Skip to Page Content
Home  |  Contact Us  |  Press Room  |  Site Overview  |  Help  |  Login  |  Register
Add to MyNCSL

2007 Breach of Information Legislation

Last update: April 16, 2007

Summary:  Bills have been introduced in at least 26 states in 2007.  See also Security Breach Laws and 20062005, 2004, 2003, and 2002 legislation. 

(Links to state web sites for bill text and status information are available here.)

ALASKA  
AK H 31
Author: Samuels (R)
Title: Personal Information and Consumer Credit
Prefiled: 01/05/2007
Introduced: 01/16/2007
Location: House Labor and Commerce Committee
Summary: Relates to breaches of security involving personal information, credit report and credit score security freezes, consumer credit monitoring, credit accuracy, protection of social security numbers, care of records, disposal of records, identity theft, furnishing consumer credit header information, credit cards, and debit cards, and to the jurisdiction of the office of administrative hearings; amends Rule 60, Alaska Rules of Civil Procedure.
Status:
01/16/2007 INTRODUCED.
01/16/2007 To HOUSE Committee on LABOR AND COMMERCE.
01/16/2007 To HOUSE Committee on JUDICIARY.
01/16/2007 To HOUSE Committee on FINANCE.
 
AK H 65
Author: Coghill (R)
Title: Personal Information and Consumer Credit
Prefiled: 01/05/2007
Introduced: 01/16/2007
Location: House Labor and Commerce Committee
Summary: Relates to breaches of security involving personal information, credit report and credit score security freezes, consumer credit monitoring, credit accuracy, protection of social security numbers, care of records, disposal of records, identity theft, furnishing consumer credit header information, credit cards, and debit cards, and to the jurisdiction of the office of administrative hearings; amends Rule 60, Alaska Rules of Civil Procedure.
Status:
01/16/2007 INTRODUCED.
01/16/2007 To HOUSE Committee on LABOR AND COMMERCE.
01/16/2007 To HOUSE Committee on JUDICIARY.
01/16/2007 To HOUSE Committee on FINANCE.
 
AK S 21
Author: Therriault (R)
Title: Personal Information and Consumer Credit
Prefiled: 01/05/2007
Introduced: 01/16/2007
Location: Senate Labor and Commerce Committee
Summary: Relates to breaches of security involving personal information, credit report and credit score security freezes, consumer credit monitoring, credit accuracy, protection of social security numbers, care of records, disposal of records, identity theft, furnishing consumer credit header information, credit cards, and debit cards, and to the jurisdiction of the office of administrative hearings; amends Rule 60, Alaska Rules of Civil Procedure.
Status:
01/16/2007 INTRODUCED.
01/16/2007 To SENATE Committee on LABOR AND COMMERCE.
01/16/2007 To SENATE Committee on JUDICIARY.
01/16/2007 To SENATE Committee on FINANCE.
 ARKANSAS
AR H 2477
Author: Lamoureux (R)
Title: Protection of Personal Information
Introduced: 03/05/2007
Last Amendment: 03/13/2007
Location: HOUSE
Summary: Enhances the protection of personal information; requires notice to a consumer of an unauthorized breach of the consumer's personal information within the past five (5) years.
Status:
03/14/2007 From HOUSE Committee on INSURANCE AND COMMERCE: Do pass.
 ARIZONA
AZ S 1042
Author: Gray (R)
Title: Notice of Personal Data Compromise
Prefiled: 12/29/2006
Introduced: 01/08/2007
Enacted: 04/10/2007
Chapter: 23
Location: Chaptered
Summary: Relates to notification for compromised personal information; relates to the Department of Public Safety, a county sheriff's department and municipal police departments; relates to requirements regarding notification of a breach of a security system and the possible compromise of personal information.
Status:
04/11/2007 Chapter No. 23
 CALIFORNIA
CA A 372
Author: Salas (D)
Title: Personal Information
Introduced: 02/15/2007
Last Amendment: 03/19/2007
Location: Assembly Judiciary Committee
Summary: Makes technical, nonsubstantive changes to provisions of existing law that allows a injured customer to institute a civil action to recover damages or for injective relief relating to existing law that requires businesses to destroy customer records, to implement and maintain reasonable security procedures and practices to protect personal information from unauthorized access, destruction, use, modification, or disclosure, and to make sure that 3rd party's getting such information maintain procedures.
Status:
03/19/2007 From ASSEMBLY Committee on JUDICIARY with author's amendments.
03/19/2007 In ASSEMBLY. Read second time and amended. Re-referred to Committee on JUDICIARY.
 
