ASSEMBLY, No STATE OF NEW JERSEY. 218th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2018 SESSION

Similar documents
ASSEMBLY, No. 514 STATE OF NEW JERSEY. 218th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2018 SESSION

ASSEMBLY, No STATE OF NEW JERSEY. 213th LEGISLATURE INTRODUCED SEPTEMBER 15, 2008

ASSEMBLY, No STATE OF NEW JERSEY. 218th LEGISLATURE INTRODUCED APRIL 5, 2018

STATE OF NEW JERSEY. ASSEMBLY, No th LEGISLATURE

STATE OF NEW JERSEY. SENATE, No th LEGISLATURE

[First Reprint] SENATE COMMITTEE SUBSTITUTE FOR. SENATE, No STATE OF NEW JERSEY. 216th LEGISLATURE ADOPTED MAY 19, 2014

Chapter PERSONAL INFORMATION PROTECTION ACT. Article 01. BREACH OF SECURITY INVOLVING PERSONAL INFORMATION

[Second Reprint] SENATE, No STATE OF NEW JERSEY. 212th LEGISLATURE INTRODUCED JUNE 12, 2006

[First Reprint] ASSEMBLY, No STATE OF NEW JERSEY. 216th LEGISLATURE INTRODUCED OCTOBER 23, 2014

STATE OF NEW JERSEY. ASSEMBLY, No th LEGISLATURE. Sponsored by: Assemblyman KEVIN J. ROONEY District 40 (Bergen, Essex, Morris and Passaic)

ASSEMBLY, No STATE OF NEW JERSEY. 218th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2018 SESSION

SENATE, No STATE OF NEW JERSEY. 218th LEGISLATURE INTRODUCED JANUARY 25, SYNOPSIS Increases annual salary of certain public employees.

ASSEMBLY, No. 170 STATE OF NEW JERSEY. 208th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 1998 SESSION

ASSEMBLY, No. 156 STATE OF NEW JERSEY. 217th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2016 SESSION

[Second Reprint] ASSEMBLY, No STATE OF NEW JERSEY. 214th LEGISLATURE INTRODUCED JUNE 14, 2010

ASSEMBLY, No STATE OF NEW JERSEY. 216th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2014 SESSION

ASSEMBLY, No. 904 STATE OF NEW JERSEY. 218th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2018 SESSION

ASSEMBLY COMMITTEE SUBSTITUTE FOR. ASSEMBLY, No STATE OF NEW JERSEY. 218th LEGISLATURE

[First Reprint] SENATE SUBSTITUTE FOR. SENATE, No STATE OF NEW JERSEY. 208th LEGISLATURE ADOPTED SEPTEMBER 28, 1998

ASSEMBLY, No STATE OF NEW JERSEY. 216th LEGISLATURE INTRODUCED MARCH 24, 2014

SENATE, No. 679 STATE OF NEW JERSEY. 218th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2018 SESSION

ASSEMBLY, No STATE OF NEW JERSEY. 215th LEGISLATURE INTRODUCED NOVEMBER 18, 2013

ASSEMBLY, No STATE OF NEW JERSEY. 216th LEGISLATURE INTRODUCED JANUARY 16, 2014

Security Breach Notification Chart

ASSEMBLY, No STATE OF NEW JERSEY. 218th LEGISLATURE INTRODUCED APRIL 5, 2018

[Second Reprint] SENATE, No. 651 STATE OF NEW JERSEY. 217th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2016 SESSION

ASSEMBLY, No STATE OF NEW JERSEY. 218th LEGISLATURE INTRODUCED MAY 7, 2018

ASSEMBLY, No STATE OF NEW JERSEY. 209th LEGISLATURE INTRODUCED JUNE 28, 2001

Security Breach Notification Chart

STATE OF NEW JERSEY. SENATE, No th LEGISLATURE. Sponsored by: Senator JOSEPH PENNACCHIO District 26 (Essex, Morris and Passaic)

ASSEMBLY, No STATE OF NEW JERSEY. 216th LEGISLATURE INTRODUCED FEBRUARY 10, 2014

ASSEMBLY, No. 594 STATE OF NEW JERSEY. 218th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2018 SESSION

ASSEMBLY, No STATE OF NEW JERSEY. 218th LEGISLATURE INTRODUCED FEBRUARY 1, SYNOPSIS Concerning the "Contractor's Registration Act.

