Skip to main content

Data Protection Map

Hawaii

Data Breach Requirements: HRS § 487N-1 et seq.

The numbering and internal citations herein are derived from the applicable state statute.

Personal Information

The term “personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted:
(1) Social Security number;
(2) Driver’s license number or Hawaii identification card number; or
(3) Account number, credit or debit card number, access code, or password that would permit access to an individual’s financial account.


Security Breach Definition

The term “security breach” means an incident of unauthorized access to and acquisition of unencrypted or unredacted records or data containing personal information where illegal use of the personal information has occurred or is reasonably likely to occur and that creates a risk of harm to a person. Any incident of unauthorized access to and acquisition of encrypted records or data containing personal information along with the confidential process or key constitutes a security breach.


Good Faith Exception

Good faith acquisition of personal information by an employee or agent of the business for a legitimate purpose is not a security breach, provided that the personal information is not used for a purpose other than a lawful purpose of the business and is not subject to further unauthorized disclosure.


Risk of Harm Analysis

See Security Breach Definition (creates a risk of harm to a person).


Notification Timeline

The breach notification shall be made without unreasonable delay, consistent with the legitimate needs of law enforcement, and consistent with any measures necessary to determine sufficient contact information, determine the scope of the breach, and restore the reasonable integrity, security, and confidentiality of the data system.


Security and Investigation Exceptions

The breach notice shall be delayed if a law enforcement agency informs the business or government agency that notification may impede a criminal investigation or jeopardize national security and requests a delay, provided that such request is made in writing, or the business or government agency documents the request contemporaneously in writing, including the name of the law enforcement officer making the request and the officer’s law enforcement agency engaged in the investigation. The breach notice shall be provided without unreasonable delay after the law enforcement agency communicates to the business or government agency its determination that notice will no longer impede the investigation or jeopardize national security.


Notification Content Requirements

(d) The breach notice shall be clear and conspicuous. The notice shall include a description of the following:
(1) The incident in general terms;
(2) The type of personal information that was subject to the unauthorized access and acquisition;
(3) The general acts of the business or government agency to protect the personal information from further unauthorized access;
(4) A telephone number that the person may call for further information and assistance, if one exists; and
(5) Advice that directs the person to remain vigilant by reviewing account statements and monitoring free credit reports.


Delivery Methods

A breach notice may be provided by one of the following methods:
(1) Written notice to the last available address the business or government agency has on record;
(2) Electronic mail notice, for those persons for whom a business or government agency has a valid email address and who have agreed to receive communications electronically if the notice provided is consistent with the provisions regarding electronic records and signatures for notices legally required to be in writing set forth in 15 U.S.C. § 7001 (The Electronic Signatures in Global and National Commerce Act);
(3) Telephonic notice, provided that contact is made directly with the affected persons; and
(4) Substitute notice, if the business or government agency demonstrates that the cost of providing notice would exceed $100,000 or that the affected class of subject persons to be notified exceeds 200,000, or if the business or government agency does not have sufficient contact information or consent to satisfy paragraph (1), (2), or (3), for only those affected persons without sufficient contact information or consent, or if the business or government agency is unable to identify particular affected persons, for only those unidentifiable affected persons.


Substitute Notice

Substitute notice shall consist of all the following:

(A) Email notice when the business or government agency has an email address for the subject persons;

(B) Conspicuous posting of the notice on the website page of the business or government agency, if one is maintained; and (C) Notification to major statewide media.


Notice to Government Agencies

In the event a business provides a breach notice to more than 1,000 persons at one time, the business shall notify in writing, without unreasonable delay, the State of Hawaii’s Office of Consumer Protection.


Consumer Reporting Agencies

In the event a business provides a breach notice to more than 1,000 persons at one time, the business shall notify in writing, without unreasonable delay, the State of Hawaii’s Office of Consumer Protection and all consumer reporting agencies of the timing, distribution, and content of the notice.


Preemption and Compliance

The following businesses shall be deemed to be in compliance with this section:
(1) A financial institution that is subject to the federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice; and
(2) Any health plan or health care provider that is subject to and in compliance with the standards for privacy or individually identifiable health information and the security standards for the protection of electronic health information of the Health Insurance Portability and Accountability Act of 1996 (HIPAA).


Data Processor Obligations

Any business located in Hawaii or any business that conducts business in Hawaii that maintains or possesses records or data containing personal information of residents of Hawaii that the business does not own or license, or any government agency that maintains or possesses records or data containing personal information of residents of Hawaii shall notify the owner or licensee of the information of any security breach immediately following discovery of the breach, consistent with the legitimate needs of law enforcement.


Data Disposal and Security: HRS §§ 487R-1 to 487R-3.

The numbering and internal citations herein are derived from the applicable state statute. See statute for any applicable exceptions or exemptions.

Key Terms

The term “disposal” means the discarding or abandonment of records containing personal information or the sale, donation, discarding, or transfer of any medium, including computer equipment or computer media, containing records of personal information, or other non-paper media upon which records of personal information are stored, or other equipment for non-paper storage of information.


The term “personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted:
(1) Social Security number;
(2) Driver’s license number or Hawaii identification card number; or
(3) Account number, credit or debit card number, access code, or password that would permit access to an individual’s financial account.


Security Requirements

Any business or government agency that conducts business in Hawaii and any business or government agency that maintains or otherwise possesses personal information of a resident of Hawaii shall take reasonable measures to protect against unauthorized access to or use of the information in connection with or after its disposal.


Written Policy

See Data Disposal (official written policies; implementing and monitoring compliance with policies and procedures).


Data Disposal

The reasonable security requirements in connection with disposal include:
(1) Implementing and monitoring compliance with policies and procedures that require the burning, pulverizing, recycling, or shredding of papers containing personal information so that information cannot be practicably read or reconstructed;
(2) Implementing and monitoring compliance with policies and procedures that require the destruction or erasure of electronic media and other non-paper media containing personal information so that the information cannot practicably be read or reconstructed; and
(3) Describing procedures relating to the adequate destruction or proper disposal of personal records as official policy in the writings of the business entity.


A business or government agency may satisfy its obligation hereunder by exercising due diligence and entering into a written contract with, and thereafter monitoring compliance by, another party engaged in the business of records destruction to destroy personal information in a manner consistent with this section. Due diligence should ordinarily include one or more of the following: (1) Reviewing an independent audit of the disposal business’ operations or its compliance with this chapter; (2) Obtaining information about the disposal business from several references or other reliable sources and requiring that the disposal business be certified by a recognized trade association or similar third party with a reputation for high standards of quality review; or (3) Reviewing and evaluating the disposal business’ information security policies or procedures, or taking other appropriate measures to determine the competency and integrity of the disposal business.


A disposal business that conducts business in Hawaii or disposes of personal information of residents of Hawaii shall take reasonable measures to dispose of records containing personal information by implementing and monitoring compliance with policies and procedures that protect against unauthorized access to, or use of, personal information during or after the collection, transportation, and disposing of such information.