ARTICLE
10 November 2016

California Amends Data Breach Notification Law To Require Notification Of Breach Of Encrypted Personal Information When Encryption Key Has Been Leaked

PR
Proskauer Rose LLP

Contributor

The world’s leading organizations and global players choose Proskauer to represent them when they need it the most. Our top tier team of star trial attorneys, acclaimed transactional lawyers and exceptionally talented partners and associates have earned a reputation for the relentless pursuit of perfection and a dauntless pursuit of success.
Encryption is the conversion of data into a form that is unreadable to an unauthorized person.
United States Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

On September 13, 2016, California Governor Jerry Brown signed into law AB 2828, an amendment to the law that requires businesses to disclose data breaches to California residents whose personal information has been compromised.

Currently, the law requires notification of a breach when a California resident's unencrypted personal information is compromised. However, effective January 1, 2017, the amended law requires notification of a security breach when (a) there is unauthorized acquisition of both encrypted personal information and the encryption key or security credential, and (b) the business has a reasonable belief that the encryption key or security credential could render such personal information readable or useable.

Encryption is the conversion of data into a form that is unreadable to an unauthorized person. The California law defines "encryption key" as the confidential key or process designed to render the data readable.

The law is applicable to all persons and businesses that own or license computerized data and conduct business in California, as well as state agencies that own or license computerized data.

California was the first state in the U.S. to require notification of security breaches (its law became effective in 2003). California last amended its data breach notification law in October 2015 to define "encrypted," as well as expand the definition of "personal information" and update the requirements for a security breach notification letter.

California Amends Data Breach Notification Law To Require Notification Of Breach Of Encrypted Personal Information When Encryption Key Has Been Leaked

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More