<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://consumerist.com/2008/02/cso-maps-state-by-state-data-breach-disclosure-laws.html" />
  <link rel="self" type="application/atom+xml" href="http://consumerist.com/atom.xml" />
  <id>tag:consumerist.com,2010:/1/tag:64.14.177.195,2008://1.359489-</id>
  <updated>2010-01-09T04:01:27Z</updated>
  <title>Comments for CSO Maps State-By-State Data Breach Disclosure Laws</title>
  <subtitle>Shoppers bite back.</subtitle>
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.32-en</generator>
  <entry>
    <id>tag:64.14.177.195,2008://1.359489</id>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2008/02/cso-maps-state-by-state-data-breach-disclosure-laws.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://consumerist.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=359489" title="CSO Maps State-By-State Data Breach Disclosure Laws" />
    <published>2008-02-22T07:37:24Z</published>
    <updated>2008-02-22T07:38:22Z</updated>
    <title>CSO Maps State-By-State Data Breach Disclosure Laws</title>
    <summary><![CDATA[--> CSO has produced an interactive U.S. map that shows what's required of companies that suffer a data breach in the 38 states that care enough about consumer rights to have passed disclosure laws. Most are modeled after California's strict SB1386 anti-ID theft law, but now you can tell at a glance what your state is doing about the issue&mdash;and in most cases you can click on the icon in the pop-up info box to see a copy of the actual law.]]></summary>
    <author>
      <name>Chris Walters</name>
      
    </author>
    
    <content type="html" xml:lang="en" xml:base="http://consumerist.com/">
      <![CDATA[<p><!--<img alt="con_smalldatabreachmap.jpg" src="http://consumerist.com/images/resources/2008/02/con_smalldatabreachmap.jpg" width="300" height="245" class="left" />--> CSO has produced an interactive U.S. map that shows <a href="http://www.csoonline.com/read/020108/ammap/ammap.html">what's required of companies that suffer a data breach</a> in the 38 states that care enough about consumer rights to have passed disclosure laws. Most are modeled after California's strict <a href="http://en.wikipedia.org/wiki/SB_1386">SB1386 anti-ID theft law</a>, but now you can tell at a glance what your state is doing about the issue&mdash;and in most cases you can click on the icon in the pop-up info box to see a copy of the actual law.</p>

<p>In a related article, CSO <a href="http://www2.csoonline.com/exclusives/column.html?CID=33533">talks to a data breach disclosure law expert</a> about what's going on at the federal level, where there are at least eight different proposed laws bouncing around D.C.<blockquote><b>Forsheit:</b> I really can't tell you why it's taking so long. There was a sense with the new Congress that there was a greater likelihood something would pass. It's just not clear why it hasn't. Clearly people are concerned with ID theft. It's mostly a bipartisan issue, so you see a lot of consensus. There are some disputed aspects, like whether notification should be mandated--as it is in many states--with any unauthorized acquisition [of data], as opposed to there being a higher threshold trigger. But those can be worked out.</p>

<p><b>SO:</b> What about the 11 states that don't yet have laws? Are they waiting for a federal bill?</p>

<p><b>Forsheit:</b> In some of those states, there have been proposals that just haven't made their way through. If we don't see federal legislation soon, those remaining states will likely enact some law</blockquote> <br />
<img alt="con_screengrabofdatabreachmap.jpg" src="http://consumerist.com/images/resources/2008/02/con_screengrabofdatabreachmap.jpg" width="463" height="335" class="left"/><br clear="all">&nbsp;<br /><a href="http://www.csoonline.com/read/020108/ammap/ammap.html">"Data Breach Notification Laws, State By State"</a> [CSOonline] </p>

<p>RELATED<br />
<a href="http://www2.csoonline.com/exclusives/column.html?CID=33533">"CSO Disclosure Series | What's Next with Disclosure Legislation?"</a> [CSOonline]<br />
</p>]]>
      
