes. In the event that more than 500 Rhode Island residents are to be notified, the municipal agency, state agency, or person shall notify the attorney general and the major credit reporting agencies as to the timing, content, and distribution of the notices and the approximate number of affected individuals. Notification to the attorney general and the major credit reporting agencies shall be made without delaying notice to affected Rhode Island residents. R.I. Gen. Laws Section 11-49.3-4(a)(2).

Is Notice To Credit Reporting Agencies Required?

Yes. See above.

Are There Security Measure Standards?

Yes. A municipal agency, state agency, or person who or that stores, collects, processes, maintains, acquires, uses, owns, or licenses personal information about a Rhode Island resident shall implement and maintain a risk-based information security program that contains reasonable security procedures and practices appropriate to the size and scope of the organization; the nature of the information; and the purpose for which the information was collected in order to protect the personal information from unauthorized access, use, modification, destruction, or disclosure and to preserve the confidentiality, integrity, and availability of such information. A municipal agency, state agency, or person shall not retain personal information for a period longer than is reasonably required to provide the services requested; to meet the purpose for which it was collected; or in accordance with a written retention policy or as may be required by law. A municipal agency, state agency, or person shall destroy all personal information, regardless of the medium that such information is in, in a secure manner, including, but not limited to, shredding, pulverization, incineration, or erasure. R.I. Gen. Laws Section 11-49.3-2(a).

Additionally, a municipal agency, state agency, or person who or that discloses personal information about a Rhode Island resident to a nonaffiliated third party shall require by written contract that the third party implement and maintain reasonable security procedures and practices appropriate to the size and scope of the organization; the nature of the information; and the purpose for which the information was collected in order to protect the personal information from unauthorized access, use, modification, destruction, or disclosure. The provisions of this section shall apply to contracts entered into after the effective date of this act. R.I. Gen. Laws Section 11-49.3-2(b).

What Are The Possible Consequences Of A Violation?

Each reckless violation of this chapter is a civil violation for which a penalty of not more than $100 per record may be adjudged against a defendant. Each knowing and willful violation of this chapter is a civil violation for which a penalty of not more than $200 per record may be adjudged against a defendant. Additionally, whenever the attorney general has reason to believe that a violation has occurred and that proceedings would be in the public interest, the attorney general may bring an action in the name of the state against the business or person in violation. R.I. Gen. Laws Section 11-49.3-5.

Are There Any Exemptions/Exceptions?

  1. Any municipal agency, state agency, or person shall be deemed to be in compliance with the security breach notification requirements of § 11-49.3-4 if: a) The municipal agency, state agency, or person maintains its own security breach procedures as part of an information security policy for the treatment of personal information and otherwise complies with the timing requirements of § 11-49.3-4, and notifies subject persons in accordance with such municipal agency’s, state agency’s, or person’s notification policies in the event of a breach of security; or b) The person maintains a security breach procedure pursuant to the rules, regulations, procedures, or guidelines established by the primary or functional regulator, as defined in 15 U.S.C. § 6809(2), and notifies subject persons in accordance with the policies or the rules, regulations, procedures, or guidelines established by the primary or functional regulator in the event of a breach of security of the system.
  2. A financial institution, trust company, credit union, or its affiliates that is subject to and examined for, and found in compliance with, the Federal Interagency Guidelines on Response Programs for Unauthorized Access to Customer Information and Customer Notice shall be deemed in compliance with this chapter.
  3. A provider of health care, health care service plan, health insurer, or a covered entity governed by the medical privacy and security rules issued by the Federal Department of Health and Human Services, Parts 160 and 164 of Title 45 of the Code of Federal Regulations, established pursuant to the Health Insurance Portability and Accountability Act of 1996 shall be deemed in compliance with this chapter. R.I. Gen. Laws Section 11-49.3-6.

Oregon

Who Is Covered?

“Covered entity” means a person that owns, licenses, maintains, stores, manages, collects, processes, acquires or otherwise possesses personal information in the course of the person’s business, vocation, occupation or volunteer activities. Or. Rev. Stat. Ann. § 646A.602(5)(a).

What Information Is Protected?

“Personal information” means:

A. A consumer’s first name or first initial and last name in combination with any one or more of the following data elements, if encryption, redaction or other methods have not rendered the data elements unusable or if the data elements are encrypted and the encryption key has been acquired:

  1. A consumer’s social security number;
  2. A consumer’s driver license number or state identification card number issued by the Department of Transportation;
  3. A consumer’s passport number or other identification number issued by the United States;
  4. A consumer’s financial account number, credit card number or debit card number, in combination with any required security code, access code or password that would permit access to a consumer’s financial account, or any other information or combination of information that a person reasonably knows or should know would permit access to the consumer’s financial account;
  5. Data from automatic measurements of a consumer’s physical characteristics, such as an image of a fingerprint, retina or iris, that are used to authenticate the consumer’s identity in the course of a financial transaction or other transaction;
  6. A consumer’s health insurance policy number or health insurance subscriber identification number in combination with any other unique identifier that a health insurer uses to identify the consumer; or
  7. Any information about a consumer’s medical history or mental or physical condition or about a health care professional’s medical diagnosis or treatment of the consumer.

B. A user name or other means of identifying a consumer for the purpose of permitting access to the consumer’s account, together with any other method necessary to authenticate the user name or means of identification.

C. Any of the data elements or any combination of the data elements described in subparagraph (A) or (B) of this paragraph without the consumer’s user name, or the consumer’s first name or first initial and last name, if: (i) Encryption, redaction or other methods have not rendered the data element or combination of data elements unusable; and (ii) The data element or combination of data elements would enable a person to commit identity theft against a consumer. Or. Rev. Stat. Ann. § 646A.602(12)(A)(a).

What Is A “Breach”?

“Breach of security” means an unauthorized acquisition of computerized data that materially compromises the security, confidentiality or integrity of personal information that a person maintains or possesses. Or. Rev. Stat. Ann. § 646A.602(1)(a).

What Triggers Notification?

The covered entity being subjected to a breach of security or receiving notice of a breach of security from a vendor. Or. Rev. Stat. Ann. § 646A.604(1).

Likelihood of Harm Analysis: A covered entity does not need to notify consumers of a breach of security if, after an appropriate investigation or after consultation with relevant federal, state or local law enforcement agencies, the covered entity reasonably determines that the consumers whose personal information was subject to the breach of security are unlikely to suffer harm. The covered entity must document the determination in writing and maintain the documentation for at least five years. Or. Rev. Stat. Ann. § 646A.604(8).