ASSEMBLY, No STATE OF NEW JERSEY. 216th LEGISLATURE INTRODUCED JUNE 22, 2015

ASSEMBLY, No STATE OF NEW JERSEY. 218th LEGISLATURE INTRODUCED MARCH 5, 2018

[First Reprint] SENATE, No. 522 STATE OF NEW JERSEY. 218th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2018 SESSION

STATE OF NEW JERSEY. SENATE, No th LEGISLATURE

SENATE, No. 414 STATE OF NEW JERSEY. 218th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2018 SESSION

STATE OF NEW JERSEY. SENATE, No th LEGISLATURE

SENATE, No STATE OF NEW JERSEY. 218th LEGISLATURE INTRODUCED FEBRUARY 26, 2018

ASSEMBLY, No STATE OF NEW JERSEY. 212th LEGISLATURE INTRODUCED JANUARY 30, 2006

ASSEMBLY, No STATE OF NEW JERSEY. 218th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2018 SESSION

SENATE, No. 872 STATE OF NEW JERSEY. 218th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2018 SESSION

ASSEMBLY, No STATE OF NEW JERSEY. 217th LEGISLATURE INTRODUCED FEBRUARY 22, 2016

ASSEMBLY, No. 989 STATE OF NEW JERSEY. 218th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2018 SESSION

SENATE CONCURRENT RESOLUTION No. 28 STATE OF NEW JERSEY. 217th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2016 SESSION

[First Reprint] ASSEMBLY, No STATE OF NEW JERSEY. 217th LEGISLATURE INTRODUCED APRIL 7, 2016

[First Reprint] ASSEMBLY COMMITTEE SUBSTITUTE FOR. ASSEMBLY, No STATE OF NEW JERSEY. 216th LEGISLATURE ADOPTED JUNE 23, 2014

ASSEMBLY, No STATE OF NEW JERSEY. 218th LEGISLATURE INTRODUCED FEBRUARY 1, 2018

Security Breach Notification Chart

1 HB By Representative Williams (P) 4 RFD: Technology and Research. 5 First Read: 13-FEB-18. Page 0

Security Breach Notification Chart

[First Reprint] SENATE COMMITTEE SUBSTITUTE FOR. SENATE, No STATE OF NEW JERSEY. 211th LEGISLATURE ADOPTED OCTOBER 14, 2004

ASSEMBLY, No STATE OF NEW JERSEY. 218th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2018 SESSION

ASSEMBLY, No STATE OF NEW JERSEY. 216th LEGISLATURE INTRODUCED FEBRUARY 10, 2014

SENATE, No STATE OF NEW JERSEY. 212th LEGISLATURE INTRODUCED JUNE 22, SYNOPSIS Increases fees and penalties under the Explosives Act.

ASSEMBLY CONCURRENT RESOLUTION No. 23 STATE OF NEW JERSEY. 218th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2018 SESSION

STATE OF NEW JERSEY. ASSEMBLY, No th LEGISLATURE. Sponsored by: Assemblyman MICHAEL PATRICK CARROLL District 25 (Morris and Somerset)

SENATE, No STATE OF NEW JERSEY. 216th LEGISLATURE INTRODUCED APRIL 28, 2014

1 SB By Senators Orr and Holley. 4 RFD: Governmental Affairs. 5 First Read: 13-FEB-18. Page 0

[Corrected Copy] SENATE, No STATE OF NEW JERSEY. 211th LEGISLATURE INTRODUCED DECEMBER 13, 2004

SENATE COMMITTEE SUBSTITUTE FOR. SENATE, Nos and 1990 STATE OF NEW JERSEY. 217th LEGISLATURE ADOPTED JANUARY 23, 2017

THE GENERAL ASSEMBLY OF PENNSYLVANIA HOUSE BILL

1 SB By Senators Orr and Holley. 4 RFD: Governmental Affairs. 5 First Read: 13-FEB-18. Page 0

STATE OF NEW JERSEY. SENATE, No th LEGISLATURE. Sponsored by: Senator ANTHONY R. BUCCO District 25 (Morris and Somerset)

ASSEMBLY, No STATE OF NEW JERSEY. 214th LEGISLATURE INTRODUCED MARCH 16, 2010

ASSEMBLY, No STATE OF NEW JERSEY. 217th LEGISLATURE INTRODUCED APRIL 4, 2016

SENATE, No STATE OF NEW JERSEY. 218th LEGISLATURE INTRODUCED FEBRUARY 22, 2018

[First Reprint] ASSEMBLY, No STATE OF NEW JERSEY. 216th LEGISLATURE INTRODUCED FEBRUARY 10, 2014

ASSEMBLY, No STATE OF NEW JERSEY. 217th LEGISLATURE INTRODUCED FEBRUARY 27, 2017

ASSEMBLY, No STATE OF NEW JERSEY. 218th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2018 SESSION

ASSEMBLY, No STATE OF NEW JERSEY. 216th LEGISLATURE INTRODUCED NOVEMBER 16, 2015

STATE OF NEW JERSEY. ASSEMBLY, No th LEGISLATURE. Sponsored by: Assemblyman BOB ANDRZEJCZAK District 1 (Atlantic, Cape May and Cumberland)

