New Jersey 2022-2023 Regular Session

New Jersey Senate Bill S1352

Introduced
2/3/22  

Caption

Revises requirements for disclosure of a breach of security of certain computerized records containing personal information.

Impact

The bill primarily revises New Jersey's approach to data breach notifications, aiming to standardize the time frame companies are required to notify affected individuals. By enforcing a deadline of five business days, it addresses concerns about delayed responses that could leave consumers vulnerable. Additionally, it clarifies that businesses must document their assessments of whether the misuse of information is possible, which they must verify through consultations with law enforcement agencies. This documentation is required to be retained for five years, ensuring a record of compliance is maintained.

Summary

Senate Bill S1352 seeks to amend existing laws regarding the disclosure protocols following a breach of security concerning personal information. Specifically, it updates the requirements introduced under the Identity Theft Prevention Act, P.L.2005, c.226, mandating that businesses and public entities in New Jersey notify affected customers within a maximum of five business days after discovering a breach. This notification must occur unless law enforcement determines delaying disclosure is necessary to avoid hindering an investigation. The bill emphasizes timely communication with customers to enhance data protection and accountability.

Contention

Notable points of contention around S1352 involve the balance between consumer protection and the operational burdens placed on businesses. Proponents of the bill argue that timely notifications are essential for consumer safety, particularly in the digital age where personal information is frequently targeted. Critics may express concerns regarding the potential costs for businesses in adapting to these stricter regulations, especially smaller companies that may lack resources to comply with enhanced cybersecurity measures and the administrative burden of adhering to tight notification timelines. Additionally, the documentation requirements could raise concerns about privacy and data management.

Companion Bills

NJ A1268

Same As Revises requirements for disclosure of a breach of security of certain computerized records containing personal information.

Similar Bills

NJ A548

Revises requirements for disclosure of a breach of security of certain computerized records containing personal information.

NJ A1268

Revises requirements for disclosure of a breach of security of certain computerized records containing personal information.

NJ S3028

Revises requirements for disclosure of a breach of security of certain computerized records containing personal information.

NJ A2079

Requires certain notifications and free credit reports for customers following breach of security of personal information within business or public entity.

NJ A1426

Requires certain notifications and free credit reports for customers following breach of security of personal information within business or public entity.

LA SB361

Provides relative to the protection of computerized data that contains personal information and requires notification of data breaches. (8/1/18)

CA AB2182

Privacy: personal information: breach: disclosure.

CA AB1035

COVID-19 emergency: small businesses: immunity from civil liability.