How Is Notice Provided To Individuals?

Timing: Notice must be provided in the most expeditious manner possible, without unreasonable delay, but not later than 45 days after discovering or receiving notification of the breach of security, but only after the covered entity undertakes reasonable measures that are necessary to:

  1. Determine sufficient contact information for the intended recipient of the notice;
  2. Determine the scope of the breach of security; and
  3. Restore the reasonable integrity, security and confidentiality of the personal information. Or. Rev. Stat. Ann. § 646A.604(3).

Delivery: Notice may be made:

  1. In writing;
  2. Electronically, if the covered entity customarily communicates with the consumer electronically or if the notice is consistent with the provisions of the E-Sign Act;
  3. By telephone, if the covered entity contacts the affected consumer directly; or
  4. With substitute notice, if the covered entity demonstrates that the cost of notification otherwise would exceed $250,000 or that the affected class of consumers exceeds 350,000, or if the covered entity does not have sufficient contact information to notify affected consumers. For the purposes of this paragraph, “substitute notice” means: (A) Posting the notice or a link to the notice conspicuously on the covered entity’s website if the covered entity maintains a website; and (B) Notifying major statewide television and newspaper media. Or. Rev. Stat. Ann. § 646A.604(4).

Content: Notice must include:

  1. A description of the breach of security in general terms;
  2. The approximate date of the breach of security;
  3. The type of personal information that was subject to the breach of security;
  4. Contact information for the covered entity;
  5. Contact information for national consumer reporting agencies; and
  6. Advice to the consumer to report suspected identity theft to law enforcement, including the Attorney General and the Federal Trade Commission. Or. Rev. Stat. Ann. § 646A.604(5).

Is Notice To The Government Required?

Yes, if the number of consumers to whom the covered entity must send the notice exceeds 250. Or. Rev. Stat. Ann. § 646A.604(1)(b).

Is Notice To Credit Reporting Agencies Required?

Yes. If a covered entity discovers or receives notice of a breach of security that affects more than 1,000 consumers, the covered entity shall notify, without unreasonable delay, all consumer reporting agencies that compile and maintain reports on consumers on a nationwide basis of the timing, distribution and content of the notice the covered entity gave to affected consumers and shall include in the notice any police report number assigned to the breach of security. A covered entity may not delay notifying affected consumers of a breach of security in order to notify consumer reporting agencies. Or. Rev. Stat. Ann. § 646A.604(6).

Are There Security Measure Standards?

Yes. A covered entity and a vendor shall develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of personal information, including safeguards that protect the personal information when the covered entity or vendor disposes of the personal information. In addition to complying with any federal law that provides greater protection to personal information than the protections that this section provides or with the HIPAA, a covered entity or vendor is in compliance if it implements an information security program that includes:

A. Administrative safeguards such as:

  1. Designating one or more employees to coordinate the security program;
  2. Identifying reasonably foreseeable internal and external risks with reasonable regularity;
  3. Assessing whether existing safeguards adequately control the identified risks;
  4. Training and managing employees in security program practices and procedures with reasonable regularity;
  5. Selecting service providers that are capable of maintaining appropriate safeguards and practices, and requiring the service providers by contract to maintain the safeguards and practices;  
  6. Adjusting the security program in light of business changes, potential threats or new circumstances; and
  7. Reviewing user access privileges with reasonable regularity.

B. Technical safeguards such as:

  1. Assessing risks and vulnerabilities in network and software design and taking reasonably timely action to address the risks and vulnerabilities;
  2. Applying security updates and a reasonable security patch management program to software that might reasonably be at risk of or vulnerable to a breach of security;
  3. Monitoring, detecting, preventing and responding to attacks or system failures; and
  4. Regularly testing, monitoring and taking action to address the effectiveness of key controls, systems and procedures.

C. Physical safeguards such as:

  1. Assessing, in light of current technology, risks of information collection, storage, usage, retention, access and disposal and implementing reasonable methods to remedy or mitigate identified risks;
  2. Monitoring, detecting, preventing, isolating and responding to intrusions timely and with reasonable regularity;
  3. Protecting against unauthorized access to or use of personal information during or after collecting, using, storing, transporting, retaining, destroying or disposing of the personal information; and
  4. Disposing of personal information, whether the covered entity or vendor disposes of the personal information on or off the covered entity’s or vendor’s premises or property, after the covered entity or vendor no longer needs the personal information for business purposes or as required by local, state or federal law by burning, pulverizing, shredding or modifying a physical record and by destroying or erasing electronic media so that the information cannot be read or reconstructed. Or. Rev. Stat. Ann. § 646A.622(1), (2).

What Are The Possible Consequences Of A Violation?

In addition to all other penalties and enforcement provisions provided by law, any person who violates or who procures, aids or abets in a violation shall be subject to a penalty of not more than $1,000 for every violation, which shall be paid to the General Fund of the State Treasury. Every violation is a separate offense and, in the case of a continuing violation, each day’s continuance is a separate violation, but the maximum penalty for any occurrence shall not exceed $500,000.  Additionally, a violation is an unlawful practice under Or. Rev. Stat. Ann. § 646.607. Or. Rev. Stat. Ann. §§ 646A.624(4); 646A.604(11)(a).

If the director has reason to believe that any person has engaged or is engaging in any violation, the director may issue an order, subject to ORS chapter 183, directed to the person to cease and desist from the violation, or require the person to pay compensation to consumers injured by the violation. The director may order compensation to consumers only upon a finding that enforcement of the rights of the consumers by private civil action would be so burdensome or expensive as to be impractical. Or. Rev. Stat. Ann. § 646A.624(3).

Are There Any Exemptions/Exceptions?

With the exception of the requirement to send notice to the attorney general, the breach notification requirements do not apply to:

  1. Personal information that is subject to, and a person that complies with, notification requirements or procedures for a breach of security that the person’s primary or functional federal regulator adopts, promulgates or issues in rules, regulations, procedures, guidelines or guidance.
  2. Personal information that is subject to, and a person that complies with, a state or federal law that provides greater protection to personal information and disclosure requirements at least as thorough as the protections and disclosure requirements provided under this section.
  3. A covered entity or vendor that complies with regulations promulgated under Title V of the Gramm-Leach-Bliley Act.
  4. A covered entity or vendor that complies with regulations promulgated under the Health Insurance Portability and Accountability Act. Or. Rev. Stat. Ann. § 646A.604(9).