CA A 512
Author: Lieber (D)
Title: Personal Information: Security Breaches
Introduced: 02/20/2007
Last Amendment: 03/26/2007
Location: Assembly Judiciary Committee
Summary: Adds medical and health care records and medical and health insurance numbers, codes, and records to the definition of personal information, thereby, requiring a state agency, or a person or business that conducts business in the state, to disclose a breach of the security of a person's unencrypted medical or health care records or medical or health insurance numbers, codes, or records.
Status:
03/26/2007 From ASSEMBLY Committee on JUDICIARY with author's amendments.
03/26/2007 In ASSEMBLY. Read second time and amended. Re-referred to Committee on JUDICIARY.
 CONNECTICUT
CT S 1089
Introducer: Joint Banks
Title: Safekeeping of Consumer Information
Introduced: 02/02/2007
Last Amendment: 03/21/2007
Location: Legislative Commissioner's Office
Summary: Encourages the safekeeping of consumer information in retail establishments; ensures that retail businesses who do not protect the personal information of their customers are held responsible for the economic consequences of a breach of security.
Status:
04/11/2007 From JOINT Committee on GENERAL LAW: Reported favorably.
04/11/2007 Filed with Legislative Commissioner's Office.
 GEORGIA
GA S 236
Author: Rogers (R)
Title: Georgia Personal Identity Protection Act
Introduced: 02/27/2007
Last Amendment: 03/19/2007
Location: House Non-Civil Judiciary Committee
Summary: Relates to the offense of identity fraud, so as to change certain provisions relating to the elements of the offense of identity fraud; to provide for a victim's right to file a report with a law enforcement agency; to provide a short title; to provide for related matters; to provide an effective date; to repeal conflicting laws.
Status:
03/28/2007 To HOUSE Committee on NON CIVIL - JUDICIARY.
 HAWAII
HI H 1312
Author: Say (D)
Title: Escrow Depository Law Revisions
Introduced: 01/22/2007
Location: House Consumer Protection and Commerce Committee
Summary: (Governor's Package Bill) Revises the escrow depository law to: (1) clarify which escrow transactions are covered by the statute and which are not; (2) update the statute to adequately reflect the present day size of the transactions routinely handled by the industry; (3) provide for more flexibility in supervising and regulating the industry; and (4) ensure adequate protection for the consumer.
Status:
01/24/2007 To HOUSE Committee on CONSUMER PROTECTION AND COMMERCE.
 
HI H 1313
Author: Say (D)
Title: Financial Institution Licensing Procedures
Introduced: 01/22/2007
Last Amendment: 02/16/2007
Location: House Judiciary Committee
Summary: (Governor's Package Bill) Eliminates obsolete requirements and improves procedures for the licensing and regulation of financial institutions.
Status:
02/16/2007 In HOUSE. Read second time. Committee amendment adopted. House Draft 1.
02/16/2007 To HOUSE Committee on JUDICIARY.
 
HI H 1315
Author: Say (D)
Title: Mortgage Brokers and Solicitors
Introduced: 01/22/2007
Location: House Consumer Protection and Commerce Committee
Summary: (Governor's Package Bill) Clarifies who is exempt from Mortgage Brokers and Solicitors provisions and what constitutes prohibited activity; establishes license application requirements and includes a written examination of the applicant or its designated responsible individual, along with a $50,000 bond requirement for a licensee; establishes biennial license renewal which includes completion of a continuing education requirement; requires that record keeping requirements are established.
Status:
01/24/2007 To HOUSE Committee on CONSUMER PROTECTION AND COMMERCE.
 
