More Posts

As the number of highly publicized data breaches continues to skyrocket and proposals for a federal data breach notification law stagnate, state legislatures around the country have been busy amending their own breach notification statutes. So far, 2015 has been a banner year for state breach law makers, with nine states formalizing amendments to their laws, and several others poised to follow suit.

Since California took the lead by enacting the first data breach statute back in 2003, 46 other states (plus D.C., Puerto Rico, Guam, and the Virgin Islands) have passed their own security breach notification requirements. And California could be credited with having started another trend in 2013 when it expanded the definition of personal information in its breach notification law to include email addresses and passwords used to access an individual’s online account. California made further revisions to its law in 2014, and since then there has been a steady stream of state law changes, many of which have followed California’s example to some extent.