
Tag Archives: data protection
Complete Text of CCPA Regulations

Privacy Legislation Chart

Georgia
Who Is Covered?
Any information broker or data collector that maintains computerized data that includes personal information of individuals. Ga. Code Ann. § 10-1-912(a).
“Data collector” means any state or local agency or subdivision thereof including any department, bureau, authority, public university or college, academy, commission, or other government entity; provided, however, that the term “data collector” shall not include any governmental agency whose records are maintained primarily for traffic safety, law enforcement, or licensing purposes or for purposes of providing public access to court records or to real or personal property information. Ga. Code Ann. § 10-1-911(2).
“Information broker” means any person or entity who, for monetary fees or dues, engages in whole or in part in the business of collecting, assembling, evaluating, compiling, reporting, transmitting, transferring, or communicating information concerning individuals for the primary purpose of furnishing personal information to nonaffiliated third parties, but does not include any governmental agency whose records are maintained primarily for traffic safety, law enforcement, or licensing purposes. Ga. Code Ann. § 10-1-911(3).
What Information Is Protected?
“Personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted or redacted:
- Social security number;
- Driver’s license number or state identification card number;
- Account number, credit card number, or debit card number, if circumstances exist wherein such a number could be used without additional identifying information, access codes, or passwords;
- Account passwords or personal identification numbers or other access codes; or
- Any of the items contained in subparagraphs 1 through 4 above when not in connection with the individual’s first name or first initial and last name, if the information compromised would be sufficient to perform or attempt to perform identity theft against the person whose information was compromised. Ga. Code Ann. § 10-1-911(6).
What Is A “Breach”?
“Breach of the security of the system” means unauthorized acquisition of an individual’s electronic data that compromises the security, confidentiality, or integrity of personal information of such individual maintained by an information broker or data collector. Good faith acquisition or use of personal information by an employee or agent of an information broker or data collector for the purposes of such information broker or data collector is not a breach of the security of the system, provided that the personal information is not used or subject to further unauthorized disclosure. Ga. Code Ann. § 10-1-911(1).
What Triggers Notification?
Notice must be given of any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of this state whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Ga. Code Ann. § 10-1-912(a).
How Is Notice Provided To Individuals?
Timing: The notice shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, or with any measures necessary to determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system. Ga. Code Ann. § 10-1-912(a).
Delivery: Notice may be made by:
- Written notice;
- Telephone notice;
- Electronic notice consistent with the requirements of the E-Sign Act; or
- Substitute notice, in certain circumstances. Ga. Code Ann. § 10-1-911(4).
Content: None specified.
Is Notice To The Government Required?
No.
Is Notice To Consumer Reporting Agencies Required?
Yes. In the event that an information broker or data collector discovers circumstances requiring notification pursuant to this Code section of more than 10,000 residents of this state at one time, the information broker or data collector shall also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nation-wide basis of the timing, distribution, and content of the notices. Ga. Code Ann. § 10-1-912(c).
Are There Security Measure Standards?
No.
What Are The Possible Consequences Of A Violation?
N/A.
Are There Any Exemptions/Exceptions
No.
Florida
Who Is Covered?
“Covered entity” means a sole proprietorship, partnership, corporation, trust, estate, cooperative, association, or other commercial entity that acquires, maintains, stores, or uses personal information. Fla. Stat. Ann. § 501.171(b).
What Information Is Protected?
“Personal information” means:
A. An individual’s first name or first initial and last name in combination with any one or more of the following data elements for that individual:
- A social security number;
- A driver license or identification card number, passport number, military identification number, or other similar number issued on a government document used to verify identity;
- A financial account number or credit or debit card number, in combination with any required security code, access code, or password that is necessary to permit access to an individual’s financial account;
- Any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; or
- An individual’s health insurance policy number or subscriber identification number and any unique identifier used by a health insurer to identify the individual.
B. A user name or e-mail address, in combination with a password or security question and answer that would permit access to an online account. Fla. Stat. Ann. § 501.171(g).
What Is A “Breach”?
“Breach of security” or “breach” means unauthorized access of data in electronic form containing personal information. Good faith access of personal information by an employee or agent of the covered entity does not constitute a breach of security, provided that the information is not used for a purpose unrelated to the business or subject to further unauthorized use. Fla. Stat. Ann. § 501.171(a).
What Triggers Notification?
Determination or reasonable belief of a breach of security. Fla. Stat. Ann. § 501.171(3), (4).
Likelihood of Harm Analysis: Notice is not required if, after an appropriate investigation and consultation with relevant federal, state, or local law enforcement agencies, the covered entity reasonably determines that the breach has not and will not likely result in identity theft or any other financial harm to the individuals whose personal information has been accessed. Such a determination must be documented in writing and maintained for at least 5 years. The covered entity shall provide the written determination to the department within 30 days after the determination. Fla. Stat. Ann. § 501.171(4)(c).
How Is Notice Provided To Individuals?
Timing: Notice to individuals shall be made as expeditiously as practicable and without unreasonable delay, taking into account the time necessary to allow the covered entity to determine the scope of the breach of security, to identify individuals affected by the breach, and to restore the reasonable integrity of the data system that was breached, but no later than 30 days after the determination of a breach or reason to believe a breach occurred, subject to certain exceptions. Fla. Stat. Ann. § 501.171(4)(a).
Delivery: Notice may be made by:
- Written notice sent to the mailing address of the individual in the records of the covered entity; or
- E-mail notice sent to the e-mail address of the individual in the records of the covered entity. Fla. Stat. Ann. § 501.171(4)(d).
Content: The notice must include:
- The date, estimated date, or estimated date range of the breach of security.
- A description of the personal information that was accessed or reasonably believed to have been accessed as a part of the breach of security.
- Information that the individual can use to contact the covered entity to inquire about the breach of security and the personal information that the covered entity maintained about the individual. Fla. Stat. Ann. § 501.171(4)(e).
Is Notice To The Government Required?