HI S 1398
Author: Hanabusa (D)
Title: Escrow Depository Transactions
Introduced: 01/22/2007
Last Amendment: 03/06/2007
Location: House Consumer Protection and Commerce Committee
Summary: (Governor's Package Bill) Revises the escrow depository law to, clarify which escrow transactions are covered by the statute and which are not, update the statute to adequately reflect the present day size of the transactions routinely handled by the industry, provide for more flexibility in supervising and regulating the industry, and ensure adequate protection for the consumer.
Status:
03/09/2007 To HOUSE Committee on CONSUMER PROTECTION AND COMMERCE.
 
HI S 1399
Author: Hanabusa (D)
Title: Financial Institution Regulations
Introduced: 01/22/2007
Last Amendment: 02/14/2007
Location: Senate Judiciary and Labor Committee
Summary: (Governor's Package Bill) Eliminates obsolete requirements; improves procedures for the licensing and regulation of financial institutions.
Status:
02/14/2007 From SENATE Committee on COMMERCE, CONSUMER PROTECTION AND AFFORDABLE HOUSING: Do pass as amended.
02/14/2007 In SENATE. Read second time. Committee amendment adopted. Senate Draft 1.
02/14/2007 To SENATE Committee on JUDICIARY AND LABOR.
 
HI S 1401
Author: Hanabusa (D)
Title: Mortgage Brokers and Solicitors Regulations
Introduced: 01/22/2007
Location: Senate Commerce, Consumer Protection and Affordable Housing Committee
Summary: (Governor's Package Bill) Clarifies who is exempt from Mortgage Brokers and Solicitors provisions and what constitutes prohibited activity; establishes license application requirements; includes a written examination of the applicant or its designated responsible individual, along with a $50,000 bond requirement for a licensee; establishes biennial license renewal which includes completion of a continuing education requirement; requires record keeping requirements to be established.
Status:
01/29/2007 To SENATE Committee on COMMERCE, CONSUMER PROTECTION AND AFFORDABLE HOUSING.
 
IL H 605
Sponsor: Riley (D)
Title: Personal Information Security Breach
Introduced: 02/02/2007
Last Amendment: 03/21/2007
Location: House Rules Committee
Summary: Amends the Personal Information Protection Act. Defines breach of the security of the system data or written material. Provides that the notice requirements of the Act apply to breaches of written material containing personal information. Provides that a data collector shall notify the resident that there has been a breach of the security of the system data or written material within a reasonable time after the discovery of the breach of the system data or written material.
Status:
03/23/2007 Rereferred to HOUSE Committee on RULES.
 MARYLAND  
MD H 123
Author: Lee (D)
Title: Personal Information Security
Introduced: 01/24/2007
Location: HOUSE
Summary: Requires a business to destroy or arrange for the destruction of records that contain specified personal information in a specified manner; requires a business that compiles, maintains, or makes available specified personal information of an individual residing in the State to implement and maintain specified security procedures and practices; requires businesses to notify specified individuals of a breach of security of a system.
Status:
03/20/2007 From HOUSE Committee on ECONOMIC MATTERS: Reported unfavorably.
   
 
MD H 208
Author: Howard (D)
Title: Electronic Records Protection
Introduced: 01/26/2007
Last Amendment: 04/06/2007
Location: Eligible for Governor
Summary: Requires specified businesses, when destroying a customer's electronic records that contain personal information of the customer, to take specified steps to protect against unauthorized access to or use of the personal information; requires those businesses when they discover or are notified of a breach of the security of the system to make an investigation related thereto and to notify the individual or individuals concerned thereof; provides exception to notification.
Status:
04/09/2007 Passed SENATE. *****To HOUSE for concurrence.
04/09/2007 HOUSE concurred in SENATE amendments.
04/09/2007 Eligible for GOVERNOR'S desk.
 
