Tag Archives: Iowa

Iowa

Who Is Covered?

Any person who owns or licenses computerized data that includes a consumer’s [Iowa resident’s] personal information that is used in the course of the person’s business, vocation, occupation, or volunteer activities. Iowa Code § 715C.2(1).

What Information Is Protected?

“Personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements that relate to the individual if any of the data elements are not encrypted, redacted, or otherwise altered by any method or technology in such a manner that the name or data elements are unreadable or are encrypted, redacted, or otherwise altered by any method or technology but the keys to unencrypt, unredact, or otherwise read the data elements have been obtained through the breach of security:

  1. Social security number.
  2. Driver’s license number or other unique identification number created or collected by a government body.
  3. Financial account number, credit card number, or debit card number in combination with any required expiration date, security code, access code, or password that would permit access to an individual’s financial account.
  4. Unique electronic identifier or routing code, in combination with any required security code, access code, or password that would permit access to an individual’s financial account.
  5. Unique biometric data, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data. Iowa Code § 715C.1(11).

What Is A “Breach”?

“Breach of security” means unauthorized acquisition of personal information maintained in computerized form by a person that compromises the security, confidentiality, or integrity of the personal information. Iowa Code § 715C.1(1).

“Breach of security” also means unauthorized acquisition of personal information maintained by a person in any medium, including on paper, that was transferred by the person to that medium from computerized form and that compromises the security, confidentiality, or integrity of the personal information. Good faith acquisition of personal information by a person or that person’s employee or agent for a legitimate purpose of that person is not a breach of security, provided that the personal information is not used in violation of applicable law or in a manner that harms or poses an actual threat to the security, confidentiality, or integrity of the personal information. Iowa Code § 715C.1(1).

What Triggers Notification?

Discovery of a breach of security. Iowa Code § 715C.2(1).

Likelihood of Harm Analysis: Notification is not required if, after an appropriate investigation or after consultation with the relevant federal, state, or local agencies responsible for law enforcement, the person determined that no reasonable likelihood of financial harm to the consumers whose personal information has been acquired has resulted or will result from the breach. Such a determination must be documented in writing and the documentation must be maintained for five years. Iowa Code § 715C.2(6).

How Is Notice Provided To Individuals?

Timing: The consumer notification shall be made in the most expeditious manner possible and without unreasonable delay, consistent with the legitimate needs of law enforcement as provided in subsection 3, and consistent with any measures necessary to sufficiently determine contact information for the affected consumers, determine the scope of the breach, and restore the reasonable integrity, security, and confidentiality of the data. Iowa Code § 715C.2(1).

Delivery: Notice may be made by:

  1. Written notice to the last available address the person has in the person’s records.
  2. Electronic notice if the person’s customary method of communication with the consumer is by electronic means or is consistent with the provisions of the E-Sign Act.
  3. Substitute notice, in certain circumstances. Iowa Code § 715C.2(4).

Content: The notice must include:

  1. A description of the breach of security.
  2. The approximate date of the breach of security.
  3. The type of personal information obtained as a result of the breach of security.
  4. Contact information for consumer reporting agencies. Advice to the consumer to report suspected incidents of identity theft to local law enforcement or the attorney general. Iowa Code § 715C.2(5).

Is Notice To The Government Required?

Yes. Any person who owns or licenses computerized data that includes a consumer’s personal information that is used in the course of the person’s business, vocation, occupation, or volunteer activities and that was subject to a breach of security requiring notification to more than five hundred residents of this state pursuant to this section shall give written notice of the breach of security to the director of the consumer protection division of the office of the attorney general within five business days after giving notice of the breach of security to any consumer pursuant to this section. Iowa Code § 715C.2(8).

Is Notice To Credit Reporting Agencies Required?

No.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

A violation of this chapter is an unlawful practice pursuant to Iowa Code § 714.16 and, in addition to the remedies provided to the attorney general pursuant to Iowa Code § 714.16, the attorney general may seek and obtain an order that a party held to violate this section pay damages to the attorney general on behalf of a person injured by the violation. Iowa Code § 715C.2(9).

Are There Any Exemptions/Exceptions?

The notification requirements do not apply to any of the following:

  1. A person who complies with notification requirements or breach of security procedures that provide greater protection to personal information and at least as thorough disclosure requirements than that provided by this section pursuant to the rules, regulations, procedures, guidance, or guidelines established by the person’s primary or functional federal regulator.
  2. A person who complies with a state or federal law that provides greater protection to personal information and at least as thorough disclosure requirements for breach of security or personal information than that provided by this section.
  3. A person who is subject to and complies with regulations promulgated pursuant to Tit. V of the federal Gramm-Leach-Bliley Act.
  4. A person who is subject to and complies with regulations promulgated pursuant to Tit. II, subtit. F of the federal Health Insurance Portability and Accountability Act. Iowa Code § 715C.2(7).