    </content>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2008://1.359489-comment:4371681</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2008://1.359489" type="text/html" href="http://consumerist.com/2008/02/cso-maps-state-by-state-data-breach-disclosure-laws.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2008/02/cso-maps-state-by-state-data-breach-disclosure-laws.html#c4371681" />
    <title>Comment from xtc46 - thinksmarter on twitter on 2008-02-24</title>
    <author>
        <name>xtc46 - thinksmarter on twitter</name>
        <uri>http://think-smarter.blogspot.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://think-smarter.blogspot.com">
        <![CDATA[<p>@<a href="#c4343549" rel="nofollow">Imhotep</a>: I'm in Hawaii and work as a computer tech with a specialty in information and data security. I just quit a company on art because they refused to take the recommended steps to protect confidential medical data and I didn't want to be in a position where civil and criminal charges could be brought against a company where I was responsible, in part, for the protection of that data. It is great for consumers and people in general, because laws like this force companies to take responsibility for the data they hold.</p>]]>
    </content>
    <published>2008-02-25T03:49:11Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2008://1.359489-comment:4357520</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2008://1.359489" type="text/html" href="http://consumerist.com/2008/02/cso-maps-state-by-state-data-breach-disclosure-laws.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2008/02/cso-maps-state-by-state-data-breach-disclosure-laws.html#c4357520" />
    <title>Comment from rhombopteryx on 2008-02-22</title>
    <author>
        <name>rhombopteryx</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p><p>Awesome, according to the map, <i>every</i> single federal law would preempt stronger state laws <b>and</b> prevent identity theft victims from suing the person who leaked the data! <br />That means <i>every</i> Senator or Congressperson who sponsored one of the bills thinks their own state legislature is too stupid to pass a good law, so they're stopping them.</p><br />
<p>Congress cares! (about their banking and data mining corporate contributors who have sloppy data protection....)</p></p>]]>
    </content>
    <published>2008-02-23T03:10:59Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2008://1.359489-comment:4350797</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2008://1.359489" type="text/html" href="http://consumerist.com/2008/02/cso-maps-state-by-state-data-breach-disclosure-laws.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2008/02/cso-maps-state-by-state-data-breach-disclosure-laws.html#c4350797" />
    <title>Comment from Barry Zuckerkorn, Esq. on 2008-02-22</title>
    <author>
        <name>Barry Zuckerkorn, Esq.</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p><p>@<a href="http://consumerist.com/359489/cso-maps-state+by+state-data-breach-disclosure-laws#c4346302" rel="nofollow">Anitra</a>: Yes, "private right of action" means that the person whose data was stolen can sue the company for failing to inform him or her as required by the statute. In the states that do not have a private right of action, usually the company can still be found liable in a lawsuit brought by the state attorney general.</p></p>]]>
    </content>
    <published>2008-02-22T23:16:06Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2008://1.359489-comment:4346302</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2008://1.359489" type="text/html" href="http://consumerist.com/2008/02/cso-maps-state-by-state-data-breach-disclosure-laws.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2008/02/cso-maps-state-by-state-data-breach-disclosure-laws.html#c4346302" />
    <title>Comment from Anitra on 2008-02-22</title>
    <author>
        <name>Anitra</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>I looked through the page but couldn't find this - what is "private right of action"? Is that saying that people whose data have been stolen can sue?</p>]]>
    </content>
    <published>2008-02-22T20:21:00Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2008://1.359489-comment:4344673</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2008://1.359489" type="text/html" href="http://consumerist.com/2008/02/cso-maps-state-by-state-data-breach-disclosure-laws.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2008/02/cso-maps-state-by-state-data-breach-disclosure-laws.html#c4344673" />
    <title>Comment from phripley on 2008-02-22</title>
    <author>
        <name>phripley</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>What law pertains:</p>
<p>Are the companies bound by the laws of the state(s) ...where they have operations?</p>
<p>...where they are headquartered?</p>
<p>...or where their customers are located?</p>]]>
    </content>
    <published>2008-02-22T18:08:57Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2008://1.359489-comment:4343549</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2008://1.359489" type="text/html" href="http://consumerist.com/2008/02/cso-maps-state-by-state-data-breach-disclosure-laws.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2008/02/cso-maps-state-by-state-data-breach-disclosure-laws.html#c4343549" />
    <title>Comment from Imhotep on 2008-02-22</title>
    <author>
        <name>Imhotep</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>California is strict?  There's NO civil or criminal penalty for failure to disclose.  Hawaii's looking real good right about now.</p>]]>
    </content>
    <published>2008-02-22T11:55:50Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2008://1.359489-comment:4343130</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2008://1.359489" type="text/html" href="http://consumerist.com/2008/02/cso-maps-state-by-state-data-breach-disclosure-laws.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2008/02/cso-maps-state-by-state-data-breach-disclosure-laws.html#c4343130" />
    <title>Comment from darkclawsofchaos on 2008-02-22</title>
    <author>
        <name>darkclawsofchaos</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p><p>@<a href="http://consumerist.com/359489/cso-maps-state+by+state-data-breach-disclosure-laws#c4341629" rel="nofollow">azntg</a>: Not to mention having the best Highway Patrol around.</p></p>]]>
    </content>
    <published>2008-02-22T10:47:09Z</published>
  </entry>

  <entry>
    <id>tag:64.14.177.195,2008://1.359489-comment:4341629</id>
    <thr:in-reply-to ref="tag:64.14.177.195,2008://1.359489" type="text/html" href="http://consumerist.com/2008/02/cso-maps-state-by-state-data-breach-disclosure-laws.html"/>
    <link rel="alternate" type="text/html" href="http://consumerist.com/2008/02/cso-maps-state-by-state-data-breach-disclosure-laws.html#c4341629" />
    <title>Comment from azntg on 2008-02-22</title>
    <author>
        <name>azntg</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Rhode Islanders seem to have it best, having private right of action plus a civil/criminal penalty for failure to disclose!</p>]]>
    </content>
    <published>2008-02-22T08:05:47Z</published>
  </entry>


</feed>



