New Jersey 2024-2025 Regular Session

New Jersey Assembly Bill A548

Introduced
1/9/24  

Caption

Revises requirements for disclosure of a breach of security of certain computerized records containing personal information.

Impact

The amendments presented by A548 specifically focus on improving customer protection against identity theft by ensuring timely notifications about potential breaches. By tightening the disclosure timeframe, the bill is designed to foster greater accountability among businesses, potentially enhancing the trust of consumers in how their personal data is handled. Conversely, some businesses may find this mandate burdensome, particularly smaller entities that might struggle to comply promptly under the threat of penalties for non-disclosure.

Summary

Bill A548 aims to revise and enhance the disclosure requirements for businesses and public entities in New Jersey that experience a breach of security involving computerized records containing personal information. The primary provision of the bill mandates that such entities must inform affected customers within five business days following the discovery of a breach. This change enforces a stricter timeline compared to previous regulations, which required disclosure 'in the most expedient time possible'. Importantly, exceptions to the notification requirement exist if an investigation determines that misuse of the information is not reasonably possible, a decision that must be substantiated in documentation.

Contention

Discussions around A548 have spurred concerns regarding the implications of increased burdens on businesses, especially in terms of the capacity to manage data breaches effectively and the costs associated with swift disclosures. Critics argue that the five-day requirement could be overly aggressive, emphasizing the need for flexibility in circumstances where law enforcement involvement is necessary or where investigations into the scope of breaches are still ongoing. Additionally, there are apprehensions about how this bill may intersect with existing state and federal regulations, including the potential overlap with the provisions of the federal 'Fair Credit Reporting Act'.

Companion Bills

NJ S3028

Same As Revises requirements for disclosure of a breach of security of certain computerized records containing personal information.

NJ A1268

Carry Over Revises requirements for disclosure of a breach of security of certain computerized records containing personal information.

NJ S1352

Carry Over Revises requirements for disclosure of a breach of security of certain computerized records containing personal information.

Similar Bills

NJ S3028

Revises requirements for disclosure of a breach of security of certain computerized records containing personal information.

NJ A1268

Revises requirements for disclosure of a breach of security of certain computerized records containing personal information.

NJ S1352

Revises requirements for disclosure of a breach of security of certain computerized records containing personal information.

NJ A2079

Requires certain notifications and free credit reports for customers following breach of security of personal information within business or public entity.

NJ A1426

Requires certain notifications and free credit reports for customers following breach of security of personal information within business or public entity.

LA SB361

Provides relative to the protection of computerized data that contains personal information and requires notification of data breaches. (8/1/18)

CA AB2182

Privacy: personal information: breach: disclosure.

CA AB1035

COVID-19 emergency: small businesses: immunity from civil liability.