![]() March 19, 2003
California Law Protecting Computerized Personal Information Takes Effect in July
Effective July 1, 2003, individuals and businesses that conduct business in California must notify California residents whenever their unencrypted "personal information" was, or is reasonably believed to have been, acquired by an unauthorized person as the result of a breach of the security of a computerized system.* The law is intended to help California residents protect themselves from becoming victims of identity theft by giving them notice whenever the privacy of their personal information stored in a computer system is compromised. What Personal Information Is Protected by the Law? The law defines "personal information" as an individual's first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted:
Personal information does not include publicly available information that is lawfully made available to the general public from federal, state or local government records. What Constitutes a Breach of Security? A "breach of the security of the system" means the unauthorized acquisition of computerized data that compromises the security, confidentiality or integrity of personal information maintained by an individual or business. Good-faith acquisition of personal information by an employee or agent of the person or business for the purposes of the person or business is not considered to be a breach of the security of the system - provided that the personal information is not used or subject to further unauthorized disclosure. What Form Must the Disclosure Take? Notice can be made in writing or electronically, in accordance with the provisions regarding electronic records and signatures set forth in Section 7001 of Title 15 of the United States Code.** If (1) the cost of providing notice using either of these methods exceeds $250,000 or (2) the number of people to be notified exceeds 500,000, then a substitute notice can be sent in one of the following ways:
By When Must Notice Be Given? The disclosure must be made in the most expedient time possible and without unreasonable delay, subject to any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. However, the notification may be delayed if a law enforcement agency determines that the notification will impede a criminal investigation. Are Public Sector Entities and Sponsors of Multiemployer Plans Affected? The law applies to "any person or business that maintains computerized data that includes personal information" and to California state agencies, but not to counties, cities, school districts or their boards, commissions or agencies. It is unclear whether the law will apply to ERISA plans, including multiemployer pension and group health plans, or will be preempted by ERISA. What Are the Penalties for Noncompliance? SB 1386 adds section 1798.84 to the California Civil Code on remedies and provides that:
Implications California-based employers and plan sponsors, as well as other employers and plan sponsors that cover California residents, should seek advice of legal counsel regarding the interpretation, implementation and implications of the law. * The law appears in § 1798.82 of the California Civil Code as added by SB 1386 (Chapter 915 of the statutes of 2002). It is available online by clicking here. It adds to the protections created by SB 168, Chapter 720 of the statutes of 2001, which addressed the use of Social Security numbers. For more information, see The Segal Company's May 15, 2002, Compliance Alert, "California Law Restricting Use of Social Security Numbers: Implications for California Employers and Sponsors of Employee Benefit Plans that Cover California Residents." ** For more information about the requirements in the United States Code, see The Segal Company's August 2000 Bulletin, "E-Signature Law Has Employee Benefit Implications."
|
||||||



