Module 14: State data security and breach notification laws Flashcards
FTC Section 5
actions against companies
misrepresenting their information security practices or failing to provide “reasonable
procedures” to protect personal information
federal vs state laws
no federal legislation directly imposes minimum information security standards
across all industries.
state legislatures have passed laws to ensure companies protect individuals’ sensitive informatioN
What states have a data breach notification law?
In March 2018, Alabama became the last of 50 states to pass a data breach notification law.
The District of Columbia, Puerto Rico, Guam and the U.S. Virgin Islands also have data breach notification laws.
State Data Security
Social Security #s
In Cali
- public posting
- mailings
- ID or membership cards
- transmission over unencrypted internet connection
- visible thru enveloper windows
Data destruction requirements
- to whom the law applies
- the required notice
- exemptions
- the covered media
- any penalties for non-compliance
North Carolina’s Data Destruction Policies and Procedures for
tangible data
#1 require the -burning -pulverizing -shredding of papers containing personal info so that info cannot be practicably read or reconstructed
North Carolina’s Data Destruction Policies and Procedures for
electronic media
Policies and procedures that require the destruction or erasure of electronic media and other non-paper media containing personal information so that the information cannot be
practicably read or reconstructed
North Carolina’s Data Destruction Policies and Procedures for
the business entity
Procedures relating to the adequate destruction or proper disposal of personal records as
official policy in the writings of the business entity
State law data security
California
-same as NC +
requires destruction such that records are unreadable or undecipherable by ANY means
State law data security
Arizona
applies only to paper records
State law data security
Alaska
applies a right to private action
State law data security
Illinois and Utah
applies to government entities
State law data security
Massachusetts
-stipulates steep penalties for each instance of improper disposal
State law data security
New Mexico HB 15
requires PI be made unreadable by shredding, erasing, or otherwise modifying
Connecticut’s Definition of Personal Info
- First Name (or initial) and last name
- SS#
- DL # or state identification card #
- Account,CC, Debit, Pin #, Access Code, or Password