Florida

Who Is Covered?

“Covered entity” means a sole proprietorship, partnership, corporation, trust, estate, cooperative, association, or other commercial entity that acquires, maintains, stores, or uses personal information. Fla. Stat. Ann. § 501.171(b).

What Information Is Protected?

“Personal information” means:

A. An individual’s first name or first initial and last name in combination with any one or more of the following data elements for that individual:

  1. A social security number;
  2. A driver license or identification card number, passport number, military identification number, or other similar number issued on a government document used to verify identity;
  3. A financial account number or credit or debit card number, in combination with any required security code, access code, or password that is necessary to permit access to an individual’s financial account;
  4. Any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; or
  5. An individual’s health insurance policy number or subscriber identification number and any unique identifier used by a health insurer to identify the individual.

B. A user name or e-mail address, in combination with a password or security question and answer that would permit access to an online account. Fla. Stat. Ann. § 501.171(g).

What Is A “Breach”?

“Breach of security” or “breach” means unauthorized access of data in electronic form containing personal information. Good faith access of personal information by an employee or agent of the covered entity does not constitute a breach of security, provided that the information is not used for a purpose unrelated to the business or subject to further unauthorized use. Fla. Stat. Ann. § 501.171(a).

What Triggers Notification?

Determination or reasonable belief of a breach of security. Fla. Stat. Ann. § 501.171(3), (4).

Likelihood of Harm Analysis: Notice is not required if, after an appropriate investigation and consultation with relevant federal, state, or local law enforcement agencies, the covered entity reasonably determines that the breach has not and will not likely result in identity theft or any other financial harm to the individuals whose personal information has been accessed. Such a determination must be documented in writing and maintained for at least 5 years. The covered entity shall provide the written determination to the department within 30 days after the determination. Fla. Stat. Ann. § 501.171(4)(c).

How Is Notice Provided To Individuals?

Timing: Notice to individuals shall be made as expeditiously as practicable and without unreasonable delay, taking into account the time necessary to allow the covered entity to determine the scope of the breach of security, to identify individuals affected by the breach, and to restore the reasonable integrity of the data system that was breached, but no later than 30 days after the determination of a breach or reason to believe a breach occurred, subject to certain exceptions. Fla. Stat. Ann. § 501.171(4)(a).

Delivery: Notice may be made by:

  1. Written notice sent to the mailing address of the individual in the records of the covered entity; or
  2. E-mail notice sent to the e-mail address of the individual in the records of the covered entity. Fla. Stat. Ann. § 501.171(4)(d).

Content: The notice must include:

  1. The date, estimated date, or estimated date range of the breach of security.
  2. A description of the personal information that was accessed or reasonably believed to have been accessed as a part of the breach of security.
  3. Information that the individual can use to contact the covered entity to inquire about the breach of security and the personal information that the covered entity maintained about the individual. Fla. Stat. Ann. § 501.171(4)(e).

Is Notice To The Government Required?

Yes. A covered entity shall provide notice to the Attorney General of any breach of security affecting 500 or more individuals in this state. Such notice must be provided to the Attorney General as expeditiously as practicable, but no later than 30 days after the determination of the breach or reason to believe a breach occurred, subject to certain exceptions. The notice must include:

  1. A synopsis of the events surrounding the breach at the time notice is provided.
  2. The number of individuals in this state who were or potentially have been affected by the breach.
  3. Any services related to the breach being offered or scheduled to be offered, without charge, by the covered entity to individuals, and instructions as to how to use such services.
  4. A copy of the notice sent to consumers or an explanation of the other actions taken.
  5. The name, address, telephone number, and e-mail address of the employee or agent of the covered entity from whom additional information may be obtained about the breach. Fla. Stat. Ann. § 501.171(3).

Is Notice To Credit Reporting Agencies Required?

Yes. If a covered entity discovers circumstances requiring notice pursuant to this section of more than 1,000 individuals at a single time, the covered entity shall also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in the Fair Credit Reporting Act, 15 U.S.C. s. 1681a(p), of the timing, distribution, and content of the notices. Fla. Stat. Ann. § 501.171(5).

Are There Security Measure Standards?

Yes. Each covered entity, governmental entity, or third-party agent shall take reasonable measures to protect and secure data in electronic form containing personal information. Fla. Stat. Ann. § 501.171(2).

Additionally, each covered entity or third-party agent shall take all reasonable measures to dispose, or arrange for the disposal, of customer records containing personal information within its custody or control when the records are no longer to be retained. Such disposal shall involve shredding, erasing, or otherwise modifying the personal information in the records to make it unreadable or undecipherable through any means. Fla. Stat. Ann. § 501.171(8).

What Are The Possible Consequences Of A Violation?

Any violation is an unfair or deceptive trade practice, and the failure to provide required notice to individuals or to the Attorney General can result in a civil penalty not to exceed $500,000, as follows:

  1. In the amount of $1,000 for each day up to the first 30 days following any violation and, thereafter, $50,000 for each subsequent 30-day period or portion thereof for up to 180 days.
  2. If the violation continues for more than 180 days, in an amount not to exceed $500,000. The civil penalties for failure to notify provided in this paragraph apply per breach and not per individual affected by the breach. Fla. Stat. Ann. § 501.171(9)

If the violation continues for more than 180 days, in an amount not to exceed $500,000.

The civil penalties for failure to notify provided in this paragraph apply per breach and not per individual affected by the breach. Fla. Stat. Ann. § 501.171(9)

There is no private cause of action. Fla. Stat. Ann. § 501.171(10).

Are There Any Exemptions/Exceptions?

Notice provided pursuant to rules, regulations, procedures, or guidelines established by the covered entity’s primary or functional federal regulator is deemed to be in compliance with the notice requirement in this subsection if the covered entity notifies affected individuals in accordance with the rules, regulations, procedures, or guidelines established by the primary or functional federal regulator in the event of a breach of security. Under this paragraph, a covered entity that timely provides a copy of such notice to the department is deemed to be in compliance with the notice requirement to the attorney general. Fla. Stat. Ann. § 501.171(4)(g).