IMATION MAP OF STATE DATA BREACH NOTIFICATION LAWS SPOTLIGHTS NEED FOR STORING AND PROTECTING SENSITIVE INFORMATION
Compliance Heat Map Illustrates Similarities and Differences in State Laws, with Virginia’s Being Most Strict; Laws Hint at Myr...
Compliance Heat Map Illustrates Similarities and Differences in State Laws, with Virginia’s Being Most Strict; Laws Hint at Myriad of Data Compliance Challenges Facing Businesses of All Sizes
“What the compliance heat map tells us is that data security needs to be at top of mind for all IT pros, as there are rules in place for nearly all states and territories and non-compliance could mean serious penalties,” saidDavid Duncan , software & security solutions marketing director, Imation . “Yet, companies also are challenged by explosive data growth and state and federal requirements that mandate active archiving, long-term retention and accessibility of that data. Businesses need resources to help navigate laws and develop secure and scalable infrastructures for data storage and protection.”
IT pros today are responsible for managing data, which includes ensuring security, business continuity and regulatory compliance. For small- to mid-sized businesses, the challenge is often to meet compliance requirements with limited resources, which leads to higher risk. In fact, the 2011 Verizon Data Breach report found that businesses with between 11 and 100 employees reported more than six times as many data breaches than businesses with between 101 and 1,000 employees, according to the online websiteBusinessNewsDaily. Further, the loss or theft of an unencrypted notebook, flash drive or removable hard disk drive can expose gigabytes, or even terabytes, of private information. IT professionals should implement strategies to protect their data through network security, data encryption and enforcement of information security policies, while staying well-informed of state compliance laws in the not-unlikely event that a data breach does occur.
Compliance Heat Map Findings
Imation’s research found most state data breach notification laws to offer similar definitions of personally identifiable information and requirements regarding the notification of affected parties. Among the research’s noteworthy findings:
- Four states have yet to enact a data breach notification law:
Alabama ,Kentucky ,New Mexico andSouth Dakota . - According to Imation’s analysis,
Virginia has the most strict law in the nation. The law provides specific requirements on what is to be included in a breach notification, requires government and credit reporting agency notification, and includes a large financial penalty relative to other states. - A few states, including
Virginia , require notification even if breached data is encrypted—if the encrypted data was stolen along with the encryption keys.
Compliance Heat Map Methodology
To conduct the research, Imation applied to the laws a series of questions, organized to evaluate the laws’ requirements regarding encryption, data that is within scope of the laws, notification of data loss and destruction of data, as well as penalties for non-compliance with the laws. Imation also considered other germane laws, such as those dictating data destruction or allowing for consumer freezing of credit report requests. Imation used publicly available information about the laws, including the legislation itself.
For more information, please visit www.imation.com/compliancemap.
About Imation
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.