Yes. A covered entity shall provide notice to the Attorney General of any breach of security affecting 500 or more individuals in this state. Such notice must be provided to the Attorney General as expeditiously as practicable, but no later than 30 days after the determination of the breach or reason to believe a breach occurred, subject to certain exceptions. The notice must include:
- A synopsis of the events surrounding the breach at the time notice is provided.
- The number of individuals in this state who were or potentially have been affected by the breach.
- Any services related to the breach being offered or scheduled to be offered, without charge, by the covered entity to individuals, and instructions as to how to use such services.
- A copy of the notice sent to consumers or an explanation of the other actions taken.
- The name, address, telephone number, and e-mail address of the employee or agent of the covered entity from whom additional information may be obtained about the breach. Fla. Stat. Ann. § 501.171(3).
Is Notice To Credit Reporting Agencies Required?
Yes. If a covered entity discovers circumstances requiring notice pursuant to this section of more than 1,000 individuals at a single time, the covered entity shall also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in the Fair Credit Reporting Act, 15 U.S.C. s. 1681a(p), of the timing, distribution, and content of the notices. Fla. Stat. Ann. § 501.171(5).
Are There Security Measure Standards?
Yes. Each covered entity, governmental entity, or third-party agent shall take reasonable measures to protect and secure data in electronic form containing personal information. Fla. Stat. Ann. § 501.171(2).
Additionally, each covered entity or third-party agent shall take all reasonable measures to dispose, or arrange for the disposal, of customer records containing personal information within its custody or control when the records are no longer to be retained. Such disposal shall involve shredding, erasing, or otherwise modifying the personal information in the records to make it unreadable or undecipherable through any means. Fla. Stat. Ann. § 501.171(8).
What Are The Possible Consequences Of A Violation?
Any violation is an unfair or deceptive trade practice, and the failure to provide required notice to individuals or to the Attorney General can result in a civil penalty not to exceed $500,000, as follows:
- In the amount of $1,000 for each day up to the first 30 days following any violation and, thereafter, $50,000 for each subsequent 30-day period or portion thereof for up to 180 days.
- If the violation continues for more than 180 days, in an amount not to exceed $500,000. The civil penalties for failure to notify provided in this paragraph apply per breach and not per individual affected by the breach. Fla. Stat. Ann. § 501.171(9)
If the violation continues for more than 180 days, in an amount not to exceed $500,000.
The civil penalties for failure to notify provided in this paragraph apply per breach and not per individual affected by the breach. Fla. Stat. Ann. § 501.171(9)
There is no private cause of action. Fla. Stat. Ann. § 501.171(10).
Are There Any Exemptions/Exceptions?
Notice provided pursuant to rules, regulations, procedures, or guidelines established by the covered entity’s primary or functional federal regulator is deemed to be in compliance with the notice requirement in this subsection if the covered entity notifies affected individuals in accordance with the rules, regulations, procedures, or guidelines established by the primary or functional federal regulator in the event of a breach of security. Under this paragraph, a covered entity that timely provides a copy of such notice to the department is deemed to be in compliance with the notice requirement to the attorney general. Fla. Stat. Ann. § 501.171(4)(g).
Arizona
Who Is Covered?
Any person that conducts business in Arizona and that owns, maintains or licenses unencrypted and unredacted computerized personal information. Ariz. Rev. Stat. § 18-552(A).
What Information Is Protected?
“Personal Information” is defined as any of the following:
A. An individual’s user name or e-mail address, in combination with a password or security question and answer, that allows access to an online account.
B. An individual’s first name or first initial and last name in combination with one or more of the following “specified data elements”:
- An individual’s social security number.
- The number on an individual’s driver license or nonoperating identification license.
- A private key that is unique to an individual and that is used to authenticate or sign an electronic record.
- An individual’s financial account number or credit or debit card number in combination with any required security code, access code or password that would allow access to the individual’s financial account.
- An individual’s health insurance identification number.
- Information about an individual’s medical or mental health treatment or diagnosis by a health care professional.
- An individual’s passport number.
- An individual’s taxpayer identification number or an identity protection personal identification number issued by the United States Internal Revenue Service.
- Unique biometric data generated from a measurement or analysis of human body characteristics to authenticate an individual when the individual accesses an online account. Ariz. Rev. Stat. § 18-551(7), (11).
What Is A “Breach”?
A “breach” or “security system breach” means an unauthorized acquisition of and unauthorized access that materially compromises the security or confidentiality of unencrypted and unredacted computerized personal information maintained as part of a database of personal information regarding multiple individuals. Ariz. Rev. Stat. § 18-551(1).
A “security incident” means an event that creates reasonable suspicion that a person’s information systems or computerized data may have been compromised or that measures put in place to protect the person’s information systems or computerized data may have failed. Ariz. Rev. Stat. § 18-551(10).
What Triggers Notification?
An investigation following a security incident that results in a determination that there has been a security system breach. Ariz. Rev. Stat. § 18-552(B).
However, a person is not required to make the notification required by subsection B of this section if the person, an independent third-party forensic auditor or a law enforcement agency determines after a reasonable investigation that a security system breach has not resulted in or is not reasonably likely to result in substantial economic loss to affected individuals Ariz. Rev. Stat. § 18-552(J).
How Is Notice Provided To Individuals?
Timing: Subject to the needs of law enforcement, notification must be provided within 45 days after a determination that there has been a security system breach.
Delivery: The notification must be provided by one of the following methods:
- Written notice.
- E-mail notice if the person has e-mail addresses for the individuals who are subject to the notice.
- Telephonic notice, if telephonic contact is made directly with the affected individuals and is not through a prerecorded message.
- Substitute notice if the person demonstrates that the cost of providing notice pursuant to paragraph 1, 2 or 3 of this subsection would exceed fifty thousand dollars, that the affected class of subject individuals to be notified exceeds one hundred thousand individuals, or that the person does not have sufficient contact information. Substitute notice consists of all of the following: (a) A written letter to the attorney general that demonstrates the facts necessary for substitute notice; and (b) Conspicuous posting of the notice for at least forty-five days on the website of the person if the person maintains one. Ariz. Rev. Stat. § 18-552(F).
