Data Breach Requirements: D.C. Code § 28-3851 et seq.
The numbering and internal citations herein are derived from the applicable state statute.
Personal Information
(3)(A) The term “personal information” means:
(i) An individual’s first name, first initial and last name, or any other personal identifier, which, in combination with any of the following data elements, can be used to identify a person or the person’s information:
(I) Social Security number, individual taxpayer identification number, passport number, driver’s license number, District of Columbia identification card number, military identification number, or other unique identification number issued on a government document commonly used to verify the identity of a specific individual;
(II) Account number, credit card number or debit card number, or any other number or code or combination of numbers or codes, such as an identification number, security code, access code, or password, that allows access to or use of an individual’s financial or credit account;
(III) Medical information;
(IV) Genetic information and deoxyribonucleic acid (DNA) profile;
(V) Health insurance information, including a policy number, subscriber information number, or any unique identifier used by a health insurer to identify the person that permits access to an individual’s health and billing information;
(VI) Biometric data of an individual generated by automatic measurements of an individual’s biological characteristics, such as a fingerprint, voice print, genetic print, retina or iris image, or other unique biological characteristic, that is used to uniquely authenticate the individual’s identity when the individual accesses a system or account; or
(VII) Any combination of data elements included in sub-sub-subparagraphs (I) through (VI) of this sub-subparagraph that would enable a person to commit identity theft without reference to a person’s first name or first initial and last name or other independent personal identifier. (ii) A username or email address in combination with a password, security question and answer, or other means of authentication, or any combination of data elements included in sub-sub-subparagraphs (I) through (VI) of sub-subparagraph (i) that permits access to an individual’s email account.
Security Breach Definition
The term “breach of the security of the system” means unauthorized acquisition of computerized or other electronic data or any equipment or device storing such data that compromises the security, confidentiality, or integrity of personal information maintained by the person or entity who conducts business in the District of Columbia.
Good Faith Exception
A “breach of the security of the system” does not include a good-faith acquisition of personal information by an employee or agency of the person or entity for the purposes of the person or entity if the personal information is not used improperly or subject to further unauthorized disclosure.
Risk of Harm Analysis
A “breach of the security of the system” does not include acquisition of personal information of an individual that the person or entity reasonably determines, after a reasonable investigation and consultation with the Office of the Attorney General for the District of Columbia and federal law enforcement agencies, will likely not result in harm to the individual.
Notification Timeline
The breach notification shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, and with any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
Security and Investigation Exceptions
The breach notification may be delayed if a law enforcement agency determines that the notification will impede a criminal investigation but shall be made as soon as possible after the law enforcement agency determines that the notification will not compromise the investigation.
Notification Content Requirements
The breach notification shall include:
(1) To the extent possible, a description of the categories of information that were, or are reasonably believed to have been, acquired by an unauthorized person, including the elements of personal information that were, or are reasonably believed to have been, acquired;
(2) Contact information for the person or entity making the notification, including the business address, telephone number, and toll-free telephone number if one is maintained;
(3) The toll-free telephone numbers and addresses for the major consumer reporting agencies, including a statement notifying the resident of the right to obtain a security freeze free of charge pursuant to 15 U.S.C. § 1681c-1 and information on how a resident may request a security freeze; and
(4) The toll-free telephone numbers, addresses, and website addresses for the following entities, including a statement that an individual can obtain information from these sources about steps to take to avoid identity theft: (A) The Federal Trade Commission; and (B) The Office of the Attorney General for the District of Columbia.
Delivery Methods
A breach notice may be provided by one of the following methods:
(A) Written notice;
(B) Electronic notice, if the customer has consented to receipt of electronic notice consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001 (The Electronic Signatures in Global and National Commerce Act); or (C)(i) Substitute notice, if the person or entity demonstrates that the cost of providing notice to persons subject to this subchapter would exceed $50,000, that the number of persons to receive notice under this subchapter exceeds 100,000, or that the person or entity does not have sufficient contact information.
Substitute Notice
Substitute notice shall consist of all of the following:
(I) Email notice when the person or entity has an email address for the subject persons;
(II) Conspicuous posting of the notice on the website page of the person or entity if the person or entity maintains one; and (III) Notice to major local and, if applicable, national media.
Notice to Government Agencies
In addition to giving the breach notification required under subsection (a) of this section, and subject to subsection (d) of this section (security and investigation exceptions), the person or entity required to give notice shall promptly provide written notice of the breach of the security of the system to the Office of the Attorney General for the District of Columbia if the breach affects 50 or more District residents. This notice shall be made in the most expedient manner possible, without unreasonable delay, and in no event later than when notice is provided under subsection (a) of this section. The written notice shall include:
(1) The name and contact information of the person or entity reporting the breach;
(2) The name and contact information of the person or entity that experienced the breach;
(3) The nature of the breach of the security of the system, including the name of the person or entity that experienced the breach;
(4) The types of personal information compromised by the breach;
(5) The number of District residents affected by the breach;
(6) The cause of the breach, including the relationship between the person or entity that experienced the breach and the person responsible for the breach, if known;
(7) The remedial action taken by the person or entity to include steps taken to assist District residents affected by the breach;
(8) The date and time frame of the breach, if known;
(9) The address and location of corporate headquarters, if outside of the District;
(10) Any knowledge of foreign country involvement; and
(11) A sample of the notice to be provided to District residents.
