An increasing number of states have passed laws and regulations requiring the implementation of policies and procedures to protect personal information.1 Fortunately, New York, California and other states have produced practical guides designed to assist businesses in navigating the patchwork quilt of state privacy and data protection laws.

Most recently, the New York State Consumer Protection Board released a guide for New York businesses regarding the handling of personal identifiable information and the avoidance of identity theft. The guide is available at:

http://www.nysconsumer.gov/pdf/the_new_york_business_guide_to_privacy.pdf

The guide discusses a number of important topics. It reviews current New York data protection laws, such as those relating to data breach notification and use of Social Security numbers. It also summarizes privacy and data security laws taking effect in 2009. The guide also suggests ways of securing and disposing of data. Finally, the guide addresses related topics as they intersect with privacy and data security, such as working with contractors and training workers to handle personal information properly (studies show that insider and partner mistakes are often a significant contributing factor in costly security breaches).

Other states also provide useful privacy resources for businesses. The Office of Information Security and Privacy Protection (http://www.oispp.ca.gov/) in California, a state which historically has set the national standard for privacy protection, makes available and frequently updates a number of resources for businesses, including:

A California Business Privacy Handbook http://www.oispp.ca.gov/consumer_privacy/pdf/ca_business_privacy_hb.pdf

Recommended Practices on Notice of Security Breach Involving Personal Information http://www.oispp.ca.gov/consumer_privacy/pdf/secbreach.pdf

Recommended Practices on Protecting the Confidentiality of Social Security Numbers http://www.oispp.ca.gov/consumer_privacy/pdf/ssnrecommendations.pdf

Recommended Practices on California Information-Sharing Disclosures and Privacy Policy Statements http://www.oispp.ca.gov/consumer_privacy/pdf/infosharingdisclos.pdf

Colorado (http://www.colorado.gov/cybersecurity/) and Wisconsin (http://privacy.wi.gov/) also make available online privacy and data security resources.

In addition to the above resources, the Privacy and Data Security Group's Privacy Law Blog, www.proskaueronprivacy.com, provides updates on recent developments in privacy and data security law on a weekly basis.

While none of these resources can serve as a substitute for legal advice tailored to your business, they provide a wealth of practical information as a starting place for understanding the growing number of legal requirements imposed on companies in all industry sectors across the country. As part of its new flat-fee risk assessment package, the attorneys in Proskauer's Privacy and Data Security Group can provide your company with an overview of all privacy and data security laws potentially applicable to your business and help you assess your company's compliance obligations. You can find more information on our flat-fee offering here:

http://www.proskauer.com/hc_images/17128-PrivacyPackage.pdf

Footnote

1. See, e.g., ARIZ. REV. STAT. § 44-1373; ARK. CODE ANN. § 4-110-104(b); CAL. CIV. CODE §§ 1798.81, 1798.81.5, 1798.85; Conn. Public Act No. 08-167 and CONN. GEN. STAT. § 42-470; MD. COM. LAW CODE ANN. §§ 14-3402(a)(4) and 14-3503; Mass. Off. of Consumer Aff. and Bus. Reg., Standards for The Protection of Personal Information of Residents of the Commonwealth, 201 CMR 17.00 et. seq., as required by MASS. GEN. LAWS. ch. 93H, §2(a); Michigan Social Security Number Privacy Act 454 of 2004; NEV. REV. STAT. § 603A.210; OR. REV. STAT. §646A.622; R.I. STAT. § 11-49.2-2(2) and (3); TEX. BUS. & COM. CODE ANN. § 48.102(a) and § 501.001 et seq.; and UTAH CODE ANN. §13-44-201.

www.proskauer.com

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.