Content: The notification must include the following:
- The approximate date of the breach.
- A brief description of the personal information included in the breach.
- The toll-free numbers and addresses for the three largest nationwide consumer reporting agencies.
- The toll-free number, address and website address for the federal trade commission or any federal agency that assists consumers with identity theft matters. Ariz. Rev. Stat. § 18-552(E).
Is Notice To The Government Required?
Yes, if the breach requires notification of more than 1,000 individuals, the Attorney General and the Director of the Arizona Department of Homeland Security must be notified in writing. Ariz. Rev. Stat. § 18-552(B).
Is Notice To Credit Reporting Agencies Required?
Yes, if the breach requires notification of more than 1,000 individuals. Ariz. Rev. Stat. § 18-552(B).
Are There Security Measure Standards?
No.
What Are The Penalties For A Violation?
The attorney general may impose a civil penalty for a violation of this article not to exceed the lesser of $10,000 per affected individual or the total amount of economic loss sustained by affected individuals, but the maximum civil penalty from a breach or series of related breaches may not exceed $500,000. This section does not prevent the attorney general from recovering restitution for affected individuals. Ariz. Rev. Stat. § 18-552(L).
Are There Any Exemptions?
Yes. A person that maintains the person’s own notification procedures as part of an information security policy for the treatment of personal information and that is otherwise consistent with the requirements of this article, including the forty-five-day notification period requirement, is deemed to be in compliance with the notification requirements of this section if the person notifies subject individuals in accordance with the person’s policies if a security system breach occurs. Ariz. Rev. Stat. § 18-552(H).
Also, a person that complies with the notification requirements or security system breach procedures pursuant to the rules, regulations, procedures, guidance or guidelines established by the person’s primary or functional federal regulator is deemed to be in compliance with the requirements of subsection B, paragraph 1 of this section. Ariz. Rev. Stat. § 18-552(I).
Arkansas
Who Is Covered?
Any person or business that: (a) acquires, owns, or licenses unencrypted computerized data that includes personal information of Arkansas residents; or (b) maintains unencrypted computerized data that includes personal information of Arkansas residents that the person or business does not own. Ark. Code Ann. § 4-110-105(a), (b).
What Information Is Protected?
“Personal information” means an individual’s first name or first initial and his or her last name in combination with any one or more of the following data elements when either the name or the data element is not encrypted or redacted:
- Social security number;
- Driver’s license number or Arkansas identification card number;
- Account number, credit card number, or debit card number in combination with any required security code, access code, or password that would permit access to an individual’s financial account;
- Medical information; and
- Biometric data.
What Is A “Breach”?
“Breach of the security of the system” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by a person or business. Ark. Code Ann. § 4-110-103(1)(A).
What Triggers Notification?
Discovery or notification of a breach of the security of the system involving the unencrypted personal information of an Arkansas resident. Ark. Code Ann. § 4-110-105(a)(1).
However, notification is not required if, after a reasonable investigation, the person or business determines that there is no reasonable likelihood of harm to customers. Ark. Code Ann. § 4-110-105(d).
How Is Notice Provided To Individuals?
Timing: A person or business that acquires, owns, or licenses computerized data that includes personal information must provide disclosure in the most expedient time and manner possible and without unreasonable delay. Ark. Code Ann. § 4-110-105(a)(2).
A person or business that maintains computerized data that includes personal information that the person or business does not own shall notify the owner or licensee that there has been a breach of the security of the system immediately following discovery. Ark. Code Ann. § 4-110-105(b)(1).
Delivery: Notice may be provided by one of the following methods:
- Written notice;
- Electronic mail notice if the notice provided is consistent with the provisions of the E-Sign Act;
- Substitute notice under certain circumstances. Ark. Code Ann. § 4-110-105(e).
Content: None specified.
Is Notice To The Government Required?
Yes, if the breach of the security of a system affects the personal information of more than 1,000 individuals. Ark. Code Ann. § 4-110-105(b)(2).
Is Notice To Credit Reporting Agencies Required?
No.
Are There Security Measure Standards?
Yes. A person or business shall take all reasonable steps to destroy or arrange for the destruction of a customer’s records within its custody or control containing personal information that is no longer to be retained by the person or business by shredding, erasing, or otherwise modifying the personal information in the records to make it unreadable or undecipherable through any means. Additionally, it is a requirement to implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. Ark. Code Ann. § 4-110-104.
What Are The Possible Consequences Of A Violation?
Any violation of this chapter is punishable by action of the Attorney General under the provisions of Arkansas Deceptive Trade Practices Act, Ark. Code Ann. § 4-88-101 et seq., which provides, in part, for restitution and penalties not to exceed $10,000 per violation. Ark. Code Ann. § 4-110-108.
Are There Any Exemptions?
Yes. The provisions of this chapter do not apply to a person or business that is regulated by a state or federal law that provides greater protection to personal information and at least as thorough disclosure requirements for breaches of the security of personal information than that provided by this chapter. Compliance with the state or federal law shall be deemed compliance with this chapter with regard to the subjects covered by this chapter. Ark. Code Ann. § 4-110-106(a)(1), (2).
Alabama
Who Is Covered?
A “covered entity” is a person, sole proprietorship, partnership, government entity, corporation, nonprofit, trust, estate, cooperative association, or other business entity that acquires or uses sensitive personally identifying information. Ala. Code § 8-38-2(2).
What Information Is Protected?
“Sensitive Personally Identifying Information” is an Alabama resident’s first name or first initial and last name in combination with one or more of the following with respect to the same Alabama resident:
- A non-truncated social security number or tax identification number.
- A non-truncated driver’s license number, state-issued identification card number, passport number, military identification number, or other unique identification number issued on a government document used to verify the identity of a specific individual.
- A financial account number, including a bank account number, credit card number, or debit card number, in combination with any security code, access code, password, expiration date, or PIN, that is necessary to access the financial account or to conduct a transaction that will credit or debit the financial account.
- Any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional.
