State Data Breach Laws Flashcards
Definition of PI
First name/initial and last name plus any of:
- Social Security number (SSN)
- Driver’s license number, state ID #
- Account number, credit or debit card number, in combination w/ any PIN, security code, access code, or password that woul
All except DC.
DC: Name, phone number, or address plus SSN, driver’s license #, ID card #, credit or debit card #, or any other # or code that allows access to/use of individual’s account.
DC’s definition is similar to GLBA.
PI includes biometric data (used in combo with first name/initial + last name to authenticate consumer identity)
CO, DE, MD, NM
PI includes unique biometric data (used alone to authenticate consumer’s identity)
IL, IA, NE, NC, WI, WY
PI includes ID # assigned by employer when used with a first name/initial and last name
ND SD (if in combination with required security code, access code, password, or biometric data)
PI includes medical info
AL, AR, CA, CO, DE, FL, IL, MD, MO, MT, ND, SD, WY (if used in combination with first name/initial and last name)
OR, RI (if used in combination with first name/initial and last name; specifically, information about an individual’s medical history, mental or physical condition or medical diagnosis or treatment)
TX (specifically the physical or mental health or condition of the individual)
VA (If used in combination with the first name/initial and last name and maintained by a state government entity)
PI includes health insurance info
AL, CA, DE, FL, IL, MD, MO, ND, WY, RI (if used in combination with first name/initial and last name)
TX
VA (If used in combination with the first name/initial and last name and maintained by a state government entity)
PI includes SSN alone
GA (if information compromised would alone be sufficient to perform or attempt to perform identity theft against the person whose information was compromised)
IN (if SSN not encrypted or redacted)
ME (if information compromised would alone be sufficient to permit a person to fraudulently assume or attempt to assume identity of the person whose information was compromised)
Breach notification obligation may be triggered by non-electronic data
AK, HI, IA (if transferred to other medium from computerized form), MA, NC, SC, WA, WI
Timing to notify:
within 30 days
CO
FL (plus additional 15 days for good cause shown)
Timing to notify:
no later than 45 days after discovery
AL, MD, NM, OH, RI, TN, WA, WI, VT