New York

Who Is Covered?

Any person or business which owns or licenses computerized data which includes private information. N.Y. Gen. Bus. Law § 899-aa(2).

 

What Information Is Protected?

“Private information” means either:

A. Personal information consisting of any information in combination with any one or more of the following data elements, when either the data element or the combination of personal information plus the data element is not encrypted, or is encrypted with an encryption key that has also been accessed or acquired:

 

  1. Social security number;
  2. Driver’s license number or non-driver identification card number;
  3. Account number, credit or debit card number, in combination with any required security code, access code, password or other information that would permit access to an individual’s financial account;
  4. Account number, credit or debit card number, if circumstances exist wherein such number could be used to access an individual’s financial account without additional identifying information, security code, access code, or password; or
  5. Biometric information, meaning data generated by electronic measurements of an individual’s unique physical characteristics, such as a fingerprint, voice print, retina or iris image, or other unique physical representation or digital representation of biometric data which are used to authenticate or ascertain the individual’s identity; or

B. A user name or email address in combination with a password or security question and answer that would permit access to an online account. N.Y. Gen. Bus. Law § 899-aa(1)(b).

 

What Is A “Breach”?

“Breach of the security of the system” shall mean unauthorized access to or acquisition of, or access to or acquisition without valid authorization, of computerized data that compromises the security, confidentiality, or integrity of private information maintained by a business. 

In determining whether information has been accessed, or is reasonably believed to have been accessed, by an unauthorized person or a person without valid authorization, such business may consider, among other factors, indications that the information was viewed, communicated with, used, or altered by a person without valid authorization or by an unauthorized person. In determining whether information has been acquired, or is reasonably believed to have been acquired, by an unauthorized person or a person without valid authorization, such business may consider the following factors, among others:

 

  1. Indications that the information is in the physical possession and control of an unauthorized person, such as a lost or stolen computer or other device containing information; or
  2. Indications that the information has been downloaded or copied; or
  3. Indications that the information was used by an unauthorized person, such as fraudulent accounts opened or instances of identity theft reported. N.Y. Gen. Bus. Law § 899-aa(1)(c).

 

What Triggers Notification?

Discovery or notification of the breach in the security of the system involving the private information of any resident of New York state whose private information was, or is reasonably believed to have been, accessed or acquired by a person without valid authorization. N.Y. Gen. Bus. Law § 899-aa(2).

Likelihood of Harm Exception: Notice to affected persons is not required if the exposure of private information was an inadvertent disclosure by persons authorized to access private information, and the person or business reasonably determines such exposure will not likely result in misuse of such information, or financial harm to the affected persons or emotional harm in the case of unknown disclosure of online credentials. N.Y. Gen. Bus. Law § 899-aa(2)(a).

 

How Is Notice Provided To Individuals?

Timing: In the most expedient time possible and without unreasonable delay, provided that such notification is made within 30 days after the breach is discovered, except for the legitimate needs of law enforcement. N.Y. Gen. Bus. Law § 899-aa(2).

Delivery: Notice may be provided by:

 

  1. Written notice;
  2. Electronic notice, provided that the person to whom notice is required has expressly consented to receiving said notice in electronic form and a log of each such notification is kept by the person or business who notifies affected persons in such form; provided further, however, that in no case shall any person or business require a person to consent to accepting said notice in said form as a condition of establishing any business relationship or engaging in any transaction.
  3. Telephone notification provided that a log of each such notification is kept by the person or business who notifies affected persons; or
  4. Substitute notice, if a business demonstrates to the state attorney general that the cost of providing notice would exceed two hundred fifty thousand dollars, or that the affected class of subject persons to be notified exceeds five hundred thousand, or such business does not have sufficient contact information. Substitute notice shall consist of all of the following: (a) email notice when such business has an email address for the subject persons, except if the breached information includes an email address in combination with a password or security question and answer that would permit access to the online account, in which case the person or business shall instead provide clear and conspicuous notice delivered to the consumer online when the consumer is connected to the online account from an internet protocol address or from an online location which the person or business knows the consumer customarily uses to access the online account; (b) conspicuous posting of the notice on such business’s website page, if such business maintains one; and (c) notification to major statewide media. N.Y. Gen. Bus. Law § 899-aa(5).

Content: Notice must include:

 

  1. Contact information for the person or business making the notification;
  2. The telephone numbers and websites of the relevant state and federal agencies that provide information regarding security breach response and identity theft prevention and protection information; and
  3. A description of the categories of information that were, or are reasonably believed to have been, accessed or acquired by a person without valid authorization, including specification of which of the elements of personal information and private information were, or are reasonably believed to have been, so accessed or acquired. N.Y. Gen. Bus. Law § 899-aa(7).

 

Is Notice To The Government Required?

Yes. In the event that any New York residents are to be notified, the person or business shall notify the state attorney general, the department of state and the division of state police, and the department of financial services as to the timing, content and distribution of the notices and approximate number of affected persons and shall provide a copy of the template of the notice sent to affected persons. Such notice shall be made without delaying notice to affected New York residents. However, notice to the department of financial services shall only be required if the person or business is a covered entity, as defined in 23 NYCRR 500l1. N.Y. Gen. Bus. Law § 899-aa(8)(a).

Additionally, any covered entity required to provide notification of a breach, including breach of information that is not “private information,” to the secretary of health and human services pursuant to HIPAA shall provide such notification to the state attorney general within five business days of notifying the secretary. N.Y. Gen. Bus. Law § 899-aa(9).

 

Is Notice To Credit Reporting Agencies Required?

Yes. In the event that more than five thousand New York residents are to be notified at one time, the person or business shall also notify consumer reporting agencies as to the timing, content and distribution of the notices and approximate number of affected persons. Such notice shall be made without delaying notice to affected New York residents. N.Y. Gen. Bus. Law § 899-aa(8)(b).

 

Are There Security Measure Standards?