[First Reprint] SENATE, No STATE OF NEW JERSEY. 217th LEGISLATURE INTRODUCED JUNE 26, 2017

SENATE, No. 82 STATE OF NEW JERSEY. 217th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2016 SESSION

ASSEMBLY, No STATE OF NEW JERSEY. 216th LEGISLATURE INTRODUCED DECEMBER 4, 2014

ASSEMBLY COMMITTEE SUBSTITUTE FOR. ASSEMBLY, No STATE OF NEW JERSEY. 215th LEGISLATURE ADOPTED DECEMBER 16, 2013

ASSEMBLY, No STATE OF NEW JERSEY. 217th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2016 SESSION

ASSEMBLY, No. 565 STATE OF NEW JERSEY. 212th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2006 SESSION

[First Reprint] ASSEMBLY, No STATE OF NEW JERSEY. 215th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2012 SESSION

SENATE, No STATE OF NEW JERSEY. 217th LEGISLATURE INTRODUCED FEBRUARY 16, 2016

Security Breach Notification Chart

STATE OF NEW JERSEY. SENATE, No th LEGISLATURE

Arent Fox LLP Survey of Data Breach Notification Statutes

SENATE CONCURRENT RESOLUTION No. 139 STATE OF NEW JERSEY. 217th LEGISLATURE INTRODUCED JANUARY 9, 2017

[First Reprint] ASSEMBLY, No STATE OF NEW JERSEY. 217th LEGISLATURE INTRODUCED APRIL 14, 2016

ASSEMBLY, No STATE OF NEW JERSEY. 218th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2018 SESSION

SENATE SUBSTITUTE FOR SENATE COMMITTEE SUBSTITUTE FOR. SENATE, No STATE OF NEW JERSEY. 215th LEGISLATURE ADOPTED NOVEMBER 29, 2012

SENATE, No. 187 STATE OF NEW JERSEY. 211th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2004 SESSION

SENATE, No. 685 STATE OF NEW JERSEY. 216th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2014 SESSION

ASSEMBLY CONCURRENT RESOLUTION No. 60 STATE OF NEW JERSEY. 218th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2018 SESSION

[First Reprint] SENATE, No. 549 STATE OF NEW JERSEY. 218th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2018 SESSION

[First Reprint] SENATE, No. 1 STATE OF NEW JERSEY. 217th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2016 SESSION

[Second Reprint] ASSEMBLY, No. 945 STATE OF NEW JERSEY. 216th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2014 SESSION

ASSEMBLY, No STATE OF NEW JERSEY. 217th LEGISLATURE INTRODUCED MAY 23, 2016

SENATE, No. 647 STATE OF NEW JERSEY. 218th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2018 SESSION

SCHWARTZ & BALLEN LLP 1990 M STREET, N.W. SUITE 500 WASHINGTON, DC

(No. 97) (Approved June 19, 2008) AN ACT

ASSEMBLY, No STATE OF NEW JERSEY. 215th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 2012 SESSION

STATE OF NEW JERSEY. ASSEMBLY, No th LEGISLATURE. Sponsored by: Assemblyman ANTHONY M. BUCCO District 25 (Morris and Somerset)

Transcription:

ASSEMBLY, No. 0 STATE OF NEW JERSEY th LEGISLATURE PRE-FILED FOR INTRODUCTION IN THE 0 SESSION Sponsored by: Assemblyman JAMES J. KENNEDY District (Middlesex, Somerset and Union) Assemblyman KEVIN J. ROONEY District 0 (Bergen, Essex, Morris and Passaic) Co-Sponsored by: Assemblyman Mukherji SYNOPSIS Requires certain notifications and free credit reports for customers following breach of security of personal information within business or public entity. CURRENT VERSION OF TEXT Introduced Pending Technical Review by Legislative Counsel. (Sponsorship Updated As Of: //0)

