Who Is Covered?
A city, county or state agency, individual or a commercial entity that conducts business in Idaho and that owns or licenses computerized data that includes personal information about a resident of Idaho. Idaho Code § 28-51-105(1).
What Information Is Protected?
“Personal information” means an Idaho resident’s first name or first initial and last name in combination with any one or more of the following data elements that relate to the resident, when either the name or the data elements are not encrypted:
- Social security number;
- Driver’s license number or Idaho identification card number; or
- Account number, or credit or debit card number, in combination with any required security code, access code, or password that would permit access to a resident’s financial account. Idaho Code § 28-51-104(5).
What Is A “Breach”?
“Breach of the security of the system” means the illegal acquisition of unencrypted computerized data that materially compromises the security, confidentiality, or integrity of personal information for one or more persons maintained by an agency, individual or a commercial entity. Good faith acquisition of personal information by an employee or agent of an agency, individual or a commercial entity for the purposes of the agency, individual or the commercial entity is not a breach of the security of the system, provided that the personal information is not used or subject to further unauthorized disclosure. Idaho Code § 28-51-104(2).
What Triggers Notification?
A determination following investigation that the misuse of information about an Idaho resident has occurred or is reasonably likely to occur. Idaho Code § 28-51-105(1).
Likelihood of Harm Exception: Notification is not necessary if, after becoming aware of a breach of the security of the system, the covered entity conducts in good faith a reasonable and prompt investigation and determines there has been no misuse and no reasonable likelihood of the misuse of an Idaho resident’s personal information. Idaho Code § 28-51-105(1).
How Is Notice Provided To Individuals?
Timing: Notice must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach, to identify the individuals affected, and to restore the reasonable integrity of the computerized data system. Idaho Code § 28-51-105(1).
Delivery: Notice may be provided by:
- Written notice to the most recent address the agency, individual or commercial entity has in its records;
- Telephonic notice;
- Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. section 7001; or
- Substitute notice, in some circumstances. Idaho Code § 28-51-104(4).
Content: Not specified.
Is Notice To The Government Required?
Only by government agencies. When an agency becomes aware of a breach of the security of the system, it shall, within 24 hours of such discovery, notify the office of the Idaho attorney general. Nothing contained in this section relieves a state agency’s responsibility to report a security breach to the office of the chief information officer within the department of administration, pursuant to the Idaho technology authority policies. Idaho Code § 28-51-105(1).
Is Notice To Credit Reporting Agencies Required?
No.
Are There Security Measure Standards?
No.
What Are The Possible Consequences Of A Violation?
If a covered agency, individual or commercial entity fails to give required notice, their primary regulator may bring a civil action to enforce compliance with that section and enjoin that agency, individual or commercial entity from further violations. Any agency, individual or commercial entity that intentionally fails to give notice in accordance with section 28-51-105, Idaho Code, shall be subject to a fine of not more than $25,000 per breach of the security of the system. Idaho Code § 28-51-107.
Are There Any Exemptions/Exceptions?
Yes. An agency, individual or a commercial entity that maintains its own notice procedures as part of an information security policy for the treatment of personal information, and whose procedures are otherwise consistent with the timing requirements of section 28-51-105, Idaho Code, is deemed to be in compliance with the notice requirements of section 28-51-105, Idaho Code, if the agency, individual or commercial entity notifies affected Idaho residents in accordance with its policies in the event of a breach of security of the system. Idaho Code § 28-51-106(1).
Also, an individual or commercial entity that is regulated by state or federal law and that maintains procedures for a breach of the security of the system pursuant to the laws, rules, regulations, guidances, or guidelines established by its primary or functional state or federal regulator is deemed to be in compliance with section 28-51-105, Idaho Code, if the individual or commercial entity complies with the maintained procedures when a breach of the security of the system occurs. Idaho Code § 28-51-106(2).
