Data Breach Requirements: Neb. Rev. St. § 87-802 et seq.
The numbering and internal citations herein are derived from the applicable state statute.
Personal Information
The term “personal information” means either of the following:
(a) A Nebraska resident’s first name or first initial and last name in combination with any one or more of the following data elements that relate to the resident if either the name or the data elements are not encrypted, redacted, or otherwise altered by any method or technology in such a manner that the name or data elements are unreadable:
(i) Social Security number;
(ii) Motor vehicle operator’s license number or state identification card number;
(iii) Account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to a resident’s financial account;
(iv) Unique electronic identification number or routing code, in combination with any required security code, access code, or password; or
(v) Unique biometric data, such as a fingerprint, voice print, or retina or iris image, or other unique physical representation; or
(b) A username or email address, in combination with a password or security question and answer, that would permit access to an online account.
Security Breach Definition
The term “breach of the security of the system” means the unauthorized acquisition of unencrypted computerized data that compromises the security, confidentiality, or integrity of personal information maintained by an individual or a commercial entity.
Good Faith Exception
Good faith acquisition of personal information by an employee or agent of an individual or a commercial entity for the purposes of the individual or the commercial entity is not a breach of the security of the system if the personal information is not used or subject to further unauthorized disclosure.
Risk of Harm Analysis
An individual or a commercial entity that conducts business in Nebraska and that owns or licenses computerized data that includes personal information about a resident of Nebraska shall, when it becomes aware of a breach of the security of the system, conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be used for an unauthorized purpose. If the investigation determines that the use of information about a Nebraska resident for an unauthorized purpose has occurred or is reasonably likely to occur, the individual or commercial entity shall give notice to the affected Nebraska resident.
Notification Timeline
A breach notification shall be made as soon as possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system.
Security and Investigation Exceptions
A breach notice may be delayed if a law enforcement agency determines that the notice will impede a criminal investigation. Notice shall be made in good faith, without unreasonable delay, and as soon as possible after the law enforcement agency determines that notification will no longer impede the investigation.
Notification Content Requirements
N/A
Delivery Methods
A breach notice may be provided by one of the following methods:
(a) Written notice;
(b) Telephonic notice;
(c) Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001 (The Electronic Signatures in Global and National Commerce Act);
(d) Substitute notice, if the individual or commercial entity required to provide notice demonstrates that the cost of providing notice will exceed $75,000, that the affected class of Nebraska residents to be notified exceeds 100,000 residents, or that the individual or commercial entity does not have sufficient contact information to provide notice. Substitute notice under this subdivision requires all of the following: (i) Email notice if the individual or commercial entity has email addresses for the members of the affected class of Nebraska residents; (ii) Conspicuous posting of the notice on the website of the individual or commercial entity if the individual or commercial entity maintains a website; and (iii) Notice to major statewide media outlets; or
(e) Substitute notice, if the individual or commercial entity required to provide notice has ten employees or fewer and demonstrates that the cost of providing notice will exceed $10,000. Substitute notice under this subdivision requires all of the following: (i) Email notice if the individual or commercial entity has email addresses for the members of the affected class of Nebraska residents; (ii) Notification by a paid advertisement in a local newspaper that is distributed in the geographic area in which the individual or commercial entity is located, which advertisement shall be of sufficient size that it covers at least one-quarter of a page in the newspaper and shall be published in the newspaper at least once a week for three consecutive weeks; (iii) Conspicuous posting of the notice on the website of the individual or commercial entity if the individual or commercial entity maintains a website; and (iv) Notification to major media outlets in the geographic area in which the individual or commercial entity is located.
Substitute Notice
See Delivery Methods.
Notice to Government Agencies
If a breach notice is required under this law, the individual or commercial entity shall also, not later than the time when notice is provided to the Nebraska resident, provide notice of the breach of security of the system to the attorney general.
Consumer Reporting Agencies
N/A
Preemption and Compliance
An individual or a commercial entity that is regulated by state or federal law and that maintains procedures for a breach of the security of the system pursuant to the laws, rules, regulations, guidances, or guidelines established by its primary or functional state or federal regulator is deemed to be in compliance with Section 87-803 if the individual or commercial entity notifies affected Nebraska residents and the attorney general in accordance with the maintained procedures in the event of a breach of the security of the system.
Data Processor Obligations
An individual or a commercial entity that maintains computerized data that includes personal information that the individual or commercial entity does not own or license shall give notice to and cooperate with the owner or licensee of the information of any breach of the security of the system when it becomes aware of a breach if use of personal information about a Nebraska resident for an unauthorized purpose occurred or is reasonably likely to occur. Cooperation includes, but is not limited to, sharing with the owner or licensee information relevant to the breach, not including information proprietary to the individual or commercial entity.
Data Disposal and Security: Neb. Rev. Stat. §§ 87-802 and 87-808.
The numbering and internal citations herein are derived from the applicable state statute. See statute for any applicable exceptions or exemptions.
Key Terms
The term “personal information” means either of the following:
(a) A Nebraska resident’s first name or first initial and last name in combination with any one or more of the following data elements that relate to the resident if either the name or the data elements are not encrypted, redacted, or otherwise altered by any method or technology in such a manner that the name or data elements are unreadable:
(i) Social Security number;
(ii) Motor vehicle operator’s license number or state identification card number;
(iii) Account, credit, or debit card number, in combination with any required security code, access code, or password that would permit access to a resident’s financial account;
(iv) Unique electronic identification number or routing code, in combination with any required security code, access code, or password; or
(v) Unique biometric data, such as a fingerprint, voice print, or retina or iris image, or other unique physical representation; or
(b) A username or email address, in combination with a password or security question and answer, that would permit access to an online account.
Security Requirements
To protect personal information from unauthorized access, acquisition, destruction, use, modification, or disclosure, an individual or a commercial entity that conducts business in Nebraska and owns, licenses, or maintains computerized data that includes personal information about a resident of Nebraska shall implement and maintain reasonable security procedures and practices that are appropriate to the nature and sensitivity of the personal information owned, licensed, or maintained and the nature and size of, and the resources available to, the business and its operations. This includes safeguards that protect the personal information when the individual or commercial entity disposes of the personal information.
An individual or commercial entity that discloses computerized data that includes personal information about a Nebraska resident to a nonaffiliated, third-party service provider shall require by contract that the service provider implement and maintain reasonable security procedures and practices that: (i) Are appropriate to the nature of the personal information disclosed to the service provider; and (ii) Are reasonably designed to help protect the personal information from unauthorized access, acquisition, destruction, use, modification, or disclosure. This does not apply to any contract entered into before July 19, 2018. Any such contract renewed on or after July 19, 2018, shall comply with the requirements of this subsection.
Data Disposal
See Security Requirements (safeguards when disposing personal information).