0 0 0 0 AN ACT concerning breaches of security of personal information and amending P.L.00, c.. BE IT ENACTED by the Senate and General Assembly of the State of New Jersey:. Section of P.L.00, c. (C.:-) is amended to read as follows:. a. Any business that conducts business in New Jersey, or any public entity that compiles or maintains computerized records that include personal information, shall disclose any breach of security of those computerized records following discovery or notification of the breach to any customer who is a resident of New Jersey whose personal information was, or is reasonably believed to have been, accessed by an unauthorized person. The disclosure to a customer shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection c. of this section, or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Disclosure of a breach of security to a customer shall not be required under this section if the business or public entity establishes that misuse of the information is not reasonably possible. Any determination shall be documented in writing and retained for five years. b. Any business or public entity that compiles or maintains computerized records that include personal information on behalf of another business or public entity shall notify that business or public entity, who shall notify its New Jersey customers, as provided in subsection a. of this section, of any breach of security of the computerized records immediately following discovery, if the personal information was, or is reasonably believed to have been, accessed by an unauthorized person. c. () Any business or public entity required under this section to disclose a breach of security of a customer's personal information shall, in advance of the disclosure to the customer, report the breach of security and any information pertaining to the breach to the Division of State Police in the Department of Law and Public Safety for investigation or handling, which may include dissemination or referral to other appropriate law enforcement entities. () The notification required by this section shall be delayed if a law enforcement agency determines that the notification will impede a criminal or civil investigation and that agency has made a request that the notification be delayed. The notification required by this section shall be made after the law enforcement agency EXPLANATION Matter enclosed in bold-faced brackets [thus] in the above bill is not enacted and is intended to be omitted in the law. Matter underlined thus is new matter.

0 0 0 0 determines that its disclosure will not compromise the investigation and notifies that business or public entity. d. For purposes of this section, notice may be provided by one of the following methods: () Written notice; or () Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in section 0 of the federal "Electronic Signatures in Global and National Commerce Act" ( U.S.C. s.00) [; or () Substitute notice, if the business or public entity demonstrates that the cost of providing notice would exceed $0,000, or that the affected class of subject persons to be notified exceeds 00,000, or the business or public entity does not have sufficient contact information. Substitute notice shall consist of all of the following: (a) E-mail notice when the business or public entity has an e- mail address; (b) Conspicuous posting of the notice on the Internet web site page of the business or public entity, if the business or public entity maintains one; and (c) Notification to major Statewide media]. e. [Notwithstanding subsection d. of this section, a business or public entity that maintains its own notification procedures as part of an information security policy for the treatment of personal information, and is otherwise consistent with the requirements of this section, shall be deemed to be in compliance with the notification requirements of this section if the business or public entity notifies subject customers in accordance with its policies in the event of a breach of security of the system.] (Deleted by amendment, P.L., c. ) (pending before the Legislature as this bill) f. In addition to any other disclosure or notification required under this section, in the event that a business or public entity discovers circumstances requiring notification pursuant to this section of more than,000 persons at one time, the business or public entity shall also notify, without unreasonable delay, all consumer reporting agencies that compile or maintain files on consumers on a nationwide basis, as defined by subsection (p) of section 0 of the federal "Fair Credit Reporting Act" ( U.S.C. s.a), of the timing, distribution and content of the notices. g. The notice required under this section shall contain contact information, including a toll free telephone number, of a customer representative of the business or public entity who shall be available to give the customer information on: () what information has been compromised and potential consequences of the breach of security; () how the company or public entity is addressing the breach;

0 0 0 0 () what steps the customer may take to safeguard the customer s information; and () notification that the customer has access to free credit reports pursuant to subsection h. of this section. h. For a period of six months following notification of a breach of security, the business or public entity shall provide a customer with access to independent credit reports from a consumer reporting agency. The business or public entity shall supply the appropriate contact information of the consumer reporting agency and pay any fees to that consumer reporting agency for supplying the customer with a credit report once per month for a period of twelve months following the customer s initial request for a credit report. The customer shall be notified of the customer s access to free credit reports when the business or public entity notifies the customer of the breach of security. (cf: P.L.00, c., s.). This act shall take effect on the first day of the third month following enactment. STATEMENT This bill requires businesses and public entities to provide customers with certain notifications following a breach of security that compromises the personal information of customers. Under current law, following a breach of security, a business or public entity must disclose the breach of security of those computerized records following discovery or notification of the breach to any customer who is a resident of New Jersey whose personal information was, or is reasonably believed to have been, accessed by an unauthorized person. The bill requires that this notification must be provided through either written or electronic notice. Under the bill, businesses and public entities may no longer provide notification through substitute notice, which is permitted under current law for certain breaches of security. The bill provides that the notice must contain contact information, including a toll free telephone number, of a customer representative of the business or public entity who is available to give the customer information on: () what information has been compromised and potential consequences of the breach of security; () how the company or public entity is addressing the breach; () what steps the customer may take to safeguard the customer s information; and () notification that the customer has access to free credit reports.

0 Additionally, under the bill, for a period of six months following notification of a breach of security, the business or public entity must provide a customer with access to independent credit reports from a consumer reporting agency. The business or public entity must supply the appropriate contact information of the consumer reporting agency and pay any fees to that consumer reporting agency for supplying the customer with a credit report once per month for a period of twelve months following the customer s initial request for a credit report. The customer shall be notified of the customer s access to free credit reports when the business or public entity notifies the customer of the breach of security.