Data Breach Requirements: Ark. Code Ann. § 4-110-101 et seq.
The numbering and internal citations herein are derived from the applicable state statute.
Personal Information
(7) The term “personal information” means an individual’s first name or first initial and his or her last name in combination with any one or more of the following data elements when either the name or the data element is not encrypted or redacted:
(A) Social Security number;
(B) Driver’s license number or Arkansas identification card number;
(C) Account number, credit card number, or debit card number in combination with any required security code, access code, or password that would permit access to an individual’s financial account;
(D) Medical information; and
(E)(i) Biometric data.
(ii) As used in this subdivision (7)(E), “biometric data” means data generated by automatic measurements of an individual’s biological characteristics, including without limitation: (a) Fingerprints; (b) Faceprint; (c) A retinal or iris scan; (d) Hand geometry; (e) Voiceprint analysis; (f) Deoxyribonucleic acid (DNA); or (g) Any other unique biological characteristics of an individual if the characteristics are used by the owner or licensee to uniquely authenticate the individual’s identity when the individual accesses a system or account;
Security Breach Definition
The term “breach of the security of the system” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by a person or business.
Good Faith Exception
A “breach of the security of the system” does not include the good faith acquisition of personal information by an employee or agent of the person or business for the legitimate purposes of the person or business if the personal information is not otherwise used or subject to further unauthorized disclosure.
Risk of Harm Analysis
A breach notification is not required if, after a reasonable investigation, the person or business determines that there is no reasonable likelihood of harm to customers.
Notification Timeline
Any person or business that acquires, owns, or licenses computerized data that includes personal information shall disclose any breach of the security of the system following discovery or notification of the breach of the security of the system to any Arkansas resident whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure shall be made in the most expedient time and manner possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, or any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the data system.
Security and Investigation Exceptions
The breach notification may be delayed if a law enforcement agency determines that the notification will impede a criminal investigation. The breach notification required shall be made after the law enforcement agency determines that it will not compromise the investigation.
Notification Content Requirements
N/A
Delivery Methods
A breach notice may be provided by one of the following methods:
(1) Written notice;
(2) Electronic mail notice if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001 (The Electronic Signatures in Global and National Commerce Act), as it existed on January 1, 2005; or (3)(A) Substitute notice if the person or business demonstrates that: (i) The cost of providing notice would exceed $250,000; (ii) The affected class of persons to be notified exceeds 500,000; or (iii) The person or business does not have sufficient contact information.
Substitute Notice
Substitute notice shall consist of all of the following:
(i) Electronic mail notice when the person or business has an electronic mail address for the subject persons;
(ii) Conspicuous posting of the notice on the website of the person or business if the person or business maintains a website; and (iii) Notification by statewide media.
Notice to Government Agencies
If a breach affects the personal information of more than one thousand (1,000) individuals, the person or business required to make a breach notification shall, at the same time the security breach is disclosed to an affected individual or within 45 days after the person or business determines that there is a reasonable likelihood of harm to customers, whichever occurs first, disclose the security breach to the attorney general.
Consumer Reporting Agencies
N/A
Preemption and Compliance
The law does not apply to a person or business that is regulated by a state or federal law that provides greater protection to personal information and at least as thorough disclosure requirements for breaches of the security of personal information than that provided by this law. Compliance with the state or federal law shall be deemed compliance with this chapter with regard to the subjects covered by this law.
Data Processor Obligations
A person or business that maintains computerized data that includes personal information that the person or business does not own shall notify the owner or licensee that there has been a breach of the security of the system immediately following discovery if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person.
Other Information
A person or business shall retain a copy of the written determination of a breach of the security of a system and supporting documentation for five (5) years from the date of determination of the breach of the security of the system. If the attorney general submits a written request for the written determination of the breach of the security of the system, the person or business shall send a copy of the written determination of the breach of the security of the system and supporting documentation to the Attorney General no later than thirty (30) days after the date of receipt of the request.
Data Disposal and Security: Ark. Code Ann. §§ 4-110-103, 4-110-104, 4-110-106.
The numbering and internal citations herein are derived from the applicable state statute. See statute for any applicable exceptions or exemptions.
Key Terms
The term “personal information” means an individual’s first name or first initial and his or her last name in combination with any one or more of the following data elements when either the name or the data element is not encrypted or redacted:
(A) Social Security number;
(B) Driver’s license number or Arkansas identification card number;
(C) Account number, credit card number, or debit card number in combination with any required security code, access code, or password that would permit access to an individual’s financial account;
(D) Medical information; and
(E)(i) Biometric data.
The term “biometric data” means data generated by automatic measurements of an individual’s biological characteristics, including without limitation:
(a) Fingerprints;
(b) Faceprint;
(c) A retinal or iris scan;
(d) Hand geometry;
(e) Voiceprint analysis;
(f) Deoxyribonucleic acid (DNA); or
(g) Any other unique biological characteristics of an individual if the characteristics are used by the owner or licensee to uniquely authenticate the individual’s identity when the individual accesses a system or account.
Security Requirements
A person or business that acquires, owns, or licenses personal information about an Arkansas resident shall implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal information from unauthorized access, destruction, use, modification, or disclosure.
Data Disposal
A person or business shall take all reasonable steps to destroy or arrange for the destruction of a customer’s records within its custody or control containing personal information that is no longer to be retained by the person or business by shredding, erasing, or otherwise modifying the personal information in the records to make it unreadable or undecipherable through any means.