Tag Archives: Arizona

Arizona

Who Is Covered?

Any person that conducts business in Arizona and that owns, maintains or licenses unencrypted and unredacted computerized personal information. Ariz. Rev. Stat. § 18-552(A).

 

What Information Is Protected?

“Personal Information” is defined as any of the following:

A. An individual’s user name or e-mail address, in combination with a password or security question and answer, that allows access to an online account.

B. An individual’s first name or first initial and last name in combination with one or more of the following “specified data elements”:

 

  1. An individual’s social security number.
  2. The number on an individual’s driver license or nonoperating identification license.
  3. A private key that is unique to an individual and that is used to authenticate or sign an electronic record.
  4. An individual’s financial account number or credit or debit card number in combination with any required security code, access code or password that would allow access to the individual’s financial account.
  5. An individual’s health insurance identification number.
  6. Information about an individual’s medical or mental health treatment or diagnosis by a health care professional.
  7. An individual’s passport number.
  8. An individual’s taxpayer identification number or an identity protection personal identification number issued by the United States Internal Revenue Service.
  9. Unique biometric data generated from a measurement or analysis of human body characteristics to authenticate an individual when the individual accesses an online account. Ariz. Rev. Stat. § 18-551(7), (11).

 

What Is A “Breach”?

A “breach” or “security system breach” means an unauthorized acquisition of and unauthorized access that materially compromises the security or confidentiality of unencrypted and unredacted computerized personal information maintained as part of a database of personal information regarding multiple individuals. Ariz. Rev. Stat. § 18-551(1).

A “security incident” means an event that creates reasonable suspicion that a person’s information systems or computerized data may have been compromised or that measures put in place to protect the person’s information systems or computerized data may have failed. Ariz. Rev. Stat. § 18-551(10).

 

What Triggers Notification?

An investigation following a security incident that results in a determination that there has been a security system breach. Ariz. Rev. Stat. § 18-552(B).

However, a person is not required to make the notification required by subsection B of this section if the person, an independent third-party forensic auditor or a law enforcement agency determines after a reasonable investigation that a security system breach has not resulted in or is not reasonably likely to result in substantial economic loss to affected individuals Ariz. Rev. Stat. § 18-552(J).

 

How Is Notice Provided To Individuals?

Timing: Subject to the needs of law enforcement, notification must be provided within 45 days after a determination that there has been a security system breach.

Delivery: The notification must be provided by one of the following methods:

 

  1. Written notice.
  2. E-mail notice if the person has e-mail addresses for the individuals who are subject to the notice.
  3. Telephonic notice, if telephonic contact is made directly with the affected individuals and is not through a prerecorded message.
  4. Substitute notice if the person demonstrates that the cost of providing notice pursuant to paragraph 1, 2 or 3 of this subsection would exceed fifty thousand dollars, that the affected class of subject individuals to be notified exceeds one hundred thousand individuals, or that the person does not have sufficient contact information. Substitute notice consists of all of the following: (a) A written letter to the attorney general that demonstrates the facts necessary for substitute notice; and (b) Conspicuous posting of the notice for at least forty-five days on the website of the person if the person maintains one. Ariz. Rev. Stat. § 18-552(F).

Content: The notification must include the following:

 

  1. The approximate date of the breach.
  2. A brief description of the personal information included in the breach.
  3. The toll-free numbers and addresses for the three largest nationwide consumer reporting agencies.
  4. The toll-free number, address and website address for the federal trade commission or any federal agency that assists consumers with identity theft matters. Ariz. Rev. Stat. § 18-552(E).

 

Is Notice To The Government Required?

Yes, if the breach requires notification of more than 1,000 individuals, the Attorney General and the Director of the Arizona Department of Homeland Security must be notified in writing. Ariz. Rev. Stat. § 18-552(B).

 

Is Notice To Credit Reporting Agencies Required?

Yes, if the breach requires notification of more than 1,000 individuals. Ariz. Rev. Stat. § 18-552(B).

 

Are There Security Measure Standards?

No.

 

What Are The Penalties For A Violation?

The attorney general may impose a civil penalty for a violation of this article not to exceed the lesser of $10,000 per affected individual or the total amount of economic loss sustained by affected individuals, but the maximum civil penalty from a breach or series of related breaches may not exceed $500,000. This section does not prevent the attorney general from recovering restitution for affected individuals. Ariz. Rev. Stat. § 18-552(L).

 

Are There Any Exemptions?

Yes. A person that maintains the person’s own notification procedures as part of an information security policy for the treatment of personal information and that is otherwise consistent with the requirements of this article, including the forty-five-day notification period requirement, is deemed to be in compliance with the notification requirements of this section if the person notifies subject individuals in accordance with the person’s policies if a security system breach occurs. Ariz. Rev. Stat. § 18-552(H).

Also, a person that complies with the notification requirements or security system breach procedures pursuant to the rules, regulations, procedures, guidance or guidelines established by the person’s primary or functional federal regulator is deemed to be in compliance with the requirements of subsection B, paragraph 1 of this section. Ariz. Rev. Stat. § 18-552(I).