Yes. Any person or business that owns or licenses computerized data which includes private information of a resident of New York must develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of the private information including, but not limited to, disposal of data. A person or business will be deemed to be in compliance with paragraph (a) of this subdivision if it is a compliant regulated entity [N.Y. Gen. Bus. Law § 899-bb(1)], or implements a data security program that includes:

A. Reasonable administrative safeguards such as the following, in which the person or business:

 

  1. Designates one or more employees to coordinate the security program;
  2. Identifies reasonably foreseeable internal and external risks;
  3. Assesses the sufficiency of safeguards in place to control the identified risks;
  4. Trains and manages employees in the security program practices and procedures;
  5. Selects service providers capable of maintaining appropriate safeguards, and requires those safeguards by contract; and
  6. Adjusts the security program in light of business changes or new circumstances; and

B. Reasonable technical safeguards such as the following, in which the person or business:

 

  1. Assesses risks in network and software design;
  2. Assesses risks in information processing, transmission and storage;
  3. Detects, prevents and responds to attacks or system failures; and
  4. Regularly tests and monitors the effectiveness of key controls, systems and procedures; and

C. Reasonable physical safeguards such as the following, in which the person or business:

 

  1. Assesses risks of information storage and disposal;
  2. Detects, prevents and responds to intrusions;
  3. Protects against unauthorized access to or use of private information during or after the collection, transportation and destruction or disposal of the information; and
  4. Disposes of private information within a reasonable amount of time after it is no longer needed for business purposes by erasing electronic media so that the information cannot be read or reconstructed. N.Y. Gen. Bus. Law § 899-bb(2).

 

What Are The Possible Consequences Of A Violation?

The attorney general may seek injunctive relief and damages for actual costs or losses incurred by a person entitled to notice if notification was not provided to such person, including consequential financial losses.

Additionally, if a court determines that a person or business violated the article knowingly or recklessly, the court may impose a civil penalty of the greater of $5,000 or up to $20 per instance of failed notification, provided that the latter amount shall not exceed $250,000. N.Y. Gen. Bus. Law § 899-aa(6)(a).

 

Are There Any Exemptions/Exceptions?

If notice of the breach of the security of the system is made to affected persons pursuant to the breach notification requirements under any of the following laws, nothing in this section shall require any additional notice to those affected persons, but notice still shall be provided to the state attorney general, the department of state and the division of state police and to consumer reporting agencies:

 

  1. Regulations promulgated pursuant to Title V of the federal Gramm-Leach-Bliley Act;
  2. Regulations implementing the Health Insurance Portability and Accountability Act and the Health Information Technology for Economic and Clinical Health Act;
  3. Part five hundred of title twenty-three of the official compilation of codes, rules and regulations of the state of New York; or
  4. Any other data security rules and regulations of, and the statutes administered by, any official department, division, commission or agency of the federal or New York state government as such rules, regulations or statutes are interpreted by such department, division, commission or agency or by the federal or New York state courts. N.Y. Gen. Bus. Law § 899-aa(2)(b).

New Mexico

Who Is Covered?

 Any person that owns or licenses elements that include personal identifying information of a New Mexico resident. N.M. Stat. Ann. § 57-12C-2(C)(6).

What Information Is Protected?

“Personal identifying information” means an individual’s first name or first initial and last name in combination with one or more of the following data elements that relate to the individual, when the data elements are not protected through encryption or redaction or otherwise rendered unreadable or unusable:

  1. Social security number;
  2. Driver’s license number;
  3. Government-issued identification number;
  4. Account number, credit card number or debit card number in combination with any required security code, access code or password that would permit access to a person’s financial account; or
  5. Biometric data N.M. Stat. Ann. § 57-12C-2(C)(1).

What Is A “Breach”?

“Security breach” means the unauthorized acquisition of unencrypted computerized data, or of encrypted computerized data and the confidential process or key used to decrypt the encrypted computerized data, that compromises the security, confidentiality or integrity of personal identifying information maintained by a person. N.M. Stat. Ann. § 57-12C-2(D).

What Triggers Notification?

A reasonable belief that the personal information of a New Mexico resident has been subject to a security breach. N.M. Stat. Ann. § 57-12C-6(A).

Likelihood of Harm Analysis: Notification to affected New Mexico residents is not required if, after an appropriate investigation, the person determines that the security breach does not give rise to a significant risk of identity theft or fraud. N.M. Stat. Ann. § 57-12C-6(B).

How Is Notice Provided To Individuals?

Timing: Notification must be made in the most expedient time possible, but not later than 45 calendar days following discovery of the security breach, except as provided in N.M. Stat. Ann. § 57-12C-9. N.M. Stat. Ann. § 57-12C-6(A).

Delivery: Notification may be by:

  1. United States mail;
  2. Electronic notification, if the person required to make the notification primarily communicates with the New Mexico resident by electronic means or if the notice provided is consistent with the requirements of 15 U.S.C. Section 7001; or
  3. A substitute notification, if the person demonstrates that: (a) the cost of providing notification would exceed $100,000; (b) the number of residents to be notified exceeds fifty thousand; or (c) the person does not have on record a physical address or sufficient contact information for the residents that the person or business is required to notify. N.M. Stat. Ann. § 57-12C-6(D).

Content: The notification must include:

  1. The name and contact information of the notifying person;
  2. A list of the types of personal identifying information that are reasonably believed to have been the subject of a security breach, if known;
  3. The date of the security breach, the estimated date of the breach or the range of dates within which the security breach occurred, if known;
  4. A general description of the security breach incident;
  5. The toll-free telephone numbers and addresses of the major consumer reporting agencies;
  6. Advice that directs the recipient to review personal account statements and credit reports, as applicable, to detect errors resulting from the security breach; and
  7. Advice that informs the recipient of the notification of the recipient’s rights pursuant to the federal Fair Credit Reporting Act. N.M. Stat. Ann. § 57-12C-7.

Is Notice To The Government Required?

Yes. A person that is required to issue notification of a security breach pursuant to the Data Breach Notification Act to more than 1,000 New Mexico residents as a result of a single security breach shall notify the office of the attorney general and major consumer reporting agencies of the security breach in the most expedient time possible, and no later than 45 calendar days, except as provided in N.M. Stat. Ann. § 57-12C-9. A person required to notify the attorney general and consumer reporting agencies pursuant to this section shall notify the attorney general of the number of New Mexico residents that received notification and shall provide a copy of the notification that was sent to affected residents within 45 calendar days following discovery of the security breach, except as provided in N.M. Stat. Ann. § 57-12C-9.

Is Notice To Credit Reporting Agencies Required?

Yes. See above.

Are There Security Measure Standards?

Yes. A person that owns or licenses personal identifying information of a New Mexico resident shall implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal identifying information from unauthorized access, destruction, use, modification or disclosure. N.M. Stat. Ann. § 57-12C-4.

