Share on LinkedInShare on LinkedIn

ARTICLE · 23 OCTOBER 2003

MICRO VIEW - New Data Security Law

United StatesMedia, Telecoms, IT, Entertainment
Deborah Birnbach
Deborah Birnbach

On July 1, 2003, a far-reaching California data security law went into effect. The new law applies to any company that stores personally identifiable information of California customers or employees, regardless of whether the company is located in California. The law mandates disclosure to California residents whose information may have been compromised if a company’s security is breached. Companies without a pre-determined action plan and notification policy can incur significant costs in complying or face lawsuits for noncompliance. The law is triggered when an unauthorized person — internal or external — acquires personal information stored in the company’s systems, or even if the company merely believes an unauthorized person may have accessed such information. "Personal information" is very broadly defined, including a first name or initial and last name in combination with a social security number, a driver’s license number, account number or other similar information. Encrypted information is exempt, making that option more valuable than ever. Private equity firms and their portfolio companies that are affected by the new law should put an action plan in place immediately for investigating and responding to data security breaches.

The content of this article does not constitute legal advice and should not be relied on in that way. Specific advice should be sought about your specific circumstances.

See more popular content from