Skip to main content

Data Protection Map

Wisconsin

Data Breach Requirements: Wis. Stat. § 134.98.

The numbering and internal citations herein are derived from the applicable state statute.

Personal Information

(b) The term “personal information” means an individual’s last name and the individual’s first name or first initial, in combination with and linked to any of the following elements, if the element is not publicly available information and is not encrypted, redacted, or altered in a manner that renders the element unreadable:

  1. The individual’s Social Security number.
  2. The individual’s driver’s license number or state identification number.
  3. The individual’s financial account number, including a credit or debit card account number, or any security code, access code, or password that would permit access to the individual’s financial account.
  4. The individual’s deoxyribonucleic acid (DNA) profile, as defined in s. 939.74(2d)(a).
  5. The individual’s unique biometric data, including fingerprint, voice print, retina or iris image, or any other unique physical representation.

Security Breach Definition

If an entity whose principal place of business is located in this state or an entity that maintains or licenses personal information in this state knows that personal information in the entity’s possession has been acquired by a person whom the entity has not authorized to acquire the personal information, the entity shall make reasonable efforts to notify each subject of the personal information.


Good Faith Exception

An entity is not required to provide a breach notice if the personal information was acquired in good faith by an employee or agent of the entity, if the personal information is used for a lawful purpose of the entity.


Risk of Harm Analysis

An entity is not required to provide a breach notice if the acquisition of personal information does not create a material risk of identity theft or fraud to the subject of the personal information.


Notification Timeline

The breach notice shall be provided within a reasonable time, not to exceed 45 days after the entity learns of the acquisition of personal information. A determination as to reasonableness herein shall include consideration of the number of notices that an entity must provide and the methods of communication available to the entity.


Security and Investigation Exceptions

A law enforcement agency may, in order to protect an investigation or homeland security, ask an entity not to provide a breach notice that is otherwise required for any period of time, and the notification process shall begin at the end of that time period. Notwithstanding, if an entity receives such a request, the entity may not provide notice of or publicize an unauthorized acquisition of personal information, except as authorized by the law enforcement agency that made the request.


Notification Content Requirements

The breach notice shall indicate that the entity knows of the unauthorized acquisition of personal information pertaining to the subject of the personal information.


Upon written request by a person who has received a breach notice, the entity that provided the notice shall identify the personal information that was acquired.


Delivery Methods

An entity shall provide the breach notice by mail or by a method the entity has previously employed to communicate with the subject of the personal information. If an entity cannot with reasonable diligence determine the mailing address of the subject of the personal information, and if the entity has not previously communicated with the subject of the personal information, the entity shall provide notice by a method reasonably calculated to provide actual notice to the subject of the personal information.


Substitute Notice

See Delivery Methods (reasonably calculated standard).


Notice to Government Agencies

N/A


Consumer Reporting Agencies

If, as the result of a single incident, an entity is required to notify 1,000 or more individuals that personal information pertaining to the individuals has been acquired, the entity shall without unreasonable delay notify all consumer reporting agencies of the timing, distribution, and content of the notices sent to the individuals.


Preemption and Compliance

The law does not apply to any of the following:
(a) An entity that is subject to, and in compliance with, the privacy and security requirements of 15 USC 6801 to 6827, or a person that has a contractual obligation to such an entity, if the entity or person has in effect a policy concerning breaches of information security.
(b) An entity that is described in 45 CFR 164.104(a), if the entity complies with the requirements of 45 CFR part 164.


Data Processor Obligations

If a person, other than an individual, who stores personal information pertaining to a resident of this state, but does not own or license the personal information, knows that the personal information has been acquired by a person whom the person storing the personal information has not authorized to acquire the personal information, and the person storing the personal information has not entered into a contract with the person that owns or licenses the personal information, the person storing the personal information shall notify the person that owns or licenses the personal information of the acquisition as soon as practicable.


Other Information

(b) If an entity whose principal place of business is not located in this state knows that personal information pertaining to a resident of this state has been acquired by a person whom the entity has not authorized to acquire the personal information, the entity shall make reasonable efforts to notify each resident of this state who is the subject of the personal information. The notice shall indicate that the entity knows of the unauthorized acquisition of personal information pertaining to the resident of this state who is the subject of the personal information.


Data Disposal and Security: Wis. Stat. § 134.97.

The numbering and internal citations herein are derived from the applicable state statute. See statute for any applicable exceptions or exemptions.

Key Terms

The term “dispose” does not include a sale of a record or the transfer of a record for value.


The term “personal information” means any of the following:

  1. Personally identifiable data about an individual’s medical condition, if the data are not generally considered to be public knowledge.
  2. Personally identifiable data that contain an individual’s account or customer number, account balance, balance owing, credit balance, or credit limit, if the data relate to an individual’s account or transaction with a financial institution.
  3. Personally identifiable data provided by an individual to a financial institution upon opening an account or applying for a loan or credit.
  4. Personally identifiable data about an individual’s federal, state, or local tax returns.

The term “personally identifiable” means capable of being associated with a particular individual through one or more identifiers or other information or circumstances.


Data Disposal

A financial institution, medical business, or tax preparation business may not dispose of a record containing personal information unless the financial institution, medical business, tax preparation business, or other person under contract with the financial institution, medical business, or tax preparation business does any of the following:
(a) Shreds the record before the disposal of the record.
(b) Erases the personal information contained in the record before the disposal of the record.
(c) Modifies the record to make the personal information unreadable before the disposal of the record.
(d) Takes actions that it reasonably believes will ensure that no unauthorized person will have access to the personal information contained in the record for the period between the record’s disposal and the record’s destruction.