Just released: How to raise venture capital in 2023

Download

Updated 2014 Data Breach Notification Costs by State

TL:DR

Key Takeaways

Carl Niedbala - Founder Shield
Carl Niedbala

Managing Partner; COO & Co-Founder

Data Breach Notification Costs

Cyber liability costs are soaring these days for all kinds of businesses (startups included).  Most people think of these “costs” as those related directly to the data breach: legal defense fees, settlements with users and 3rd party vendors, and forensic costs.

Loss attributed to data breach notification costs can go under the radar.  When user data is compromised, the company must take steps to notify users that the their personal data has been [potentially] leaked.  Seems simple enough, but the problem is that data breach notification laws differ across all 50 states.  Each state can have it’s own way of thinking about:

  • what constitutes Personally Identifiable Information (“PII”)
  • what constitutes a breach
  • when users must be notified (i.e. a “known” breach vs “reasonable belief a breach has occurred…”)
  • how notification should be made
  • safe harbor provisions that decrease liability under the statute
  • who is subject to the breach notification law (based on company operations, size, location…)

As you can see, navigating the breach notification legal landscape can get expensive pretty quickly.  A good Cyber liability insurance policy can mitigate a ton of this risk by covering data breach notification costs as well as more “traditional” data breach costs.

If you’re curious about the laws in your state, law firm Mintz Levin created a quick cheat sheet of breach notification laws by state that has been updated as recently as August 2014.  You can dive in to look at the laws in your specific state, but here are a couple big picture takeaways from the document:

  • The general definition of “PII” is as follows: “An individual’s first name or first initial and last name plus one or more of following data elements: (i) Social Security number, (ii) driver’s license number or state-issued ID card number, (iii) account number, credit card number or debit card number combined with any security code, access code, PIN or password needed to access an account and generally applies to computerized data that includes PI.”
    • NOTE: California has one of the most sweeping definitions varying from the above:  “any user name or email address, in combination with a password or security question and answer that would permit access to an online account.”
  • The only states that don’t have breach notification laws are the following: Alabama, New Mexico, South Dakota.

 

Take some time to see where your state falls on the breach notification. If you don’t know and you have any questions, reach out! Or give us a call. If you want, you can skip the small talk and go ahead and get a quote.

Related Articles

cyber insurance 2025
January 15 • Cyber Liability

Cyber Insurance 2025: A Review & Outlook

Explore the evolving cyber threat landscape, including AI-powered attacks, supply chain disruptions, and nation-state threats. Learn how these trends are impacting cyber insurance pricing and discover essential strategies for mitigating cyber risks and protecting your business.

AI Compliance
December 30 • Cyber Liability

How to Conduct a Thorough DPIA for AI Compliance [with GDPR]

This article outlines the key steps involved in conducting a Data Protection Impact Assessment (DPIA) for AI systems, emphasizing the importance of identifying and mitigating risks to comply with GDPR and build trust with data subjects.

data breach 2024
October 1 • Cyber Liability

Top 10 Cyber Security Data Breaches of 2024

Cybersecurity under attack in 2024! Discover the top 10 data breaches that rocked the world. Learn how major companies fell victim to cybercriminals. Understand the risks and take action to protect your business from cyber threats.

supply chain disruptions
August 27 • Cyber Liability

Cyber Attacks & Supply Chain Disruptions: Startup’s Worst Enemy?

Explore the evolving threat landscape for supply chain disruptions, mitigation strategies, and the importance of risk management in today’s volatile business environment.

cyber insurance pricing trends 2024
March 13 • Cyber Liability

Cyber Insurance Pricing Trends 2024

Uncertain about cyber insurance costs in 2024? Our article explores pricing trends, expert predictions on rate increases, and strategies to potentially reduce your cyber insurance premium.

cyber liability insurance premiums
March 4 • Cyber Liability

7 “Must Haves” For Cyber Liability Insurance in 2024

With cyber liability insurance premiums rising, business leaders must have the inside scoop to keep costs low. Our partners at Blacksmith InfoSec delve into those tips and tricks.