Tag Archives: Nebraska

Nebraska

Who Is Covered?

An individual or a commercial entity that conducts business in Nebraska and that owns or licenses computerized data that includes personal information about a resident of Nebraska. Neb. Rev. Stat. Ann § 87-803(1).

What Information Is Protected?

Personal information means either of the following:

A. A user name or email address, in combination with a password or security question and answer, that would permit access to an online account; or

B. A Nebraska resident’s first name or first initial and last name in combination with any one or more of the following data elements that relate to the resident if either the name or the data elements are not encrypted, redacted, or otherwise altered by any method or technology in such a manner that the name or data elements are unreadable:

  1. Social security number;
  2. Motor vehicle operator’s license number or state identification card number;
  3. Account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to a resident’s financial account;
  4. Unique electronic identification number or routing code, in combination with any required security code, access code, or password; or
  5. Unique biometric data, such as a fingerprint, voice print, or retina or iris image, or other unique physical representation. Neb. Rev. Stat. Ann § 87-802(5).

What Is A “Breach”?

Breach of the security of the system means the unauthorized acquisition of unencrypted computerized data that compromises the security, confidentiality, or integrity of personal information maintained by an individual or a commercial entity. Good faith acquisition of personal information by an employee or agent of an individual or a commercial entity for the purposes of the individual or the commercial entity is not a breach of the security of the system if the personal information is not used or subject to further unauthorized disclosure. Acquisition of personal information pursuant to a search warrant, subpoena, or other court order or pursuant to a subpoena or order of a state agency is not a breach of the security of the system. Neb. Rev. Stat. Ann § 87-802(1).

What Triggers Notification?

After becoming aware of a breach of the security of the system, determining there is a likelihood that personal information has been or will be used for an unauthorized purpose and that the use of information about a Nebraska resident for an unauthorized purpose has occurred or is reasonably likely to occur. Neb. Rev. Stat. Ann § 87-803(1).

How Is Notice Provided To Individuals?

Timing: Notice shall be made as soon as possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system. Neb. Rev. Stat. Ann § 87-803(1).

Delivery: Notice may be by:

  1. Written notice;
  2. Telephonic notice;
  3. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. 7001; or
  4. Substitute notice, if the individual or commercial entity required to provide notice demonstrates that the cost of providing notice will exceed seventy-five thousand dollars, that the affected class of Nebraska residents to be notified exceeds one hundred thousand residents, or that the individual or commercial entity does not have sufficient contact information to provide notice. Neb. Rev. Stat. Ann § 87-802(4).

Content: None specified.

Is Notice To The Government Required?

Yes. If notice of a breach of security of the system is required, the individual or commercial entity shall also, not later than the time when notice is provided to the Nebraska resident, provide notice of the breach of security of the system to the Attorney General. Neb. Rev. Stat. Ann § 87-803(2).

Is Notice To Credit Reporting Agencies Required?

No.

Are There Security Measure Standards?

Yes. To protect personal information from unauthorized access, acquisition, destruction, use, modification, or disclosure, an individual or a commercial entity that conducts business in Nebraska and owns, licenses, or maintains computerized data that includes personal information about a resident of Nebraska shall implement and maintain reasonable security procedures and practices that are appropriate to the nature and sensitivity of the personal information owned, licensed, or maintained and the nature and size of, and the resources available to, the business and its operations, including safeguards that protect the personal information when the individual or commercial entity disposes of the personal information. Neb. Rev. Stat. Ann § 87-808(1).

Additionally, an individual or commercial entity that discloses computerized data that includes personal information about a Nebraska resident to a nonaffiliated, third-party service provider shall require by contract that the service provider implement and maintain reasonable security procedures and practices that:

  1. Are appropriate to the nature of the personal information disclosed to the service provider; and
  2. Are reasonably designed to help protect the personal information from unauthorized access, acquisition, destruction, use, modification, or disclosure. Neb. Rev. Stat. Ann § 87-808(2).

An individual or commercial entity is in compliance with these security procedures and practices if it:

  1. Complies with a state or federal law that provides greater protection to personal information than the protections that this section provides; or
  2. Complies with the regulations promulgated under Title V of the Gramm-Leach-Bliley Act or the Health Insurance Portability and Accountability Act if the individual or commercial entity is subject to either or both of such acts or sections. Neb. Rev. Stat. Ann § 87-808(3).

What Are The Possible Consequences Of A Violation?

For purposes of the data breach notification requirements, the Attorney General may issue subpoenas and seek and recover direct economic damages for each affected Nebraska resident. Neb. Rev. Stat. Ann § 87-808(1).

A violation of section 87-808 [security standards] shall be considered an unfair or deceptive act or practice under Neb. Rev. Stat. Ann § 59-1602, and the attorney general may seek an injunction and civil penalties. A violation of section 87-808 does not give rise to a private cause of action. Neb. Rev. Stat. Ann § 87-808(2).

Are There Any Exemptions/Exceptions

An individual or a commercial entity that maintains its own notice procedures which are part of an information security policy for the treatment of personal information and which are otherwise consistent with the timing requirements of section 87-803, is deemed to be in compliance with the notice requirements of section 87-803 if the individual or the commercial entity notifies affected Nebraska residents and the Attorney General in accordance with its notice procedures in the event of a breach of the security of the system. Neb. Rev. Stat. Ann § 87-804(2). 

Also, an individual or a commercial entity that is regulated by state or federal law and that maintains procedures for a breach of the security of the system pursuant to the laws, rules, regulations, guidances, or guidelines established by its primary or functional state or federal regulator is deemed to be in compliance with section 87-803 if the individual or commercial entity notifies affected Nebraska residents and the Attorney General in accordance with the maintained procedures in the event of a breach of the security of the system. Neb. Rev. Stat. Ann § 87-804(1).