Tag Archives: Wisconsin

Wisconsin

Who Is Covered?

“Entity” means a person, other than an individual, that does any of the following:

  1. Conducts business in this state and maintains personal information in the ordinary course of business.
  2. Licenses personal information in this state.
  3. Maintains for a resident of this state a depository account as defined in s. 815.18 (2) (e).
  4. Lends money to a resident of this state. Wis. Stat. Ann. § 134.98(1)(a).

What Information Is Protected?

“Personal information” means an individual’s last name and the individual’s first name or first initial, in combination with and linked to any of the following elements, if the element is not publicly available information and is not encrypted, redacted, or altered in a manner that renders the element unreadable:

  1. The individual’s social security number.
  2. The individual’s driver’s license number or state identification number.
  3. The number of the individual’s financial account number, including a credit or debit card account number, or any security code, access code, or password that would permit access to the individual’s financial account.
  4. The individual’s deoxyribonucleic acid profile, as defined in s. 939.74 (2d) (a).
  5. The individual’s unique biometric data, including fingerprint, voice print, retina or iris image, or any other unique physical representation. Wis. Stat. Ann. § 134.98(1)(b).

What Is A “Breach”?

Knowledge that personal information of a resident of Wisconsin has been acquired by a person not authorized to acquire the personal information by:

  1. An entity whose principal place of business is located in this state or an entity that maintains or licenses personal information in this state; or
  2. An entity whose principal place of business is not located in this state. Wis. Stat. Ann. § 134.98(2)(a), (b).

What Triggers Notification?

Knowledge that personal information in the entity’s possession has been acquired by a person not authorized to acquire the personal information. Wis. Stat. Ann. § 134.98(2)(a), (b).

However, an entity is not required to provide notice of the acquisition of personal information if any of the following applies:

  1. The acquisition of personal information does not create a material risk of identity theft or fraud to the subject of the personal information. 
  2. The personal information was acquired in good faith by an employee or agent of the entity, if the personal information is used for a lawful purpose of the entity. Wis. Stat. Ann. § 134.98(2)(cm).

How Is Notice Provided To Individuals?

Timing: Subject to the needs of law enforcement, an entity shall provide the notice within a reasonable time, not to exceed 45 days after the entity learns of the acquisition of personal information. A determination as to reasonableness under this paragraph shall include consideration of the number of notices that an entity must provide and the methods of communication available to the entity. Wis. Stat. Ann. § 134.98(3)(a).

Delivery: An entity must provide notice by mail or by a method the entity has previously employed to communicate with the subject of the personal information. If an entity cannot with reasonable diligence determine the mailing address of the subject of the personal information, and if the entity has not previously communicated with the subject of the personal information, the entity shall provide notice by a method reasonably calculated to provide actual notice to the subject of the personal information. Wis. Stat. Ann. § 134.98(3)(b).

Content: The notice shall indicate that the entity knows of the unauthorized acquisition of personal information pertaining to the subject of the personal information. Wis. Stat. Ann. § 134.98(2)(b).

Is Notice To The Government Required?

No.

Is Notice To Credit Reporting Agencies Required?

Yes. If, as the result of a single incident, an entity is required to notify 1,000 or more individuals that personal information pertaining to the individuals has been acquired, the entity shall without unreasonable delay notify all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notices sent to the individuals. Wis. Stat. Ann. § 134.98(2)(br).

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

Failure to comply with this section is not negligence or a breach of any duty, but may be evidence of negligence or a breach of a legal duty. Wis. Stat. Ann. § 134.98(4).

Are There Any Exemptions/Exceptions?

This section does not apply to any of the following: a) An entity that is subject to, and in compliance with, the privacy and security requirements of 15 USC 6801 to 6827, or a person that has a contractual obligation to such an entity, if the entity or person has in effect a policy concerning breaches of information security. b) An entity that is described in 45 CFR 164.104 (a), if the entity complies with the requirements of 45 CFR part 164. Wis. Stat. Ann. § 134.98(3m).