Module 14: State data security and breach notification laws Flashcards

1
Q

FTC Section 5

A

actions against companies
misrepresenting their information security practices or failing to provide “reasonable
procedures” to protect personal information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

federal vs state laws

A

no federal legislation directly imposes minimum information security standards
across all industries.

state legislatures have passed laws to ensure companies protect individuals’ sensitive informatioN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What states have a data breach notification law?

A

In March 2018, Alabama became the last of 50 states to pass a data breach notification law.

The District of Columbia, Puerto Rico, Guam and the U.S. Virgin Islands also have data breach notification laws.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

State Data Security

Social Security #s

A

In Cali

  • public posting
  • mailings
  • ID or membership cards
  • transmission over unencrypted internet connection
  • visible thru enveloper windows
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Data destruction requirements

A
  • to whom the law applies
  • the required notice
  • exemptions
  • the covered media
  • any penalties for non-compliance
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

North Carolina’s Data Destruction Policies and Procedures for

tangible data

A
#1 require the
-burning
-pulverizing
-shredding
of papers containing personal info so that info cannot be practicably read or reconstructed
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

North Carolina’s Data Destruction Policies and Procedures for

electronic media

A

Policies and procedures that require the destruction or erasure of electronic media and other non-paper media containing personal information so that the information cannot be
practicably read or reconstructed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

North Carolina’s Data Destruction Policies and Procedures for

the business entity

A

Procedures relating to the adequate destruction or proper disposal of personal records as
official policy in the writings of the business entity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

State law data security

California

A

-same as NC +

requires destruction such that records are unreadable or undecipherable by ANY means

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

State law data security

Arizona

A

applies only to paper records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

State law data security

Alaska

A

applies a right to private action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

State law data security

Illinois and Utah

A

applies to government entities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

State law data security

Massachusetts

A

-stipulates steep penalties for each instance of improper disposal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

State law data security

New Mexico HB 15

A

requires PI be made unreadable by shredding, erasing, or otherwise modifying

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Connecticut’s Definition of Personal Info

A
  • First Name (or initial) and last name
  • SS#
  • DL # or state identification card #
  • Account,CC, Debit, Pin #, Access Code, or Password
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Connecticut’s Definition of

Covered entities

A

any person who conducts business in this state and who, in the ordinary course of such person’s business, owns, licenses or maintains computerized data that includes personal information.

17
Q

Connecticut’s Definition of

security breach

A

A security breach is unauthorized access to or acquisition of

  • -electronic files
  • -media,
  • -databases or
  • -computerized data

containing personal information

–when access to the personal information has not been secured by encryption or by any other method or technology that
renders the personal information unreadable or unusable

18
Q

Connecticut’s

Whom to notify

A
  • -state residents whose personal information is believed to have been compromised
  • -State Attorney General; other entities
19
Q

Connecticut

When to notify

A
  • -in the most expeditious time possible
  • -without unreasonable delay

average seems to be 45 days

20
Q

Connecticut

What to include in notification

A
  • description of incident
  • personal info subject to the breach
  • prevention measures
  • monitoring accounts
  • contacting regulators
21
Q

Connecticut

How to notify

A
  • written
  • telephone
  • email
  • conspicious postings
  • media outlets
22
Q

Connecticut

Exceptions

A
  • HIPPA
  • GLBA (gramm-leach-bliley act)
  • Breach notification already in place
  • safe harbor for encrpyted, redacted, unreadable or unusable data
23
Q

Connecticut

Penalties and Rights of Action

A

-enforcement reserved to the state attorney general (in most states)

24
Q

true or false:

Most US States have laws limiting the use of SS#s?

A

true

25
Q

true or false?

data destruction requirements are often built into state data breach laws?

A

true

26
Q

In the event of a data breach, Connecticut’s breach notification law defines personal
information as the first name (or initial) and last name in combination with one or more what?
Select all that apply.

A) Social Security number
B) Driver’s license number
C) Mailing address
D) Phone number
E) Bank account or card number in combination with a security or access code
A

A
B
E

27
Q

Which states specify extensive requirements for data breach notifications?

A) Hawaii
B) Virgin Islands
C) Maryland
D) Massachusetts
E) California
A

All US States

28
Q

True or False?

In the case of state requirements regarding data breach notification, email notice is always required first?

A

false

29
Q

True or False?

State laws regarding data breaches may require 3rd party notifications to the state attorney general

A

true

30
Q

Which are exceptions to state data breach notification laws?

A)entities that already follow breach notification procedures that are compatible with state law
B) Entities enrolled in self-certification programs that meet industry security standards
C)entities subject to other, more stringent data breach notification laws

A

C