Skip to main content

Data Protection Map

Alaska

Data Breach Requirements: Alaska Stat. Ann. § 45.48.010 et seq.

The numbering and internal citations herein are derived from the applicable state statute.

Personal Information

(7) The term “personal information” means information in any form on an individual that is not encrypted or redacted, or is encrypted and the encryption key has been accessed or acquired, and that consists of a combination of

(A) An individual’s name; and (B) one or more of the following information elements:

(i) The individual’s Social Security number;

(ii) The individual’s driver’s license number or state identification card number;

(iii) Except as provided in (iv) of this subparagraph, the individual’s account number, credit card number, or debit card number;

(iv) If an account can only be accessed with a personal code, the number in (iii) of this subparagraph and the personal code; in this sub-subparagraph, “personal code” means a security code, an access code, a personal identification number, or a password; (v) Passwords, personal identification numbers, or other access codes for financial accounts.


Security Breach Definition

The term “breach of the security” means unauthorized acquisition, or reasonable belief of unauthorized acquisition, of personal information that compromises the security, confidentiality, or integrity of the personal information maintained by the information collector.


The term “acquisition” includes acquisition by

(A) photocopying, facsimile, or other paper-based method;

(B) a device, including a computer, that can read, write, or store information that is represented in numerical form; or

(C) a method not identified by (A) or (B) of this paragraph.


Good Faith Exception

The good faith acquisition of personal information by an employee or agent of an information collector for a legitimate purpose of the information collector is not a breach of the security of the information system if the employee or agent does not use the personal information for a purpose unrelated to a legitimate purpose of the information collector and does not make further unauthorized disclosure of the personal information.


Risk of Harm Analysis

A data breach notification is not required if, after an appropriate investigation and after written notification to the state attorney general, the covered person determines that there is not a reasonable likelihood that harm to the consumers whose personal information has been acquired has resulted or will result from the breach. The determination shall be documented in writing, and the documentation shall be maintained for five years. The notification required by this subsection may not be considered a public record open to inspection by the public.


Notification Timeline

An information collector shall make the breach notification disclosure in the most expeditious time possible and without unreasonable delay and as necessary to determine the scope of the breach and restore the reasonable integrity of the information system.


Security and Investigation Exceptions

An information collector may delay disclosing the breach if an appropriate law enforcement agency determines that disclosing the breach will interfere with a criminal investigation. However, the information collector shall disclose the breach to the state resident in the most expeditious time possible and without unreasonable delay after the law enforcement agency informs the information collector in writing that disclosure of the breach will no longer interfere with the investigation.


Notification Content Requirements

N/A


Delivery Methods

An information collector shall make the breach notification disclosure

(1) by a written document sent to the most recent address the information collector has for the state resident;

(2) by electronic means if the information collector’s primary method of communication with the state resident is by electronic means or if making the disclosure by the electronic means is consistent with the provisions regarding electronic records and signatures required for notices legally required to be in writing under 15 U.S.C. § 7001 (The Electronic Signatures in Global and National Commerce Act); or

(3) if the information collector demonstrates that the cost of providing notice would exceed $150,000, that the affected class of state residents to be notified exceeds 300,000, or that the information collector does not have sufficient contact information to provide notice, by

(A) electronic mail if the information collector has an electronic mail address for the state resident;

(B) conspicuously posting the disclosure on the internet website of the information collector if the information collector maintains an internet website; and

(C) providing a notice to major statewide media.


Substitute Notice

See Delivery Methods.


Notice to Government Agencies

See Risk of Harm Analysis.


Consumer Reporting Agencies

(a) If an information collector is required notify more than 1,000 state residents of a breach, the information collector shall also notify without unreasonable delay all consumer credit reporting agencies and provide the agencies with the timing, distribution, and content of the notices to state residents.

(b) This section may not be construed to require the information collector to provide the consumer reporting agencies identified under (a) of this section with the names or other personal information of the state residents whose personal information was subject to the breach.

(c) This section does not apply to an information collector who is subject to the Gramm-Leach-Bliley Act.


Preemption and Compliance

N/A


Data Processor Obligations

Immediately after the information recipient discovers the breach, the information recipient shall give notification of the breach to the information distributor who owns the personal information or who licensed the use of the personal information to the information recipient. The information recipient shall cooperate with the information distributor as necessary to allow the information distributor to comply with its legal obligations. In this subsection “cooperate” means sharing with the information distributor information relevant to the breach, except for confidential business information or trade secrets.


Data Disposal and Security: Alaska Stat. Ann. § 45.48.500 et seq.

The numbering and internal citations herein are derived from the applicable state statute. See statute for any applicable exceptions or exemptions.

Key Terms

The term “dispose” means:

(A) the discarding or abandonment of records containing personal information;

(B) the sale, donation, discarding, or transfer of

(i) any medium, including computer equipment or computer media, that contains records of personal information;

(ii) non-paper media, other than that identified under (i) of this subparagraph, on which records of personal information are stored; and

(iii) equipment for non-paper storage of information.


The term “personal information” means: (A) an individual’s passport number, driver’s license number, state identification number, bank account number, credit card number, debit card number, other payment card number, financial account information, or information from a financial application; or (B) a combination of an individual’s (i) name; and (ii) medical information, insurance policy number, employment information, or employment history.


Written Policies

A business or governmental agency shall adopt written policies and procedures that relate to the adequate destruction and proper disposal of records containing personal information.


See Data Disposal (implementing and monitoring compliance with policies and procedures).


Data Disposal

When disposing of records that contain personal information, a business and a governmental agency shall take all reasonable measures necessary to protect against unauthorized access to or use of the records.


The measures that may be taken to comply with the data disposal requirements include:

(1) implementing and monitoring compliance with policies and procedures that require the burning, pulverizing, or shredding of paper documents containing personal information so that the personal information cannot practicably be read or reconstructed;
(2) implementing and monitoring compliance with policies and procedures that require the destruction or erasure of electronic media and other non-paper media containing personal information so that the personal information cannot practicably be read or reconstructed;
(3) after due diligence, entering into a written contract with a third party engaged in the business of record destruction to dispose of records containing personal information in a manner consistent with AS 45.48.500-45.48.590. The term “due diligence” ordinarily includes performing one or more of the following:

(i) reviewing an independent audit of the third party’s operations and its compliance with AS 45.48.500-45.48.590;
(ii) obtaining information about the third party from several references or other reliable sources and requiring that the third party be certified by a recognized trade association or similar organization with a reputation for high standards of quality review; or
(iii) reviewing and evaluating the third party’s information security policies and procedures, or taking other appropriate measures to determine the competency and integrity of the third party.


Other Information

If a business or governmental agency has otherwise complied with the provisions of AS 45.48.500-45.48.590 in the selection of a third party engaged in the business of record destruction, the business or governmental agency is not liable for the disposal of records under AS 45.48.500-45.48.590 after the business or governmental agency has relinquished control of the records to the third party for the destruction of the records.


A business or governmental agency is not liable for the disposal of records under AS 45.48.500-45.48.590 after the business or governmental agency has relinquished control of the records to the individual to whom the records pertain.