Tennessee Revamps Its State Data Breach Notification Statute

B
BakerHostetler

Contributor

BakerHostetler logo
Recognized as one of the top firms for client service, BakerHostetler is a leading national law firm that helps clients around the world address their most complex and critical business and regulatory issues. With five core national practice groups — Business, Labor and Employment, Intellectual Property, Litigation, and Tax — the firm has more than 970 lawyers located in 14 offices coast to coast. BakerHostetler is widely regarded as having one of the country’s top 10 tax practices, a nationally recognized litigation practice, an award-winning data privacy practice and an industry-leading business practice. The firm is also recognized internationally for its groundbreaking work recovering more than $13 billion in the Madoff Recovery Initiative, representing the SIPA Trustee for the liquidation of Bernard L. Madoff Investment Securities LLC. Visit bakerlaw.com
Tennessee amended its data breach notification statute to potentially require notification of a data breach to affected individuals regardless of whether the personal information involved in the security incident was encrypted.
United States Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

Tennessee amended its data breach notification statute to potentially require notification of a data breach to affected individuals regardless of whether the personal information involved in the security incident was encrypted. On July 1, Tennessee becomes the first state to remove its encryption safe harbor; there is still an ability to perform a risk analysis under the new law. This means that although there is not a blanket exception for encryption, it can still be considered as part of your risk analysis to determine if notification is necessary.

The amendment also requires businesses and government agencies to notify Tennessee residents affected by data breaches within 45 days of discovering the data breach. While the vast majority of states require notification in the "most expedient time possible" and "without unreasonable delay," Tennessee becomes the eighth state to enact legislation that sets a specific time period for notification to affected individuals.

The new law also expands the definition of "unauthorized person." Tennessee requires any information holder to disclose a breach of the security of the system to any resident of Tennessee whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person. According to the new law, "unauthorized person" now includes "an employee of the information holder who is discovered by the information holder to have obtained personal information and intentionally used it for an unlawful purpose."

For additional information regarding data breach notification statutes enacted in the United States and worldwide, please refer to BakerHostetler's State-by-State Survey of Data Breach Notification Laws, Key Issues in State Data Breach Notification Laws, and International Compendium of Data Privacy Laws.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More