State Breach Notification, SSN Protections, and Identity Theft Laws
California enacted the first breach law in 2002; all 50 states now have one. Breach-law personal information centers on name + SSN, driver's license/ID, or financial account number. States also protect SSNs and all 50 have identity theft laws; FACTA preempted much credit-report law but left identity-theft authority.
How this supports CIPP/US study
Use this lesson to connect a privacy programme decision with the relevant regulator, duty or enforcement route. Continue with the CIPP/US exam questions.
In most state data breach notification laws, personal information means an individual's first name or initial and last name combined with one or more of: (1) Social Security number; (2) driver's license or state ID number; or (3) financial account, credit, or debit card number. This is narrower than the comprehensive-law definition.
California enacted the first breach notification law in 2002; every state followed. Many laws require reports to state AGs and confer AG enforcement if the breach reveals inadequate security controls. States also protect SSNs - for example, California bars businesses from publicly posting them or requiring transmission over an unencrypted connection.
In 2003, FACTA amended the FCRA and preempted many state credit-report laws, but states retained power to enact identity-theft laws. All 50 states have identity-theft laws, and more than half permit restitution for victims.
Key terms - quick answers
What is “Data breach notification law”?
What is “Social Security number”?
What is “Identity theft laws”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.