MD S 194
Author: Kelley (D)
Title: Consumer Protection
Introduced: 01/26/2007
Last Amendment: 04/06/2007
Location: Eligible for Governor
Summary: Requires specified businesses, when destroying a customer's records that contain personal information of the customer, to take specified steps to protect against unauthorized access to or use of the personal information under specified circumstances.
Status:
04/09/2007 SENATE concurred in HOUSE amendments.
04/09/2007 Eligible for GOVERNOR'S desk.
 MISSOURI
MO H 377
Sponsor: Wildberger (D)
Title: Release of Personal Information
Introduced: 01/11/2007
Location: House Special Committee on Financial Institutions
Summary: Changes the laws regarding the release of personal information to unauthorized persons.
Status:
03/29/2007 To HOUSE Special Committee on FINANCIAL INSTITUTIONS.
  MISSISSIPPI  
MS S 2089
Author: Tollison (D)
Title: Clean Credit And Identity Theft Protection Act
Introduced: 01/02/2007
Last Amendment: 02/08/2007
Location: Died
Summary: Creates the Clean Credit and Identity Theft Protection Act.
Status:
02/12/2007 Died on calendar.
   
 MONTANA
MT S 33
Author: Steinbeisser (R)
Title: Social Security Numbers
Prefiled: 11/27/2006
Introduced: 01/03/2007
Last Amendment: 02/02/2007
Location: House Appropriations Committee
Summary: Requires state and local government agencies to develop procedures regarding social security numbers and to provide notification of a computer security breach of a government agency or third party contracting with government.
Status:
02/26/2007 To HOUSE Committee on APPROPRIATIONS.
 NEW JERSEY
NJ A 259
Sponsor: Chivukula (D)
Title: Computer Systems
Introduced: 01/10/2006
Location: Assembly Consumer Affairs Committee
Summary: Requires businesses to disclose any breach of security of computer systems to customers and to destroy certain personal information no longer retained.
Status:
01/10/2006 INTRODUCED.
01/10/2006 To ASSEMBLY Committee on CONSUMER AFFAIRS.
 
NJ A 2104
Sponsor: Beck (R)
Title: Unauthorized Use of Information Offense Creation
Introduced: 01/30/2006
Location: Assembly Judiciary Committee
Summary: Creates offenses pertaining to unauthorized use of confidential information; makes it a crime to negligently provide confidential information to a third party without first taking reasonable and adequate steps to ensure the person is authorized to request such information.
Status:
01/30/2006 INTRODUCED.
01/30/2006 To ASSEMBLY Committee on JUDICIARY.
 
NJ AR 190
Sponsor: McKeon (D)
Title: Financial Data Protection Act, 2005
Prefiled: 05/22/2006
Introduced: 06/01/2006
Location: Assembly Financial Institutions and Insurance Committee
Summary: Memorializes Congress and President to oppose Financial Data Protection Act of 2005.
Status:
06/12/2006 From ASSEMBLY Committee on FINANCIAL INSTITUTIONS AND INSURANCE.
 
NJ SR 51
Sponsor: Turner (D)
Title: Financial Data Protection Act
Prefiled: 05/11/2006
Introduced: 05/15/2006
Location: Senate Commerce Committee
Summary: Memorializes Congress and President to oppose Financial Data Protection Act of 2005.
Status:
05/15/2006 INTRODUCED.
05/15/2006 To SENATE Committee on COMMERCE.
 NEW YORK
NY A 2261
Sponsor: Rules Cmt
Title: Security Breach Notification
Introduced: 01/16/2007
Location: Assembly Consumer Affairs and Protection Committee
Summary: Provides that any person, firm, partnership, association or corporation that collects, owns, maintains or uses personal information shall disclose a breach of security related to personal information concerning 25 or more residents in the state; provides notification within two business days after learning of the breach; provides methods for notification; provides steps to be taken to destroy or arrange for the destruction of such information; allows for injunctions and civil penalties for violations.
Status:
01/16/2007 INTRODUCED.
01/16/2007 To ASSEMBLY Committee on CONSUMER AFFAIRS AND PROTECTION.
 OKLAHOMA
OK H 1633
Author: Joyner (R)
Title: Breach of Security
Prefiled: 01/22/2007
Introduced: 02/05/2007
Location: House Rules Committee
Summary: Relates to technology; relates to disclosure of breach of security of computerized personal information; expands scope of law; specifies time for notification of breach of security; expands definition of breach of security of the system; modifies definitions; adds definitions; provides exception for notification; establishes penalties for failure to provide notice; exempts agencies from penalty; authorizes the Attorney General to enforce the penalties.
Status:
02/06/2007 To HOUSE Committee on RULES.
 OREGON
OR H 2442
Author: Merkley (D)
Title: Personal Information Security
Introduced: 01/10/2007
Location: House Consumer Protection Committee
Summary: Requires a business that owns, possesses or uses personal information to notify individual when breach of security that may result in misuse of personal information occurs; requires Department of Consumer and Business Services to establish registry of businesses that own, possess or use personal information; requires business that owns, possesses or uses personal information to provide individual, upon request, with copy of personal information about individual maintained by business.
Status:
01/17/2007 To HOUSE Committee on CONSUMER PROTECTION.
 RHODE ISLAND
RI H 5103
Author: Gemma (D)
Title: Criminal Offenses
Introduced: 01/18/2007
Location: House Corporations Committee
Summary: Would establish rules of disclosure of personal information about insurers, by businesses to third-parties, rules of notification to consumers of breaches in the security protecting consumer identification information as well as civil penalties and damages for violation of the disclosure and notification rules. This act would take effect upon passage.
Status:
02/07/2007 Scheduled for hearing and/or consideration.
 
