State Data Breach Laws Flashcards

1
Q

Definition of PI

First name/initial and last name plus any of:

  • Social Security number (SSN)
  • Driver’s license number, state ID #
  • Account number, credit or debit card number, in combination w/ any PIN, security code, access code, or password that woul
A

All except DC.

DC: Name, phone number, or address plus SSN, driver’s license #, ID card #, credit or debit card #, or any other # or code that allows access to/use of individual’s account.

DC’s definition is similar to GLBA.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

PI includes biometric data (used in combo with first name/initial + last name to authenticate consumer identity)

A

CO, DE, MD, NM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

PI includes unique biometric data (used alone to authenticate consumer’s identity)

A

IL, IA, NE, NC, WI, WY

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

PI includes ID # assigned by employer when used with a first name/initial and last name

A

ND SD (if in combination with required security code, access code, password, or biometric data)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

PI includes medical info

A

AL, AR, CA, CO, DE, FL, IL, MD, MO, MT, ND, SD, WY (if used in combination with first name/initial and last name)

OR, RI (if used in combination with first name/initial and last name; specifically, information about an individual’s medical history, mental or physical condition or medical diagnosis or treatment)

TX (specifically the physical or mental health or condition of the individual)

VA (If used in combination with the first name/initial and last name and maintained by a state government entity)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

PI includes health insurance info

A

AL, CA, DE, FL, IL, MD, MO, ND, WY, RI (if used in combination with first name/initial and last name)

TX

VA (If used in combination with the first name/initial and last name and maintained by a state government entity)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

PI includes SSN alone

A

GA (if information compromised would alone be sufficient to perform or attempt to perform identity theft against the person whose information was compromised)

IN (if SSN not encrypted or redacted)

ME (if information compromised would alone be sufficient to permit a person to fraudulently assume or attempt to assume identity of the person whose information was compromised)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Breach notification obligation may be triggered by non-electronic data

A

AK, HI, IA (if transferred to other medium from computerized form), MA, NC, SC, WA, WI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Timing to notify:

within 30 days

A

CO

FL (plus additional 15 days for good cause shown)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Timing to notify:

no later than 45 days after discovery

A

AL, MD, NM, OH, RI, TN, WA, WI, VT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly