Tuesday, October 11, 2011

A New Data Breach Notification Law Has Been Signed In

People like privacy.Head’s up, California IT professionals!

At the end of August, California SB 24 was signed into law and will kick in on January 1st, 2012.

SB 24 amends the infamous SB 1386 (sections 1798.329 & 1798.82 of the California Civil Code), which is the data breach notification law that requires companies to notify Californians should their personal information be accessed in a system security breach.

New changes included in the California SB 24 law:

  • Data breach notification letters to affected individuals must include:

    • a general description of the incident

    • the information exposed (name, address, etc.)

    • specifics on when the breach occurred

    • contact information of the major credit reporting agencies (if social security numbers were compromised)



  • A copy of the data beach notification letter must be sent to the state’s Attorney General if the security breach affects more than 500 people.


The amendment is geared to help individuals whose information was compromised in a security breach to receive a more resourceful and less confusing notification letter from the organizations involved.

To read the text of the bill, go here.

What precautions have you taken to make sure your customer data is safe?

Photo Credit: alancleaver_2000

No comments:

Post a Comment