Additionally, a person that owns or licenses records containing personal identifying information of a New Mexico resident shall arrange for proper disposal of the records when they are no longer reasonably needed for business purposes. As used in this section, “proper disposal” means shredding, erasing or otherwise modifying the personal identifying information contained in the records to make the personal identifying information unreadable or undecipherable. N.M. Stat. Ann. § 57-12C-3.

What Are The Possible Consequences Of A Violation?

When the attorney general has a reasonable belief that a violation of the Data Breach Notification Act has occurred, the attorney general may bring an action on the behalf of individuals and in the name of the state alleging a violation of that act. 

In any action filed by the attorney general pursuant to the Data Breach Notification Act, the court may: (1) issue an injunction; and (2) award damages for actual costs or losses, including consequential financial losses.

If the court determines that a person violated the Data Breach Notification Act knowingly or recklessly, the court may impose a civil penalty of the greater of $25,000 or, in the case of failed notification, $10 per instance of failed notification up to a maximum of $150,000. N.M. Stat. Ann. § 57-12C-11.

Are There Any Exemptions/Exceptions?

Any person that is licensed to maintain or possess computerized data containing personal identifying information of a New Mexico resident that the person does not own or license shall notify the owner or licensee of the information of any security breach in the most expedient time possible, but not later than forty-five calendar days following discovery of the breach, except as provided in Section 9 of the Data Breach Notification Act; provided that notification to the owner or licensee of the information is not required if, after an appropriate investigation, the person determines that the security breach does not give rise to a significant risk of identity theft or fraud. N.M. Stat. Ann. § 57-12C-6(C).

Nevada

Who Is Covered?

Any data collector that owns or licenses computerized data which includes personal information. Nev. Rev. Stat. Ann. § 603A.220(1).

“Data collector” means any governmental agency, institution of higher education, corporation, financial institution or retail operator or any other type of business entity or association that, for any purpose, whether by automated collection or otherwise, handles, collects, disseminates or otherwise deals with nonpublic personal information. Nev. Rev. Stat. Ann. § 603A.030.

What Information Is Protected?

“Personal information” means a natural person’s first name or first initial and last name in combination with any one or more of the following data elements, when the name and data elements are not encrypted:

  1. Social security number.
  2. Driver’s license number, driver authorization card number or identification card number.
  3. Account number, credit card number or debit card number, in combination with any required security code, access code or password that would permit access to the person’s financial account.
  4. A medical identification number or a health insurance identification number.
  5. A user name, unique identifier or electronic mail address in combination with a password, access code or security question and answer that would permit access to an online account. Nev. Rev. Stat. Ann. § 603A.040(1).

What Is A “Breach”?

“Breach of the security of the system data” means unauthorized acquisition of computerized data that materially compromises the security, confidentiality or integrity of personal information maintained by the data collector. The term does not include the good faith acquisition of personal information by an employee or agent of the data collector for a legitimate purpose of the data collector, so long as the personal information is not used for a purpose unrelated to the data collector or subject to further unauthorized disclosure. Nev. Rev. Stat. Ann. § 603A.020.

What Triggers Notification?

The discovery or notification of the breach of data relating to any resident of Nevada whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Nev. Rev. Stat. Ann. § 603A.220(1).

How Is Notice Provided To Individuals?

Timing: The disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the system data. Nev. Rev. Stat. Ann. § 603A.220(1).

Delivery: Notice may be by:

  1. Written notification.
  2. Electronic notification, if the notification provided is consistent with the provisions of the E-Sign Act.
  3. Substitute notification, if the data collector demonstrates that the cost of providing notification would exceed $250,000, the affected class of subject persons to be notified exceeds 500,000 or the data collector does not have sufficient contact information. Nev. Rev. Stat. Ann. § 603A.220(4).

Content: None specified.

Is Notice To The Government Required?

No.

Is Notice To Credit Reporting Agencies Required?

Yes. If a data collector determines that notification is required to be given pursuant to the provisions of this section to more than 1,000 persons at any one time, the data collector shall also notify, without unreasonable delay, any consumer reporting agency that compiles and maintains files on consumers on a nationwide basis, of the time the notification is distributed and the content of the notification. Nev. Rev. Stat. Ann. § 603A.220(6)

Are There Security Measure Standards?

Yes. A data collector that maintains records which contain personal information of a resident of this state shall implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification or disclosure. Nev. Rev. Stat. Ann. § 603A.210(1).

Contract Requirements: Additionally, a contract for the disclosure of the personal information of a resident of this state which is maintained by a data collector must include a provision requiring the person to whom the information is disclosed to implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification or disclosure. Nev. Rev. Stat. Ann. § 603A.210(3).

Payment Cards: If a data collector doing business in this state accepts a payment card in connection with a sale of goods or services, the data collector shall comply with the current version of the Payment Card Industry (PCI) Data Security Standard, as adopted by the PCI Security Standards Council or its successor organization, with respect to those transactions, not later than the date for compliance set forth in the Payment Card Industry (PCI) Data Security Standard or by the PCI Security Standards Council or its successor organization. Nev. Rev. Stat. Ann. § 603A.215(1).

Destruction of Records: A business that maintains records which contain personal information concerning the customers of the business shall take reasonable measures to ensure the destruction of those records when the business decides that it will no longer maintain the records. “Reasonable measures to ensure the destruction” means any method that modifies the records containing the personal information in such a way as to render the personal information contained in the records unreadable or undecipherable, including, without limitation: (1) Shredding of the record containing the personal information; or (2) Erasing of the personal information from the records. Nev. Rev. Stat. Ann. § 603A.200.

What Are The Possible Consequences Of A Violation?

If the Attorney General or a district attorney of any county has reason to believe that any person is violating, proposes to violate or has violated the provisions of Nev. Rev. Stat. Ann. § 603A.010 to 603A.290, inclusive, the Attorney General or district attorney may bring an action against that person to obtain a temporary or permanent injunction against the violation. Nev. Rev. Stat. Ann. § 603A.290.

Are There Any Exemptions/Exceptions?