RI H 5223
Author: Gemma (D)
Title: Identity Theft Protection
Introduced: 01/30/2007
Location: House Corporations Committee
Summary: Establishes rules of disclosure of personal information about insurers, by businesses to third-parties; concerns rules of notification to consumers of breaches in the security protecting consumer identification information; concerns civil penalties and damages for violation of the disclosure and notification rules.
Status:
02/07/2007 Scheduled for hearing and/or consideration.
02/07/2007 In HOUSE Committee on CORPORATIONS: Committee recommends measure to be held for further study.
 SOUTH CAROLINA
SC H 3035
Author: Kirsh (D)
Title: Identity Theft Protection Act
Prefiled: 12/13/2006
Introduced: 01/09/2007
Location: House Judiciary Committee
Summary: Enacts the Identity Theft Protection Act; provides for protections in connection with consumer credit-reporting agencies and with the use and communication of a consumer's social security number, imposition of a security freeze on a consumer's credit report and disclosure of unauthorized access; prohibits requiring the use of personal identifying information on a mortgage.
Status:
01/09/2007 INTRODUCED.
01/09/2007 To HOUSE Committee on JUDICIARY.
 
SC S 8
Author: Thomas (R)
Title: Identity Fraud and Theft Protection
Prefiled: 11/29/2006
Introduced: 01/09/2007
Location: Senate Banking and Insurance Committee
Summary: Enacts the Financial Identity Fraud and Identity Theft Protection Act; relates to consumer credit-reporting agencies, social security numbers, security freezes, and disclosure of unauthorized access to personal identifying information; relates to attorney fees, mortgage records, household garbage, and credit or debit card receipts.
Status:
01/09/2007 INTRODUCED.
01/09/2007 To SENATE Committee on BANKING AND INSURANCE.
 TENNESSEE
TN S 256
Author: Haynes (D)
Title: Consumer Credit Protection and Identify Theft
Introduced: 02/05/2007
Location: Senate Commerce, Labor and Agriculture Committee
Summary: Amends the act known as the Clean Credit and Identify Theft Protection Act of 2007; concerns a consumer report or credit report by any written, oral, or other communication of any information by a consumer reporting agency bearing on a consumer's credit worthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living which is used or expected to be used or collected in whole or in part for the purpose of serving as a factor.
Status:
02/08/2007 To SENATE Committee on COMMERCE, LABOR AND AGRICULTURE.
 TEXAS
TX S 223
Author: Ellis (D)
Title: Computerized Data Loss
Introduced: 01/12/2007
Location: Senate Business and Commerce Committee
Summary: Relates to a loss of computerized data or breach of computer security involving sensitive personal information.
Status:
01/30/2007 To SENATE Committee on BUSINESS AND COMMERCE.
 VIRGINIA
VA H 2140
Author: Brink (D)
Title: Data Breach Notification
Prefiled: 01/08/2007
Introduced: 01/10/2007
Location: Tabled in Committee
Summary: Requires an individual or a commercial entity that owns or licenses computerized data that includes personal information to conduct in good faith a reasonable and prompt investigation when it becomes aware of a breach of the security of the system; contains alternative notification provisions.
Status:
02/01/2007 In HOUSE Committee on COMMERCE AND LABOR: Tabled.
 
