Amendment
Bill No. 0481
Amendment No. 417689
CHAMBER ACTION
Senate House
.
.
.






1Representative Waters offered the following:
2
3     Amendment
4     Remove lines 368-408 and insert:
5     (c)  The administrative sanctions for failure to notify
6provided in this subsection shall apply per breach and not per
7individual affected by the breach.
8     (d)  The administrative sanctions for failure to notify
9provided in this subsection shall not apply in the case of
10personal information in the custody of any governmental agency
11or subdivision, unless that governmental agency or subdivision
12has entered into a contract with a contractor or third-party
13administrator to provide governmental services. In such case,
14the contractor or third-party administrator shall be a person to
15whom the administrative sanctions provided in this subsection
16would apply, although such contractor or third-party
17administrator found in violation of the notification
18requirements provided in this subsection would not have an
19action for contribution or set-off available against the
20employing agency or subdivision.
21     (2)(a)  Any person who maintains computerized data that
22includes personal information on behalf of another business
23entity shall disclose to the business entity for which the
24information is maintained any breach of the security of the
25system as soon as practicable, but no later than 10 days
26following the determination, if the personal information was, or
27is reasonably believed to have been, acquired by an unauthorized
28person. The person who maintains the data on behalf of another
29business entity and the business entity on whose behalf the data
30is maintained may agree who will provide the notice, if any is
31required, as provided in paragraph (1)(a), provided only a
32single notice for each breach of the security of the system
33shall be required. If agreement regarding notification cannot be
34reached, the person who has the direct business relationship
35with the resident of this state shall be subject to the
36provisions of paragraph (1)(a).
37     (b)  Any person required to disclose to a business entity
38under paragraph (a) who fails to do so within 10 days after the
39determination of a breach or receipt of notification from law
40enforcement as provided in subsection (3) is liable for an
41administrative fine not to exceed $500,000, as follows:
42     1.  In the amount of $1,000 for each day the breach goes
43undisclosed for up to 30 days and, thereafter, $50,000 for each
4430-day period or portion thereof for up to 180 days.
45     2.  If disclosure is not made within 180 days, any person
46required to make disclosures under paragraph (a) who fails to do
47so is subject to an administrative fine of up to $500,000.
48     (c)  The administrative sanctions for nondisclosure
49provided in this subsection shall apply per breach and not per
50individual affected by the breach.
51     (d)  The administrative sanctions for nondisclosure


CODING: Words stricken are deletions; words underlined are additions.