Earlier this year, Mississippi passed legislation requiring organizations to notify individuals whose personal information is compromised by a data breach. With only Alabama, Kentucky, New Mexico and South Dakota as the remaining states without data breach notification laws, Mississippi joins the vast majority of states to have passed such legislation. House Bill 583 will not go into effect until July 1, 2011, but its form and structure tracks many other states’ notice requirements in the event of a data breach.
Based on California’s original definition of personally identifying information (PII), for a breach to trigger the Mississippi notification requirement, the leaked PII must include a name along with a social security number or driver’s license or an account number in combination with any required security or access code. In the event of a triggering breach, notification must be made to individuals only, not to government regulators or any credit reporting agencies. However, in cases where the breaching organization reasonably determines that the breach is not likely to result in harm to the affected individuals, the notification requirement is waived. The law also includes a safe harbor for organizations that secure PII by encryption or other technologies rendering the PII “unreadable or unusable.”
Although there are many similarities between Mississippi’s breach requirement and other state breach notification requirements, significant differences exist with respect to acceptable time to notify, criminal and civil penalties, safe harbors and exemptions. For the vast majority of businesses handling personal information, a careful review of PII handling policies as well as an implementation of a breach notification procedure is recommended. For an outline of the major requirements under each state’s breach notification law, please see our State Data Breach Notification Laws chart.
About the author
Andrew Martin:
As an associate attorney with extensive prior experience advising information technology start-ups, Andrew’s practice focuses on finding solutions for his clients’ intellectual property issues. Due to his extensive experience in the software and technology industries, Andrew understands both the practical and legal issues involved in IP licensing agreements and disputes. In addition to licensing, Andrew helps his clients find new ways to use existing technologies to assist his clients in areas such as data privacy compliance. Andrew uses his diverse background which includes founding a record label and working for a world-wide concert promoter when counseling the firm’s entertainment clients.
Get in touch: amartin@scottandscottllp.com | 800.596.6176