Consumer Data Privacy Law
Consumer Data Privacy and Online Monitoring
Available at: https://iga.in.gov/pdf-documents/123/2023/senate/bills/SB0005/SB0005.05.ENRH.pdf
Data Breach Requirements: Ind. Code § 24-4.9-1-1 et seq.
The numbering and internal citations herein are derived from the applicable state statute.
Personal Information
The term “personal information” means:
(1) A Social Security number that is not encrypted or redacted; or
(2) An individual’s first and last names, or first initial and last name, and one or more of the following data elements that are not encrypted or redacted:
(A) A driver’s license number.
(B) A state identification card number.
(C) A credit card number.
(D) A financial account number or debit card number in combination with a security code, password, or access code that would permit access to the person’s account; or
(3) information collected by an adult oriented website operator, or their designee, under Indiana Code 24-4-23.
Security Breach Definition
The term “breach of the security of data” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by a person. The term includes the unauthorized acquisition of computerized data that have been transferred to another medium, including paper, microfilm, or a similar medium, even if the transferred data are no longer in a computerized format.
Good Faith Exception
A breach does not include the good faith acquisition of personal information by an employee or agent of the person for lawful purposes of the person, if the personal information is not used or subject to further unauthorized disclosure.
Risk of Harm Analysis
A data breach notification must be provided if the database owner knows, should know, or should have known that the unauthorized acquisition constituting the breach has resulted in or could result in identity deception (as defined in IC 35-43-5-3.5), identity theft, or fraud affecting the Indiana resident.
Notification Timeline
A person required to make a disclosure or notification under this chapter shall make the disclosure or notification without unreasonable delay, but not more than forty-five (45) days after the discovery of the breach.
Security and Investigation Exceptions
For purposes of this section, a delay is reasonable if the delay is: (1) necessary to restore the integrity of the computer system; (2) necessary to discover the scope of the breach; or (3) if in response to a request from the attorney general or a law enforcement agency to delay disclosure because disclosure will: (A) impede a criminal or civil investigation; or (B) jeopardize national security.
A person required to make a breach disclosure or notification shall make the disclosure or notification as soon as possible after: (1) delay is no longer necessary to restore the integrity of the computer system or to discover the scope of the breach; or (2) the attorney general or a law enforcement agency notifies the person that delay will no longer impede a criminal or civil investigation or jeopardize national security.
Notification Content Requirements
N/A
Delivery Methods
(a) Except as provided in subsection (b), a database owner required to make a disclosure under this chapter shall make the disclosure using one (1) of the following methods:
(1) Mail.
(2) Telephone.
(3) Facsimile (fax).
(4) Electronic mail, if the database owner has the electronic mail address of the affected Indiana resident.
(5) Substitute Notice.
Substitute Notice
(b) If a database owner required to make a disclosure under this chapter is required to make the disclosure to more than five hundred thousand (500,000) Indiana residents, or if the database owner required to make a disclosure under this chapter determines that the cost of the disclosure will be more than two hundred fifty thousand dollars ($250,000), the database owner required to make a disclosure under this chapter may elect to make the disclosure by using both of the following methods:
(1) Conspicuous posting of the notice on the website of the database owner, if the database owner maintains a website.
(2) Notice to major news reporting media in the geographic area where Indiana residents affected by the breach of the security of a system reside.
Notice to Government Agencies
If a database owner makes a data breach disclosure, the database owner shall also disclose the breach to the attorney general.
Consumer Reporting Agencies
A database owner required to make a breach disclosure to more than 1,000 consumers shall also disclose to each consumer reporting agency information necessary to assist the consumer reporting agency in preventing fraud, including personal information of an Indiana resident affected by the breach.
Preemption and Compliance
(a) Except as provided in subsection (b), this section does not apply to a database owner that maintains its own data security procedures as part of an information privacy, security policy, or compliance plan under:
(1) The federal USA PATRIOT Act (P.L. 107-56);
(2) Executive Order 13224;
(3) The federal Driver’s Privacy Protection Act (18 U.S.C. 2721 et seq.);
(4) The federal Fair Credit Reporting Act (15 U.S.C. 1681 et seq.);
(5) The Gramm-Leach-Bliley Act; or
(6) The Health Insurance Portability and Accountability Act of 1996 (HIPAA).
(b) This section applies to a current or former health care provider (as defined by IC 4-6-14-2) who is a database owner or former database owner: (1) to which an exemption under subsection (a)(6) applies or applied; and (2) whose information privacy, security policy, or compliance plan: (A) does not require the database owner or former database owner to maintain and implement reasonable procedures; or (B) is not implemented by the database owner or former database owner; to ensure that the personal information described in subsection (a), including health records (as defined by IC 4-6-14-2.5), is protected and safeguarded from unlawful use or disclosure after the database owner or former database owner ceases to be a covered entity under the Health Insurance Portability and Accountability Act.
A financial institution that complies with the disclosure requirements prescribed by the Federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice or the Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice, as applicable, is not required to make a disclosure under this chapter.
Data Processor Obligations
A person that maintains computerized data but that is not a database owner shall notify the database owner if the person discovers that personal information was or may have been acquired by an unauthorized person.
Other Information
A database owner that maintains its own disclosure procedures as part of an information privacy, security policy, or compliance plan under:
(1) The federal USA PATRIOT Act (P.L. 107-56);
(2) Executive Order 13224;
(3) The federal Driver’s Privacy Protection Act (18 U.S.C. 2781 et seq.);
(4) The federal Fair Credit Reporting Act (15 U.S.C. 1681 et seq.);
(5) The Gramm-Leach-Bliley Act; or
(6) The Health Insurance Portability and Accountability Act of 1996 (HIPAA);
is not required to make a disclosure under this chapter if the database owner’s information privacy, security policy, or compliance plan requires that Indiana residents be notified of a breach of the security of data without unreasonable delay and the database owner complies with the database owner’s information privacy, security policy, or compliance plan.
Data Disposal and Security: Ind. Code §§ 24-4.9-2-3, 24-4.9-2-10, and 24-4.9-3-3.5.
The numbering and internal citations herein are derived from the applicable state statute. See statute for any applicable exceptions or exemptions.
Key Terms
The term “database owner” means a person that owns or licenses computerized data that includes personal information.
The term “personal information” means:
(1) A Social Security number that is not encrypted or redacted; or
(2) An individual’s first and last names, or first initial and last name, and one (1) or more of the following data elements that are not encrypted or redacted:
(A) A driver’s license number.
(B) A state identification card number.
(C) A credit card number.
(D) A financial account or debit card number in combination with a security code, password, or access code that would permit access to the person’s account.
Security Requirements
A database owner shall implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect and safeguard from unlawful use or disclosure any personal information of Indiana residents collected or maintained by the database owner.
Data Disposal
A database owner shall not dispose of or abandon records or documents containing unencrypted and unredacted personal information of Indiana residents without shredding, incinerating, mutilating, erasing, or otherwise rendering the personal information illegible or unusable.