Washington

Who Is Covered?

Any person or business that conducts business in Washington and that owns or licenses data that includes personal information. Wash. Rev. Code Ann. § 19.255.010(1).

What Information Is Protected?

“Personal information” is:

A. An individual’s first name or first initial and last name in combination with any one or more of the following data elements:

  1. Social security number;
  2. Driver’s license number or Washington identification card number;
  3. Account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account, or any other numbers or information that can be used to access a person’s financial account;
  4. Full date of birth;
  5. Private key that is unique to an individual and that is used to authenticate or sign an electronic record;
  6. Student, military, or passport identification number;
  7. Health insurance policy number or health insurance identification number;
  8. Any information about a consumer’s medical history or mental or physical condition or about a health care professional’s medical diagnosis or treatment of the consumer; or
  9. Biometric data generated by automatic measurements of an individual’s biological characteristics such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that is used to identify a specific individual;

B. Username or email address in combination with a password or security questions and answers that would permit access to an online account; and

C. Any of the data elements or any combination of the data elements described in subsection A, above, without the consumer’s first name or first initial and last name if:

  1. Encryption, redaction, or other methods have not rendered the data element or combination of data elements unusable; and
  2. The data element or combination of data elements would enable a person to commit identity theft against a consumer. Rev. Code Wash. (ARCW) § 19.255.005(2)(a).

What Is A “Breach”?

“Breach of the security of the system” means unauthorized acquisition of data that compromises the security, confidentiality, or integrity of personal information maintained by the person or business. Good faith acquisition of personal information by an employee or agent of the person or business for the purposes of the person or business is not a breach of the security of the system when the personal information is not used or subject to further unauthorized disclosure. Wash. Rev. Code Ann. § 19.255.005(1).

What Triggers Notification?

Any breach of the security of the system involving a resident’s personal information that was, or is reasonably believed to have been, acquired by an unauthorized person and the personal information was not secured. Wash. Rev. Code Ann. § 19.255.010(1).

Likelihood of Harm Analysis: Notice is not required if the breach of the security of the system is not reasonably likely to subject consumers to a risk of harm. The breach of secured personal information must be disclosed if the information acquired and accessed is not secured during a security breach or if the confidential process, encryption key, or other means to decipher the secured information was acquired by an unauthorized person. Wash. Rev. Code Ann. § 19.255.010(1).

How Is Notice Provided To Individuals?

Timing: Notification to affected consumers must be made in the most expedient time possible, without unreasonable delay, and no more than 30 calendar days after the breach was discovered, unless the delay is at the request of law enforcement or the delay is due to any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Wash. Rev. Code Ann. § 19.255.010(8).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. Sec. 7001;
  3. Substitute notice, if the person or business demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars, or that the affected class of subject persons to be notified exceeds five hundred thousand, or the person or business does not have sufficient contact information. Substitute notice shall consist of all of the following: (i) Email notice when the person or business has an email address for the subject persons; (ii) Conspicuous posting of the notice on the website page of the person or business, if the person or business maintains one; and (iii) Notification to major statewide media. Wash. Rev. Code Ann. § 19.255.010(4)(a)-(c).

If the breach of the security of the system involves personal information including a user name or password, notice may be provided electronically or by email. The notice must inform the person whose personal information has been breached to promptly change his or her password and security question or answer, as applicable, or to take other appropriate steps to protect the online account with the person or business and all other online accounts for which the person whose personal information has been breached uses the same user name or email address and password or security question or answer. Wash. Rev. Code Ann. § 19.255.010(4)(d)(i).

However, when the breach of the security of the system involves login credentials of an email account furnished by the person or business, the person or business may not provide the notification to that email address, but must provide notice using another method described [above]. The notice must inform the person whose personal information has been breached to promptly change his or her password and security question or answer, as applicable, or to take other appropriate steps to protect the online account with the person or business and all other online accounts for which the person whose personal information has been breached uses the same user name or email address and password or security question or answer. Wash. Rev. Code Ann. § 19.255.010(4)(d)(ii).