- An individual’s health insurance policy number or subscriber identification number and any unique identifier used by a health insurer to identify the individual.
- A user name or email address, in combination with a password or security question and answer that would permit access to an online account affiliated with the covered entity that is reasonably likely to contain or is used to obtain sensitive personally identifying information. Ala. Code § 8-38-2(6)(a).
What Is A “Breach”?
A “breach of security” or “breach” is the unauthorized acquisition of data in electronic form containing sensitive personally identifying information. Acquisition occurring over a period of time committed by the same entity constitutes one breach. Ala. Code § 8-38-2(1).
What Triggers Notification?
Notification is required when a covered entity determines that, as a result of a breach of security, sensitive personally identifying information has been acquired or is reasonably believed to have been acquired by an unauthorized person, and is reasonably likely to cause substantial harm to the individuals to whom the information relates, it shall give notice of the breach to each individual. Ala. Code § 8-38-5(a).
How Is Notice Provided To Individuals?
Timing: Notice to individuals shall be made as expeditiously as possible and without unreasonable delay. Ala. Code § 8-38-5(b).
Delivery: Notice must be given in writing, sent to the mailing address of the individual in the records of the covered entity, or by email notice sent to the email address of the individual in the records of the covered entity. Ala. Code § 8-38-5(d).
Substitute notice is allowed if direct notice is not feasible due to any of the following:
- Excessive cost. The term includes either of the following: a) Excessive cost to the covered entity relative to the resources of the covered entity. b) The cost to the covered entity exceeds $500,000.
- Lack of sufficient contact information for the individual required to be notified.
- The affected individuals exceed 100,000 persons.
Substitute notice must be by both:
- A conspicuous notice on the Internet website of the covered entity, if the covered entity maintains a website, for a period of 30 days; and
- Notice in print and in broadcast media, including major media in urban and rural areas where the affected individuals reside. Ala. Code § 8-38-6(e).
Content: The notice must include, at a minimum, all of the following:
- The date, estimated date, or estimated date range of the breach.
- A description of the sensitive personally identifying information that was acquired by an unauthorized person as part of the breach.
- A general description of the actions taken by a covered entity to restore the security and confidentiality of the personal information involved in the breach.
- A general description of steps an affected individual can take to protect himself or herself from identity theft.
- Information that the individual can use to contact the covered entity to inquire about the breach. Ala. Code § 8-38-5(d).
Is Notice To The Government Required?
Yes. If the number of individuals a covered entity is required to notify exceeds 1,000, the entity must provide written notice of the breach to the Attorney General as expeditiously as possible and without unreasonable delay. Ala. Code § 8-38-6(a).
The written notice must include:
- A synopsis of the events surrounding the breach at the time that notice is provided.
- The approximate number of individuals in the state who were affected by the breach.
- Any services related to the breach being offered or scheduled to be offered, without charge, by the covered entity to individuals, and instructions on how to use the services.
- The name, address, telephone number, and email address of the employee or agent of the covered entity from whom additional information may be obtained about the breach. Ala. Code § 8-38-6(b).
Is Notice To Credit Reporting Agencies Required?
Yes. If a covered entity discovers circumstances requiring notice of more than 1,000 individuals at a single time, the entity shall also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notices. Ala. Code § 8-38-7.
Are There Security Measure Standards?
Yes. “Reasonable security measures” means security measures practicable for the covered entity to implement and maintain, including consideration of all of the following:
- Designation of an employee or employees to coordinate the covered entity’s security measures to protect against a breach of security. An owner or manager may designate himself or herself.
- Identification of internal and external risks of a breach of security.
- Adoption of appropriate information safeguards to address identified risks of a breach of security and assess the effectiveness of such safeguards.
- Retention of service providers, if any, that are contractually required to maintain appropriate safeguards for sensitive personally identifying information.
- Evaluation and adjustment of security measures to account for changes in circumstances affecting the security of sensitive personally identifying information.
- Keeping the management of the covered entity, including its board of directors, if any, appropriately informed of the overall status of its security measures. Ala. Code § 8-38-3(b).
Additionally, an assessment of a covered entity’s security must be based upon the entity’s reasonable security measures as a whole and shall place an emphasis on data security failures that are multiple or systemic, including consideration of all of the following:
- The size of the covered entity.
- The amount of sensitive personally identifying information and the type of activities for which the sensitive personally identifying information is accessed, acquired, maintained, stored, utilized, or communicated by, or on behalf of, the covered entity.
- The covered entity’s cost to implement and maintain the reasonable security measures to protect against a breach of security relative to its resources. Ala. Code § 8-38-3(c).
Furthermore, a covered entity or third-party agent shall take reasonable measures to dispose, or arrange for the disposal, of records containing sensitive personally identifying information within its custody or control when the records are no longer to be retained pursuant to applicable law, regulations, or business needs. Disposal shall include shredding, erasing, or otherwise modifying the personal information in the records to make it unreadable or undecipherable through any reasonable means consistent with industry standards. Ala. Code § 8-38-10.
What Are The Possible Consequences Of A Violation?
A violation of the notification provisions is an unlawful trade practice under the Alabama Deceptive Trade Practices Act, with penalties not to exceed $500,000 per breach. Additionally, civil penalties of not more than $5,000 per day may be assessed for each consecutive day that the covered entity fails to take reasonable action to comply with the notice provisions. Ala. Code § 8-38-9.
Are There Any Exemptions?
Yes. A) An entity subject to or regulated by federal laws, rules, regulations, procedures, or guidance on data breach notification established or enforced by the federal government; or B) is subject to or regulated by state laws, rules, regulations, procedures, or guidance on data breach notification that are established or enforced by state government, and are at least as thorough as the notice requirements provided in Alabama’s breach notification law, is exempt from this chapter as long as the entity does all of the following:
- Maintains procedures pursuant to those laws, rules, regulations, procedures, or guidance.
- Provides notice to affected individuals pursuant to those laws, rules, regulations, procedures, or guidance.
- Timely provides a copy of the notice to the Attorney General when the number of individuals the entity notified exceeds 1,000.
