Security Breach Law in Virginia, New Privacy Requirements

Security Breach Law in Virginia, New Privacy Requirements

Va. Code § 18.2-186.6 § 32.1-127.1:05 is a data breach notification law that was initially passed in the U.S. state of Virginia in 2008 and has been amended several times since, most recently in 2019. As Virginia is only one of a handful of states within the U.S. that has passed a comprehensive data protection law in the form of the Virginia Consumer Data Protection Act or VCDPA, Va. Code § 18.2-186.6 § 32.1-127.1:05 represents a part of an already existing legal framework within the state geared towards protecting personal data and privacy. As such, Va. Code § 18.2-186.6 § 32.1-127.1:05 establishes the protocol that businesses within the state are responsible for following in the event that a data breach occurs, as well as the punishments that can be handed down for violating this protocol.

What is the scope and application of Va. Code § 18.2-186.6 § 32.1-127.1:05?

In terms of the scope and application of Va. Code § 18.2-186.6 § 32.1-127.1:05, the provisions set forth in the law are applicable to any “an individual, corporation, business trust, estate, partnership, limited partnership, limited liability partnership, limited liability company, association, organization, joint venture, government, governmental subdivision, agency, or instrumentality or any other legal entity, whether for profit or not for profit (collectively, Entity) that owns or licenses computerized data that includes PI.” Alternatively, the law also contains separate provisions for certain entities within Virginia, such as healthcare facilities and government agencies.

What are the data breach notification requirements under Va. Code § 18.2-186.6 § 32.1-127.1:05?

Much like other data breach notification laws around the U.S., Va. Code § 18.2-186.6 § 32.1-127.1:05 mandates that business entities provide notification to affected parties should a data breach occur. However, the law differs from many other data breach notification laws in that it also covers employee tax income data. With this being said, in addition to providing consumers with information such as the extent and scope of the breach, as well as the types of personal information that were disclosed during the breach, business entities within Virginia that “that own or license computerized data relating to state income tax withheld” must also provide notification to the Virginia attorney general should they experience a data breach.

Moreover, all data breach notifications that are provided to individuals and parties within the state of Virginia must contain the following information:

What types of personal information are covered under Va. Code § 18.2-186.6 § 32.1-127.1:05?

As Va. Code § 18.2-186.6 § 32.1-127.1:05 protects both personal and health information, there are two categories of data that are protected under the law. To this point, the following types of personal information are legally protected in the event that a data breach takes place, in combination with a Virginia resident’s first name or first initial and last name, permitting the following data elements have not been encrypted or redacted:

Conversely, Va. Code § 18.2-186.6 § 32.1-127.1:05 also protects the following types of medical information:

What are the penalties for Va. Code § 18.2-186.6 § 32.1-127.1:05?

The provisions that were laid out in Va. Code § 18.2-186.6 § 32.1-127.1:05 are enforceable by the Virginia attorney general. Subsequently, the Virginia attorney general has the authority to impose numerous sanctions and penalties against business entities and organizations within the state that are found to be in violation of the law. Most notably, business entities that fail to comply with the law are subject to a monetary penalty of up to $150,000 per breach. Additionally, data breaches that involve healthcare information are subject to a separate set of punishments, in accordance with federal legislation such as the Health Insurance Portability and Accountability Act or HIPAA.

The provisions of Va. Code § 18.2-186.6 § 32.1-127.1:05 in conjunction with the Virginia Consumer Data Protection Act represent the legal framework for protecting the personal data and privacy of citizens within the state of Virginia. Through the regulations set forth in such legislation, residents of Virginia have multiple avenues they can pursue in the event that their personal information is compromised for any reason. As such, Virginia residents are afforded a level of data protection that is not standard within most states around the country, as the U.S. has yet to pass a comprehensive data protection law at the federal level.

Related Reads