State Privacy Laws (Part 2) Flashcards

Examine emerging state privacy frameworks and trends shaping the evolving U.S. privacy landscape. (73 cards)

1
Q

What must online platforms consider under the California Age-Appropriate Design Code Act?

A

The best interests of child users.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does the Act prohibit by default regarding location data?

RE: California Age-Appropriate Design Code

A

Collecting, sharing, or selling children’s location data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Name five types of data breaches.

A
  • Unintended disclosure
  • Hacking/malware
  • Payment card fraud
  • Insider threats
  • Physical loss
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the four steps in incident response?

A
  • Confirm
  • Contain
  • Notify
  • Follow up
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are signs that may confirm a data breach?

A
  • Multiple failed logins
  • Inactive account use
  • Unknown programs/devices
  • After-hours access
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What actions are involved in containment?

A
  • Isolate traffic
  • Recover items
  • Purge emails
  • Contact cybersecurity
  • Document actions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What must be considered before notifying individuals of a breach?

A
  • Legal requirements
  • Timing
  • Content
  • Risk mitigation
  • Data lost
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are examples of follow-up actions after a breach?

A
  • Training
  • Audits
  • Plan analysis
  • DLP tools
  • Pen testing
  • Simulated exercises
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is OMB M-17-12?

(Office of Management and Budget)

A

An OMB memo titled: ‘Preparing for and Responding to a Breach of PII’.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What team is central to the M-17-12 framework?

A

Privacy Incident Response Team

(PIRT)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What compliance documents are part of breach prep?

A
  • Privacy Impact Assessments
  • System Security Plan
  • Authority to Operate
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What key steps are in the breach response framework?

A
  • Scope of breach
  • Assess impact
  • Mitigate risk
  • Notify individuals
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What responsibilities do vendors have under M-17-12?

A
  • Train employees
  • Encrypt PII
  • Notify agency of breach
  • Cooperate in investigation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are common features of state breach laws?

A
  • Define PI
  • Covered entities
  • Thresholds
  • Exceptions
  • Penalties
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the base definition of personal information (PI) across all states?

A

First name/initial + last name AND SSN, license/ID number, or account/card.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Who must be notified in a data breach?

A
  • Affected individuals
  • State AGs
  • Agencies
  • CRAs (~2/3 states)
  • Third parties
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is the most common timeframe for notification?

A

Within 45 days; 30 days preferred for national firms.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

When can breach notification be delayed?

A
  • When criminal activity is suspected
  • Law enforcement requests delay
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is Puerto Rico’s notification timeline?

A

Notify Department of Consumer Affairs within 10 days.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What should breach notification contain?

A
  • Event description
  • PII affected
  • Protection plan
  • Contacts
  • Identity theft resources
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is substitute notification?

A

Public notice on website/media if individual notice is burdensome.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

When must CRAs be notified of a breach?

A

Typically when 500 to 10,000+ residents are affected depending on state.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What are common exceptions to breach notification?

A
  • HIPAA/GLBA coverage
  • Compatible policies
  • Encrypted/redacted data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What changes did the FCC make to breach rules in 2023?

