Cynthia J. Larose and Michael B. Katz of Mintz Levin write: During 2016, amendments to breach notification laws in five states went into effect (California, Nebraska, Oregon, Rhode Island and Tennessee). And by the end of last year, well over twenty states had introduced or were considering new regulations or amendments to their existing security breach…
Category: State/Local
Three States Join Others to Expand Personal Information Definition to Include Usernames or Email Addresses
Mark L. Krotoski and W. Scott Tester of Morgan Lewis remind entities that duty to notify of a breach depends on state definitions of “personal information,” and more states are now including usernames or email addresses as personal information: Illinois, Nebraska, and Nevada are the latest to add usernames or email addresses to the definition…
Hooray for transparency: Massachusetts puts data breach archive online
The state’s announcement: The Office of Consumer Affairs and Business Regulation today announced the online public availability of its Data Breach Notification Archive. The Massachusetts Data Security Law (M.G.L. c.93H) requires any entity that keeps a Massachusetts resident’s personal information to notify affected residents, the Office of Consumer Affairs and Business Regulation, and the Attorney…
NY financial regulator to delay cyber security rules
Suzanne Barlynne reports: New York’s financial regulator will delay an anticipated Jan. 1 deadline for banks and insurers doing business in the state to comply with controversial cyber security rules, a person familiar with the matter said. The regulator, the New York State Department of Financial Services, will publish a revamped version of its cyber…
CT: Bristol Board of Ed adopts new student data security policy
Susan Corica reports: The Board of Education has adopted a new policy to protect the privacy of student data, to comply with new state legislation. […] Under the new policy, “for any contract that we generate, after Oct. 1 of 2016, we need to have a clause in there that tells us exactly how they…
Bryan Cave Data Security Breach Handbook – 2016
From Bryan Cave, this free resource on Incident Readiness and Response: Since the first publication of this handbook in 2014, the legal ramifications for mishandling a data security incident have become more severe. In the United States, the number of federal and state laws that claim to regulate data security has mushroomed. The European Union has also…