Data Breach Requirements: NMSA 1978, § 57-12C-1 et seq.
The numbering and internal citations herein are derived from the applicable state statute.
Personal Information
The term “personal identifying information” means an individual’s first name or first initial and last name in combination with one or more of the following data elements that relate to the individual, when the data elements are not protected through encryption or redaction or otherwise rendered unreadable or unusable:
(a) Social Security number;
(b) Driver’s license number;
(c) Government-issued identification number;
(d) Account number, credit card number, or debit card number in combination with any required security code, access code, or password that would permit access to a person’s financial account; or
(e) Biometric data.
Security Breach Definition
The term “security breach” means the unauthorized acquisition of unencrypted computerized data, or of encrypted computerized data and the confidential process or key used to decrypt the encrypted computerized data, that compromises the security, confidentiality, or integrity of personal identifying information maintained by a person.
Good Faith Exception
A security breach does not include the good-faith acquisition of personal identifying information by an employee or agent of a person for a legitimate business purpose of the person, provided that the personal identifying information is not subject to further unauthorized disclosure.
Risk of Harm Analysis
A breach notification to affected New Mexico residents is not required if, after an appropriate investigation, the person determines that the security breach does not give rise to a significant risk of identity theft or fraud.
Notification Timeline
A breach notification shall be made in the most expedient time possible, but not later than 45 calendar days following discovery of the security breach.
Security and Investigation Exceptions
The breach notification may be delayed:
A. if a law enforcement agency determines that the notification will impede a criminal investigation; or
B. as necessary to determine the scope of the security breach and restore the integrity, security, and confidentiality of the data system.
Notification Content Requirements
The breach notification shall contain:
A. The name and contact information of the notifying person;
B. A list of the types of personal identifying information that are reasonably believed to have been the subject of a security breach, if known;
C. The date of the security breach, the estimated date of the breach, or the range of dates within which the security breach occurred, if known;
D. A general description of the security breach incident;
E. The toll-free telephone numbers and addresses of the major consumer reporting agencies;
F. Advice that directs the recipient to review personal account statements and credit reports, as applicable, to detect errors resulting from the security breach; and
G. Advice that informs the recipient of the notification of the recipient’s rights pursuant to the federal Fair Credit Reporting Act.
Delivery Methods
A breach notice may be provided by one of the following methods:
(1) United States mail;
(2) Electronic notification, if the person required to make the notification primarily communicates with the New Mexico resident by electronic means or if the notice provided is consistent with the requirements of 15 U.S.C. § 7001 (The Electronic Signatures in Global and National Commerce Act); or (3) A substitute notification, if the person demonstrates that: (a) the cost of providing notification would exceed $100,000; (b) the number of residents to be notified exceeds 50,000; or (c) the person does not have on record a physical address or sufficient contact information for the residents that the person or business is required to notify.
Substitute Notice
Substitute notification shall consist of:
(1) Sending electronic notification to the email address of those residents for whom the person has a valid email address;
(2) Posting notification of the security breach in a conspicuous location on the website of the person required to provide notification if the person maintains a website; and
(3) Sending written notification to the office of the attorney general and major media outlets in New Mexico.
Notice to Government Agencies
A person who is required to issue a breach notification to more than 1,000 New Mexico residents as a result of a single security breach shall notify the Office of the Attorney General in the most expedient time possible, and no later than 45 calendar days, subject to the security and investigation exceptions.
Consumer Reporting Agencies
A person that is required to issue a breach notification to more than 1,000 New Mexico residents as a result of a single security breach shall notify the office of the major consumer reporting agencies in the most expedient time possible, and no later than 45 calendar days, subject to the security and investigation exceptions.
Preemption and Compliance
The breach notification requirements shall not apply to a person subject to the federal Gramm-Leach-Bliley Act or the Health Insurance Portability and Accountability Act of 1996 (HIPAA).
Data Processor Obligations
Any person that is licensed to maintain or possess computerized data containing personal identifying information of a New Mexico resident that the person does not own or license shall notify the owner or licensee of the information of any security breach in the most expedient time possible, but not later than 45 calendar days following discovery of the breach, except as provided in Section 9 of the Data Breach Notification Act, provided that notification to the owner or licensee of the information is not required if, after an appropriate investigation, the person determines that the security breach does not give rise to a significant risk of identity theft or fraud.
Other Information
A person required to notify the attorney general and consumer reporting agencies of a security breach shall notify the attorney general of the number of New Mexico residents that received a breach notification and shall provide a copy of the notification that was sent to affected residents within 45 calendar days following discovery of the security breach, subject to the security and investigation exceptions.
Data Disposal and Security: NMSA 1978, §§ 57-12c-2 - 57-12c-5.
The numbering and internal citations herein are derived from the applicable state statute. See statute for any applicable exceptions or exemptions.
Key Terms
The term “personal identifying information” means an individual’s first name or first initial and last name in combination with one or more of the following data elements that relate to the individual, when the data elements are not protected through encryption or redaction or otherwise rendered unreadable or unusable:
(a) Social Security number;
(b) Driver’s license number;
(c) Government-issued identification number;
(d) Account, credit, or debit card number in combination with any required security code, access code, or password that would permit access to a person’s financial account; or
(e) Biometric data.
The term “proper disposal” means shredding, erasing, or otherwise modifying the personal identifying information contained in the records to make the personal identifying information unreadable or undecipherable.
The term “service provider” means any person that receives, stores, maintains, licenses, processes, or otherwise is permitted access to personal identifying information through its provision of services directly to a person that is subject to regulation.
Security Requirements
A person that owns or licenses personal identifying information of a New Mexico resident shall implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal identifying information from unauthorized access, destruction, use, modification, or disclosure.
A person that discloses personal identifying information of a New Mexico resident pursuant to a contract with a service provider shall require by contract that the service provider implement and maintain reasonable security procedures and practices appropriate to the nature of the personal identifying information and to protect it from unauthorized access, destruction, use, modification or disclosure.
Data Disposal
A person that owns or licenses records containing personal identifying information of a New Mexico resident shall arrange for proper disposal of the records when they are no longer reasonably needed for business purposes.