This notice shall not be delayed on the grounds that the total number of District residents affected by the breach has not yet been ascertained.
Consumer Reporting Agencies
If any person or entity is required by subsection (a) or (b) of this section to notify more than 1,000 persons of a breach, the person shall also notify, without unreasonable delay, all consumer reporting agencies of the timing, distribution and content of the notices. Nothing in this subsection shall be construed to require the person to provide to the consumer reporting agency the names or other personal identifying information of breach notice recipients. This subsection shall not apply to a person or entity who is required to notify consumer reporting agencies of a breach pursuant to Title V of the Gramm-Leach-Bliley Act.
Preemption and Compliance
A person or entity that maintains procedures for a breach notification system under Title V of the Gramm-Leach-Bliley Act, or the breach notification rules issued pursuant to the Health Insurance Portability Accountability Act of 1996 (HIPAA), or the Health Information Technology for Economic and Clinical Health Act (HITECH), and provides notice in accordance with such acts, and any rules, regulations, guidance, and guidelines thereto, to each affected resident in the event of a breach, shall be deemed to be in compliance with this section with respect to the notification of residents whose personal information is included in the breach. The person or entity shall, in all cases, provide written notice of the breach of the security of the system to the Office of the Attorney General for the District of Columbia.
Data Processor Obligations
Any person or entity who maintains, handles, or otherwise possesses computerized or other electronic data that includes personal information that the person or entity does not own shall notify the owner or licensee of the information of any breach of the security of the system in the most expedient time possible following discovery.
Other Information
Notwithstanding subsection (a-1) of this section, in the case of a breach of the security of the system that only involves personal information as defined in § 28-3851 (3)(A)(ii), the person or entity may comply with this section by providing the notification in electronic format or other form that directs the person to change the person’s password and security question or answer, as applicable, or to take other steps appropriate to protect the email account with the person or entity and all other online accounts for which the person whose personal information has been breached uses the same username or email address and password or security question or answer.
When a person or entity experiences a breach of the security of the system and such breach includes or is reasonably believed to include a Social Security number or taxpayer identification number, the person or entity shall offer to each District resident whose Social Security number or taxpayer identification number was released identity theft protection services at no cost for a period of not less than 18 months. The person or entity that experienced the breach of the security of its system shall provide all information necessary for District residents to enroll in the services.
Data Disposal and Security: D.C. Code § 28-3852.01
The numbering and internal citations herein are derived from the applicable state statute. See statute for any applicable exceptions or exemptions.
Key Terms
The term “personal information” means:
(i) An individual’s first name, first initial, and last name, or any other personal identifier, which, in combination with any of the following data elements, can be used to identify a person or the person’s information:
(I) Social security number, individual taxpayer identification number, passport number, driver’s license number, District of Columbia identification card number, military identification number, or other unique identification number issued on a government document commonly used to verify the identity of a specific individual;
(II) Account number, credit card number, or debit card number, or any other number or code or combination of numbers or codes, such as an identification number, security code, access code, or password, that allows access to or use of an individual’s financial or credit account;
(III) Medical information;
(IV) Genetic information and deoxyribonucleic acid (DNA) profile;
(V) Health insurance information, including a policy number, subscriber information number, or any unique identifier used by a health insurer to identify the person that permits access to an individual’s health and billing information;
(VI) Biometric data of an individual generated by automatic measurements of an individual’s biological characteristics, such as a fingerprint, voice print, genetic print, retina or iris image, or other unique biological characteristic, that is used to uniquely authenticate the individual’s identity when the individual accesses a system or account; or
(VII) Any combination of data elements included in sub-sub-subparagraphs (I) through (VI) of this sub-subparagraph that would enable a person to commit identity theft without reference to a person’s first name or first initial and last name or other independent personal identifier.
(ii) A username or email address in combination with a password, security question and answer, or other means of authentication, or any combination of data elements included in sub-sub-subparagraphs (I) through (VI) of sub-subparagraph (i) that permits access to an individual’s email account.
Security Requirements
To protect personal information from unauthorized access, use, modification, disclosure, or a reasonably anticipated hazard or threat, a person or entity that owns, licenses, maintains, handles, or otherwise possesses personal information of an individual residing in the District shall implement and maintain reasonable security safeguards, including procedures and practices that are appropriate to the nature of the personal information and the nature and size of the entity or operation.
A person or entity that uses a nonaffiliated third party as a service provider to perform services for a person or entity and discloses personal information about an individual residing in the District under a written agreement with the third party shall require by the agreement that the third party implement and maintain reasonable security procedures and practices that: (1) Are appropriate to the nature of the personal information disclosed to the nonaffiliated third party; and (2) Are reasonably designed to protect the personal information from unauthorized access, use, modification, and disclosure.
Data Disposal
When a person or entity is destroying records, including computerized or electronic records and devices containing computerized or electronic records, that contain personal information of a consumer, employee, or former employee of the person or entity, the person or entity shall take reasonable steps to protect against unauthorized access to or use of the personal information, taking into account:
(1) The sensitivity of the records;
(2) The nature and size of the business and its operations;
(3) The costs and benefits of different destruction and sanitation methods; and (4) Available technology.