A data collector will be deemed in compliance with the notification requirements if it:

  1. Maintains its own notification policies and procedures as part of an information security policy for the treatment of personal information that is otherwise consistent with the timing requirements of this section shall be deemed to be in compliance with the notification requirements of this section if the data collector notifies subject persons in accordance with its policies and procedures in the event of a breach of the security of the system data.
  2. Is subject to and complies with the privacy and security provisions of the Gramm-Leach-Bliley Act, 15 U.S.C. §§ 6801, et seq., shall be deemed to be in compliance with the notification requirements of this section. Nev. Rev. Stat. Ann. § 603A.220(5).

Nebraska

Who Is Covered?

An individual or a commercial entity that conducts business in Nebraska and that owns or licenses computerized data that includes personal information about a resident of Nebraska. Neb. Rev. Stat. Ann § 87-803(1).

What Information Is Protected?

Personal information means either of the following:

A. A user name or email address, in combination with a password or security question and answer, that would permit access to an online account; or

B. A Nebraska resident’s first name or first initial and last name in combination with any one or more of the following data elements that relate to the resident if either the name or the data elements are not encrypted, redacted, or otherwise altered by any method or technology in such a manner that the name or data elements are unreadable:

  1. Social security number;
  2. Motor vehicle operator’s license number or state identification card number;
  3. Account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to a resident’s financial account;
  4. Unique electronic identification number or routing code, in combination with any required security code, access code, or password; or
  5. Unique biometric data, such as a fingerprint, voice print, or retina or iris image, or other unique physical representation. Neb. Rev. Stat. Ann § 87-802(5).

What Is A “Breach”?

Breach of the security of the system means the unauthorized acquisition of unencrypted computerized data that compromises the security, confidentiality, or integrity of personal information maintained by an individual or a commercial entity. Good faith acquisition of personal information by an employee or agent of an individual or a commercial entity for the purposes of the individual or the commercial entity is not a breach of the security of the system if the personal information is not used or subject to further unauthorized disclosure. Acquisition of personal information pursuant to a search warrant, subpoena, or other court order or pursuant to a subpoena or order of a state agency is not a breach of the security of the system. Neb. Rev. Stat. Ann § 87-802(1).

What Triggers Notification?

After becoming aware of a breach of the security of the system, determining there is a likelihood that personal information has been or will be used for an unauthorized purpose and that the use of information about a Nebraska resident for an unauthorized purpose has occurred or is reasonably likely to occur. Neb. Rev. Stat. Ann § 87-803(1).

How Is Notice Provided To Individuals?

Timing: Notice shall be made as soon as possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system. Neb. Rev. Stat. Ann § 87-803(1).

Delivery: Notice may be by:

  1. Written notice;
  2. Telephonic notice;
  3. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. 7001; or
  4. Substitute notice, if the individual or commercial entity required to provide notice demonstrates that the cost of providing notice will exceed seventy-five thousand dollars, that the affected class of Nebraska residents to be notified exceeds one hundred thousand residents, or that the individual or commercial entity does not have sufficient contact information to provide notice. Neb. Rev. Stat. Ann § 87-802(4).

Content: None specified.

Is Notice To The Government Required?

Yes. If notice of a breach of security of the system is required, the individual or commercial entity shall also, not later than the time when notice is provided to the Nebraska resident, provide notice of the breach of security of the system to the Attorney General. Neb. Rev. Stat. Ann § 87-803(2).

Is Notice To Credit Reporting Agencies Required?

No.

Are There Security Measure Standards?

Yes. To protect personal information from unauthorized access, acquisition, destruction, use, modification, or disclosure, an individual or a commercial entity that conducts business in Nebraska and owns, licenses, or maintains computerized data that includes personal information about a resident of Nebraska shall implement and maintain reasonable security procedures and practices that are appropriate to the nature and sensitivity of the personal information owned, licensed, or maintained and the nature and size of, and the resources available to, the business and its operations, including safeguards that protect the personal information when the individual or commercial entity disposes of the personal information. Neb. Rev. Stat. Ann § 87-808(1).

Additionally, an individual or commercial entity that discloses computerized data that includes personal information about a Nebraska resident to a nonaffiliated, third-party service provider shall require by contract that the service provider implement and maintain reasonable security procedures and practices that:

  1. Are appropriate to the nature of the personal information disclosed to the service provider; and
  2. Are reasonably designed to help protect the personal information from unauthorized access, acquisition, destruction, use, modification, or disclosure. Neb. Rev. Stat. Ann § 87-808(2).

An individual or commercial entity is in compliance with these security procedures and practices if it:

  1. Complies with a state or federal law that provides greater protection to personal information than the protections that this section provides; or
  2. Complies with the regulations promulgated under Title V of the Gramm-Leach-Bliley Act or the Health Insurance Portability and Accountability Act if the individual or commercial entity is subject to either or both of such acts or sections. Neb. Rev. Stat. Ann § 87-808(3).

What Are The Possible Consequences Of A Violation?

For purposes of the data breach notification requirements, the Attorney General may issue subpoenas and seek and recover direct economic damages for each affected Nebraska resident. Neb. Rev. Stat. Ann § 87-808(1).

A violation of section 87-808 [security standards] shall be considered an unfair or deceptive act or practice under Neb. Rev. Stat. Ann § 59-1602, and the attorney general may seek an injunction and civil penalties. A violation of section 87-808 does not give rise to a private cause of action. Neb. Rev. Stat. Ann § 87-808(2).

Are There Any Exemptions/Exceptions

An individual or a commercial entity that maintains its own notice procedures which are part of an information security policy for the treatment of personal information and which are otherwise consistent with the timing requirements of section 87-803, is deemed to be in compliance with the notice requirements of section 87-803 if the individual or the commercial entity notifies affected Nebraska residents and the Attorney General in accordance with its notice procedures in the event of a breach of the security of the system. Neb. Rev. Stat. Ann § 87-804(2). 

Also, an individual or a commercial entity that is regulated by state or federal law and that maintains procedures for a breach of the security of the system pursuant to the laws, rules, regulations, guidances, or guidelines established by its primary or functional state or federal regulator is deemed to be in compliance with section 87-803 if the individual or commercial entity notifies affected Nebraska residents and the Attorney General in accordance with the maintained procedures in the event of a breach of the security of the system. Neb. Rev. Stat. Ann § 87-804(1).

Maryland

Who Is Covered?

A business that owns, licenses, or maintains computerized data that includes personal information of an individual residing in Maryland. Md. Code Ann., Com. Law § 14-3504(b).

 

What Information Is Protected?

