The New Mexico Legislature passed the ‘ Data Breach Notification Act ’ (the Act) on March 15. Governor Susana Martinez has 20 days from the date the Act was passed to sign it into law. If enacted, the Act would require a person, other than a person who is subject to the Health Insurance Portability and Accountability Act of 1996 or the Gramm-Leach-Bliley Act , that “owns or maintains” records containing a New Mexico resident’s personal identifying information (PII) to notify the resident if his or her PII is “reasonably believed” to have been subject to a security breach. In most cases, notification is required within 45 days. Under the Act, PII is defined as an individual’s last name and first name or first initial in combination with one or more specified data elements, when the data elements are not rendered unreadable or unusable through encryption, redaction, or another means. The five specified data elements or categories of data elements in the Act are (i) so...
Comments
Post a Comment