District of Columbia
Who Is Covered?
Any person or entity who conducts business in the District of Columbia, and who, in the course of such business, owns or licenses computerized or other electronic data that includes personal information. D.C. Code § 28-3852(a).
What Information Is Protected?
“Personal information” means:
A. An individual’s first name, first initial and last name, or any other personal identifier, which, in combination with any of the following data elements, can be used to identify a person or the person’s information:
- Social security number, individual taxpayer identification number, passport number, driver’s license number, District of Columbia identification card number, military identification number, or other unique identification number issued on a government document commonly used to verify the identity of a specific individual;
- Account number, credit card number or debit card number, or any other number or code or combination of numbers or codes, such as an identification number, security code, access code, or password, that allows access to or use of an individual’s financial or credit account;
- Medical information;
- Genetic information and deoxyribonucleic acid profile;
- Health insurance information, including a policy number, subscriber information number, or any unique identifier used by a health insurer to identify the person that permits access to an individual’s health and billing information;
- Biometric data of an individual generated by automatic measurements of an individual’s biological characteristics, such as a fingerprint, voice print, genetic print, retina or iris image, or other unique biological characteristic, that is used to uniquely authenticate the individual’s identity when the individual accesses a system or account; or
- Any combination of data elements included in paragraphs 1 through 6 above that would enable a person to commit identity theft without reference to a person’s first name or first initial and last name or other independent personal identifier.
B. A user name or e-mail address in combination with a password, security question and answer, or other means of authentication, or any combination of data elements included in paragraphs 1 through 6 above that permits access to an individual’s e-mail account. D.C. Code § 28-3851(3).
What Is A “Breach”?
“Breach of the security of the system” means unauthorized acquisition of computerized or other electronic data or any equipment or device storing such data that compromises the security, confidentiality, or integrity of personal information maintained by the person or entity who conducts business in the District of Columbia. D.C. Code § 28-3851(1)(A).
Likelihood of Harm Exception: A “breach of the security of the system” does not include the acquisition of personal information of an individual that the person or entity reasonably determines, after a reasonable investigation and consultation with the Office of the Attorney General for the District of Columbia and federal law enforcement agencies, will likely not result in harm to the individual. D.C. Code § 28-3851(1)(B)(3).
What Triggers Notification?
Discovery of a breach of the security of the system. D.C. Code § 28-3852(a).
How Is Notice Provided To Individuals?
Timing: Notification must be made promptly and in the most expedient time possible and without unreasonable delay, subject to certain exceptions. D.C. Code § 28-3852(a).
Delivery: Notice may be made by:
- Written notice;
- Electronic notice if consistent with the requirements of the E-Sign Act;
- Substitute notice in certain circumstances. D.C. Code § 28-3851(2).
Content: The notification must include:
- To the extent possible, a description of the categories of information that were, or are reasonably believed to have been, acquired by an unauthorized person, including the elements of personal information that were, or are reasonably believed to have been, acquired;
- Contact information for the person or entity making the notification, including the business address, telephone number, and toll-free telephone number if one is maintained;
- The toll-free telephone numbers and addresses for the major consumer reporting agencies, including a statement notifying the resident of the right to obtain a security freeze free of charge pursuant to 15 U.S.C. § 1681c-1 and information regarding how a resident may request a security freeze; and
- The toll-free telephone numbers, addresses, and website addresses for the following entities, including a statement that an individual can obtain information from these sources about steps to take to avoid identity theft: (a) The Federal Trade Commission; and (b) The Office of the Attorney General for the District of Columbia. D.C. Code § 28-3852(a-1).
Additionally, the notification must offer to each District resident whose social security number or tax identification number was released identity theft protection services at no cost to such District resident for a period of not less than 18 months. The person or entity that experienced the breach of the security of its system shall provide all information necessary for District residents to enroll in the services required under this section. D.C. Code § 28-3852b.
Is Notice To The Government Required?
Yes. If the breach involves more than 50 residents, notice must be promptly given to the Attorney General including the following information:
- The name and contact information of the person or entity reporting the breach;
- The name and contact information of the person or entity that experienced the breach
- The nature of the breach of the security of the system, including the name of the person or entity that experienced the breach;
- The types of personal information compromised by the breach;
- The number of District residents affected by the breach;
- The cause of the breach, including the relationship between the person or entity that experienced the breach and the person responsible for the breach, if known;
- The remedial action taken by the person or entity to include steps taken to assist District residents affected by the breach;
- The date and time frame of the breach, if known;
- The address and location of corporate headquarters, if outside of the District;
- Any knowledge of foreign country involvement; and
- A sample of the notice to be provided to District residents. D.C. Code § 28-3852(b-1).
Is Notice To Credit Reporting Agencies Required?
Yes. If more than 1,000 notices must be sent, notice must also be provided to all national consumer reporting agencies without unreasonable delay. D.C. Code § 28-3852(c).
Are There Security Measure Standards?
Yes. A covered person or entity must implement and maintain reasonable security safeguards, including procedures and practices that are appropriate to the nature of the personal information and the nature and size of the entity or operation. D.C. Code § 28-3852a(a).
Additionally, when a person or entity is destroying records, including computerized or electronic records and devices containing computerized or electronic records, that contain personal information of a consumer, employee, or former employee of the person or entity, the person or entity shall take reasonable steps to protect against unauthorized access to or use of the personal information, taking into account: 1) The sensitivity of the records; 2) The nature and size of the business and its operations; 3) The costs and benefits of different destruction and sanitation methods; and 4) Available technology. D.C. Code § 28-3852a(c).
What Are The Possible Consequences Of A Violation?
A violation is an unfair or deceptive trade practice under D.C. Code § 28-3904(kk), which allows the attorney general to seek injunctive relief and civil penalties up to $5,000 per violation and up to $10,000 for each subsequent violation pursuant to D.C. Code § 28-3909. Consumers may bring a private cause of action pursuant to D.C. Code § 28-3905(k)(1)(A). D.C. Code § 28-3853.