“Personal information” means:

A. An individual’s first name or first initial and last name in combination with any one or more of the following data elements, when the data elements are not encrypted, redacted, or otherwise protected by another method that renders the information unreadable or unusable:

  1. A social security number, an individual taxpayer identification number, a passport number, or other identification number issued by the federal government;
  2. A driver’s license number or state identification card number;
  3. An account number, a credit card number, or a debit card number, in combination with any required security code, access code, or password, that permits access to an individual’s financial account;
  4. Health information, including information about an individual’s mental health;
  5. A health insurance policy or certificate number or health insurance subscriber identification number, in combination with a unique identifier used by an insurer or an employer that is self-insured, that permits access to an individual’s health information; 
  6. Biometric data of an individual generated by automatic measurements of an individual’s biological characteristics such as a fingerprint, voice print, genetic print, retina or iris image, or other unique biological characteristic, that can be used to uniquely authenticate the individual’s identity when the individual accesses a system or account; or
  7. For purposes of the notifications required under § 14-3504(b)(2), (c), (d), (e), (f), and (g) of this subtitle, genetic information with respect to an individual;Md. Code Ann., Com. Law § 14-3501(e).

B. A user name or e-mail address in combination with a password or security question and answer that permits access to an individual’s e-mail account; or

C. For the purposes of the requirements of this title other than the notifications required under § 14-3504(b)(2), (c), (d), (e), (f), and (g) of this subtitle, genetic information with respect to an individual when the genetic information is not encrypted, redacted, or otherwise protected by another method that renders the information unreadable or unusable, including:

  1. Data, regardless of its format, that results from the analysis of a biological sample of the individual or from another source that enables equivalent information to be obtained and that concerns genetic material;
  2. Deoxyribonucleic acids;
  3. Ribonucleic acids;
  4. Genes;
  5. Chromosomes;
  6. Alleles;
  7. Genomes;
  8. Alterations or modifications to deoxyribonucleic acids or ribonucleic acids;
  9. Single nucleotide polymorphisms;
  10. Uninterrupted data that results from the analysis of a biological sample from the individual or other sources; and
  11. Information extrapolated, derived, or inferred from item 1, 2, 3, 4, 5, 6, 7, 8, 9, or 10 of this item. Md. Code Ann., Com. Law § 14-3501

 

What Is A “Breach”?

“Breach of the security of a system” means the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of the personal information maintained by a business. Md. Code Ann., Com. Law § 14-3504(a).

 

What Triggers Notification?

A determination following an investigation that the breach of the security of the system creates a likelihood that personal information has been or will be misused. Md. Code Ann., Com. Law § 14-3504(b).

 

Likelihood of Harm Analysis

Notification to the individual in not necessary if the business reasonably determines that the breach of the security of the system does not create a likelihood that personal information has been or will be misused. Md. Code Ann., Com. Law § 14-3504(c)(2).

 

How Is Notice Provided To Individuals?

Timing: Notice must be given as soon as reasonably practicable, but not later than 45 days after the business discovers or is notified of the breach of the security system. Md. Code Ann., Com. Law § 14-3504(b)(3).

 

Delivery: Notice may be made by:

  1. Written notice sent to the most recent address of the individual in the records of the business;
  2. Electronic mail to the most recent electronic mail address of the individual in the records of the business, if: (i)  The individual has expressly consented to receive electronic notice; or (ii)  The business conducts its business primarily through Internet account transactions or the Internet;
  3. Telephonic notice, to the most recent telephone number of the individual in the records of the business; or
  4. Substitute notice if the business does not have sufficient contact information to give notice in accordance with item (1), (2), or (3) of this subsection. Substitute notice shall consist of: shall consist of: (a) Electronically mailing the notice to an individual entitled to notification under subsection (b) of this section, if the business has an electronic mail address for the individual to be notified; (b) Conspicuous posting of the notice on the website of the business, if the business maintains a website; and (c) Notification to major print or broadcast media in geographic areas where the individuals affected by the breach likely reside.

 

Content: Except for a breach involving only an email account, notification must include:

  1. To the extent possible, a description of the categories of information that were, or are reasonably believed to have been, acquired by an unauthorized person, including which of the elements of personal information were, or are reasonably believed to have been, acquired;
  2. Contact information for the business making the notification, including the business’s address, telephone number, and toll-free telephone number if one is maintained;
  3. The toll-free telephone numbers and addresses for the major consumer reporting agencies; and
  4. The toll-free telephone numbers, addresses, and website addresses for the Federal Trade Commission and the Office of the Attorney General, and a statement that an individual can obtain information from these sources about steps the individual can take to avoid identity theft. Md. Code Ann., Com. Law § 14-3504(g).

If the breach involves only an email account, notification may be made in electronic or other form, subject to several restrictions, that directs the individual whose personal information has been breached promptly to:

  1. Change the individual’s password and security question or answer, as applicable; or
  2. Take other steps appropriate to protect the email account with the business and all other online accounts for which the individual uses the same user name or email and password or security question or answer. Md. Code Ann., Com. Law § 14-3504(i).

 

Is Notice To The Government Required?

Yes, notice must be provided to the Attorney General prior to providing notice to affected residents. The notice shall include, at a minimum: (i) The number of affected individuals residing in the State; (ii) A description of the breach of the security of a system, including when and how it occurred; (iii) Any steps the business has taken or plans to take relating to the breach of the security of a system; and (iv) The form of notice that will be sent to affected individuals and a sample notice. Md. Code Ann., Com. Law § 14-3504(h).

 

Is Notice To Credit Reporting Agencies Required?

Yes. If a business is required under § 14-3504 of this subtitle to give notice of a breach of the security of a system to 1,000 or more individuals, the business also shall notify, without unreasonable delay, each consumer reporting agency that compiles and maintains files on consumers on a nationwide basis of the timing, distribution, and content of the notices. Md. Code Ann., Com. Law § 14-3506(a).

 

Are There Security Measure Standards?

Yes. To protect personal information from unauthorized access, use, modification, or disclosure, a business that owns or licenses personal information of an individual residing in the state shall implement and maintain reasonable security procedures and practices that are appropriate to the nature of the personal information owned or licensed and the nature and size of the business and its operations. Md. Code Ann., Com. Law § 14-3503(a).

Additionally, a business that uses a nonaffiliated third party as a service provider to perform services for the business and discloses personal information about an individual residing in the state under a written contract with the third party shall require by contract that the third party implement and maintain reasonable security procedures and practices that are:

 

  1. Appropriate to the nature of the personal information disclosed to the nonaffiliated third party; and
  2. Reasonably designed to help protect the personal information from unauthorized access, use, modification, disclosure, or destruction.

