Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

US State Data Security Laws & Regulations

State-level data protection laws are becoming more common in the United States. These states have laws that govern minimum cybersecurity requirements:  

PCI DSS
Icon Reasons State Cybersecurity Data Protection California
CA SB1386
US Federal Laws
Icon Reasons State Cybersecurity Data Protection Massachusetts
MA 201 CMR 17.00
US State Laws
Icon Reasons State Cybersecurity Data Protection Minnesota
Plastic Card Security Act
EU GDPR
Icon Reasons State Cybersecurity Data Protection Nevada
NV SB227
International Laws
Icon Reasons State Cybersecurity Data Protection Oregon
OR ORS 646.200
International Laws
Icon Reasons State Cybersecurity Data Protection Washington
WA HB 1149

Why should you take these state-level Information Security laws seriously? The reason is simple: A single negligent breach can close your business forever, because liability insurance will not cover professional negligence. Without the ability to prove steps were taken to ensure due care and due diligence were applied to your business operations, you may be considered negligent in a lawsuit. Additionally, Information Security policies are a tool that you can use to enforce proper conduct by your employees.

Common Questions

Frequently-Asked Questions

Here are answers to common questions about US state data security laws:

Which state laws require businesses to protect personal information?
Many states impose a reasonable security duty on businesses that hold residents' personal information. Examples include California Civil Code 1798.81.5, Massachusetts 201 CMR 17.00, which requires a written information security program, Nevada NRS 603A.210, and Oregon ORS 646A.622. These laws generally apply based on where the affected residents live, not where the business is located. ComplianceForge offers editable policy and documentation templates you can use to document due care under these state requirements.
Does Nevada law require PCI DSS compliance?
Yes, under NRS 603A.215, a data collector doing business in Nevada that accepts payment cards for the sale of goods or services must comply with the current version of the Payment Card Industry (PCI) Data Security Standard. Data collectors not covered by that requirement may not transfer personal information electronically outside their secure system, or move data storage devices beyond their logical or physical controls, unless the information is encrypted.
What is the Minnesota Plastic Card Security Act?
The Minnesota Plastic Card Security Act is the common name for Minnesota Statutes section 325E.64, enacted in 2007. It prohibits businesses that accept payment cards in Minnesota from retaining card security codes, PIN verification code numbers, or full magnetic stripe track data after a transaction is authorized, or more than 48 hours after authorization for PIN debit transactions. A business that violates it and suffers a breach must reimburse card issuers for reasonable costs such as card reissuance.
What did California SB 1386 require?
California SB 1386, enacted in 2002, created the state's data breach notification requirement. It requires businesses and state agencies that maintain computerized data containing personal information to notify California residents whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The requirement is now codified at Civil Code 1798.82 for businesses and 1798.29 for agencies, and a breach affecting more than 500 residents also requires sending a sample notice to the Attorney General.
Can businesses be liable for payment card breaches in Washington?
Yes, Washington's RCW 19.255.020, enacted in 2010 through HB 1149, allows financial institutions to recover reasonable card reissuance costs from processors, large businesses and vendors whose failure to take reasonable care led to a breach of account information. A covered business is one that processes more than 6 million card transactions a year. A processor, business or vendor is not liable if the data was encrypted at the time of the breach, or if it was certified PCI DSS compliant and validated by an annual assessment within one year before the breach.