Are There Exemptions/Exceptions?
A person or entity that maintains procedures for a breach notification system under the GLBA or the breach notification rules established pursuant to HIPAA, or HITECH, and provides notice in accordance with such Acts, and any rules, regulations, guidance and guidelines thereto, to each affected resident in the event of a breach, shall be deemed to be in compliance with this section with respect to the notification of residents whose personal information is included in the breach. The person or entity shall, in all cases, provide written notice of the breach of the security of the system to the Office of the Attorney General. D.C. Code § 28-3852(g).
Delaware
Who Is Covered?
Any person who conducts business in Delaware and who owns or licenses computerized data that includes personal information. 6 Del. C. § 12B-102(a).
What Information Is Protected?
“Personal information” means a Delaware resident’s first name or first initial and last name in combination with any one or more of the following data elements that relate to that individual:
- Social security number.
- Driver’s license number or state or federal identification card number.
- Account number, credit card number, or debit card number, in combination with any required security code, access code, or password that would permit access to a resident’s financial account.
- Passport number.
- A username or email address, in combination with a password or security question and answer that would permit access to an online account.
- Medical history, medical treatment by a health-care professional, diagnosis of mental or physical condition by a health care professional, or deoxyribonucleic acid profile.
- Health insurance policy number, subscriber identification number, or any other unique identifier used by a health insurer to identify the person.
- Unique biometric data generated from measurements or analysis of human body characteristics for authentication purposes.
- An individual taxpayer identification number. 6 Del. C. § 12B-101(7).
What Is A “Breach”?
“Breach of security” means:
- The unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information. Good faith acquisition of personal information by an employee or agent of any person for the purposes of such person is not a breach of security, provided that the personal information is not used for an unauthorized purpose or subject to further unauthorized disclosure.
- The unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information is not a breach of security to the extent that personal information contained therein is encrypted, unless such unauthorized acquisition includes, or is reasonably believed to include, the encryption key and the person that owns or licenses the encrypted information has a reasonable belief that the encryption key could render that personal information readable or useable. 6 Del. C. § 12B-101(1).
What Triggers Notification?
The determination of a breach of security involving the personal information of a resident of Delaware. “Determination of the breach of security” means the point in time at which a person who owns, licenses, or maintains computerized data has sufficient evidence to conclude that a breach of security of such computerized data has taken place. 6 Del. C. §§ 12B-102(a); 12B-101(2).
Likelihood of Harm Analysis: Notice is not required if, after an appropriate investigation, it is reasonably determined that a breach of security is unlikely to result in harm to any individuals whose personal information has been breached. 6 Del. C. § 12B-102(a).
How Is Notice Provided To Individuals?
Timing: Notice must be made without unreasonable delay but not later than 60 days after determination of the breach of security, subject to certain exceptions. 6 Del. C. § 12B-102(c).
Delivery: Notice may be made by:
- Written notice;
- Telephonic notice;
- Electronic notice if consistent with the E-Sign Act;
- Substitute notice, in certain circumstances. 6 Del. C. § 12B-101(5).
Content: None specified unless the breach includes a social security number, in which case the person shall offer to each resident, whose personal information, including social security number, was breached or is reasonably believed to have been breached, credit monitoring services at no cost to such resident for a period of one year. Such person shall provide all information necessary for such resident to enroll in such services and shall include information on how such resident can place a credit freeze on such resident’s credit file. 6 Del. C. § 12B-102(e).
Is Notice To The Government Required?
The Attorney General must be notified if the number of affected residents exceeds 500. 6 Del. C. § 12B-102(d).
Is Notice To Credit Reporting Agencies Required?
No.
Are There Security Measure Standards?
Yes. Any person who conducts business in Delaware and owns, licenses, or maintains personal information shall implement and maintain reasonable procedures and practices to prevent the unauthorized acquisition, use, modification, disclosure, or destruction of personal information collected or maintained in the regular course of business. 6 Del. C. § 12B-100.
What Are The Possible Consequences Of A Violation?
The Attorney General may bring an action in law or equity to address the violations of this chapter and for other relief that may be appropriate to ensure proper compliance with this chapter or to recover direct economic damages resulting from a violation, or both. 6 Del. C. § 12B-104.
Are There Any Exemptions/Exceptions?
A person that maintains its own notice procedures as part of an information security policy for the treatment of personal information, and whose procedures are otherwise consistent with the timing requirements of this chapter is deemed to be in compliance with the notice requirements of this chapter if the person notifies affected Delaware residents in accordance with its policies in the event of a breach of security. 6 Del. C. § 12B-103(a).
Additionally, a person that is regulated by state or federal law, including HIPAA and GLBA ,and that maintains procedures for a breach of security pursuant to the laws, rules, regulations, guidance, or guidelines established by its primary or functional state or federal regulator is deemed to be in compliance with this chapter if the person notifies affected Delaware residents in accordance with the maintained procedures when a breach of security occurs. 6 Del. C. § 12B-103(b).
Connecticut
Who Is Covered?
Any person who owns, licenses or maintains computerized data that includes personal information. Conn. Gen. Stat. § 36a-701b(a)(1).
What Information Is Protected?
“Personal information” means an individual’s (A) first name or first initial and last name in combination with any one, or more, of the following data: (i) Social Security number; (ii) taxpayer identification number; (iii) identity protection personal identification number issued by the Internal Revenue Service; (iv) driver’s license number, state identification card number, passport number, military identification number or other identification number issued by the government that is commonly used to verify identity; (v) credit or debit card number; (vi) financial account number in combination with any required security code, access code or password that would permit access to such financial account; (vii) medical information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; (viii) health insurance policy number or subscriber identification number, or any unique identifier used by a health insurer to identify the individual; or (ix) biometric information consisting of data generated by electronic measurements of an individual’s unique physical characteristics used to authenticate or ascertain the individual’s identity, such as a fingerprint, voice print, retina or iris image; or (B) user name or electronic mail address, in combination with a password or security question and answer that would permit access to an online account. Conn. Gen. Stat. § 36a-701b(a).
