Alabama Becomes 50th State To Enact Data Breach Notification Law

Author:Ms Cynthia Larose
Profession:Mintz, Levin, Cohn, Ferris, Glovsky and Popeo, P.C.
 
FREE EXCERPT

Alabama has joined the "crazy quilt" of state data breach notification laws with the governor's signature of the Alabama Data Breach Notification Act of 2018.

Things to take note of under the Alabama law:

The law requires entities to "implement and maintain reasonable security measures" and includes a granular list of what such security measures should include. An interesting component of reasonable security measures is "keeping the management of the covered entity, including its board of directors, if any, appropriately informed of the overall status of its security measures." Notification to residents within 45 days after a breach has been discovered if it is reasonably likely to cause substantial harm. The definition of "personal information" is expanded to include health information and user name or email address in combination with a password. Notice to the Alabama Attorney General if notice is provided...

To continue reading

FREE SIGN UP