Tag Archives: District of Columbia

District of Columbia

Who Is Covered?

Any person or entity who conducts business in the District of Columbia, and who, in the course of such business, owns or licenses computerized or other electronic data that includes personal information. D.C. Code § 28-3852(a).

What Information Is Protected?

“Personal information” means:

A. An individual’s first name, first initial and last name, or any other personal identifier, which, in combination with any of the following data elements, can be used to identify a person or the person’s information:

  1. Social security number, individual taxpayer identification number, passport number, driver’s license number, District of Columbia identification card number, military identification number, or other unique identification number issued on a government document commonly used to verify the identity of a specific individual;
  2. Account number, credit card number or debit card number, or any other number or code or combination of numbers or codes, such as an identification number, security code, access code, or password, that allows access to or use of an individual’s financial or credit account;
  3. Medical information;
  4. Genetic information and deoxyribonucleic acid profile;
  5. Health insurance information, including a policy number, subscriber information number, or any unique identifier used by a health insurer to identify the person that permits access to an individual’s health and billing information;
  6. Biometric data of an individual generated by automatic measurements of an individual’s biological characteristics, such as a fingerprint, voice print, genetic print, retina or iris image, or other unique biological characteristic, that is used to uniquely authenticate the individual’s identity when the individual accesses a system or account; or
  7. Any combination of data elements included in paragraphs 1 through 6 above that would enable a person to commit identity theft without reference to a person’s first name or first initial and last name or other independent personal identifier.

B. A user name or e-mail address in combination with a password, security question and answer, or other means of authentication, or any combination of data elements included in paragraphs 1 through 6 above that permits access to an individual’s e-mail account. D.C. Code § 28-3851(3).

What Is A “Breach”?

“Breach of the security of the system” means unauthorized acquisition of computerized or other electronic data or any equipment or device storing such data that compromises the security, confidentiality, or integrity of personal information maintained by the person or entity who conducts business in the District of Columbia. D.C. Code § 28-3851(1)(A).

Likelihood of Harm Exception: A “breach of the security of the system” does not include the acquisition of personal information of an individual that the person or entity reasonably determines, after a reasonable investigation and consultation with the Office of the Attorney General for the District of Columbia and federal law enforcement agencies, will likely not result in harm to the individual. D.C. Code § 28-3851(1)(B)(3).

What Triggers Notification?

Discovery of a breach of the security of the system. D.C. Code § 28-3852(a).

How Is Notice Provided To Individuals?

Timing: Notification must be made promptly and in the most expedient time possible and without unreasonable delay, subject to certain exceptions. D.C. Code § 28-3852(a).

Delivery: Notice may be made by:

  1. Written notice;
  2. Electronic notice if consistent with the requirements of the E-Sign Act;
  3. Substitute notice in certain circumstances. D.C. Code § 28-3851(2).

Content: The notification must include:

  1. To the extent possible, a description of the categories of information that were, or are reasonably believed to have been, acquired by an unauthorized person, including the elements of personal information that were, or are reasonably believed to have been, acquired;
  2. Contact information for the person or entity making the notification, including the business address, telephone number, and toll-free telephone number if one is maintained;
  3. The toll-free telephone numbers and addresses for the major consumer reporting agencies, including a statement notifying the resident of the right to obtain a security freeze free of charge pursuant to 15 U.S.C. § 1681c-1 and information regarding how a resident may request a security freeze; and
  4. The toll-free telephone numbers, addresses, and website addresses for the following entities, including a statement that an individual can obtain information from these sources about steps to take to avoid identity theft: (a) The Federal Trade Commission; and (b) The Office of the Attorney General for the District of Columbia. D.C. Code § 28-3852(a-1).

Additionally, the notification must offer to each District resident whose social security number or tax identification number was released identity theft protection services at no cost to such District resident for a period of not less than 18 months. The person or entity that experienced the breach of the security of its system shall provide all information necessary for District residents to enroll in the services required under this section. D.C. Code § 28-3852b.

Is Notice To The Government Required?

Yes. If the breach involves more than 50 residents, notice must be promptly given to the Attorney General including the following information:

  1. The name and contact information of the person or entity reporting the breach;
  2. The name and contact information of the person or entity that experienced the breach
  3. The nature of the breach of the security of the system, including the name of the person or entity that experienced the breach;
  4. The types of personal information compromised by the breach;
  5. The number of District residents affected by the breach;
  6. The cause of the breach, including the relationship between the person or entity that experienced the breach and the person responsible for the breach, if known;
  7. The remedial action taken by the person or entity to include steps taken to assist District residents affected by the breach;
  8. The date and time frame of the breach, if known;
  9. The address and location of corporate headquarters, if outside of the District;
  10. Any knowledge of foreign country involvement; and
  11. A sample of the notice to be provided to District residents. D.C. Code § 28-3852(b-1).

Is Notice To Credit Reporting Agencies Required?

Yes. If more than 1,000 notices must be sent, notice must also be provided to all national consumer reporting agencies without unreasonable delay. D.C. Code § 28-3852(c).

Are There Security Measure Standards?

Yes. A covered person or entity must implement and maintain reasonable security safeguards, including procedures and practices that are appropriate to the nature of the personal information and the nature and size of the entity or operation. D.C. Code § 28-3852a(a).

Additionally, when a person or entity is destroying records, including computerized or electronic records and devices containing computerized or electronic records, that contain personal information of a consumer, employee, or former employee of the person or entity, the person or entity shall take reasonable steps to protect against unauthorized access to or use of the personal information, taking into account: 1) The sensitivity of the records; 2) The nature and size of the business and its operations; 3) The costs and benefits of different destruction and sanitation methods; and 4) Available technology. D.C. Code § 28-3852a(c).

What Are The Possible Consequences Of A Violation?

A violation is an unfair or deceptive trade practice under D.C. Code § 28-3904(kk), which allows the attorney general to seek injunctive relief and civil penalties up to $5,000 per violation and up to $10,000 for each subsequent violation pursuant to D.C. Code § 28-3909. Consumers may bring a private cause of action pursuant to D.C. Code § 28-3905(k)(1)(A). D.C. Code § 28-3853.

Are There Exemptions/Exceptions?

A person or entity that maintains procedures for a breach notification system under the GLBA or the breach notification rules established pursuant to HIPAA, or HITECH, and provides notice in accordance with such Acts, and any rules, regulations, guidance and guidelines thereto, to each affected resident in the event of a breach, shall be deemed to be in compliance with this section with respect to the notification of residents whose personal information is included in the breach. The person or entity shall, in all cases, provide written notice of the breach of the security of the system to the Office of the Attorney General. D.C. Code § 28-3852(g).