Last Action | to Judiciary (S) |
---|---|
Title | AN ACT relating to the security of personal information. |
Bill Documents | Introduced |
Impact Statements | Local Mandate |
Bill Request Number | 13 |
Sponsor | W. Westerfield |
Summary of Original Version | Amend KRS 61.931 to include user name, e-mail address, and security questions with answers in the definition of "personal information" involved in a data security breach of information held by state and local government agencies; amend KRS 61.933 to allow a civil cause of action for actual damages, attorney's fees and court costs in Franklin Circuit Court against state and local government agencies who violate the investigation and notice procedures of KRS 61.931 to 61.934, waiving sovereign immunity; amend KRS 365.732, regarding data security breaches in businesses, to expand the definition of "breach of the security system" to include noncomputerized records as well as computerized records, records which are accessed as well as records which are acquired, and encrypted records when the key is also compromised; define "encryption" as meeting National Institute of Standards and Technology guidelines; expand definition of "personally identifiable information" to mirror the definition of "personal information" in KRS 61.931; include third party agents who contract with information holders in the section's provisions; limit time frames for notice of breaches. |
Index Headings of Original Version |
Courts, Circuit - Franklin Circuit, data security breach by state and local governments, venue for Data Processing - Data security breach, failure to provide notice of, damages for Local Government - Data security breach, failure to provide notice of, damages for Science and Technology - Data security breach, failure to provide notice of, damages for State Agencies - Data security breach, failure to provide notice of, damages for Trade Practices and Retailing - Data security breach, failure to provide notice of, damages for Information Technology - Data security breach, failure to provide notice of, damages for Civil Actions - Data security breach, failure to provide notice of, damages for Civil Actions - State and local governments, data security breach by, waiver of sovereign immunity Claims - Data security breach actions, failure to provide notice of, damages for Commerce - Data security breach, failure to provide notice of, damages for Local Mandate - State and local governments, data security breach by, waiver of sovereign immunity |
01/03/17 |
|
---|---|
01/07/17 |
|
Last updated: 1/16/2019 3:02 PM (EST)