A

Broadened ‘breach’ and ‘covered data’ to include any unauthorized access, use, or disclosure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
**When** must the **FCC be notified** of a breach?
Within **7 days** if 500 or more individuals are affected.
26
What does **Utah SB 127** require?
Entities must report system security breaches to: * AG * Utah Cyber Center
27
What change did **Texas** make under its **Identity Theft Act** in 2023?
**Shortened breach** notification deadline from 60 **to 30 days**.
28
What is **Nevada SB 370**?
A consumer **health data privacy law**.
29
Who is considered a '**regulated entity**' under Nevada SB 370?
Any **business in NV** or **targeting NV residents** that determines purpose and means of processing consumer health data.
30
What is '**consumer health data**' under Nevada SB 370?
Data identifying a consumer's **physical or mental health status**. ## Footnote Examples: general health, surgeries, medications, vitals, gender-affirming care, biometrics, genetics, geolocation.
31
What **obligations** do regulated entities have under **NV SB 370**?
* Privacy policy * Voluntary consent * Administrative/technical/physical safeguards
32
What **restrictions** are placed on data use under **NV SB 370**?
* No sale or sharing without written consent * No geofencing within 1,750 feet of medical facilities
33
What is **GIPA**?
Illinois' **Genetic Information Privacy Act**, enacted in 1998.
34
What type of information counts as '**genetic information**' under **GIPA**?
Data from **physicals** and family **medical histories**.
35
Which states (and one municipality) have **laws** regulating automated decision-making (ADM)?
* California * Colorado * Connecticut * Virginia * New York City
36
What is **profiling** under Colorado law?
Automated processing of PII to evaluate or **predict economic, health, preferences, behavior**, etc.
37
What are examples of **high-risk ADM** activities?
* Financial services * Housing * Insurance * Education * Justice * Employment * Health care * Essential goods
38
How does **NYC** regulate **ADM in hiring**?
Requires transparency for '**automated employment decision tools**'. | (AEDTs)
39
What is **NYC Local Law 144** also known as?
NYC Bias Audit Law or AEDT Audit Law.
40
What is an **AEDT**?
Computational tool using **ML/statistics/AI** that assists or replaces hiring decisions.
41
What are the **key audit requirements** under NYC Local Law 144?
* Annual * Independent * Assess disparate impact by race, ethnicity, and sex
42
What **notice** must candidates receive?
**10-day notice** before AEDT use, with option for alternative evaluation.
43
**Who** enforces NYC Local Law 144?
NYC Department of Consumer and Worker Protection | (DCWP)
44
What is **Colorado's SB21-169**?
A law protecting consumers from **unfair discrimination in insurance practices**.
45
What does **CO SB21-169** prohibit?
Insurers from using ECDIS, algorithms, or predictive models that lead to unfair discrimination. ## Footnote ECDIS: External Consumer Data and Information Services
46
What is **ECDIS**?
**External Consumer Data and Information Services** used to supplement or replace underwriting factors.
47
What is **required** from insurers under **CO SB21-169**?
A Governance and Risk Management Framework for ECDIS use.
48
What must **insurers** document and submit under **CO SB21-169**?
Comprehensive records and reports to the Division of Insurance (DOI).
49
What is **Verifiable Parental Consent**? | (VPC)
A process requiring reasonable efforts to ensure that a **parent is notified and authorizes** the collection, use, or disclosure of a child’s personal information.
50
What **law** establishes the VPC requirement?
The Children’s Online Privacy Protection Act | (COPPA) ## Footnote Codified at 15 U.S.C. 6501 and implemented under 16 CFR 312.
51
Under **COPPA amendments** what can parents consent to separately?
Parents may consent to data collection without consenting to data disclosure unless disclosure is integral to the service.
52
Why is **VPC** required?
To give parents **control over what content children under 13** can access and how their data is collected or used.
53
What are the **major requirements** for operators under COPPA?
Provide parents with **detailed direct notice** and **obtain affirmative express consent** before collecting personal data.
54
What are **common methods** used for VPC that may reduce accessibility?
Submitting **a credit card number** or **government-issued ID** which can limit equitable access.
55
What does **Texas’ SCOPE Act** regulate? | (Securing Children Online through Parental Empowerment Act)
Prohibits **sharing or selling minors' data** without parental consent.
56
What does the New York **Child Data Protection Act** prohibit? | (CDPA)
It **restricts websites** and apps from collecting or selling data from **children under 18** unless COPPA-compliant or with informed consent.
57
What is the **NAIC**? | (National Association of Insurance Commissioners)
A **standard-setting** organization that coordinates **multi-state insurance regulation**.
58
What does **AIS stand** for in the NAIC AIS Governance Guidelines?
Artificial Intelligence Systems
59
When did the NAIC issue the **AIS Governance Model Bulletin**?
December 2023
60
What do the NAIC AIS Governance Guidelines **require** insurers to establish?
A documented **organization-wide AI governance framework** overseeing all AI systems.
61
What are the **guiding principles** emphasized by the AIS Governance Guidelines?
* Transparency * Fairness * Accountability * Ethical use of AI
62
**Who is accountable** under the AIS Governance Guidelines?
**Senior management** holds accountability for AI governance and compliance.
63
What does '**proportionate controls**' mean in the context of AIS Governance Guidelines?
Controls should **match the level of risk and complexity** of AI applications.
64
What must the **governance structure** address under the AIS Governance Guidelines?
Policies, procedures, and risk management across the AI development life cycle.
65
What **third-party considerations** are included in the AIS Governance Guidelines?
Insurers must manage third-party AI vendors and service providers responsibly.
66
How do the AIS Governance Guidelines address **consumer transparency**?
They require **notice to consumers regarding AI use** and ensure transparency in automated decisions.
67
What is the **Iowa Consumer Data Protection Act** (2025)?
* A **business-friendly** privacy law effective 2025 * Does **not provide** a right to correct inaccurate data * Includes a **90-day** cure period
68
What is the **Kentucky Consumer Data Protection** Act (2026)?
**Does not require** businesses to recognize **universal opt-out** mechanisms.
69
What is the **Maryland Online Data Privacy Act** (2025)?
* A strong privacy law * Restricts sensitive data processing * Prohibits geofencing * Bans sale of covered health data
70
What is unique about the **Minnesota Consumer Data Privacy Act** (2025)?
* Special profiling rights * Right to opt out of automated decision-making * Receive detailed explanations about profiling impacts
71
What is notable about the **Nebraska Data Privacy Act** (2025)?
* It excludes **SBA-defined small businesses** * Has **no numerical** revenue or consumer threshold
72
What makes the **New Hampshire SB 255** (2025) unique?
* Lower applicability threshold of **35,000 consumers** * Provides a **60-day** cure period
73
What is the **Rhode Island Data Transparency and Privacy Protection Act** (2026)?
It imposes **transparency requirements** on commercial websites and ISPs **regardless of business size or thresholds**.