Summary of State Data Breach Notification Laws

Jeff Kosseff · 2017

Section 1.2 of this book describes the common requirements of the data breach notification laws in forty-seven states and the District of Columbia.These summaries focus on the obligations of private companies; government agencies also often face separate notice obligations if they experience data breaches.For ease of reference, particularly for companies that are dealing with a data breach, this appendix summarizes key provisions of each of these forty-eight laws, including the types of personal information that trigger the breach notice requirement, significant exceptions to that requirement, and notice and format of breach notices.Note that most state notification laws allow electronic notice; in all of these cases, consent to receive notices electronically must be consistent with the federal E-SIGN Act.For ease of reference, this appendix includes many of the most important parts of the state laws, rather than merely reprinting the statutes in full.However, the state laws do have additional requirements that are specific to the state.Moreover, the breach notification laws could have been amended since the publication of this book; indeed, typically a few states each year amend their breach notice laws.Accordingly, it always is prudent for legal counsel to review the current version of the applicable breach notice laws to confirm requirements. AlaskaAlaska Stat.§ § 45.48.010 et seq.Types of personal information covered: An individual's first name or first initial and last name, in combination with at least one of the following elements: Social Security number, driver's license or state ID card number, credit card or debit card number and personal code if applicable, and passwords or PINS or other access codes for financial accounts. Summary of State Data Breach Notification Laws Appendix BExceptions to notice requirement: (1) If all of the personal information was encrypted, provided that the encryption key was not also disclosed; and(2) if after an appropriate investigation and a written notification to the Alaska Attorney General, the company determines that "there is not a reasonable likelihood that harm to consumers whose personal information has been acquired has resulted or will result from the breach, " but the company must retain this documentation for five years.Timing of notice to individuals: Disclosure must be made "in the most expeditious time possible and without unreasonable delay" unless a delay is necessary for law enforcement or to determine the scope of the breach and restore the system's integrity.Form of notice to individuals: Three options: (1) written document sent to most recent known mailing address; (2) email if that is company's primary method of communication with the individual; or (3) substitute notice if the cost of providing notice would exceed $150,000, the affected class in the state exceeds 300,000, or the company does not have sufficient information to provide notice.Substitute notice consists of email if the address is known, conspicuously posting disclosure on company's website, and notice to major statewide media.Notice to state regulators or credit bureaus: The State Attorney General must be notified if company determines that there is not a risk of harm and therefore individual notice is unnecessary.Notice to credit bureaus is required if more than 1000 Alaska residents are notified, but this requirement does not apply if the company is subject to the Gramm-Leach-Bliley Act. Arizona Ariz. Rev. Stat. § 44-7501Types of personal information covered: An individual's first name or first initial and last name in combination with at least one of the following: (1) Social Security number; (2) driver's license or state ID number; or (3) financial account or credit card or debit card number in combination with required security code, access code, or passcode (if necessary for access).Exceptions to notice requirement: The notice requirement does not apply to (1) information that is encrypted or redacted; (2) if after reasonable investigation the company determines that the breach does not pose a reasonable likelihood of substantial economic loss; (3) if the company is subject to the requirements of GLBA or HIPAA; (4) if the company complies with the notification requirements of its "primary or functional federal regulator, " or (5) if it follows its own notification procedures as part of an information security policy.10.

Read the paper · More papers on PaperTik