How many states have data breach notification laws?
all 50
preemption of state data breach notification laws
Fair and Accurate Credit Transactions Act (FACTA) preempted many state laws related to consumer credit reports, but states retained power to enact laws addressing identity theft
What are the key components of state data breach notification laws?
What does “personal information” cover under state data breach notification laws?
in majority of laws, includes individual’s first name or first initial and last name in combination with any one, or more, the following data:
1. SS #
2. driver’s license # or state ID card #
3. financial account # or credit/debit card #, often in combination with any required security code, access code, or passwords that would permit access to an individual’s financial account
What does “covered entities” include under state data breach notification laws?
in most states, “covered entities” include those:
1. that conduct business in the state; and
2. that, in the ordinary course of such person’s business, maintain computerized data that includes PI
What is defined as a “security breach” under state data breach notification laws?
often includes following elements:
nearly all states apply a risk-of-harm analysis in determining whether an incident involving personal data constitutes a regulated breach
Who do you typically notify under state data breach notification laws?
typically affected parties, state AG or other state agencies and nationwide CRAs
When do you notify of a breach under state data breach notification laws?
common phrase is “as expeditiously as possible and without unreasonable delay” which allows affected entity to conduct a reasonable investigation to determine scope of breach and restore reasonable integrity of data system
What do you include in a notification letter under state data breach notification laws?
almost ½ of states mandate specific content be included in the notification such as:
How should you notify under state data breach notification laws?
generally focus on providing written notification to affected parties using postal mail (email or telephone usually OK if affected party has opted into that mode of communication)
What are the notice requirements for state AGs under state data breach notification laws?
What are the notice requirements for CRAs under state data breach notification laws?
What are four exceptions to providing data breach notification under state data breach notification laws?
What does enforcement look like under state data breach notification laws?
in each of 50 states, covered entities subject to civil penalties if they violate state data breach notification law