Data Destruction Standards: When a business is destroying a customer’s, an employee’s, or a former employee’s records that contain personal information of the customer, employee, or former employee, the business shall take reasonable steps to protect against unauthorized access to or use of the personal information, taking into account:

 

  1. The sensitivity of the records;
  2. The nature and size of the business and its operations;
  3. The costs and benefits of different destruction methods; and
  4. Available technology.

 

What Are The Possible Consequences Of A Violation?

A violation is an unfair or deceptive trade practice which allows for enforcement action by the Attorney General and a private right of action for any injury or loss sustained. Md. Code Ann., Com. Law §§ 14-3508; 13-401.

 

Are There Any Exemptions/Exceptions?

A business that complies with the requirements for notification procedures, the protection or security of personal information, or the destruction of personal information under the rules, regulations, procedures, or guidelines established by the primary or functional federal or state regulator of the business shall be deemed to be in compliance with this subtitle. Md. Code Ann., Com. Law § 14-3507(b).

Additionally, businesses that are subject to and in compliance with GLBA, FACTA or HIPAA, among other acts, are deemed to be in compliance. Md. Code Ann., Com. Law § 14-3507(c), (d).

Louisiana

Who Is Covered?

Any person that owns or licenses computerized data that includes personal information, or any agency that owns or licenses computerized data that includes personal information. La. Rev. Stat. Ann. § 51:3074

What Information Is Protected?

“Personal information” means the first name or first initial and last name of an individual resident of this state in combination with any one or more of the following data elements, when the name or the data element is not encrypted or redacted:

  1. Social security number.
  2. Driver’s license number or state identification card number.
  3. Account number, credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account.
  4. Passport number.
  5. Biometric data, meaning data generated by automatic measurements of an individual’s biological characteristics, such as fingerprints, voice print, eye retina or iris, or other unique biological characteristic that is used by the owner or licensee to uniquely authenticate an individual’s identity when the individual accesses a system or account. La. Rev. Stat. Ann. § 51:3073(4).

What Is A “Breach”?

“Breach of the security of the system” means the compromise of the security, confidentiality, or integrity of computerized data that results in, or there is a reasonable likelihood to result in, the unauthorized acquisition of and access to personal information maintained by an agency or person. Good faith acquisition of personal information by an employee or agent of an agency or person for the purposes of the agency or person is not a breach of the security of the system, provided that the personal information is not used for, or is subject to, unauthorized disclosure. La. Rev. Stat. Ann. § 51:3073(2).

What Triggers Notification?

Discovery of a breach in the security of the system involving a resident’s personal information that was, or is reasonably believed to have been, acquired by an unauthorized person. La. Rev. Stat. Ann. § 51:3074(C).

Likelihood of Harm Analysis: Notification as provided in this Section shall not be required if after a reasonable investigation, the person or business determines that there is no reasonable likelihood of harm to the residents of this state. The person or business shall retain a copy of the written determination and supporting documentation for five years from the date of discovery of the breach of the security system. If requested in writing, the person or business shall send a copy of the written determination and supporting documentation to the attorney general no later than thirty days from the date of receipt of the request. La. Rev. Stat. Ann. § 51:3074(I).

How Is Notice Provided To Individuals?

Timing: Notification must be made in the most expedient time possible and without unreasonable delay but not later than sixty days from the discovery of the breach, consistent with the legitimate needs of law enforcement or any measures necessary to determine the scope of the breach, prevent further disclosures, and restore the reasonable integrity of the data system. La. Rev. Stat. Ann. § 51:3074(E).

Delivery: Notification may be made by:

  1. Written notification.
  2. Electronic notification, if the notification provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. 7001.
  3. Substitute notification, if an agency or person demonstrates that the cost of providing notification would exceed one hundred thousand dollars, or that the affected class of persons to be notified exceeds one hundred thousand, or the agency or person does not have sufficient contact information. La. Rev. Stat. Ann. § 51:3074(G).

Content: None specified.

Is Notice To The Government Required?

Yes. When notice to Louisiana citizens is required, the person or agency shall provide written notice detailing the breach of the security of the system to the Consumer Protection Section of the Attorney General’s Office. Notice shall include the names of all Louisiana citizens affected by the breach. La. Admin. Code tit.16 § III.701(A).

Is Notice To Credit Reporting Agencies Required?

No.

Are There Security Measure Standards?

Yes. Any person that conducts business in the state or that owns or licenses computerized data that includes personal information, or any agency that owns or licenses computerized data that includes personal information, shall implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. La. Rev. Stat. Ann. § 51:3074(A).

Also, any person that conducts business in the state or that owns or licenses computerized data that includes personal information, or any agency that owns or licenses computerized data that includes personal information shall take all reasonable steps to destroy or arrange for the destruction of the records within its custody or control containing personal information that is no longer to be retained by the person or business by shredding, erasing, or otherwise modifying the personal information in the records to make it unreadable or undecipherable through any means. La. Rev. Stat. Ann. § 51:3074(B).

What Are The Possible Consequences Of A Violation?

A civil action may be instituted to recover actual damages resulting from the failure to disclose in a timely manner to a person that there has been a breach of the security system resulting in the disclosure of a person’s personal information. La. Rev. Stat. Ann. § 51:3075.

Additionally, failure to provide timely notice may be punishable by a fine not to exceed $5,000 per violation. Notice to the attorney general shall be timely if received within 10 days of distribution of notice to Louisiana citizens. Each day notice is not received by the attorney general shall be deemed a separate violation. La. Admin. Code tit.16 § III.701(B).

Are There Any Exemptions/Exceptions?

An agency or person that maintains a notification procedure as part of its information security policy for the treatment of personal information which is otherwise consistent with the timing requirements of this Section shall be considered to be in compliance with the notification requirements of this Section if the agency or person notifies subject persons in accordance with the policy and procedure in the event of a breach of security of the system. La. Rev. Stat. Ann. § 51:3074(H).

Also, a financial institution that is subject to and in compliance with the Federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice, issued on March 7, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency and the Office of Thrift Supervision, and any revisions, additions, or substitutions relating to said interagency guidance, shall be deemed to be in compliance with this Chapter. La. Rev. Stat. Ann. § 51:3076.