Showing posts with label California data breach notification law. Show all posts
Showing posts with label California data breach notification law. Show all posts

Wednesday, September 07, 2011





California Enhances Data Breach Notification Requirements

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Under new legislation that will take effect next year, persons and entities doing business in California will be required to make additional disclosures in the event that the security of their computerized data systems are breached.

Existing law requires companies doing business in California to disclose data breaches involving the personal information of California residents.

The recent legislation (Senate Bill 24, Chapter 197) amended California Civil Code Sec. 1798.82, adding several specific requirements as to the form and substance of breach notifications. As amended, the statute requires breach notifications to be in plain language.

At a minimum, notifications must contain the following:

• The name and contact information of the notifying person or business.

• The types of personal information that were the subject of the breach.

• The date or estimated date of the breach.

• Whether notification was delayed as a result of a law enforcement investigation.

• A general description of the breach incident.

• The toll-free telephone numbers and addresses of the major credit reporting agencies, if the breach exposed California residents’ Social Security, driver's license, or identification card numbers.

At the discretion of the notifying company, the security breach notification may also include any of the following:

• Information about what the notifying company has done to protect individuals whose information has been breached.

• Advice on steps that persons whose information has been breached may take to protect themselves.
In addition, if notification is made to more than 500 California residents as a result of a single breach of the security system, the notifying company must electronically submit a single sample copy of the notification, excluding any personally identifiable information, to the California Attorney General.

The legislation was signed by Governor Jerry Brown on August 31, 2011, and will take effect on January 1, 2012. Similar bills were vetoed by former Governor Arnold Schwarzenegger in 2009 and 2010.

The current version of the law appears at CCH Privacy Law in Marketing ¶30,500.

Monday, October 04, 2010





Schwarzenegger Again Vetoes Amendments to California Data Breach Law

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Proposed legislation to amend California's data security breach notification law was vetoed by Governor Arnold Schwarzenegger on September 29, 2010.

Senate Bill 1166 would have required any agency, person, or business required to issue a notification under existing law to meet additional requirements regarding that notification.

The legislation would have required security breach notifications to be written in plain language and to contain certain specified information, including contact information regarding the breach, the types of information breached, and, if possible to determine, the date of the breach.

It also would have required notification to the California Attorney General of breaches affecting more than 500 California residents.

Schwarzenegger vetoed an identical bill in 2009.

Veto Statement

In a message to the members of the California Senate, Schwarzenegger said:

“California's landmark law on data breach notification has had many beneficial results. Informing individuals whose personal information was compromised in a breach of what their risks are and what they can do to protect themselves is an important consumer protection benefit. This bill is unnecessary, however, because there is no evidence that there is a problem with the information provided to consumers. Moreover, there is no additional consumer benefit gained by requiring the Attorney General to become a repository of breach notices when this measure does not require the Attorney General to do anything with the notices.

“Since this measure would place additional unnecessary mandates on businesses without a corresponding consumer benefit, I am unable to sign this bill.”

Further information about CCH Privacy Law in Marketing appears here.

Friday, October 09, 2009





North Carolina Data Breach Law Amended . . .

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

North Carolina’s data breach notification law has been amended to add to the information that must be included in a breach notice.

Session Law 2009-355 (S.B. 1017) provides that breach notices must include the toll-free numbers and addresses for the major consumer reporting agencies and the toll-free numbers, addresses, and website addresses for the Federal Trade Commission and the North Carolina Attorney General’s Office. The notices must also include a statement that the notified persons can obtain information from these sources about preventing identity theft.

Businesses providing notice to consumers of data security breaches must also notify the Consumer Protection Division of the Attorney General’s Office of the nature of the breach, the number of affected consumers, steps taken to investigate the breach, steps taken to prevent a future breach, and information about the timing, distribution, and content of the notice.

The updated statute, which took effect October 1, 2009, will appear at CCH Privacy Law in Marketing ¶30,500.

. . . California Data Breach Amendment Sent to Governor

A bill that would require California security breach notifications to be written in plain language and to contain certain specified information was sent to Governor Arnold Schwarzenegger on September 11, 2009.

Senate Bill 20 would amend the state's data breach notification law to require notifications to include contact information regarding the breach, the types of information breached, and the date of the breach. The bill also would provide that a security breach notification may include other specified information, at the discretion of the entity issuing the notification.

Notice to Attorney General

Under the proposed amendments, any agency, person, or business required to provide a security breach notification under existing law to more than 500 California residents as a result of a single breach would have to submit a sample copy of the notification electronically to the Attorney General.

The bill also would amend the substitute notice provisions of California's security breach notification law to require that an entity providing substitute notice also provide notice to the Office of Privacy Protection within the State and Consumer Services Agency.

The current version of the statute appears at CCH Privacy Law in Marketing ¶30,500.