VA H 3148
Author: Bulova (D)
Title: Compromised Data Disclosure Act
Introduced: 01/19/2007
Location: Tabled in Committee
Summary: Relates to the Compromised Data Disclosure Act.
Status:
01/29/2007 In HOUSE Committee on SCIENCE AND TECHNOLOGY: Tabled.
 
VA S 1224
Author: Howell (D)
Title: Database Breach Notification
Introduced: 01/10/2007
Location: SENATE
Summary: Relates to database breach notification.
Status:
02/06/2007 Left in committee.
 
 WASHINGTON  
WA S 5341
Author: Kline (D)
Title: Harm Caused By Breaches
Introduced: 01/17/2007
Location: Senate Consumer Protection and Housing Committee
Summary: Specifies penalties for harm caused by breaches of security that compromise personal information; provides that a court may award damages up to the actual amount of economic damages or five hundred dollars, whichever is greater; provides a violation constitutes an unfair or deceptive practice in violation of chapter 19.86 RCW.
Status:
01/17/2007 INTRODUCED.
01/17/2007 To SENATE Committee on CONSUMER PROTECTION AND HOUSING.
 WEST VIRGINIA
WV H 2175
Sponsor: Marshall (D)
Title: Acquisition of Security Compromising Data
Introduced: 01/16/2007
Location: House Judiciary Committee
Summary: Relates to the unauthorized acquisition of data that compromises the security, confidentiality, or integrity of personal information maintained by the data collector.
Status:
01/16/2007 INTRODUCED.
01/16/2007 To HOUSE Committee on JUDICIARY.
 
WV H 2263
Sponsor: Brown (D)
Title: Clean Credit Information and Identity Theft Protection
Introduced: 01/16/2007
Location: House Judiciary Committee
Summary: Ensures clean credit information and identity theft protection (FN).
Status:
01/16/2007 INTRODUCED.
01/16/2007 To HOUSE Committee on JUDICIARY.
 
WV H 2705
Sponsor: Marshall (D)
Title: Consumer Right to Impose Freeze on Credit Reports
Introduced: 01/30/2007
Location: House Judiciary Committee
Summary: Establishes a procedure whereby a consumer may implement a security freeze to prohibit a consumer reporting agency from releasing all or any part of the consumer's credit report.
Status:
01/30/2007 INTRODUCED.
01/30/2007 To HOUSE Committee on JUDICIARY.
 WYOMING
WY S 53
Author: Case (R)
Title: Credit Freezes
Prefiled: 12/28/2006
Introduced: 01/09/2007
Last Amendment: 02/22/2007
Enacted: 03/01/2007
Chapter: 162
Location: Chaptered
Summary: Relates to consumer protection; provides for notice to consumers affected by breaches of consumer information databases; authorizes consumers to prohibit release of information maintained by credit rating agencies; provides definitions; provides exceptions.
Status:
03/01/2007 Signed by GOVERNOR.
03/01/2007 Chapter No. 162
 
WY S 65
Author: Johnson (R)
Title: Identity Theft Protection
Prefiled: 01/05/2007
Introduced: 01/09/2007
Location: Died
Summary: Relates to consumer protection; provides for notice to consumers affected by breaches of consumer information databases, as specified; authorizes consumers to prohibit release of information maintained by credit rating agencies, as specified; provides definitions; provides exceptions.
Status:
02/09/2007 Died in Committee.

 

 

Back arrow, return to previous page Return to Breach of Information Home

 

Powered By State Net, Copyright (c) 2007

Denver Office: Tel: 303-364-7700 | Fax: 303-364-7800 | 7700 East First Place | Denver, CO 80230 | Map
Washington Office: Tel: 202-624-5400 | Fax: 202-737-1069 | 444 North Capitol Street, N.W., Suite 515 | Washington, D.C. 20001