Chapter 8: State Laws Flashcards

1
Q

T/F: If a job seeker doesn’t consent to a credit report, it is illegal to reject them based on FCRA?

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How many states banned using credit reports in hiring decisions?

A

11 plus DC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

CFIPA aka

A

SB-1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

CFIPA

A

California Financial Information Privacy Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

CFIPA purpose…

A

Controls sharing of consumer financial information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

CFIPA requirement for sharing with affiliate

A

Provide notification and allow customers to opt out before sharing data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

CFIPA requirement for sharing with non-affiliate 3rd party

A

Express written consent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

CFIPA discrimination provision

A

May not discriminate against those not providing consent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

CFIPA penalties

A

Up to $2,500 per violation
$500,000 max per incident
No cap for willful violations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

CalECPA requirements

A

Warrant to access “electronic communication information”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

CalECPA Exemptions (2)

A

Access with permission, if recovering stolen property
Emergencies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

CCPA Personal information categories

A

Name
SSN
Address
IP Address
Email Address
Biometric info
Web browsing history
Geolocation data
Retail transactions
Inferences drawn from such information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

CCPA preemption exception

A

CCPA doesn’t apply when it is preempted by other laws (CFIPA, HIPAA, GLBA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

CCPA Rights (5)

A

Right to Know
Right to Access
Right to Delete
Right to opt-out
Nondiscrimination

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

CCPA Right to know

A

Businesses must notify customers about what they collect and how it is used when it is collected. Also, purpose limitation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

CCPA Right to Access

A

Consumers have a right to know what information companies have and be able to receive a copy in a portable format

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

CCPA Right to delete

A

Businesses must delete any PI that is collected.
Exceptions: Info needed to complete transactions, detect fraud, legal requirements, and a few others

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

CCPA Right to opt out

A

Businesses that intend to sell PI must give consumers the right to opt out

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

CCPA nondiscrimination

A

People exercising rights must not be treated differently

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

CCPA Private right of action requirements

A

Unauthorized disclosure of unencrypted data.
Must include combo of name and another identifier

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

CCPA Private right of action fines

A

$100-$750 per incident. Actual damages if greater

22
Q

CPRA

A

Passed by voters
Introduces “Sensitive Personal Information”

23
Q

New CPRA rights

A

Correction
Opt-out of automated decision making
Know about automated decision making
Restrict Sensitive personal information

24
Q

CPPA

A

California Consumer Privacy Protection Agency

25
CPPA purpose
Enforce CPRA and CCPA
26
CPRA targeted advertising
Must regulate the use of PI
27
CPRA Audits and Risk Assessments
Required if processing consumer PI poses a significant risk to privacy or security
28
Delware Online Privacy and Protection Act (DOPPA)
Applies to websites accessible to people in Delaware. Excludes hosting providers.
29
DOPPA requirements
Privacy policy Process to review and update PI Info about how Do Not Track is handled Infor about 3rd parties collecting PI
30
DOPPA childrens protections apply to
Anyone under 18
31
DOPPA prohibits advertising ______ to children?
Adult products including tanning beds
32
DOPPA rules for book service providers
May not share reading habits with the gov't without a court order
33
Nevada SB 538
Website must have privacy policies covering the basics (collection, use, sharing, 3rd parties). Applies to websites with 20K plus visits
34
Nevada SB 538
30 day cure period Up to $5,000 fine
35
NJ Personal Information and Privacy Protection Act
Limits when and how companies scan ID cards. Also, storage, retention, and destruction
36
NJ PIPA fines
$2,500 first offense Up to $5.000 for the rest
37
Washington Biometric Privacy Law
Covers biometric identifiers for Washington residents Excludes photo and video
38
Washington biometric law use limitations
Notice of collection Consent required to store biometric data
39
Washington Biometric Privacy Law opt-out scenarios
People can opt-out of having data disclosed
40
Facebook BIPA fine (2021)
$650 million
41
NYDFS
Requires financial institutions to implement security controls
42
NYDFS aligned with what standard?
NIST CSF
43
NYDFS NIST CSF requirements
Hire a CISO Risk assessments Pentest Annual reports on the security program Annual compliance certification
44
NYDFS breach reporting
Required to report to state officials or agencies
45
Washington HB 1149 Bank Card law
Businesses that mismanage bank cards causing a breach must pay for replacement
46
TN SB 2005 Breach Notification avoidance
If data is encrypted up to federal standards and they can show the keys were not compromised
47
IL Breach notification
Must notify if Usernames or emails and passwords are taken
48
CA AB 2828 breach notification
Must notify if encrypted data and keys are compromised
49
NM HB 15 Breach notification
Encrypted data with keys. Biometric data
50
MA HB 4806 Breach notification
Instructions on how to place credit freeze Timelines for notification Must offer credit monitoring
51
Utah Consumer Privacy Act Scope
Businesses exceeding $5 Million or processing data of over 100K Utah residents, or 25K residents if data is sold.