What Is A “Breach”?
“Breach of security” means unauthorized access to or unauthorized acquisition of electronic files, media, databases or computerized data, containing personal information when access to the personal information has not been secured by encryption or by any other method or technology that renders the personal information unreadable or unusable. Conn. Gen. Stat. § 36a-701b(a)(1).
What Triggers Notification?
Discovery of the breach to any resident of this state whose personal information was breached or is reasonably believed to have been breached. Conn. Gen. Stat. § 36a-701b(b)(1).
Likelihood of Harm Analysis: However, notification is not required if, after an appropriate investigation and consultation with relevant federal, state and local agencies responsible for law enforcement, the person reasonably determines that the breach will not likely result in harm to the individuals whose personal information has been acquired and accessed. Conn. Gen. Stat. § 36a-701b(b)(1).
How Is Notice Provided To Individuals?
Timing: Notice shall be made without unreasonable delay but not later than sixty days after the discovery of such breach, unless a shorter time is required under federal law, subject to certain exceptions. Conn. Gen. Stat. § 36a-701b(b)(1).
Delivery: Notice may be provided by:
- Written notice;
- Telephone notice;
- Electronic notice consistent with the requirements of the E-Sign Act;
- Substitute notice, provided such person demonstrates that the cost of providing notice in accordance with subdivision (1), (2) or (3) of this subsection would exceed $250,000, that the affected class of subject persons to be notified exceeds 500,000 persons or that the person does not have sufficient contact information. Substitute notice shall consist of the following: a) Electronic mail notice when the person has an electronic mail address for the affected persons; b) conspicuous posting of the notice on the website of the person if the person maintains one; and c) notification to major statewide media, including newspapers, radio and television. Conn. Gen. Stat. § 36a-701b(e).
In the event of a breach of login credentials under subparagraph (B) of subdivision (2) of subsection (a) of this section, notice to a resident may be provided in electronic or other form that directs the resident whose personal information was breached or is reasonably believed to have been breached to promptly change any password or security question and answer, as applicable, or to take other appropriate steps to protect the affected online account and all other online accounts for which the resident uses the same user name or electronic mail address and password or security question and answer. Conn. Gen. Stat. § 36a-701b(f)(1).
Content: The notice must offer affected residents appropriate identity theft prevention services and, if applicable, identity theft mitigation services. Such service or services must be provided at no cost to such residents for a period of not less than 24 months. The notice must provide all information necessary for such residents to enroll in the service or services and include information on how such residents can place a credit freeze on their credit files. Conn. Gen. Stat. § 36a-701b(b)(2)(B).
Likelihood of Harm Exception: Notification is not required if, after an appropriate investigation the person reasonably determines that the breach will not likely result in harm to the individuals whose personal information has been acquired or accessed. Conn. Gen. Stat. § 36a-701b(a)(1).
Is Notice To The Government Required?
Yes. Notice of a breach of security must be provided to the Attorney General. Conn. Gen. Stat. § 36a-701b(b)(2)(A).
Is Notice To Credit Reporting Agencies Required?
No.
Are There Security Measure Standards?
No.
What Are The Possible Consequences Of A Violation?
Failure to comply with the requirements constitutes an unfair trade practice for purposes of section 42-110b and shall be enforced by the Attorney General. Conn. Gen. Stat. § 36a-701b(g).
Are There Any Exemptions/Exceptions?
Any person that maintains such person’s own security breach procedures as part of an information security policy for the treatment of personal information and otherwise complies with the timing requirements of this section, shall be deemed to be in compliance with the security breach notification requirements of this section, provided such person notifies, as applicable, residents of this state, owners and licensees in accordance with such person’s policies in the event of a breach of security and in the case of notice to a resident, such person also notifies the Attorney General not later than the time when notice is provided to the resident.
Any person that maintains such a security breach procedure pursuant to the rules, regulations, procedures or guidelines established by the primary or functional regulator, as defined in 15 U.S.C. 6809(2), shall be deemed to be in compliance with the security breach notification requirements of this section, provided (1) such person notifies, as applicable, such residents of this state, owners, and licensees required to be notified under and in accordance with the policies or the rules, regulations, procedures or guidelines established by the primary or functional regulator in the event of a breach of security, and (2) if notice is given to a resident of this state in accordance with subdivision (1) of this subsection regarding a breach of security, such person also notifies the Attorney General not later than the time when notice is provided to the resident. Conn. Gen. Stat. § 36a-701b(g).
Any person that is subject to and in compliance with the privacy and security standards under the Health Insurance Portability and Accountability Act of 1996 and the Health Information Technology for Economic and Clinical Health Act (“HITECH”) shall be deemed to be in compliance with this section, provided that (1) any person required to provide notification to Connecticut residents pursuant to HITECH shall also provide notice to the Attorney General not later than the time when notice is provided to such residents if notification to the Attorney General would otherwise be required under subparagraph (A) of subdivision (2) of subsection (b) of this section, and (2) the person otherwise complies with the requirements of subparagraph (B) of subdivision (2) of subsection (b) of this section.Conn. Gen. Stat. § 36a-701b(h).
California
Who Is Covered?
A person or business doing business in California that: (a) owns or licenses computerized data that includes personal information; or (b) maintains computerized data that includes personal information that the person or business does not own. Cal Civ Code § 1798.82(a), (b).
What Information Is Protected?
For the purposes of providing disclosure of a breach, “personal information” is defined as:
A. An individual’s first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted:
- Social security number.
- Driver’s license number, California identification card number, tax identification number, passport number, military identification number, or other unique identification number issued on a government document commonly used to verify the identity of a specific individual.
- Account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account.
- Medical information.
- Health insurance information.
- Unique biometric data generated from measurements or technical analysis of human body characteristics, such as a fingerprint, retina, or iris image, used to authenticate a specific individual. Unique biometric data does not include a physical or digital photograph, unless used or stored for facial recognition purposes.
