State of Illinois
2005 and 2006 HB3743
Introduced 2/24/2005, by Rep. Rosemary Mulligan SYNOPSIS AS INTRODUCED: |
Creates the Security Breach Notification Act. Requires any person or business conducting business in the State, and that owns or licenses computerized data that includes personal information, to disclose any breach of the security of the system following discovery or notification of the breach in the security of the data to any person whose unencrypted personal information was, or is reasonably believed to have been acquired by an unauthorized person. Requires any person or business that maintains computerized data that includes personal information that the person or business does not own, to notify the owner or licensee of the information of any breach of the security of the data immediately following discovery of such breach, if the personal information was, or is reasonably believed to have been acquired by an unauthorized person. Provides that notice may be provided to a customer in one of the following ways: (1) written notice; (2) electronic notice; or (3) substitute notice if the person or business demonstrates that the cost of providing notice would exceed $250,000, or the affected class of persons to be notified exceeds 500,000, or the person or business does not have sufficient contact information. Provides a private right of action for a violation of the Act.
| |
HB3743 |
LRB094 11457 RXD 42382 b |
1 |
| AN ACT concerning security.
2 |
| Be it enacted by the People of the State of Illinois,
3 |
| represented in the General Assembly:
4 |
| Section 1. Short title. This Act may be cited as the |
5 |
| Security Breach Notification Act. |
6 |
| Section 5. Definitions. In this Act: |
7 |
| "Breach of the security of the system" means unauthorized |
8 |
| acquisition of computerized data that compromises the |
9 |
| security, confidentiality, or integrity of personal |
10 |
| information maintained by a person or business. "Breach of the |
11 |
| security of the system" does not include good faith acquisition |
12 |
| of personal information by an employee or agent of the person |
13 |
| or business, provided that the personal information is not used |
14 |
| or subject to further unauthorized disclosure. |
15 |
| "Personal information" means an individual's first name or |
16 |
| first initial and last name in combination with any one or more |
17 |
| of the following data elements, when either the name or the |
18 |
| data elements are not encrypted: |
19 |
| (1) Social security number. |
20 |
| (2) Driver's license number or Illinois State |
21 |
| Identification Card number. |
22 |
| (3) Account number, credit or debit card number, in |
23 |
| combination with any
required security code, access code, |
24 |
| or password that would permit access to an individual's |
25 |
| financial account.
26 |
| "Personal information" does not include publicly available |
27 |
| information that is lawfully made available to the general |
28 |
| public from federal, State, or local government records.
29 |
| Section 10. Security breach; notification. |
30 |
| (a) Any person or business that conducts business in the |
31 |
| State, and that owns or licenses computerized data that |