On discovering a data breach, which regulators or other government agencies should be notified?
List: - Once the extent of the incident is understood and the affected parties are identified, counsel will need to evaluate whether a data breach has occurred according to the legal framework of the states in which the affected customers reside. Unauthorized access to certain types of data by a third party may automatically trigger a notice obligation in some states, while other states require a risk of material harm to the affected party as a result of the unauthorized access. What is considered “personal information” or sensitive data in one state, such as name and physical address, may not be considered personal information in another state and give rise to a notice requirement.
-
Under North Carolina law, a security breach is defined as either: (1) unauthorized acquisition of unencrypted data containing personal information where illegal use of the personal information has occurred or there is a material risk of harm; or (2) unauthorized access and acquisition of encrypted data containing personal information and the encryption key. Once it is determined that a breach has occurred under the affected parties’ state law, each state law will also need to be examined to determine if notification to the affected party must be made as well as notice to that state attorney general or other government office. If a breach occurs in North Carolina, notifications must be sent to the North Carolina customers and to the North Carolina Attorney General.
-
All businesses should consider whether it is appropriate to notify local law enforcement or federal agencies such as the Federal Bureau of Investigation or U.S. Secret Service. Certain businesses may also have notification obligations to federal regulators, including the Securities and Exchange Commission and/or law enforcement. In the case of certain types of information, such as protected health information, a business may need to notify the Federal Trade Commission and/or the U.S. Department of Health and Human Services. Businesses may also have obligations under international laws including the European Union’s General Data Protection Regulation.