14. State Data Security and Breach Flashcards

You may prefer our related Brainscape-certified flashcards:
1
Q

Recent developments: WA

A

Washington Biometric Privacy Law (H.B. 1493) (2017)

Governs how biometric information can be obtained and handled for commercial purposes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Recent developments: CA

A

California Electronic Communications Privacy Act (2015)

Extends California’s due process requirements and privacy protections to electronic information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Recent developments: NV

A

Nevada SB 538 (2017)

Requires notice for online collection and disclosure of personally identifiable information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Recent developments: IL

A

• Illinois Right to Know Act (2017)

Requires that commercial websites or online services that collect PI through the internet about individual customers must notify those customers of certain specified information pertaining to its personal information sharing practices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Recent developments: NY

A

New York Department of Financial Services Cybersecurity Regulation (2017)

Imposes strict cybersecurity rules on covered organizations including requiring a detailed cybersecurity plan, the designation of a DPO, the enactment of a comprehensive cybersecurity policy, and the initiation and maintenance of a reporting system for cybersecurity events

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Recent developments: NJ

A

New Jersey Personal Information and Privacy Protection Act (2017)

▪ Limits the purposes for which retail establishments may lawfully scan a person’s government-issued ID card (e.g., a driver’s license)
▪ Limits what data can be collected from ID cards and how the data can be retained and used

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Recent developments: DE

A

Delaware Online Privacy and Protection Act (2016)

Requires online operators “to conspicuously post a privacy policy identifying the personally identifiable information it collects on users and how it responds to do-not track signals”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Recent developments VA:

A

The Virginia Consumer Data Protection Act (CDPA)

▪ Signed into law in March 2021 (takes effect January 1, 2023)
▪ Only the second state to enact comprehensive privacy legislation (California was the first)
▪ Draws heavily from the proposed Washington Privacy Act (defeated for the third time in 2021) and includes components similar to the California Consumer Privacy Act
▪ Notable features of CDPA:
• Affirmative consent or opt-in requirements to process sensitive personal data
• Right to opt-out of processing related to sales of personal data, targeted
advertising and profiling that produces legal or similarly significant effects
• Mandatory data protection assessments for sales, targeted advertising, certain profiling, and processing of sensitive data that presents a heightened risk of harm
• Obligation to confirm processing, provide a copy of personal data in a portable format, and to correct or delete data upon consumer request

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

State data security: Data destruction- NC

A

Policies and procedures that require the burning, pulverizing or shredding of papers containing personal information so that information cannot be practicably read or reconstructed

Policies and procedures that require the destruction or erasure of electronic media and other non-paper media containing personal information so that the information cannot practicably be read or reconstructed

Procedures relating to the adequate destruction or proper disposal of personal records as official policy in the writings of the business entity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

State data security: Data destruction- CA

A

Requires destruction such that records are unreadable or undecipherable by ANY means

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

State data security: Data destruction- AZ

A

Applies only to paper records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

State data security: Data destruction- AL

A

Applies a right to private action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

State data security: Data destruction- IL and UT

A

Applies only to government entities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

State data security: Data destruction- MA

A

Stipulates steep penalties for each instance of improper disposal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

State data security: Data destruction- NM

A

Requires PI be made unreadable by shredding, erasing or otherwise modifying

How well did you know this?
1
Not at all
2
3
4
5
Perfectly