Consumer Data Privacy Law
Consumer Data Privacy and Online Monitoring
Available at: https://publications.tnsosfiles.com/acts/113/pub/pc0408.pdf
Data Breach Requirements: Tenn.C.A. § 47-18-2107 et seq.
The numbering and internal citations herein are derived from the applicable state statute.
Personal Information
Personal information (A) Means an individual’s first name or first initial and last name, in combination with any one (1) or more of the following data elements:
(i) Social Security number;
(ii) Driver’s license number; or
(iii) Account, credit card, or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account.
Security Breach Definition
The term “breach of system security” means the acquisition of unencrypted computerized data; or encrypted computerized data and the encryption key by an unauthorized person that materially compromises the security, confidentiality, or integrity of personal information maintained by the information holder.
Good Faith Exception
A “breach of system security” does not include the good faith acquisition of personal information by an employee or agent of the information holder for the purposes of the information holder if the personal information is not used or subject to further unauthorized disclosure.
Risk of Harm Analysis
N/A
Notification Timeline
The breach notification must be made no later than 45 days from the discovery or notification of the breach of system security, unless a longer period of time is required due to the legitimate needs of law enforcement.
Security and Investigation Exceptions
The breach notification may be delayed if a law enforcement agency determines that the notification will impede a criminal investigation. If the notification is delayed, it must be made no later than 45 days after the law enforcement agency determines that notification will not compromise the investigation.
Notification Content Requirements
N/A
Delivery Methods
A breach notice may be provided by one of the following methods:
(1) Written notice;
(2) Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001 (The Electronic Signatures in Global and National Commerce Act) or if the information holder’s primary method of communication with the resident of this state has been by electronic means; or
(3) Substitute notice, if the information holder demonstrates that the cost of providing notice would exceed $250,000, that the affected class of subject persons to be notified exceeds 500,000 persons, or the information holder does not have sufficient contact information and the notice consists of all of the following:
(A) Email notice, when the information holder has an email address for the subject persons;
(B) Conspicuous posting of the notice on the information holder’s website, if the information holder maintains a website page; and
(C) Notification to major statewide media
Substitute Notice
See Delivery Methods.
Notice to Government Agencies
N/A
Consumer Reporting Agencies
If an information holder discovers circumstances requiring breach notification to more than 1,000 persons at one time, the information holder must also notify, without unreasonable delay, all consumer reporting agencies and credit bureaus that compile and maintain files on consumers on a nationwide basis, of the timing, distribution, and content of the notices.
Preemption and Compliance
This law does not apply to any information holder that is subject to: (1) Title V of the Gramm-Leach-Bliley Act; or (2) The Health Insurance Portability and Accountability Act of 1996, as amended.
Data Processor Obligations
Any information holder that maintains computerized data that includes personal information that the information holder does not own shall notify the owner or licensee of the information of any breach of system security if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure must be made no later than 45 days from the discovery or notification of the breach of system security, unless a longer period of time is required due to the legitimate needs of law enforcement.
Other Information
“Unauthorized person” includes an employee of the information holder who is discovered by the information holder to have obtained personal information with the intent to use it for an unlawful purpose.
Data Disposal and Security: Tenn.C.A. § 39-14-150.
The numbering and internal citations herein are derived from the applicable state statute. See statute for any applicable exceptions or exemptions.
Key Terms
The term “personal identifying information” means a customer’s:
(A) Social Security number;
(B) Driver license identification number;
(C) Savings account number;
(D) Checking account number;
(E) PIN (personal identification number) or password;
(F) Complete credit or debit card number;
(G) Demand deposit account number;
(H) Health insurance identification number; or
(I) Unique biometric data.
Data Disposal
If a private entity or business maintains a record that contains any personal identifying information concerning one of its customers, and the entity, by law, practice, or policy discards such records after a specified period of time, any record containing the personal identifying information shall not be discarded unless the business:
(A) Shreds or burns the customer’s record before discarding the record;
(B) Erases the personal identifying information contained in the customer’s record before discarding the record;
(C) Modifies the customer’s record to make the personal identifying information unreadable before discarding the record; or
(D) Takes action to destroy the customer’s personal identifying information in a manner that it reasonably believes will ensure that no unauthorized persons have access to the personal identifying information contained in the customer’s record for the period of time between the record’s disposal and the record’s destruction.
Other Information
The methods of destroying the personal identifying information set forth herein shall be considered the minimum standards. If a private entity or business by law, practice or policy currently is required to have or otherwise has in place more stringent methods and procedures for destroying the personal identifying information in a customer’s record, the private entity or business may continue to destroy the identifying information in the more stringent manner.