Tag Archives: Indiana

Indiana

Who Is Covered?

“Data base owner” means a person that owns or licenses computerized data that includes personal information. Ind. Code Ann. § 24-4.9-2-3.

 

What Information Is Protected?

“Personal information” means:

 

  1. A Social Security number that is not encrypted or redacted; or
  2. An individual’s first and last names, or first initial and last name, and one or more of the following data elements that are not encrypted or redacted: (A) A driver’s license number; (B) A state identification card number; (C) A credit card number; (D) A financial account number or debit card number in combination with a security code, password, or access code that would permit access to the person’s account. Ind. Code Ann. § 24-4.9-2-10.

 

What Is A “Breach”?

“Breach of the security of data” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by a person. The term includes the unauthorized acquisition of computerized data that have been transferred to another medium, including paper, microfilm, or a similar medium, even if the transferred data are no longer in a computerized format. Ind. Code Ann. § 24-4.9-2-2(a).

The term does not include the following:

 

  1. Good faith acquisition of personal information by an employee or agent of the person for lawful purposes of the person, if the personal information is not used or subject to further unauthorized disclosure.
  2. Unauthorized acquisition of a portable electronic device on which personal information is stored, if all personal information on the device is protected by encryption and the encryption key: (A) has not been compromised or disclosed; and (B) is not in the possession of or known to the person who, without authorization, acquired or has access to the portable electronic device. Ind. Code Ann. § 24-4.9-2-2(a).

 

What Triggers Notification?

Discovering or being notified of a breach of the security of data involving an Indiana resident where: 1) unencrypted personal information was or may have been acquired by an unauthorized person; or 2) encrypted personal information was or may have been acquired by an unauthorized person with access to the encryption key; provided, the data base owner knows, should know, or should have known that the unauthorized acquisition constituting the breach has resulted in or could result in identity deception, identity theft, or fraud affecting the Indiana resident. Ind. Code Ann. § 24-4.9-3-1.

 

How Is Notice Provided To Individuals?

Timing: A person required to make a disclosure or notification under this chapter shall make the disclosure or notification without unreasonable delay, but more than 45 days after the discovery of the breach, subject to certain exceptions. Ind. Code Ann. § 24-4.9-3-1(a).

Delivery: Disclosure may be made by:

 

  1. Mail;
  2. Telephone;
  3. Fax;
  4. Email, if the data base owner has the email address of the affected Indiana resident; or
  5. Substitute service in certain circumstances. Ind. Code Ann. § 24-4.9-3-4(a).

Content: None specified.

 

Is Notice To The Government Required?

Yes. Notice to the Attorney General is required whenever disclosure is required to Indiana residents. Ind. Code Ann. § 24-4.9-3-1(c).

 

Is Notice To Credit Reporting Agencies Required?

Yes. A data base owner required to make a disclosure to more than 1,000 consumers shall also disclose to each consumer reporting agency information necessary to assist the consumer reporting agency in preventing fraud, including personal information of an Indiana resident affected by the breach of the security of a system. Ind. Code Ann. § 24-4.9-3-1(b).

 

Are There Security Measure Standards?

Yes. Subject to certain exceptions [see § 24-4.9-3-3.5(a)], a data base owner shall implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect and safeguard from unlawful use or disclosure any personal information of Indiana residents collected or maintained by the data base owner. Ind. Code Ann. § 24-4.9-3-3.5(c).

Additionally, a data base owner shall not dispose of or abandon records or documents containing unencrypted and unredacted personal information of Indiana residents without shredding, incinerating, mutilating, erasing, or otherwise rendering the personal information illegible or unusable. Ind. Code Ann. § 24-4.9-3-3.5(d).

A person that knowingly or intentionally fails to comply with [the safeguard provisions] commits a deceptive act that is actionable only by the attorney general under this section, who may obtain:

 

  1. An injunction to enjoin further violations of this section.
  2. A civil penalty of not more than $5,000 per deceptive act.
  3. The attorney general’s reasonable costs in: a) the investigation of the deceptive act; and b) maintaining the action. Ind. Code Ann. § 24-4.9-3-3.5(e), (f).

 

What Are The Possible Consequences Of A Violation?

A person that fails to make a disclosure or notification commits a deceptive act that is actionable only by the attorney general under this chapter, and a failure to make a required disclosure or notification in connection with a related series of breaches of the security of data constitutes one deceptive act. Burns Ind. Code Ann. § 24-4.9-4-1.

The Attorney General may bring an action to obtain:

 

  1. An injunction to enjoin future violations of IC 24-4.9-3.
  2. A civil penalty of not more than $150,000 per deceptive act.
  3. The attorney general’s reasonable costs in: a) the investigation of the deceptive act; and b) maintaining the action. Burns Ind. Code Ann. § 24-4.9-4-2.

 

Are There Any Exemptions/Exceptions?

A data base owner that maintains its own disclosure procedures as part of an information privacy policy or a security policy is not required to make a separate disclosure under this chapter if the data base owner’s information privacy policy or security policy is at least as stringent as the disclosure requirements described in [the Indiana law]. Burns Ind. Code Ann. § 24-4.9-3-4(c).

Also, a data base owner that maintains its own disclosure procedures as part of an information privacy, security policy, or compliance plan under any of the following acts is not required to make a disclosure under this chapter if the data base owner’s information privacy, security policy, or compliance plan requires that Indiana residents be notified of a breach of the security of data without unreasonable delay and the data base owner complies with the data base owner’s information privacy, security policy, or compliance plan:

 

  1. The federal USA PATRIOT Act;
  2. Executive Order 13224;
  3. The federal Driver’s Privacy Protection Act;
  4. The federal Fair Credit Reporting Act;
  5. The federal Financial Modernization Act of 1999; or
  6. The federal Health Insurance Portability and Accountability Act. Burns Ind. Code Ann. § 24-4.9-3-4(d)