New Mexico

Who Is Covered?

 Any person that owns or licenses elements that include personal identifying information of a New Mexico resident. N.M. Stat. Ann. § 57-12C-2(C)(6).

What Information Is Protected?

“Personal identifying information” means an individual’s first name or first initial and last name in combination with one or more of the following data elements that relate to the individual, when the data elements are not protected through encryption or redaction or otherwise rendered unreadable or unusable:

  1. Social security number;
  2. Driver’s license number;
  3. Government-issued identification number;
  4. Account number, credit card number or debit card number in combination with any required security code, access code or password that would permit access to a person’s financial account; or
  5. Biometric data N.M. Stat. Ann. § 57-12C-2(C)(1).

What Is A “Breach”?

“Security breach” means the unauthorized acquisition of unencrypted computerized data, or of encrypted computerized data and the confidential process or key used to decrypt the encrypted computerized data, that compromises the security, confidentiality or integrity of personal identifying information maintained by a person. N.M. Stat. Ann. § 57-12C-2(D).

What Triggers Notification?

A reasonable belief that the personal information of a New Mexico resident has been subject to a security breach. N.M. Stat. Ann. § 57-12C-6(A).

Likelihood of Harm Analysis: Notification to affected New Mexico residents is not required if, after an appropriate investigation, the person determines that the security breach does not give rise to a significant risk of identity theft or fraud. N.M. Stat. Ann. § 57-12C-6(B).

How Is Notice Provided To Individuals?

Timing: Notification must be made in the most expedient time possible, but not later than 45 calendar days following discovery of the security breach, except as provided in N.M. Stat. Ann. § 57-12C-9. N.M. Stat. Ann. § 57-12C-6(A).

Delivery: Notification may be by:

  1. United States mail;
  2. Electronic notification, if the person required to make the notification primarily communicates with the New Mexico resident by electronic means or if the notice provided is consistent with the requirements of 15 U.S.C. Section 7001; or
  3. A substitute notification, if the person demonstrates that: (a) the cost of providing notification would exceed $100,000; (b) the number of residents to be notified exceeds fifty thousand; or (c) the person does not have on record a physical address or sufficient contact information for the residents that the person or business is required to notify. N.M. Stat. Ann. § 57-12C-6(D).

Content: The notification must include:

  1. The name and contact information of the notifying person;
  2. A list of the types of personal identifying information that are reasonably believed to have been the subject of a security breach, if known;
  3. The date of the security breach, the estimated date of the breach or the range of dates within which the security breach occurred, if known;
  4. A general description of the security breach incident;
  5. The toll-free telephone numbers and addresses of the major consumer reporting agencies;
  6. Advice that directs the recipient to review personal account statements and credit reports, as applicable, to detect errors resulting from the security breach; and
  7. Advice that informs the recipient of the notification of the recipient’s rights pursuant to the federal Fair Credit Reporting Act. N.M. Stat. Ann. § 57-12C-7.

Is Notice To The Government Required?

Yes. A person that is required to issue notification of a security breach pursuant to the Data Breach Notification Act to more than 1,000 New Mexico residents as a result of a single security breach shall notify the office of the attorney general and major consumer reporting agencies of the security breach in the most expedient time possible, and no later than 45 calendar days, except as provided in N.M. Stat. Ann. § 57-12C-9. A person required to notify the attorney general and consumer reporting agencies pursuant to this section shall notify the attorney general of the number of New Mexico residents that received notification and shall provide a copy of the notification that was sent to affected residents within 45 calendar days following discovery of the security breach, except as provided in N.M. Stat. Ann. § 57-12C-9.

Is Notice To Credit Reporting Agencies Required?

Yes. See above.

Are There Security Measure Standards?

Yes. A person that owns or licenses personal identifying information of a New Mexico resident shall implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal identifying information from unauthorized access, destruction, use, modification or disclosure. N.M. Stat. Ann. § 57-12C-4.

Additionally, a person that owns or licenses records containing personal identifying information of a New Mexico resident shall arrange for proper disposal of the records when they are no longer reasonably needed for business purposes. As used in this section, “proper disposal” means shredding, erasing or otherwise modifying the personal identifying information contained in the records to make the personal identifying information unreadable or undecipherable. N.M. Stat. Ann. § 57-12C-3.

What Are The Possible Consequences Of A Violation?

When the attorney general has a reasonable belief that a violation of the Data Breach Notification Act has occurred, the attorney general may bring an action on the behalf of individuals and in the name of the state alleging a violation of that act. 

In any action filed by the attorney general pursuant to the Data Breach Notification Act, the court may: (1) issue an injunction; and (2) award damages for actual costs or losses, including consequential financial losses.

If the court determines that a person violated the Data Breach Notification Act knowingly or recklessly, the court may impose a civil penalty of the greater of $25,000 or, in the case of failed notification, $10 per instance of failed notification up to a maximum of $150,000. N.M. Stat. Ann. § 57-12C-11.

Are There Any Exemptions/Exceptions?

Any person that is licensed to maintain or possess computerized data containing personal identifying information of a New Mexico resident that the person does not own or license shall notify the owner or licensee of the information of any security breach in the most expedient time possible, but not later than forty-five calendar days following discovery of the breach, except as provided in Section 9 of the Data Breach Notification Act; provided that notification to the owner or licensee of the information is not required if, after an appropriate investigation, the person determines that the security breach does not give rise to a significant risk of identity theft or fraud. N.M. Stat. Ann. § 57-12C-6(C).