Data Breach Requirements: O.C.G.A. § 10-1-910 et seq.
The numbering and internal citations herein are derived from the applicable state statute.
Personal Information
(6) The term “personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted or redacted:
(A) Social Security number;
(B) Driver’s license number or state identification card number;
(C) Account number, credit card number, or debit card number, if circumstances exist wherein such a number could be used without additional identifying information, access codes, or passwords;
(D) Account passwords or personal identification numbers or other access codes; or
(E) Any of the items contained in subparagraphs (A) through (D) of this paragraph when not in connection with the individual’s first name or first initial and last name, if the information compromised would be sufficient to perform or attempt to perform identity theft against the person whose information was compromised.
Security Breach Definition
The term “breach of the security of the system” means unauthorized acquisition of an individual’s electronic data that compromises the security, confidentiality, or integrity of personal information of such individual maintained by an information broker or data collector.
Good Faith Exception
Good faith acquisition or use of personal information by an employee or agent of an information broker or data collector for the purposes of such information broker or data collector is not a breach of the security of the system, provided that the personal information is not used or subject to further unauthorized disclosure.
Risk of Harm Analysis
N/A
Notification Timeline
The breach notice shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, or with any measures necessary to determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system.
Security and Investigation Exceptions
The breach notification may be delayed if a law enforcement agency determines that the notification will compromise a criminal investigation. The notification shall be made after the law enforcement agency determines that it will not compromise the investigation.
Notification Content Requirements
N/A
Delivery Methods
A breach notice may be provided by one of the following methods:
(A) Written notice;
(B) Telephone notice;
(C) Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001 (The Electronic Signatures in Global and National Commerce Act); or (D) Substitute notice, if the information broker or data collector demonstrates that the cost of providing notice would exceed $50,000, that the affected class of individuals to be notified exceeds 100,000, or that the information broker or data collector does not have sufficient contact information to provide written or electronic notice to such individuals.
Substitute Notice
Substitute notice shall consist of all of the following:
(i) Email notice, if the information broker or data collector has an email address for the individuals to be notified;
(ii) Conspicuous posting of the notice on the information broker’s or data collector’s website page, if the information broker or data collector maintains one; and
(iii) Notification to major state-wide media.
Notice to Government Agencies
N/A
Consumer Reporting Agencies
In the event that an information broker or data collector discovers circumstances requiring notification of more than 10,000 residents of this state at one time, the information broker or data collector shall also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nation-wide basis of the timing, distribution, and content of the notices.
Preemption and Compliance
No express provision.
Data Processor Obligations
Any person or business that maintains computerized data on behalf of an information broker or data collector that includes personal information of individuals that the person or business does not own shall notify the information broker or data collector of any breach of the security of the system within 24 hours following discovery, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person.
Other Information
The term “information broker” means any person or entity who, for monetary fees or dues, engages in whole or in part in the business of collecting, assembling, evaluating, compiling, reporting, transmitting, transferring, or communicating information concerning individuals for the primary purpose of furnishing personal information to nonaffiliated third parties, but does not include any governmental agency whose records are maintained primarily for traffic safety, law enforcement, or licensing purposes.
Data Disposal and Security: O.C.G.A. § 10-15-1 et seq.
The numbering and internal citations herein are derived from the applicable state statute. See statute for any applicable exceptions or exemptions.
Key Terms
The term “discard” means to throw away, get rid of, or eliminate.
The term “dispose” means the sale or transfer of a record for value to a company or business engaged in the business of record destruction.
The term “personal information” means:
(A) Personally identifiable data about a customer’s medical condition, if the data are not generally considered to be public knowledge;
(B) Personally identifiable data which contain a customer’s account or identification number, account balance, balance owing, credit balance, or credit limit, if the data relate to a customer’s account or transaction with a business;
(C) Personally identifiable data provided by a customer to a business upon opening an account or applying for a loan or credit; or
(D) Personally identifiable data about a customer’s federal, state, or local income tax return.
The term “personally identifiable” means capable of being associated with a particular customer through one or more identifiers, including, but not limited to, a customer’s fingerprint, photograph, or computerized image, Social Security number, passport number, driver identification number, personal identification card number, date of birth, medical information, or disability information. A customer’s name, address, and telephone number shall not be considered personally identifiable data unless one or more of them are used in conjunction with one or more of the identifiers listed here.
The term “record” means any material on which written, drawn, printed, spoken, visual, or electromagnetic information is recorded or preserved, regardless of physical form or characteristics.
Data Disposal
A business may not discard a record containing personal information unless it:
(1) Shreds the customer’s record before discarding the record;
(2) Erases the personal information contained in the customer’s record before discarding the record;
(3) Modifies the customer’s record to make the personal information unreadable before discarding the record; or
(4) Takes actions that it reasonably believes will ensure that no unauthorized person will have access to the personal information contained in the customer’s record for the period between the record’s disposal and the record’s destruction.