- Information or data collected through the use or operation of an automated license plate recognition system, or
B. A username or email address, in combination with a password or security question and answer that would permit access to an online account. Cal Civ Code § 1798.82(h).
What Is A “Breach”?
“Breach of the security of the system” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the person or business. Good faith acquisition of personal information by an employee or agent of the person or business for the purposes of the person or business is not a breach of the security of the system, provided that the personal information is not used or subject to further unauthorized disclosure. Cal Civ Code § 1798.82(g).
What Triggers Notification?
Discovery or notification of the breach in the security of the data to a resident of California (1) whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, or, (2) whose encrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person and the encryption key or security credential was, or is reasonably believed to have been, acquired by an unauthorized person and the person or business that owns or licenses the encrypted information has a reasonable belief that the encryption key or security credential could render that personal information readable or usable. Cal Civ Code § 1798.82(a).
How Is Notice Provided To Individuals?
Timing: The disclosure shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Cal Civ Code § 1798.82(a).
Delivery: Notice may be provided by one of the following:
- Written notice.
- Electronic notice, if the notice provided is consistent with the provisions of the E-Sign Act.
- Substitute notice, if the person or business demonstrates that the cost of providing notice would exceed $250,000, or that the affected class of subject persons to be notified exceeds 500,000, or the person or business does not have sufficient contact information. Substitute notice must consist of all of the following: a) Email notice when the person or business has an email address for the subject persons. b) Conspicuous posting, for a minimum of 30 days, of the notice on the internet website page of the person or business, if the person or business maintains one. For purposes of this subparagraph, conspicuous posting on the person’s or business’s internet website means providing a link to the notice on the home page or first significant page after entering the internet website that is in larger type than the surrounding text, or in contrasting type, font, or color to the surrounding text of the same size, or set off from the surrounding text of the same size by symbols or other marks that call attention to the link. c) Notification to major statewide media. Cal Civ Code § 1798.82(j).
Content: The statute provides a sample notification form that must include the following information, and the Attorney General provides online forms.
- The name and contact information of the reporting person or business subject to this section.
- A list of the types of personal information that were or are reasonably believed to have been the subject of a breach.
- If the information is possible to determine at the time the notice is provided, then any of the following: (i) the date of the breach, (ii) the estimated date of the breach, or (iii) the date range within which the breach occurred. The notification shall also include the date of the notice.
- Whether notification was delayed as a result of a law enforcement investigation, if that information is possible to determine at the time the notice is provided.
- A general description of the breach incident, if that information is possible to determine at the time the notice is provided.
- The toll-free telephone numbers and addresses of the major credit reporting agencies if the breach exposed a social security number or a driver’s license or California identification card number.
- If the person or business providing the notification was the source of the breach, an offer to provide appropriate identity theft prevention and mitigation services, if any, shall be provided at no cost to the affected person for not less than 12 months along with all information necessary to take advantage of the offer to any person whose information was or may have been breached if the breach exposed or may have exposed personal information. Cal Civ Code § 1798.82(d).
Is Notice To The Government Required?
Yes. A person or business that is required to issue a security breach notification pursuant to this section to more than 500 California residents as a result of a single breach of the security system shall electronically submit a single sample copy of that security breach notification, excluding any personally identifiable information, to the Attorney General. Cal Civ Code § 1798.82(f).
Is Notice To Consumer Reporting Agencies Required?
No.
Are There Security Measure Standards?
Yes. A business that owns, licenses, or maintains personal information about a California resident must implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. Cal Civ Code § 1798.81.5(b).
Additionally, a business that discloses personal information about a California resident pursuant to a contract with a nonaffiliated third party that is not subject to subdivision (b) shall require by contract that the third party implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. Cal Civ Code § 1798.81.5(c).
Further, a business shall take all reasonable steps to dispose, or arrange for the disposal, of customer records within its custody or control containing personal information when the records are no longer to be retained by the business by (a) shredding, (b) erasing, or (c) otherwise modifying the personal information in those records to make it unreadable or undecipherable through any means. Cal Civ Code § 1798.81.
These security measure and data disposal requirements do not apply to:
- A provider of health care, health care service plan, or contractor regulated by the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1).
- A financial institution as defined in Section 4052 of the Financial Code and subject to the California Financial Information Privacy Act (Division 1.2 (commencing with Section 4050) of the Financial Code).
- A covered entity governed by the medical privacy and security rules issued by the federal Department of Health and Human Services, Parts 160 and 164 of Title 45 of the Code of Federal Regulations, established pursuant to the Health Insurance Portability and Availability Act of 1996 (HIPAA).
- An entity that obtains information under an agreement pursuant to Article 3 (commencing with Section 1800) of Chapter 1 of Division 2 of the Vehicle Code and is subject to the confidentiality requirements of the Vehicle Code.
- A business that is regulated by state or federal law providing greater protection to personal information than that provided by this section in regard to the subjects addressed by this section. Compliance with that state or federal law shall be deemed compliance with this section with regard to those subjects. This paragraph does not relieve a business from a duty to comply with any other requirements of other state and federal law regarding the protection and privacy of personal information. Cal Civ Code § 1798.81.5(e).
What Are The Possible Consequences Of A Violation?
Under the breach notification laws, any customer injured by a violation may institute a civil action to recover damages. Additionally, if the business is subject to the California Consumer Privacy Act, a consumer can recover an amount not less than $100 and not greater than $750 per incident or actual damages, whichever is greater, for a violation of the duty to implement and maintain reasonable security procedures and practices. Cal Civ Code § 1798.84(b); Cal Civ Code § 1798.150(a).
The general breach notification law provides for injunctive relief but not civil penalties. Cal Civ Code § 1798.84(e).
Are There Any Exemptions/Exceptions?
The data breach notification law does not contain any exemptions or exceptions, but the California Consumer Privacy Act does not apply to, among other things, personal information collected, processed, sold, or disclosed pursuant to the federal Gramm-Leach-Bliley Act, protected health information that is collected by a covered entity or business associate pursuant to HIPAA and certain activity governed by the FCRA. Cal Civ Code § 1798.145.