Content: The notice must be written in plain language and include the following information:

  1. The name and contact information of the reporting person or business subject to this section;
  2. A list of the types of personal information that were or are reasonably believed to have been the subject of a breach;
  3. A time frame of exposure, if known, including the date of the breach and the date of the discovery of the breach; and
  4. The toll-free telephone numbers and addresses of the major credit reporting agencies if the breach exposed personal information. Wash. Rev. Code Ann. § 19.255.010(6).

Is Notice To The Government Required?

Yes. Any person or business that is required to issue a notification pursuant to this section to more than 500 Washington residents as a result of a single breach shall notify the attorney general of the breach no more than 30 days after the breach was discovered. The notice must include:

  1. The number of Washington consumers affected by the breach, or an estimate if the exact number is not known;
  2. A list of the types of personal information that were or are reasonably believed to have been the subject of a breach;
  3. A time frame of exposure, if known, including the date of the breach and the date of the discovery of the breach;
  4. A summary of steps taken to contain the breach; and
  5. A single sample copy of the security breach notification, excluding any personally identifiable information. Wash. Rev. Code Ann. § 19.255.010(7).

Is Notice To Credit Reporting Agencies Required?

No.

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

The attorney general may bring an action in the name of the state, or as parens patriae on behalf of persons residing in the state, to enforce this chapter. For actions brought by the attorney general to enforce this chapter, the legislature finds that the practices covered by this chapter are matters vitally affecting the public interest for the purpose of applying the consumer protection act, chapter 19.86 RCW. For actions brought by the attorney general to enforce this chapter, a violation of this chapter is not reasonable in relation to the development and preservation of business and is an unfair or deceptive act in trade or commerce and an unfair method of competition for purposes of applying the consumer protection act, chapter 19.86 RCW. Wash. Rev. Code Ann. § 19.255.040(2).

Additionally, any consumer injured by a violation of this chapter may institute a civil action to recover damages. Wash. Rev. Code Ann. § 19.255.040(3).

Are There Any Exemptions/Exceptions?

A covered entity under the federal Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. Sec. 1320d et seq., is deemed to have complied with the requirements of this chapter with respect to protected health information if it has complied with section 13402 of the federal Health Information Technology for Economic and Clinical Health Act, P.L. 111-5 as it existed on July 24, 2015. Covered entities shall notify the attorney general pursuant to RCW 19.255.010(7) in compliance with the timeliness of notification requirements of section 13402 of the federal Health Information Technology for Economic and Clinical Health Act, P.L. 111-5 as it existed on July 24, 2015, notwithstanding the timeline in RCW 19.255.010(7). Wash. Rev. Code Ann. § 19.255.030(1).

Additionally, a financial institution under the authority of the Office of the Comptroller of the Currency, the Federal Deposit Insurance Corporation, the National Credit Union Administration, or the Federal Reserve System is deemed to have complied with the requirements of this chapter with respect to “sensitive customer information” as defined in the Interagency Guidelines Establishing Information Security Standards, 12 C.F.R. Part 30, Appendix B, 12 C.F.R. Part 208, Appendix D-2, 12 C.F.R. Part 225, Appendix F, and 12 C.F.R. Part 364, Appendix B, and 12 C.F.R. Part 748, Appendices A and B, as they existed on July 24, 2015, if the financial institution provides notice to affected consumers pursuant to the interagency guidelines and the notice complies with the customer notice provisions of the Interagency Guidelines Establishing Information Security Standards and the Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice under 12 C.F.R. Part 364 as it existed on July 24, 2015. The entity shall notify the attorney general pursuant to RCW 19.255.010 in addition to providing notice to its primary federal regulator. Wash. Rev. Code Ann. § 19.255.030(2).

Payment Processors

Note: Additional requirements apply to a person or entity “that directly processes or transmits account information for or on behalf of another person as part of a payment processing service.” See Wash. Rev. Code Ann. § 19.255.020.