Perkins Coie has compiled an updated resource (141 pages) of state data breach notification laws:
Category: Breach Laws
Texas amends the effects of its data breach law on out-of-state residents
Joseph J. Lazzarotti of Jackson Lewis LLP writes: On June 14, 2013, Texas Governor Rick Perry signed S.B. 1610 amending Texas’ data breach notification law to remove language limiting the application of the data breach notification requirement to Texas residents and residents of states that do not require notification, permit, for residents of states other than Texas that require notification of a breach, notice to be…
Vermont and North Dakota Amend Breach Notice Laws
Michael Young writes: On May 13, 2013, Vermont Governor Peter Shumlin signed H.513 into law. The new law includes an amendment to Vermont’s Security Breach Notice Act, 9 V.S.A. § 2435. Previously, under § 2435, Vermont-regulated financial institutions were exempt from notifying any Vermont authority in case of a security breach involving personally identifiable data. The new…
Dutch govt proposes data breach notification requirements
Telecompaper reports: The Dutch government has proposed legislation tightening rules for disclosing breaches of personal data. The proposal sent to parliament by the justice ministry would require any breach of personal data, whether by public or private organisations, to be disclosed both to the privacy regulator CBp and to the person whose data was compromised….
Senator Toomey reintroduces bill to preempt state data breach notification laws
John Eggerton reports that Senator Pat Toomey (R-PA) has introduced the “Data Security and Breach Notification Act of 2013” (S. 1193). Although the bill’s text is not yet available online, it’s reportedly the same bill he introduced last year: In the event of data breaches, “the bill would direct companies possessing personal data to notify…
Data breach notification rules should only apply where individuals are ‘severely affected’, say EU Ministers
Out-Law.com reports: Businesses should only have to report that they have experienced a personal data breach in cases where it is likely that individuals’ rights and freedoms have been “severely affected” by such a breach, EU Ministers have proposed. The Working Party on Information Exchange and Data Protection (DAPIX), set up within the structure’s of…